Added by on 2011-06-20

Today we’re continuing our WiFi series with the example of cracking a WPA-Pre Shared Key. We started by diving into a PSK brute force with John the Ripper with a previously captured 4-way handshake. Sice we’ve taken a step back and covered promiscuous and monitor mode in terms of packet sniffing, and how MAC addresses come into play here. And now we’ll cover the ingredients needed for this recipe of passphrase cracking delightfulness.

Download HD Download MP4 Download WMV



As I just mentioned our wireless NIC is in monitor mode airmon-ng start wlan0. This is just one of 6 modes that our wireless NIC can operate in. The other 5 are: Master, Managed, Ad-hoc, Mesh and Repeater.

A wireless NIC in Master Mode is often referred to as an Access Point or Base Station. Typically it’s an embedded device with a proprietary OS or slim down Linux installation setup to provide network access to clients.

My WiFi Pineapple here for instance is an access point and I can see the NIC is in Master mode by issuing iwconfig ath0

Now if I come back to my localhost and issue lsusb I see I have my trusty Realtek 8187L installed. And if I check airdriver-ng loaded I see that it’s using the mac80211 driver. With that I know to use the iw command to check the cards capabilities. I just need to know the physical ID first, so running airmon-ng shows that it’s phy1. So now running iw phy phy1 info will show me all of its supported modes. Of course this is a lot of output. Typically I’ve been piping this output to more or less, but today I’ll pipe it to grep.

Grep will show me just what I ask for. In this instance I’m looking for the word “modes”. Issuing iw phy phy1 info | grep modes yields a match, but I’ll need to see a few lines past. For that I’ll tack on A8 to get 8 lines following. iw phy phy1 info | grep -A8 modes shows me that my card only supports the managed and monitor modes.

So that brings us to Managed:

Interfaces in Managed Mode, aka Infrastructure Mode, are considered clients or stations and are the devices connected to an access point. Your laptop, nintendo DS, iPhone, etc.

To connect to my open access point here I can issue iwconfig wlan1 mode managed then iwconfig wlan1 essid Pineapple. If I check iwconfig wlan1 I can see it has associated with the access point.

Ad-hoc, aka Peer-to-Peer, is a mode where wireless devices can communicate with each other without the need for a centralized base-station or access point. This can be useful for small groups of devices in close proximity, but the performance will decrease as the number of devices increases.

For all of the devices on the Ad-Hoc network to communicate with each other they must use the same ESSID. To setup my interface I’ll issue iwconfig wlan0 channel 1 essid myadhocnetwork mode ad-hoc

Now I can see here my cell is not associated, and that’s because this radio is the only one on this ad-hoc network. How sad? I’d tell wlan1 to join wlan0 so they can party together, but as we discovered just a moment ago wlan1 only supports the managed and monitor modes.

The next wireless mode is Mesh. You can think of a mesh as a sort of planned ad-hoc network. Mesh networks, or mesh clouds, are comprised of radios acting as routers, gateways and clients. In a mesh network nodes can communicate as long as they have at least one common connection. For example node A can talk to node C if they are both within range of node B. Likewise, if a node were to go down a mesh can heal itself by routing through other nodes in the network.

We could probably do an entire series on mesh networking, but suffice it to say for now that’s the jist.

And our final mode is Repeater. A wireless interface in repeater mode can be configured to connect to a wireless network, and repeat the signal. The practical application here is to extend the range of a single access-point.

And as always we value your feedback and suggestions. If you have a tip to share with me, email tips@hak5.org. And be sure to check out our sister show Hak5 for more great stuff, just like this. I’ll be there reminding you to trust your technolust.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

71 Comments

  • Thys 1 year ago

    realtek

  • Quiz Answer Mac address: 00:E0:4C
    Vendor: RealtekS REALTEK SEMICONDUCTOR CORP.

  • 00:E0:4C is Realtek Semiconductor Corp.

  • Josh 1 year ago

    Realtek Semiconductor Corp.

  • Brent 1 year ago

    Realtek

  • Rolando F. 1 year ago

    Realtek

  • George K. 1 year ago

    00-E0-4c is manufactured by:

    REALTEK SEMICONDUCTOR CORP.
    1F, NO. 11, INDUSTRY E. RD. IX
    SCIENCE-BASED INDUSTRIAL PARK
    HSINCHU 300
    TAIWAN, REPUBLIC OF CHINA

  • Doug Jobe 1 year ago

    REALTEK SEMICONDUCTOR CORP

  • Ryan 1 year ago

    Is the card a Realtek card?

  • Pablo 1 year ago

    Is this 00:e0:4c Realtek Semiconductor Corp.?

  • jbhttp://hak5.org/episodes/haktip-9 1 year ago

    The manufacturer is Realtek!

    00-E0-4C (hex) REALTEK SEMICONDUCTOR CORP.
    00E04C (base 16) REALTEK SEMICONDUCTOR CORP.
    1F, NO. 11, INDUSTRY E. RD. IX
    SCIENCE-BASED INDUSTRIAL PARK
    HSINCHU 300
    TAIWAN, REPUBLIC OF CHINA

    from http://standards.ieee.org/develop/regauth/oui/oui.txt

  • BErickson 1 year ago

    The of the chipset of 00:e0:4c is from Realtek

  • CanadianTaco 1 year ago

    00:E0:40 = realtek semiconductor corp.?

  • REALTEK SEMICONDUCTOR CORP.

    woopwoop

  • Kevin Fisk 1 year ago

    Darren,

    Saw your HakTip today. I like what you folks have done with the new season, and am enjoying more frequency technolust!

    The manufacturer with the OUI is Realtek Semiconductor Corp.

  • F4t4l 1 year ago

    realtek semiconductor corp.

  • Christian Lees 1 year ago

    00E04C = Realtek

  • mootz 1 year ago

    00:E0:4C = Intel
    BTW, the HakTips are great. short and sweet. keep them coming.

  • Glenn 1 year ago

    REALTEK SEMICONDUCTOR CORP.
    ^^

  • mootz 1 year ago

    00:E0:4C – did I say Intel? sorry, I meant Realtek Semiconductor Co.

  • Loughlin Gethins 1 year ago

    Realtek

  • Stephan 1 year ago

    It’s Realtek semiconductor corp.

  • Scotty 1 year ago

    The manufacturer of that MAC is REALTEK SEMICONDUCTOR CORP.

    YAY!

  • Israel Newham 1 year ago

    00:E0:4C belongs to realtek semiconductor corp

  • Doug Jobe 1 year ago

    The device is a REALTEK SEMICONDUCTOR CORP made product email for my address.

  • Denis 1 year ago

    the OUI of 00E04C is REALTEK SEMICONDUCTOR CORP.

  • Bryceten 1 year ago

    Realtek Semiconductor Corp.

  • rain 1 year ago

    realtek semiconductor corp

  • Khaosinc 1 year ago

    00:E0:4C belongs to realtek semiconductor corp.
    Hit me up HAK5!! ;)

  • Sebastian_Smith 1 year ago

    Realtek Semiconductor Corp.

  • Lostthegame 1 year ago

    is it realtek semiconductor corp?

  • blacktox 1 year ago

    REALTEK SEMICONDUCTOR CORP

  • Randy 1 year ago

    Hi Darren,

    The manufacture of the USB WiFi adapter is: REALTEK SEMICONDUCTOR CORP.

    I love the hack tips, keep them coming.
    Randy

  • Justwonthegame 1 year ago

    Is it realtek semiconductor corp.?

  • Richard Morse 1 year ago

    00:E0:4C realtek semiconductor corp.

  • Seth Minerva 1 year ago

    answer to question Vendor: RealtekS REALTEK SEMICONDUCTOR CORP.

  • AdrianGudus 1 year ago

    The manufacture of your USB Wireless device is: realtek semiconductor corp

  • Brian Salter 1 year ago

    The vendor is Realtek Semiconductor Corp.

  • The manufacturer for that OUI is REALTEK SEMICONDUCTOR CORP.

    Thanks for the haktip! I liked the run down!

    Jamis

  • Brandon Watts 1 year ago

    The manufacturer is realtek semiconductor corp.

  • Andrew 1 year ago

    Hi is it RealtekS REALTEK SEMICONDUCTOR CORP 00:e0:4c. Andrew

  • Josh 1 year ago

    RealtekS REALTEK SEMICONDUCTOR CORP.

  • BrianH 1 year ago

    Realtek Semiconductor Corp.

    It’s actually an Alfa adapter.

  • The device is manufactured by ALFA Network, it’s the AWUS036H
    The chip in the device is RTL8187L, manufactued by Realtek Semiconductor Corp.

  • Javier 1 year ago

    Frak! I guess i’m too late… 00:E0:4C is for Realtek, more specifically the chipset is an Realtek 8187L used in your Alfa Network USB Wireless Adapter AWUS036H

  • Gehric 1 year ago

    A bit slow of the mark but its Realtek

  • Javier 1 year ago

    Frak! I guess i’m too late… 00:E0:4C is for Realtek, more specifically the chipset is an Realtek 8187L used in this Alfa Network USB Wireless Adapter AWUS036H

  • Gehric 1 year ago

    Hiya Darren, could you do a little demonstration on the Wireless Repeater segment as i am keen to extend my wireless capabilities

    Your avid watcher Gehric

  • Javier 1 year ago

    Frak! I guess i’m too late… 00:E0:4C is for Realtek Semiconductor Corp, more specifically the chipset is an Realtek 8187L used in this Alfa Network USB Wireless Adapter AWUS036H

  • 00:E0:AC its from midsco, inc.

  • hack sig op 215 1 year ago

    I know it has been posted but
    it is
    00E04C realtek semiconductor corp.

    Keep up the great show and tips

  • nova5 1 year ago

    00-E0-AC (hex) MIDSCO, INC.
    00E0AC (base 16) MIDSCO, INC.
    710 ROUTE 46 EAST
    FAIRFIELD NJ 07004
    UNITED STATES

  • samy 1 year ago

    NEXWARE CORP.

  • Andy 1 year ago

    There is no correct answer for this question, as Darren is a hacker, and could have modified the MAC address with macchanger. :-D

  • Gohst 1 year ago

    It seems that everyone skipped the part of the video where Darren said “The first one to answer gets the adapter”

  • Lisiano 1 year ago

    OUI 00:E0:4C belongs to Realtek Semiconductor Corp.
    The device is an Alfa with the RTL8187 chipset.

    Btw. Love the show! Keep up the Technolust!

  • Scott Malugin 1 year ago

    realtek semiconductor corp.

  • MAC address 00E04C
    Company REALTEK SEMICONDUCTOR CORP.

  • last 1 year ago

    REALTEK SEMICONDUCTOR CORP.

  • Fox_Nakamori 1 year ago

    00:E0:4C = Realtek Semiconductor Corp, but the card itself is an Alfa

  • 53 70 65 65 64 47 65 65 6b 1 year ago

    01010010 01100101 01100001 01101100 01110100 01100101 01101011

  • MadNav 1 year ago

    Darren,
    Here’s a browser search provider for vendor/mac lookups that you and crue may find of interest;

    No cats were skinned in obtaining these results ;)
    Hoorah for Kerberos!

    GLHF & KUTGW

  • LatinDistro2012 1 year ago

    Vendor: RealtekS REALTEK SEMICONDUCTOR CORP.

  • Michael S. 1 year ago

    Prefix Vendor
    00E04C realtek semiconductor corp.

    although I knew what it was cause I have one too :D

  • chuxxsss 1 year ago

    Realtek as above. used in your AlFA I think.

  • 00:e0:4c = REALTEK SEMICONDUCTOR CORP.

  • Austin F 1 year ago

    You’re all wrong.
    What is Realtek Semiconductor Company.

    haha lol

  • quartz 1 year ago

    alfa

  • I Think Its Realtek

  • Dr.C 1 year ago

    Realtek RTL8187B Wireless 802.11b/g 54Mbp s USB 2.0 Network Adapter

  • Mir Imran 6 months ago

    Please
    I have installed backtrack 5 r3 through VM ware workstation 9.0 …but when i type airmon-ng
    it shows no interface..please help me by sending the info in my mail….that will be most kindness to me.