SecurityTubeBeta
Watch ... Learn ... Contribute
securitytube home
programming videos
tools videos
basics videos
fun
divider
upload video on SecurityTube
rss feed for SecurityTube

AirodumpNG Basics (Part I)

 

Airodump-NG is used to perform packet capture of raw 802.11 frames and is particularly suitable for collecting WEP IVs (Initialization Vectors) for the intent of using them with Aircrack-NG. Airodump-NG is a part of Aircrack-NG suite of products which are used for auditing wireless networks. These tools automate in between steps involved in WEP cracking, from setting the interface in monitor mode to sniffing packets, re-injecting packets, examining these packets against different attack vectors, cracking the WEP key and finally decrypting the WEP-encrypted packets. Airodump-NG automates the wireless packet sniffing, device detection and classification step.

Airodump-NG is not just packet capturing tool, but it also analyses IEEE 802.11 wireless packets and constructs Access Point and Client records. Airodump-NG splits the display screen in to two parts horizontally. The upper portion contains Access Points information while lower portion displays information related to Stations (Clients). Airodump- NG sniffs and parses the beacon packets for creating the AP record information. AP details include the MAC address of the access point, the channel on which the AP is operating, the maximum data rate supported, the encryption and cipher settings, signal strength received from the AP, number of beacon and data packets received for AP etc. These kinds of details are displayed for all the APs seen in capture time.

The association information and the packet statistics are important parts of Station information. The AP to which the station is associated is displayed against every station. For probing stations ‘not associated’ is displayed in the AP information. Number of data packets for the station along with signal strength and missing packet count is also displayed for every client. Every associated or non-associated station when sends targeted probe requests include SSID in the probe packets. This SSID is also recorded by the airodump and is displayed against every client.

This video explains the usage of Airosump-NG and talks about every column in AP and Station details.

Enable Javascript or Download Flash Playe if you see this!

 
Related Videos from: AircrackNG Suite of Wireless Tools
divider
You are Viewing this Video Now!
347 views
741 views
425 views
414 views

For cracking the WEP keys you can check out videos on Aireplay-ng and Airdecap-ng

Links

1. Airodump-NG download

2. AirodumpNG Linux Man page

 
Author
Amit-Vartak

Amit Vartak, 27 is working in wired and wireless security fields since last 3-4 years. His current area of interest includes IEEE 802.11 (Wi-Fi) suite of protocols, vulnerabilities in these protocols and countermeasure for those vulnerabilities. Working on cutting edge tools and technology always keeps him busy. He has contributed from concept level to final prototyping for the presentations in Defcon 2007 (The Emperor Has No Cloak - WEP Cloaking Exposed) and Toorcon 2007 (Caffe latte attack). He holds 2 patents with USPTO (current status: Patent Pending) and a few papers in IEEE journals on wireless protocol vulnerabilities. Prior to this, he was working on MEMS (Micro Electro Mechanical Systems) and has published a few papers in SPIE and ICMAT. (Yeah… kindda orthogonal fields… but technology really doesn’t limit the talent :) He did his masters in Electrical Engineering from one of the premier institutes in India, Indian Institute of Technology, Bombay (IIT-Bombay) and his under graduation, from University of Mumbai in Electronics and Telecommunication Engineering. He is currently working with AirTight Networks Inc. as a team lead in technology group since last 3 years.You can get in touch with him at amitcv[at]gmail[dot]com

 
©2007 Freak Labs