Jump to content

httpCRASH

Active Members
  • Posts

    107
  • Joined

  • Last visited

Posts posted by httpCRASH

  1. Hi,

    I have a couple of branded Netgear routers, i have direct console access, and can see they are running openwrt KAMIKAZE (7.09)

    but cant find the wireless conf, i know i can flash them with a standart openwrt image and get them running, but for the fun of it i would like to find the WPA2 key they have already, and see if they are all the same :D

    anyone who knows a way to display the key, or to locate the config file when its not in the standart location?

    EDIT: I have also tried to connect to one with reaver to try and get the info via WPS, but reaver wont associate, and it dossent look like win7 gets the WPS connection box either when trying to connect to it, but i know that WPS should be enable on them, because thats the way they are paired (they are used as a network brigde)

    79347194-6A14-44DA-8ADE-D056D7768BB1.JPG

    C0B742D0-857C-40EB-8C96-E6034C8DEBA5.JPG

    8132CED7-7E19-4F71-A80E-2E1159DB922E.JPG

  2. Hi,

    i have an app that is pulling data from a server, the first versions of the app sent all data unencrypted,

    so the fun part was to make the app connect to ones own server, feeding it responses that looked like it came from the real server, but had som different values.

    the newer versions of the app is using a token + salt, so you cant just replicate an original response..

    but someone told me that it was possible to change the program a little, so it would always generate the same token, and theirby making it possible to "clone" the original responses.

    i know nothing about modyfying compiled code, but would like to learn, so if anyone have any good pointers :)

    EDIT: lol, the topic text really got f#ยค% up, but no way to change it :D

  3. I think so, digip.

    bobbyb1980, let's keep it to a friendly tone, forum-wide.

    There would have be some sort of "alert" or abnormal activity to bring to your attention that someone may be on your wireless network. Unless you sit and watch your access point logs for anomalies, what you are saying just isn't practical.

    There are however very EXPENSIVE WiFi auditing solutions out there which will monitor for rouge access points, and do packet inspection all to a centralized server with monitor points scattered across your environment.

    if its "only" about intrusion prevention, and cost is not the biggest problem a CISCO MARS server maybe? :D

    would really like to get my hands on one ;)

  4. This is my version of a nice set up. As soon as i get time i will upload more pictures if anybody is interested. ON BOARD = 7.5 amp battery, 100 watt power inverter, Padded spots for computer and wifi pineapple, and a power hookup for wifi pineapple. And all this fits in a nice briefcase. If anyone else has any other good ideas let me know.

    nice,

    i was thinking to do something simular with antennas and on/off button on the outside, i have this old laptop briefcase im going to use...

    A433B414-89BC-464A-849E-8BBCF6A7CB37.JPG

    what battery are you using??

  5. I just tripped across this through my livejournal, and thought it was too cool not to share.

    <a href="http://www.reprap.org/bin/view/Main/WebHome" target="_blank">http://www.reprap.org/bin/view/Main/WebHome</a>

    The project is called Reprap. It's a plastic extrusion machine for creating 3 dimensional objects, but here's the perk; it can make most of (60%) its own parts, so you can run off additional copies. The criteria for the design required that all the other parts be easy to acquire in most places. I just wish I had the money and space to piece one together. Check it out! It's too cool for this kind of community to miss out on.

    Anyone here who has a Reprap?

    im about to start a build of one together with some friends, and looking for the plastic parts, and yes, i know we can find them on ebay, but i would rather buy them from another Hak5 follower, preferable from Europe (due to customs)

  6. hi just a couple of questions..

    (a)

    is it wise to wait for mk4 or just go buy a AP-51 or next best a Fonera ?

    (b)i read in the forums that u can put mk3 on a fonera mk2 is that right ?

    i only ask cos here in the UK ap-51's are hard to get , if i order from usa it will cost me more to get it posted than the actual ap-51 itself

    and from what i read a Fonera is next best to the ap-51 for a pineapple. im wondering when will the mk4 be out cos then it will be new hardware again

    wont it ? saving me buying old hardware so to speak

    thanx.

    Hi,

    If your from UK you can buy an AP51 from Germany like i did, im from Denmark, so also within EU, and have the same stupid customs rules as you, and as long as you buy from another EU country your good ;)

    http://shop.varia-store.com/product_info.php?info=p1396_ALFA-Network-AP51-802-11b-g-Mini-Wireless-Router.html

  7. Well I live in the Netherlands and the data sim prepaid pricing is just ridiculous. It's 0,33 eurocent per MB. Or you could go for a monthly payment and get 350MB's of data and pay 20 euros each month. So I don't think that gonna be an option :(

    damm, thats insane...

    in Denmark i can get a mobile phone subscription with 16GB data, 16 hours of calls, unlimited sms & mms, and free calls within the provider for about 40$ or 31 euro a month...

    and if i use more than 16GB of data they dont charge more,

    they just set the speed to 64 Kbit rest of that month instead of 4 Mbit.

  8. Console cables are serial cables, not ethernet, they just use the same plug.

    yes, i know its not the same thing, im a CISCO tech... but if all 4 cables used for 10/100 ethernet is connected in the RJ45 plug, would it then not be possible to make a "software network card" that is sending/reciving on the rigth connectors?..

    i see it with other stuff all the time, where people with great coding skills writes some code, and makes hardware do stuff its not supose to, and i admit that my coding skills is close to non-existing, i can mod shell and javascripts if they got errors, and thats pretty much it, thats why im trowing it out there :)

  9. i was thinking the same thoughts just with a jailbroken iphone/ipad instead, mostly because there is already 2 diffrent CISCO console cables for IOS wich uses the RJ45 connecter, so my guess is that someone with the rigth coding skills could use one of theese cables for ethernet instead of console?

    http://redpark.myshopify.com/products/console-cable

    and

    http://bestcelldist.com/apple_iphone_3g_serial_data_cable_flexserial.html with an DB9 to RJ45 rollover cable

  10. No your pineapple is not broken. Are you starting your computers up from cold boot? Try that and see. The other thing is, do you have another wifi that they remember (such as your home network) that may have a stronger signal strength? Even if its not stronger they may connect to that automatically. That is why I'm testing a deauth script that will automatically use my alfa realtek card to deauth everyone around it besides the pineapple - which, on all 6 of my tests here this morning have been successful in bringing the folks to my pineapple. So even if they don't connect to your pineapple automatically, you might want to consider actively preventing them from connecting to others. This would be the most effective way to get people on the pineapple, and keep them there.

    telot

    Can we see that deauth script? :P

  11. Caedis the first time I flashed my hack shop mk3 I had to set my static ip to 192.168.0.1

    for some reason that worked, and now if I flash it I have to set my static ip to 192.168.1.1 or 192.168.1.100

    it doesn't make since to me but I played around for an hour trying different ip address to use

    sorry in advance if this doesn't help.

    I also have to set my ip static to one in the 192.168.1.x range for the flash util to work correctly in win7, and disable my other ethernet adapter (witch i find weird, A's im not using that range anywhere else on my network)

  12. Well, it was worth a shot. Typically, I use a HP Procurve Switch and just port mirror to my laptop so I get both in and out that way, but it's almost always short term troubleshooting. I do like the copper taps Mr-Protocol! I'm thinking of just buying a usb to ethernet adapter and attempting to bridge two ethernet connections for both tap ports in Ubuntu. That would do the trick.

    Thanks!

    if you just need ethernet to USB, then i can recomend theese http://cgi.ebay.co.uk/ws/eBayISAPI.dll?ViewItem&item=170735483163

    got a couple of them, and they work out of the box with backtrack (and im sure other linux distros too)

    im using one when doing ICS to my pineapple, to connect both pineapple and lan to my laptop..

  13. Well, normally the victims do not know about the pineapple ui.

    But you are right of course.

    I could restrict access to ceartain IPs / mac addresses.

    I will give it some though.

    Sebkinne

    but then it should be mac a filter, or total optional.. because if you run the pinapple without any ICS, and only with phising sites, then you should still be able to connect to it from a mobile device...

    so i dont think that binding it to 172.16.42.42 would be the right way to go...

  14. Reflashing will have newest bug fixes and features. 10 minutes (mine only took like 5 minutes) for the latest and greatest updates, that is not so much to ask. By the time you ssh and do all the messing around you could have it done lol.

    I agree, and why only fix the login, and not get the rest of the new fixes.. that makes no sence B)

×
×
  • Create New...