RUSSIX - MODWLL

Procedures for Cracking Encryption

This Live Linux CD contains a number of tools to detect and to gain access to poorly secured WLANs.  Also included are a number of tools to highlight WLAN insecurities and some general network information gathering tools.  All tools start by typing their name at a shell prompt.  A number of tools have been scripted to start up with correctly configured cards etc, these tools begin with start-:


Also note that a dictionary file for password cracking can be found at /KNOPPIX/files/english.txt and .bin files for file2air are also found in /KNOPPIX/files


Wireless Network Detection

start-kismet               starts kismet in 802.11b/g mode - NOTE: although kismet will appear to start with the ipw2100 chipset the driver is not loaded and you will not pick up any stations
start-ath-a                 starts kismet with madwifi driver (Atheros chipset) set to scan 802.11a channels only
start-ath-abg              starts kismet with madwifi driver set to scan all 802.11 channels                                  
start-wellenreiter
airodump


WEP/WPA Cracking

start-airsnort

aircrack
cowpatty
wepattack
chopchop

LEAP Cracking

asleap
genkeys

Mapping

start-gps                starts a USB GPS device
conf-gps                confirms GPS device is communicating correctly
gpsmap

Kismet Tools

klc.pl                    combines kismet dump files
klv.pl                    produces HTML output from kismet dump files
warkizniz-linux      converts kismet files to netstumbler compatible input files

Packet Generation - used to deauthenticate clients to aid WEP/WPA cracking

aireplay
file2air
void11_hopper
void11_penetration

Networking Tools

nmap
start-ethereal

Other Wireless Tools

airmon.sh            puts WLAN cards into/out of monitor mode - also displays Driver used by WLAN card
airsnarf               MITM tool
apmode.sh          Software Access Point
fakeap.pl            Floods airspace with fake access points
start-hotspotter    MITM tool


Password Tools

john                   john the ripper
rcrack                rainbow crack
samcrack           dumps SysKey encrypted SAM file from Windows host
dsniff
mailsnarf
urlsnarf

Misc Tools

usb                    mounts and copies all generated dump files to USB device
erase                  carries out a single wipe of hda for privacy

webspy
802ether
airdecap
airforge


Procedures for Cracking Encryption

Procedures for obtaining the SSID of a cloaked network


Procedures for adding a client to a network with no connected clients


Procedures for cracking WEP when there are no clients attached to the network

Procedures for cracking WEP if little or no network traffic is being generated


Procedures for cracking WEP on a network with high traffic


Procedures for cracking WPA
-PSK

Procedures for cracking LEAP

MOVIES

WPA Cracking

WEP Cracking with no data being passed