PwnStar Posted May 27, 2009 Posted May 27, 2009 Normally hang out with the BT group aka “onryo” there. First post here. Hopefully not my last. I have a rouge AP with karma functionality that launches ettercap for packet capture and traffic manipulation. Most of the scripting is by DarkOperator aka BadKarma. Using a Alfa 500mW AWUS036H with a 21dBm yagi. OS is BT4 with mac80211 patched drivers. OK my problem. Looking in wireshark I am seeing that packets flowing though the tap at0 seem to swell over 1500 on MTU = bad. This seemed to be causing fragmentation and ICPM are/were leaking out. Yup you guessed it, servers drop the packets. KK fixed using iwconfig to set the MTU down to 1400 on wlan0 and the at0 tap and now using eth0 (cable for transparency and not a second wifi card). Dropped Moxie’s SSLstrip. The rouge AP looks more or less good in WS. Airbase-ng is doing what it should in P mode…lies to beacons about its essid. Anybody have a clue why EVERY rouge out there is so damn slow? Hitting remote_browser pages are fast but not passed quickly to eth0. This leads me to believe something is "bad" from the tap to et0. Has anybody ever got one working that is working smoothly? onryo Quote
miT Posted June 15, 2009 Posted June 15, 2009 Normally hang out with the BT group aka “onryo” there. First post here. Hopefully not my last. I have a rouge AP with karma functionality that launches ettercap for packet capture and traffic manipulation. Most of the scripting is by DarkOperator aka BadKarma. Using a Alfa 500mW AWUS036H with a 21dBm yagi. OS is BT4 with mac80211 patched drivers. OK my problem. Looking in wireshark I am seeing that packets flowing though the tap at0 seem to swell over 1500 on MTU = bad. This seemed to be causing fragmentation and ICPM are/were leaking out. Yup you guessed it, servers drop the packets. KK fixed using iwconfig to set the MTU down to 1400 on wlan0 and the at0 tap and now using eth0 (cable for transparency and not a second wifi card). Dropped Moxie’s SSLstrip. The rouge AP looks more or less good in WS. Airbase-ng is doing what it should in P mode…lies to beacons about its essid. Anybody have a clue why EVERY rouge out there is so damn slow? Hitting remote_browser pages are fast but not passed quickly to eth0. This leads me to believe something is "bad" from the tap to et0. Has anybody ever got one working that is working smoothly? onryo I'm in the midst of starting up a rouge setup and a sluggish performance on the victims end did cross my mind. Would love to see some input on this topic! Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.