<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>非礼勿视 &#187; SpoonWep2</title>
	<atom:link href="http://felixqu.com/tag/spoonwep2/feed/" rel="self" type="application/rss+xml" />
	<link>http://felixqu.com</link>
	<description>电脑 网络 技术 科技 体育 理财 包罗万象</description>
	<lastBuildDate>Sat, 04 Sep 2010 05:59:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Ubuntu 注入破解 WEP</title>
		<link>http://felixqu.com/2010/03/19/ubuntu-spoonwep2/</link>
		<comments>http://felixqu.com/2010/03/19/ubuntu-spoonwep2/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 02:49:08 +0000</pubDate>
		<dc:creator>飞力</dc:creator>
				<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[aircrack-ng]]></category>
		<category><![CDATA[BT3]]></category>
		<category><![CDATA[BT4]]></category>
		<category><![CDATA[KUbuntu]]></category>
		<category><![CDATA[SpoonWep2]]></category>
		<category><![CDATA[SpoonWpa]]></category>
		<category><![CDATA[WEP]]></category>
		<category><![CDATA[WPA SpoonWep]]></category>

		<guid isPermaLink="false">http://felixqu.com/?p=790</guid>
		<description><![CDATA[由于虚拟机下的 BT3、BT4 不支持内置无线网卡，以前一直没尝试过这个，现在入手了 USB 无线网卡，心理开始痒痒了。 BT3、BT4应用面非常狭窄，我手上正好有个 KUbuntu 9.10 的虚拟机，何不在 Ubuntu... ]]></description>
			<content:encoded><![CDATA[<p>由于虚拟机下的 <a href="http://felixqu.com/tag/bt3/" class="st_tag internal_tag" rel="tag" title="Posts tagged with BT3">BT3</a>、<a href="http://felixqu.com/tag/bt4/" class="st_tag internal_tag" rel="tag" title="Posts tagged with BT4">BT4</a> 不支持内置无线网卡，以前一直没尝试过这个，现在入手了 USB 无线网卡，心理开始痒痒了。</p>
<p><a href="http://felixqu.com/tag/bt3/" class="st_tag internal_tag" rel="tag" title="Posts tagged with BT3">BT3</a>、<a href="http://felixqu.com/tag/bt4/" class="st_tag internal_tag" rel="tag" title="Posts tagged with BT4">BT4</a>应用面非常狭窄，我手上正好有个 <a href="http://felixqu.com/tag/kubuntu/" class="st_tag internal_tag" rel="tag" title="Posts tagged with KUbuntu">KUbuntu</a> 9.10 的虚拟机，何不在 <a href="http://felixqu.com/tag/ubuntu/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Ubuntu">Ubuntu</a> 下试试呢。</p>
<p>网上看到，<a href="http://felixqu.com/tag/ubuntu/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Ubuntu">Ubuntu</a> 下要支持 ar9170 芯片的 WN111 v2 网卡，需要更新 firmware，http://wireless.kernel.org/en/users/Drivers/ar9170，但是我查了下 md5 , 发现 <a href="http://felixqu.com/tag/kubuntu/" class="st_tag internal_tag" rel="tag" title="Posts tagged with KUbuntu">KUbuntu</a>/<a href="http://felixqu.com/tag/ubuntu/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Ubuntu">Ubuntu</a> 9.10 已经自带了这个最新的 firmware，这一步骤就可以省略了。如果你是 9.04 或更早版本，请自行检查。</p>
<p>第一步，打开 Konsole，输入：</p>
<p>sudo apt-get install <a href="http://felixqu.com/tag/aircrack-ng/" class="st_tag internal_tag" rel="tag" title="Posts tagged with aircrack-ng">aircrack-ng</a></p>
<p>这是破解 <a href="http://felixqu.com/tag/wep/" class="st_tag internal_tag" rel="tag" title="Posts tagged with WEP">WEP</a>、WPA的工具包，Spoonwep 和 Spoonwap 其实只是 GUI 而已。</p>
<p>喜欢新立得的朋友也可以在新立得里安装。</p>
<p><span id="more-790"></span></p>
<p>第二部安装 JRE，在 Konsole 里输入：</p>
<p>sudo apt-get install sun-java6-jre</p>
<p>然后下载 SpoonWep and <a href="http://felixqu.com/tag/spoonwpa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWpa">SpoonWpa</a> for <a href="http://felixqu.com/tag/ubuntu/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Ubuntu">Ubuntu</a></p>
<p><a href="http://felixqu.com/wp-content/uploads/2010/03/spoonwep-wpa-modified-ubuntu-1120.zip">spoonwep-wpa-modified-ubuntu-1120</a></p>
<p>这是某牛人移植到 <a href="http://felixqu.com/tag/ubuntu/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Ubuntu">Ubuntu</a> 上的 <a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">SpoonWep2</a> 安装包，里面还包括了 <a href="http://felixqu.com/tag/spoonwpa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWpa">SpoonWpa</a>。</p>
<p>装好以后，先把 WN111 插入，让 <a href="http://felixqu.com/tag/ubuntu/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Ubuntu">Ubuntu</a> 先认出来，现在版本的 <a href="http://felixqu.com/tag/ubuntu/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Ubuntu">Ubuntu</a> 会自己打开无线网络，由于我们的工作是抓包破解，因此需要把无线网络关闭（顶部系统工具栏最右边）。</p>
<p>之后在 Konsole 输入：</p>
<p>sudo spoonwep</p>
<p>就会弹出 SpoonWep 窗口了。</p>
<div id="attachment_792" class="wp-caption alignnone" style="width: 538px"><a href="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-01.png" rel="lightbox[790]"><img class="size-full wp-image-792" title="SpoonWep2" src="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-01.png" alt="SpoonWep2" width="528" height="437" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">SpoonWep2</a></p></div>
<p>在第一个界面里选择 WLAN0，Driver 选择 Normal 即可，MODE 选择 Unknow Victim，点击 NEXT。</p>
<div id="attachment_794" class="wp-caption alignnone" style="width: 538px"><a href="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-02.png" rel="lightbox[790]"><img class="size-full wp-image-794" title="SpoonWep2 扫描界面" src="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-02.png" alt="SpoonWep2 扫描界面" width="528" height="437" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">SpoonWep2</a> 扫描界面</p></div>
<p>然后就会出现上图这个扫描界面。点击右上角的 LAUNCH，就会扫描目前的无线 AP 啦，见下图，当然只能搜到<a href="http://felixqu.com/tag/wep/" class="st_tag internal_tag" rel="tag" title="Posts tagged with WEP">WEP</a>加密的AP。</p>
<div id="attachment_795" class="wp-caption alignnone" style="width: 538px"><a href="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-03.png" rel="lightbox[790]"><img class="size-full wp-image-795" title="SpoonWep2扫描结果" src="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-03.png" alt="SpoonWep2扫描结果" width="528" height="437" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">SpoonWep2</a>扫描结果</p></div>
<p>选中一个 DATA 多的 ESSID，DATA 越多越容易破解。下面会出现和这个 AP 有通信的客户端，见下图</p>
<div id="attachment_796" class="wp-caption alignnone" style="width: 538px"><a href="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-04.png" rel="lightbox[790]"><img class="size-full wp-image-796" title="SpoonWep2选择AP" src="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-04.png" alt="SpoonWep2选择AP" width="528" height="437" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">SpoonWep2</a>选择AP</p></div>
<p>同样道理，选择一个 Packets 多的。然后点 Selection OK，会出现下面的界面。</p>
<div id="attachment_797" class="wp-caption alignnone" style="width: 538px"><a href="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-05.png" rel="lightbox[790]"><img class="size-full wp-image-797" title="SpoonWep2 准备攻击" src="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-05.png" alt="SpoonWep2 准备攻击" width="528" height="437" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">SpoonWep2</a> 准备攻击</p></div>
<p>直接点左上角的 LAUNCH 按钮。</p>
<p>如果看到像下图那样，很多的 ASSOCIATING，就点击 ABORT放弃，然后再点 LAUNCH重试。</p>
<div id="attachment_798" class="wp-caption alignnone" style="width: 538px"><a href="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-06.png" rel="lightbox[790]"><img class="size-full wp-image-798" title="SpoonWep2 攻击失败" src="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-06.png" alt="SpoonWep2 攻击失败" width="528" height="437" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">SpoonWep2</a> 攻击失败</p></div>
<p>直到看到这样的信息</p>
<div id="attachment_799" class="wp-caption alignnone" style="width: 538px"><a href="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-07.png" rel="lightbox[790]"><img class="size-full wp-image-799" title="SpoonWep2攻击开始" src="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-07.png" alt="SpoonWep2攻击开始" width="528" height="437" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">SpoonWep2</a>攻击开始</p></div>
<p>这时候，旁边会出来一个 SpoonWep Dump 窗口，注意看窗口里的 #Data 这一列，如果像下图这样，等了很久一直是0，就说明注入攻击失败，就需要你在攻击面板换一种攻击方式（就是第一个下拉框），或者换一个客户端，或者过一会儿再试试。</p>
<div id="attachment_800" class="wp-caption alignnone" style="width: 502px"><a href="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-08.png" rel="lightbox[790]"><img class="size-full wp-image-800" title="SpoonWep2 DUMP窗口" src="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-08.png" alt="SpoonWep2 DUMP窗口" width="492" height="345" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">SpoonWep2</a> DUMP窗口</p></div>
<p>下图是换用 P0841 Replay 方式注入攻击。</p>
<div id="attachment_806" class="wp-caption alignnone" style="width: 535px"><a href="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-09.png" rel="lightbox[790]"><img class="size-full wp-image-806" title="SpoonWep2 攻击2" src="http://felixqu.com/wp-content/uploads/2010/03/SpoonWep2-09.png" alt="SpoonWep2 攻击2" width="525" height="443" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">SpoonWep2</a> 攻击2</p></div>
<p>下图是换用第四种攻击方式</p>
<div id="attachment_809" class="wp-caption alignnone" style="width: 535px"><a href="http://felixqu.com/wp-content/uploads/2010/03/Spoonwep2-10.png" rel="lightbox[790]"><img class="size-full wp-image-809" title="Spoonwep2攻击4" src="http://felixqu.com/wp-content/uploads/2010/03/Spoonwep2-10.png" alt="Spoonwep2攻击4" width="525" height="445" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">Spoonwep2</a>攻击4</p></div>
<p>如果看到 Data 数值有上升，如下图</p>
<div id="attachment_811" class="wp-caption alignnone" style="width: 499px"><a href="http://felixqu.com/wp-content/uploads/2010/03/Spoonwep2-11.png" rel="lightbox[790]"><img class="size-full wp-image-811" title="Spoonwep2 DUMP窗口" src="http://felixqu.com/wp-content/uploads/2010/03/Spoonwep2-11.png" alt="Spoonwep2 DUMP窗口" width="489" height="350" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">Spoonwep2</a> DUMP窗口</p></div>
<p>你就可以去冲杯咖啡，找个片子看看，快则几分钟，慢则半小时不到就会查到 <a href="http://felixqu.com/tag/wep/" class="st_tag internal_tag" rel="tag" title="Posts tagged with WEP">Wep</a> 密码了，如下图：</p>
<div id="attachment_812" class="wp-caption alignnone" style="width: 537px"><a href="http://felixqu.com/wp-content/uploads/2010/03/Spoonwep2-12.png" rel="lightbox[790]"><img class="size-full wp-image-812" title="Spoonwep2攻击成功" src="http://felixqu.com/wp-content/uploads/2010/03/Spoonwep2-12.png" alt="Spoonwep2攻击成功" width="527" height="444" /></a><p class="wp-caption-text"><a href="http://felixqu.com/tag/spoonwep2/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SpoonWep2">Spoonwep2</a>攻击成功</p></div>
<p>注意密码是不包括中间的冒号的。</p>
<p>本文参考了 <a href="http://www.anywlan.com/BBS/" target="_blank">anywlan</a> 论坛的很多文章，谢谢前人的经验。</p>
<h3  class="related_post_title">无视其他</h3><ul class="related_post"><li><a href="http://felixqu.com/2007/12/21/kubuntu804-not-lts/" title="KUbuntu 8.04 将不是 LTS">KUbuntu 8.04 将不是 LTS</a></li><li><a href="http://felixqu.com/2007/12/02/ubuntu-hardy-alpha-1/" title="Ubuntu 8.04 Alpha 1">Ubuntu 8.04 Alpha 1</a></li><li><a href="http://felixqu.com/2010/03/25/ubuntu-10-04-beta1-preview-1/" title="Ubuntu 10.04 beta1 尝鲜——初步体验">Ubuntu 10.04 beta1 尝鲜——初步体验</a></li><li><a href="http://felixqu.com/2010/03/25/ubuntu-10-04-beta1-preview-setup/" title="Ubuntu 10.04 beta1 尝鲜——安装">Ubuntu 10.04 beta1 尝鲜——安装</a></li><li><a href="http://felixqu.com/2010/03/23/ubuntu-spoonwap/" title="Ubuntu 注入破解 WAP 尝试">Ubuntu 注入破解 WAP 尝试</a></li><li><a href="http://felixqu.com/2008/11/02/ubuntu-904-schedule/" title="Ubuntu 9.04 开发进程">Ubuntu 9.04 开发进程</a></li><li><a href="http://felixqu.com/2008/10/31/ubuntu-810-release/" title="Ubuntu 8.10 发布">Ubuntu 8.10 发布</a></li><li><a href="http://felixqu.com/2008/10/28/ubuntu-810-coming-soon/" title="Ubuntu 8.10 即将发布">Ubuntu 8.10 即将发布</a></li><li><a href="http://felixqu.com/2008/04/03/ubuntu-804-will-release-on-24th-april/" title="【转贴】Ubuntu 8.04 将于 4 月 24 日发布">【转贴】Ubuntu 8.04 将于 4 月 24 日发布</a></li><li><a href="http://felixqu.com/2007/10/29/azureus-for-ubuntu/" title="Ubuntu上使用最新的Azureus 3">Ubuntu上使用最新的Azureus 3</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://felixqu.com/2010/03/19/ubuntu-spoonwep2/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
