Today we’re continuing our WiFi series with the example of cracking a WPA-Pre Shared Key. We started by diving into a PSK brute force with John the Ripper with a previously captured 4-way handshake. Sice we’ve taken a step back and covered promiscuous and monitor mode in terms of packet sniffing, and how MAC addresses come into play here. And now we’ll cover the ingredients needed for this recipe of passphrase cracking delightfulness.
Download HD Download MP4 Download WMV
As I just mentioned our wireless NIC is in monitor mode airmon-ng start wlan0. This is just one of 6 modes that our wireless NIC can operate in. The other 5 are: Master, Managed, Ad-hoc, Mesh and Repeater.
A wireless NIC in Master Mode is often referred to as an Access Point or Base Station. Typically it’s an embedded device with a proprietary OS or slim down Linux installation setup to provide network access to clients.
My WiFi Pineapple here for instance is an access point and I can see the NIC is in Master mode by issuing iwconfig ath0
Now if I come back to my localhost and issue lsusb I see I have my trusty Realtek 8187L installed. And if I check airdriver-ng loaded I see that it’s using the mac80211 driver. With that I know to use the iw command to check the cards capabilities. I just need to know the physical ID first, so running airmon-ng shows that it’s phy1. So now running iw phy phy1 info will show me all of its supported modes. Of course this is a lot of output. Typically I’ve been piping this output to more or less, but today I’ll pipe it to grep.
Grep will show me just what I ask for. In this instance I’m looking for the word “modes”. Issuing iw phy phy1 info | grep modes yields a match, but I’ll need to see a few lines past. For that I’ll tack on A8 to get 8 lines following. iw phy phy1 info | grep -A8 modes shows me that my card only supports the managed and monitor modes.
So that brings us to Managed:
Interfaces in Managed Mode, aka Infrastructure Mode, are considered clients or stations and are the devices connected to an access point. Your laptop, nintendo DS, iPhone, etc.
To connect to my open access point here I can issue iwconfig wlan1 mode managed then iwconfig wlan1 essid Pineapple. If I check iwconfig wlan1 I can see it has associated with the access point.
Ad-hoc, aka Peer-to-Peer, is a mode where wireless devices can communicate with each other without the need for a centralized base-station or access point. This can be useful for small groups of devices in close proximity, but the performance will decrease as the number of devices increases.
For all of the devices on the Ad-Hoc network to communicate with each other they must use the same ESSID. To setup my interface I’ll issue iwconfig wlan0 channel 1 essid myadhocnetwork mode ad-hoc
Now I can see here my cell is not associated, and that’s because this radio is the only one on this ad-hoc network. How sad? I’d tell wlan1 to join wlan0 so they can party together, but as we discovered just a moment ago wlan1 only supports the managed and monitor modes.
The next wireless mode is Mesh. You can think of a mesh as a sort of planned ad-hoc network. Mesh networks, or mesh clouds, are comprised of radios acting as routers, gateways and clients. In a mesh network nodes can communicate as long as they have at least one common connection. For example node A can talk to node C if they are both within range of node B. Likewise, if a node were to go down a mesh can heal itself by routing through other nodes in the network.
We could probably do an entire series on mesh networking, but suffice it to say for now that’s the jist.
And our final mode is Repeater. A wireless interface in repeater mode can be configured to connect to a wireless network, and repeat the signal. The practical application here is to extend the range of a single access-point.
And as always we value your feedback and suggestions. If you have a tip to share with me, email tips@hak5.org. And be sure to check out our sister show Hak5 for more great stuff, just like this. I’ll be there reminding you to trust your technolust.




realtek
Quiz Answer Mac address: 00:E0:4C
Vendor: RealtekS REALTEK SEMICONDUCTOR CORP.
00:E0:4C is Realtek Semiconductor Corp.
Realtek Semiconductor Corp.
Realtek
Realtek
00-E0-4c is manufactured by:
REALTEK SEMICONDUCTOR CORP.
1F, NO. 11, INDUSTRY E. RD. IX
SCIENCE-BASED INDUSTRIAL PARK
HSINCHU 300
TAIWAN, REPUBLIC OF CHINA
REALTEK SEMICONDUCTOR CORP
Is the card a Realtek card?
Is this 00:e0:4c Realtek Semiconductor Corp.?
The manufacturer is Realtek!
00-E0-4C (hex) REALTEK SEMICONDUCTOR CORP.
00E04C (base 16) REALTEK SEMICONDUCTOR CORP.
1F, NO. 11, INDUSTRY E. RD. IX
SCIENCE-BASED INDUSTRIAL PARK
HSINCHU 300
TAIWAN, REPUBLIC OF CHINA
from http://standards.ieee.org/develop/regauth/oui/oui.txt
The of the chipset of 00:e0:4c is from Realtek
00:E0:40 = realtek semiconductor corp.?
REALTEK SEMICONDUCTOR CORP.
woopwoop
Darren,
Saw your HakTip today. I like what you folks have done with the new season, and am enjoying more frequency technolust!
The manufacturer with the OUI is Realtek Semiconductor Corp.
realtek semiconductor corp.
00E04C = Realtek
00:E0:4C = Intel
BTW, the HakTips are great. short and sweet. keep them coming.
REALTEK SEMICONDUCTOR CORP.
^^
00:E0:4C – did I say Intel? sorry, I meant Realtek Semiconductor Co.
Realtek
It’s Realtek semiconductor corp.
The manufacturer of that MAC is REALTEK SEMICONDUCTOR CORP.
YAY!
00:E0:4C belongs to realtek semiconductor corp
The device is a REALTEK SEMICONDUCTOR CORP made product email for my address.
the OUI of 00E04C is REALTEK SEMICONDUCTOR CORP.
Realtek Semiconductor Corp.
realtek semiconductor corp
00:E0:4C belongs to realtek semiconductor corp.
Hit me up HAK5!!
Realtek Semiconductor Corp.
is it realtek semiconductor corp?
REALTEK SEMICONDUCTOR CORP
Hi Darren,
The manufacture of the USB WiFi adapter is: REALTEK SEMICONDUCTOR CORP.
I love the hack tips, keep them coming.
Randy
Is it realtek semiconductor corp.?
00:E0:4C realtek semiconductor corp.
answer to question Vendor: RealtekS REALTEK SEMICONDUCTOR CORP.
The manufacture of your USB Wireless device is: realtek semiconductor corp
The vendor is Realtek Semiconductor Corp.
The manufacturer for that OUI is REALTEK SEMICONDUCTOR CORP.
Thanks for the haktip! I liked the run down!
Jamis
The manufacturer is realtek semiconductor corp.
Hi is it RealtekS REALTEK SEMICONDUCTOR CORP 00:e0:4c. Andrew
RealtekS REALTEK SEMICONDUCTOR CORP.
Realtek Semiconductor Corp.
It’s actually an Alfa adapter.
The device is manufactured by ALFA Network, it’s the AWUS036H
The chip in the device is RTL8187L, manufactued by Realtek Semiconductor Corp.
Frak! I guess i’m too late… 00:E0:4C is for Realtek, more specifically the chipset is an Realtek 8187L used in your Alfa Network USB Wireless Adapter AWUS036H
A bit slow of the mark but its Realtek
Frak! I guess i’m too late… 00:E0:4C is for Realtek, more specifically the chipset is an Realtek 8187L used in this Alfa Network USB Wireless Adapter AWUS036H
Hiya Darren, could you do a little demonstration on the Wireless Repeater segment as i am keen to extend my wireless capabilities
Your avid watcher Gehric
Frak! I guess i’m too late… 00:E0:4C is for Realtek Semiconductor Corp, more specifically the chipset is an Realtek 8187L used in this Alfa Network USB Wireless Adapter AWUS036H
00:E0:AC its from midsco, inc.
I know it has been posted but
it is
00E04C realtek semiconductor corp.
Keep up the great show and tips
00-E0-AC (hex) MIDSCO, INC.
00E0AC (base 16) MIDSCO, INC.
710 ROUTE 46 EAST
FAIRFIELD NJ 07004
UNITED STATES
NEXWARE CORP.
There is no correct answer for this question, as Darren is a hacker, and could have modified the MAC address with macchanger.
It seems that everyone skipped the part of the video where Darren said “The first one to answer gets the adapter”
OUI 00:E0:4C belongs to Realtek Semiconductor Corp.
The device is an Alfa with the RTL8187 chipset.
Btw. Love the show! Keep up the Technolust!
realtek semiconductor corp.
MAC address 00E04C
Company REALTEK SEMICONDUCTOR CORP.
REALTEK SEMICONDUCTOR CORP.
00:E0:4C = Realtek Semiconductor Corp, but the card itself is an Alfa
01010010 01100101 01100001 01101100 01110100 01100101 01101011
Darren,
Here’s a browser search provider for vendor/mac lookups that you and crue may find of interest;
No cats were skinned in obtaining these results
Hoorah for Kerberos!
GLHF & KUTGW
Vendor: RealtekS REALTEK SEMICONDUCTOR CORP.
Prefix Vendor
00E04C realtek semiconductor corp.
although I knew what it was cause I have one too
Realtek as above. used in your AlFA I think.
00:e0:4c = REALTEK SEMICONDUCTOR CORP.
You’re all wrong.
What is Realtek Semiconductor Company.
haha lol
alfa
I Think Its Realtek
Realtek RTL8187B Wireless 802.11b/g 54Mbp s USB 2.0 Network Adapter
Please
I have installed backtrack 5 r3 through VM ware workstation 9.0 …but when i type airmon-ng
it shows no interface..please help me by sending the info in my mail….that will be most kindness to me.