osdir.com
mailing list archive

Subject: Question on sniffing with scapy - msg#00008

List: security.scapy.general

Date: Prev Next Index Thread: Prev Next Index
I have forwarded the question here since I think I can seek more help because currently I'm not using scapy for wireless stuffs.

---------- Forwarded message ----------
From: Tobias Kuehne <Tobias.Kuehne@xxxxxxxxxxxxxxxxxxxxxxxx>
Date: Dec 7, 2005 5:59 PM
Subject: Question on sniffing with scapy
To: geek00l@xxxxxxxxx

Hi!

I just found your blog http://geek00l.blogspot.com/ and read some posts
on scapy.

I've got a problem with it. I am trying to reinject 802.11 frames, using
an Atheros Card and the patched madwifi driver on Linux 2.4.31.

Also I'm sniffing the traffic, to see what it is reinjecting on another
machine with a prism 2 card.

The problem is: on every packet I sniff with scapy with

sniff(iface="ath0raw", filter="ether dst 00:09:5b:12:3d:5b", count = 1)

it adds 4 more bytes at the end and I don't know why... any idea?
An example follows.

Original:

10:11: 32.771600 DA:00:09:5b:12:3d:5b (oui Unknown) SA:00:11:24:23:cd:2f
(oui Unknown) BSSID:76:27:f2:22:ae:bc (oui Unknown) Data IV:bdef7a Pad 0
KeyID 0
         0x0000:  0840 d500 0009 5b12 3d5b 0011 2423 cd2f
         0x0010:  7627 f222 aebc f0ed 7aef bd00 3979 02c8
         0x0020:  1c98 dfd8 435e b7ab 4b5c f65f 02fc d945
         0x0030:  7937 732e 44f0 a986 60dc 4160 23ce 113d
         0x0040:  9f04 d899 31b2 ede0 620e 4e1f b9e8 a9b9
         0x0050:  401b 3669 f690 8900 976e da02 c3c5 a176
         0x0060:  fef6 1fc9 f506 e5d9 c2c5 1648 6901 6825
         0x0070:  d2dc 92ec ddb3 c526 666e d4dd

hexdump() of the packet that was sniffed with scapy:

08 40 D5 00 00 09 5B 12 3D 5B 00 11 24 23 CD 2F
76 27 F2 22 AE BC F0 ED 7A EF BD 00 39 79 02 C8
1C 98 DF D8 43 5E B7 AB 4B 5C F6 5F 02 FC D9 45
79 37 73 2E 44 F0 A9 86 60 DC 41 60 23 CE 11 3D
9F 04 D8 99 31 B2 ED E0 62 0E 4E 1F B9 E8 A9 B9
40 1B 36 69 F6 90 89 00 97 6E DA 02 C3 C5 A1 76
FE F6 1F C9 F5 06 E5 D9 C2 C5 16 48 69 01 68 25
D2 DC 92 EC DD B3 C5 26 66 6E D4 DD A6 49 80 2B


Best regards from Germany,

  Tobias.


--
Best Regards,

Lee
Was this page helpful?
Yes No
Thread at a glance:

Previous Message by Date: click to view message preview

0EM Software

TOP 10 NEW TITLES  ON SALE NOW!   1 Office Pro 2003   2 Adobe Photoshop 9.0   3 Windows XP Pro   4 Adobe Acrobat 7 Pro   5 Flash MX 2004   6 Corel Draw 12   7 Norton Antivirus 2005   8 Windows 2003 Server   9 Alias Maya 6 Wavefrt   10 Adobe Illustrator 11   See more by this manufacturer     Microsoft     Symantec     Adobe Microsoft Office Professional Edition 2003    by Microsoft ListPrice: $550.00 OurPrice: $69.95 YouSave: $480.05 ( 87%) Availability: Available for INSTANT download! Sales Rank: #1 Average Customer Review: (based on 44 reviews) Microsoft Windows XP Professional    by Microsoft ListP rice: $200.00 OurPrice: $49.95 YouSave: $150.05 ( 75%) Availability: Available for INSTANT download! Sales Rank: #2 Average Customer Review: (based on 38 reviews) Adobe Photoshop CS2 V 9.0    by Adobe ListPrice: $599.00 OurPrice: $69.95 YouSave: $529.05 ( 88%) Availability: Available for INSTANT download! Sales Rank: #3 Average Customer Review: (based on 33 reviews)

Next Message by Date: click to view message preview

Re: Question on sniffing with scapy

On Wed, 7 Dec 2005, Lee Chin Sheng wrote: I have forwarded the question here since I think I can seek more help because currently I'm not using scapy for wireless stuffs. ---------- Forwarded message ---------- From: Tobias Kuehne <Tobias.Kuehne@xxxxxxxxxxxxxxxxxxxxxxxx> Date: Dec 7, 2005 5:59 PM Subject: Question on sniffing with scapy To: geek00l@xxxxxxxxx Hi! I just found your blog http://geek00l.blogspot.com/ and read some posts on scapy. I've got a problem with it. I am trying to reinject 802.11 frames, using an Atheros Card and the patched madwifi driver on Linux 2.4.31. Also I'm sniffing the traffic, to see what it is reinjecting on another machine with a prism 2 card. The problem is: on every packet I sniff with scapy with sniff(iface="ath0raw", filter="ether dst 00:09:5b:12:3d:5b", count = 1) it adds 4 more bytes at the end and I don't know why... any idea? It seems to be the ICV field, that tcpdump discard. As I don't have the WEP key, I can't decrypt the packet and check nothing is missing. -- Philippe Biondi <phil@ secdev.org> SecDev.org Computer Security/R&D http://www.secdev.org PGP KeyID:3D9A43E2 FingerPrint:C40A772533730E39330DC0985EE8FF5F3D9A43E2 --------------------------------------------------------------------- Desinscription: envoyez un message a: scapy.ml-unsubscribe@xxxxxxxxxx Pour obtenir de l'aide, ecrivez a: scapy.ml-help@xxxxxxxxxx

Previous Message by Thread: click to view message preview

0EM Software

TOP 10 NEW TITLES  ON SALE NOW!   1 Office Pro 2003   2 Adobe Photoshop 9.0   3 Windows XP Pro   4 Adobe Acrobat 7 Pro   5 Flash MX 2004   6 Corel Draw 12   7 Norton Antivirus 2005   8 Windows 2003 Server   9 Alias Maya 6 Wavefrt   10 Adobe Illustrator 11   See more by this manufacturer     Microsoft     Symantec     Adobe Microsoft Office Professional Edition 2003    by Microsoft ListPrice: $550.00 OurPrice: $69.95 YouSave: $480.05 ( 87%) Availability: Available for INSTANT download! Sales Rank: #1 Average Customer Review: (based on 44 reviews) Microsoft Windows XP Professional    by Microsoft ListP rice: $200.00 OurPrice: $49.95 YouSave: $150.05 ( 75%) Availability: Available for INSTANT download! Sales Rank: #2 Average Customer Review: (based on 38 reviews) Adobe Photoshop CS2 V 9.0    by Adobe ListPrice: $599.00 OurPrice: $69.95 YouSave: $529.05 ( 88%) Availability: Available for INSTANT download! Sales Rank: #3 Average Customer Review: (based on 33 reviews)

Next Message by Thread: click to view message preview

Re: Question on sniffing with scapy

On Wed, 7 Dec 2005, Lee Chin Sheng wrote: I have forwarded the question here since I think I can seek more help because currently I'm not using scapy for wireless stuffs. ---------- Forwarded message ---------- From: Tobias Kuehne <Tobias.Kuehne@xxxxxxxxxxxxxxxxxxxxxxxx> Date: Dec 7, 2005 5:59 PM Subject: Question on sniffing with scapy To: geek00l@xxxxxxxxx Hi! I just found your blog http://geek00l.blogspot.com/ and read some posts on scapy. I've got a problem with it. I am trying to reinject 802.11 frames, using an Atheros Card and the patched madwifi driver on Linux 2.4.31. Also I'm sniffing the traffic, to see what it is reinjecting on another machine with a prism 2 card. The problem is: on every packet I sniff with scapy with sniff(iface="ath0raw", filter="ether dst 00:09:5b:12:3d:5b", count = 1) it adds 4 more bytes at the end and I don't know why... any idea? It seems to be the ICV field, that tcpdump discard. As I don't have the WEP key, I can't decrypt the packet and check nothing is missing. -- Philippe Biondi <phil@ secdev.org> SecDev.org Computer Security/R&D http://www.secdev.org PGP KeyID:3D9A43E2 FingerPrint:C40A772533730E39330DC0985EE8FF5F3D9A43E2 --------------------------------------------------------------------- Desinscription: envoyez un message a: scapy.ml-unsubscribe@xxxxxxxxxx Pour obtenir de l'aide, ecrivez a: scapy.ml-help@xxxxxxxxxx
Sign up for updates to this mailing list. email:
Loading Comments...
Home | News | Patents | Sitemap | FAQ | advertise

Advertising by