{"id":1548,"date":"2017-03-08T19:28:59","date_gmt":"2017-03-08T10:28:59","guid":{"rendered":"http:\/\/matoken.org\/blog\/?p=1548"},"modified":"2017-03-08T19:35:33","modified_gmt":"2017-03-08T10:35:33","slug":"packet-capture-and-check-id-pass-of-pqi-air-pen","status":"publish","type":"post","link":"https:\/\/matoken.org\/blog\/2017\/03\/08\/packet-capture-and-check-id-pass-of-pqi-air-pen\/","title":{"rendered":"\u30d1\u30b1\u30c3\u30c8\u30ad\u30e3\u30d7\u30c1\u30e3\u3057\u3066PQI Air Pen\u306eID\/PASS\u3092\u8abf\u3079\u308b"},"content":{"rendered":"<p>\u9001\u6599\u8fbc\u307f500\u5186\u3060\u3063\u305f\u306e\u3067\u30dd\u30c1\u3063\u3066\u3057\u307e\u3044\u307e\u3057\u305f\uff0eX200\u306e\u30b8\u30e3\u30f3\u30af\u4ee5\u6765\u306e\u30b3\u306e\u624b\u306e\u8cb7\u3044\u7269\uff0e<\/p>\n<ul>\n<li><a href=\"http:\/\/hitoriblog.com\/?p=48779\" title=\"\u300cPQI Air Pen\u300dLinux\u642d\u8f09\u3067telnet\u3067\u304d\u308b\u30ef\u30a4\u30e4\u30ec\u30b9\u30a2\u30af\u30bb\u30b9\u30dd\u30a4\u30f3\u30c8\u304c500\u5186\">\u300cPQI Air Pen\u300dLinux\u642d\u8f09\u3067telnet\u3067\u304d\u308b\u30ef\u30a4\u30e4\u30ec\u30b9\u30a2\u30af\u30bb\u30b9\u30dd\u30a4\u30f3\u30c8\u304c500\u5186<\/a><\/li>\n<\/ul>\n<p>\u3061\u3087\u3063\u3068\u53e4\u3044\u3082\u306e\u3067\u3059\u304cftp\/telnet\u306a\u3069\u304c\u958b\u3044\u3066\u3066\u8272\u3005\u904a\u3079\u308b\u3088\u3046\u3067\u3059\uff0ePQI Air Card(\u521d\u4ee3)\u3082\u6301\u3063\u3066\u3044\u307e\u3059\u304c\uff0c\u3053\u308c\u306f\u30d0\u30c3\u30c6\u30ea\u30fc\u5185\u8535\u3067AP\u6a5f\u80fd\u306a\u3069\u3082\u3042\u308a\u307e\u3059\uff0e<\/p>\n<h2 id=\"_1\">\u3061\u3087\u3063\u3068\u53e9\u3044\u3066\u307f\u308b<\/h2>\n<p>dhcp\u306e\u63d0\u4f9b\u3055\u308c\u3066\u3044\u308b\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b1\u30fc\u30d6\u30eb\u3092\u7e4b\u3044\u3067\u96fb\u6e90\u3092\u308c\u3066\u3061\u3087\u3063\u3068\u53e9\u3044\u3066\u307f\u307e\u3059\uff0e<\/p>\n<p>\u307e\u305a\u306fdhcp pool\u306eip\u304b\u3089\u63a2\u3057\u3066\u307f\u307e\u3059\uff0e<\/p>\n<div class=\"codehilite\">\n<pre><span><\/span>$ sudo nmap -sP <span class=\"m\">192<\/span>.168.2.200-\r\nStarting Nmap <span class=\"m\">7<\/span>.40 <span class=\"o\">(<\/span> https:\/\/nmap.org <span class=\"o\">)<\/span> at <span class=\"m\">2017<\/span>-03-08 <span class=\"m\">11<\/span>:33 JST\r\n  :\r\nNmap scan report <span class=\"k\">for<\/span> <span class=\"m\">192<\/span>.168.2.214\r\nHost is up <span class=\"o\">(<\/span><span class=\"m\">0<\/span>.0012s latency<span class=\"o\">)<\/span>.\r\nMAC Address: <span class=\"m\">80<\/span>:DB:31:01:A4:B8 <span class=\"o\">(<\/span>Power Quotient International<span class=\"o\">)<\/span>\r\n  :\r\n<\/pre>\n<\/div>\n<p>192.168.2.214\u3067\u3057\u305f\uff0e\u30dd\u30fc\u30c8\u30b9\u30ad\u30e3\u30f3\u3057\u3066\u307f\u307e\u3059\uff0e<\/p>\n<div class=\"codehilite\">\n<pre><span><\/span>$ nmap -A <span class=\"m\">192<\/span>.168.2.214\r\n\r\nStarting Nmap <span class=\"m\">7<\/span>.40 <span class=\"o\">(<\/span> https:\/\/nmap.org <span class=\"o\">)<\/span> at <span class=\"m\">2017<\/span>-03-08 <span class=\"m\">11<\/span>:45 JST\r\nNmap scan report <span class=\"k\">for<\/span> <span class=\"m\">192<\/span>.168.2.214\r\nHost is up <span class=\"o\">(<\/span><span class=\"m\">0<\/span>.037s latency<span class=\"o\">)<\/span>.\r\nNot shown: <span class=\"m\">995<\/span> closed ports\r\nPORT     STATE SERVICE VERSION\r\n<span class=\"m\">21<\/span>\/tcp   open  ftp     vsftpd <span class=\"m\">2<\/span>.0.7\r\n<span class=\"m\">23<\/span>\/tcp   open  telnet  BusyBox telnetd <span class=\"m\">1<\/span>.0\r\n<span class=\"m\">53<\/span>\/tcp   open  domain  dnsmasq <span class=\"m\">2<\/span>.52\r\n<span class=\"p\">|<\/span> dns-nsid:\r\n<span class=\"p\">|<\/span>_  bind.version: dnsmasq-2.52\r\n<span class=\"m\">80<\/span>\/tcp   open  http    Brivo EdgeReader access control http interface\r\n<span class=\"p\">|<\/span>_http-title: PQI Air Pen\r\n<span class=\"m\">8080<\/span>\/tcp open  http    Mongoose httpd <span class=\"m\">3<\/span>.7 <span class=\"o\">(<\/span>directory listing<span class=\"o\">)<\/span>\r\n<span class=\"p\">|<\/span>_http-title: Index of \/\r\nService Info: OS: Unix<span class=\"p\">;<\/span> Device: security-misc\r\n\r\nService detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\r\nNmap <span class=\"k\">done<\/span>: <span class=\"m\">1<\/span> IP address <span class=\"o\">(<\/span><span class=\"m\">1<\/span> host up<span class=\"o\">)<\/span> scanned in <span class=\"m\">37<\/span>.14 seconds\r\n$ nmap -P <span class=\"m\">0<\/span>-65536 <span class=\"m\">192<\/span>.168.2.214\r\n\r\nStarting Nmap <span class=\"m\">7<\/span>.40 <span class=\"o\">(<\/span> https:\/\/nmap.org <span class=\"o\">)<\/span> at <span class=\"m\">2017<\/span>-03-08 <span class=\"m\">11<\/span>:37 JST\r\nNmap scan report <span class=\"k\">for<\/span> <span class=\"m\">192<\/span>.168.2.214\r\nHost is up <span class=\"o\">(<\/span><span class=\"m\">0<\/span>.035s latency<span class=\"o\">)<\/span>.\r\nNot shown: <span class=\"m\">995<\/span> closed ports\r\nPORT     STATE SERVICE\r\n<span class=\"m\">21<\/span>\/tcp   open  ftp\r\n<span class=\"m\">23<\/span>\/tcp   open  telnet\r\n<span class=\"m\">53<\/span>\/tcp   open  domain\r\n<span class=\"m\">80<\/span>\/tcp   open  http\r\n<span class=\"m\">8080<\/span>\/tcp open  http-proxy\r\n\r\nNmap <span class=\"k\">done<\/span>: <span class=\"m\">1<\/span> IP address <span class=\"o\">(<\/span><span class=\"m\">1<\/span> host up<span class=\"o\">)<\/span> scanned in <span class=\"m\">0<\/span>.61 seconds\r\n<\/pre>\n<\/div>\n<p>80\u756a\u30dd\u30fc\u30c8\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u3068\u8a8d\u8a3c\u7121\u3057\u3067\u8a2d\u5b9a\u753b\u9762\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u307e\u3057\u305f\uff0e8080\u756a\u306f\u30d5\u30a1\u30a4\u30eb\u306e\u30a2\u30af\u30bb\u30b9\u304c\u51fa\u6765\u307e\u3059\uff0e\u3053\u3061\u3089\u3082\u8a8d\u8a3c\u306a\u3057\uff0e<\/p>\n<p>ftp\/telnet\u306f\u6d41\u77f3\u306b\u672a\u8a8d\u8a3c\u3067\u306f\u99c4\u76ee\u306e\u3088\u3046\u3067\u3059\uff0e<\/p>\n<div class=\"codehilite\">\n<pre><span><\/span>$ nc <span class=\"m\">192<\/span>.168.2.214 <span class=\"m\">21<\/span>\r\n<span class=\"m\">220<\/span> <span class=\"o\">(<\/span>vsFTPd <span class=\"m\">2<\/span>.0.7<span class=\"o\">)<\/span>\r\nUSER anonimouse\r\n<span class=\"m\">331<\/span> Please specify the password.\r\nPASS matoken@gmail.com\r\n<span class=\"m\">530<\/span> Login incorrect.\r\n$ nc <span class=\"m\">192<\/span>.168.2.214 <span class=\"m\">23<\/span>\r\n\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd!\ufffd\ufffd\ufffd\ufffd          <span class=\"o\">(<\/span>none<span class=\"o\">)<\/span> login: \r\n\r\n<span class=\"o\">(<\/span>none<span class=\"o\">)<\/span> login: \r\n<\/pre>\n<\/div>\n<p>\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u4e2d\u306b\u5165\u3063\u3066\u3044\u305f\u30de\u30cb\u30e5\u30a2\u30eb\u306b\u306f\u7279\u306bID\/PASS\u307d\u3044\u3082\u306e\u306e\u60c5\u5831\u306f\u3042\u308a\u307e\u305b\u3093\uff0e<br \/>\n\u3067\u3082\u30b9\u30de\u30fc\u30c8\u30d5\u30a9\u30f3\u7528\u30a2\u30d7\u30ea\u3067\u30d5\u30a1\u30a4\u30eb\u306e\u3084\u308a\u53d6\u308a\u304c\u53ef\u80fd\u306a\u3088\u3046\u306a\u306e\u3067\u305d\u306e\u30d1\u30b1\u30c3\u30c8\u3092\u8997\u3051\u3070\u308f\u304b\u308a\u305d\u3046\u3067\u3059\uff0e<br \/>\n\uff03\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3067\u691c\u7d22\u3059\u308b\u3068ID\/PASS\u306f\u898b\u3064\u304b\u308b\u306e\u3067\u3059\u304c\uff0c\u305b\u3063\u304b\u304f\u306a\u306e\u3067?<br \/>\n\uff03\uff03\u305d\u3046\u3044\u3048\u3070PENTAX KP\u306e\u30a2\u30d7\u30ea\u306e\u30d1\u30b1\u30c3\u30c8\u3082\u8997\u3044\u3066\u307f\u305f\u3044\uff0e<\/p>\n<h2 id=\"_2\">\u30d1\u30b1\u30c3\u30c8\u30ad\u30e3\u30d7\u30c1\u30e3\u3057\u3066\u307f\u308b<\/h2>\n<p>\u9069\u5f53\u306aWi-Fi\u306e\u4f7f\u3048\u308bPC\u3092\u7528\u610f\u3057\u3066\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30ab\u30fc\u30c9\u3092monitor mode\u306b\u3057\u3066\u30d1\u30b1\u30c3\u30c8\u30ad\u30e3\u30d7\u30c1\u30e3\u3092\u3057\u307e\u3059\uff0e<br \/>\n\u4eca\u56de\u306f\u3053\u3093\u306a\u611f\u3058\uff0e<\/p>\n<ul>\n<li>PC : LENOVO Thinkpad X200<\/li>\n<li>NIC : Intel Corporation PRO\/Wireless 5100 AGN<\/li>\n<li>OS : Ubuntu 17.04 amd64<\/li>\n<li>Driver : iwldvm, iwlwifi<\/li>\n<\/ul>\n<h3 id=\"aqi-air-pen\">AQI Air Pen\u306e\u7121\u7dda\u30c1\u30e3\u30f3\u30cd\u30eb\u3092\u78ba\u8a8d\u3057\u3066\u304a\u304f<\/h3>\n<ul>\n<li>\u3053\u3053\u3067\u306f11<\/li>\n<\/ul>\n<div class=\"codehilite\">\n<pre><span><\/span>$ nmcli d wifi <span class=\"p\">|<\/span> egrep <span class=\"s1\">&#39;SSID|PQI&#39;<\/span>\r\n*  SSID                \u30e2\u30fc\u30c9    CHAN  \u30ec\u30fc\u30c8     \u4fe1\u53f7  \u30d0\u30fc  \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \r\n   PQI Air Pen         \u30a4\u30f3\u30d5\u30e9  <span class=\"m\">11<\/span>    <span class=\"m\">54<\/span> Mbit\/s  <span class=\"m\">100<\/span>   \u2582\u2584\u2586\u2588  --           \r\n<\/pre>\n<\/div>\n<div class=\"codehilite\">\n<pre><span><\/span>$ sudo \/sbin\/iwlist wls1 scanning <span class=\"p\">|<\/span> grep -B <span class=\"m\">5<\/span> <span class=\"s2\">&quot;PQI Air Pen&quot;<\/span>\r\n          Cell <span class=\"m\">09<\/span> - Address: <span class=\"m\">80<\/span>:DB:31:01:A4:B7\r\n                    Channel:11\r\n                    Frequency:2.462 GHz <span class=\"o\">(<\/span>Channel <span class=\"m\">11<\/span><span class=\"o\">)<\/span>\r\n                    <span class=\"nv\">Quality<\/span><span class=\"o\">=<\/span><span class=\"m\">70<\/span>\/70  Signal <span class=\"nv\">level<\/span><span class=\"o\">=<\/span>-28 dBm  \r\n                    Encryption key:off\r\n                    ESSID:<span class=\"s2\">&quot;PQI Air Pen&quot;<\/span>\r\n<\/pre>\n<\/div>\n<h3 id=\"phy\">phy\u3068\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u306e\u78ba\u8a8d<\/h3>\n<div class=\"codehilite\">\n<pre><span><\/span>$ \/sbin\/iw dev\r\nphy#0\r\n        Interface wls1\r\n                ifindex <span class=\"m\">8<\/span>\r\n                wdev 0x3\r\n                addr <span class=\"m\">00<\/span>:22:fa:33:45:6a\r\n                <span class=\"nb\">type<\/span> managed\r\n                channel <span class=\"m\">8<\/span> <span class=\"o\">(<\/span><span class=\"m\">2447<\/span> MHz<span class=\"o\">)<\/span>, width: <span class=\"m\">20<\/span> MHz, center1: <span class=\"m\">2447<\/span> MHz\r\n                txpower <span class=\"m\">15<\/span>.00 dBm\r\n<\/pre>\n<\/div>\n<h3 id=\"monitor-mode\">\u30c7\u30d0\u30a4\u30b9\u304cmonitor mode\u306b\u306a\u308c\u308b\u304b\u78ba\u8a8d\u3059\u308b<\/h3>\n<p>monitor\u306b\u306a\u308c\u306a\u3044\u5834\u5408\u306f\u30c9\u30e9\u30a4\u30d0\u3092\u5909\u66f4\u3059\u308b\u3068\u5bfe\u5fdc\u3067\u304d\u308b\u5834\u5408\u3082\u3042\u308a\u307e\u3059\uff0e<\/p>\n<div class=\"codehilite\">\n<pre><span><\/span>$ \/sbin\/iw phy phy0 info <span class=\"p\">|<\/span> lv\r\n  :\r\n        Supported interface modes:\r\n                 * IBSS\r\n                 * managed\r\n                 * monitor\r\n  :\r\n        software interface modes <span class=\"o\">(<\/span>can always be added<span class=\"o\">)<\/span>:\r\n                 * monitor\r\n<\/pre>\n<\/div>\n<h3 id=\"monitor-mode_1\">monitor mode\u306e\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u3092\u4f5c\u308b<\/h3>\n<div class=\"codehilite\">\n<pre><span><\/span>$ sudo iw phy phy0 interface add mon0 <span class=\"nb\">type<\/span> monitor\r\n<\/pre>\n<\/div>\n<h3 id=\"managed-mode\">managed mode\u306e\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u3092\u524a\u9664\u3059\u308b<\/h3>\n<div class=\"codehilite\">\n<pre><span><\/span>$ sudo iw dev wls1 del\r\n<\/pre>\n<\/div>\n<h3 id=\"monitor-modemon0up\">monitor mode\u306e\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9(mon0)\u3092Up\u3059\u308b<\/h3>\n<div class=\"codehilite\">\n<pre><span><\/span>$ sudo ifconfig mon0 up\r\n<\/pre>\n<\/div>\n<h3 id=\"monitor-mode_2\">monitor mode\u306e\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u306e\u7121\u7dda\u30c1\u30e3\u30f3\u30cd\u30eb\u3092\u8a2d\u5b9a\u3059\u308b<\/h3>\n<p>\u4e0a\u306e\u65b9\u306711\u30c1\u30e3\u30f3\u30cd\u30eb\u3060\u3063\u305f\u306e\u30672462\u306b\u8a2d\u5b9a\u3057\u307e\u3059\uff0e<\/p>\n<div class=\"codehilite\">\n<pre><span><\/span>$ sudo iw dev mon0 <span class=\"nb\">set<\/span> freq <span class=\"m\">2462<\/span>\r\n<\/pre>\n<\/div>\n<p>\u4ed6\u306e\u30c1\u30e3\u30f3\u30cd\u30eb\u306f\u3053\u3093\u306a\u611f\u3058<\/p>\n<blockquote>\n<p>ch1 : 2412<br \/>\nch2 : 2417<br \/>\nch3 : 2422<br \/>\nch4 : 2427<br \/>\nch5 : 2432<br \/>\nch6 : 2437<br \/>\nch7 : 2442<br \/>\nch8 : 2447<br \/>\nch9 : 2452<br \/>\nch10 : 2457<br \/>\nch11 : 2462<br \/>\nch12 : 2467<br \/>\nch13 : 2472<br \/>\nch14 : 2484  <\/p>\n<\/blockquote>\n<h3 id=\"_3\">\u78ba\u8a8d<\/h3>\n<div class=\"codehilite\">\n<pre><span><\/span>$ \/sbin\/iwconfig mon0\r\n<\/pre>\n<\/div>\n<h2 id=\"_4\">\u30d1\u30b1\u30c3\u30c8\u30ad\u30e3\u30d7\u30c1\u30e3\u3092\u3057\u306a\u304c\u3089\u30b9\u30de\u30fc\u30c8\u30d5\u30a9\u30f3\u516c\u5f0f\u30a2\u30d7\u30ea\u3092\u4f7f\u3063\u3066\u307f\u308b<\/h2>\n<p>\u203b\u30d1\u30b1\u30c3\u30c8\u304c\u305f\u304f\u3055\u3093\u98db\u3093\u3067\u3044\u308b\u3088\u3046\u306a\u5834\u5408\u306f\u30d5\u30a3\u30eb\u30bf\u3092\u66f8\u3044\u305f\u308aWireshark\u306a\u3069\u3092\u4f7f\u3046\u3068\u4fbf\u5229\u3067\u3059\uff0e<\/p>\n<p>\u30d1\u30b1\u30c3\u30c8\u3092\u30ad\u30e3\u30d7\u30c1\u30e3\u3057\u306a\u304c\u3089\u30b9\u30de\u30fc\u30c8\u30d5\u30a9\u30f3\u3067PQi Air Pen\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306b\u7e4b\u3044\u3060\u72b6\u614b\u3067\u516c\u5f0f\u30a2\u30d7\u30ea\u3092\u8d77\u52d5\u3057\u3066\u66f4\u65b0\u306a\u3069\u3092\u884c\u3044\u307e\u3059\uff0e<\/p>\n<div class=\"codehilite\">\n<pre><span><\/span>$ sudo tcpdump -i mon0 -n -A -s0\r\n    :\r\n<span class=\"m\">01<\/span>:26:05.670158 <span class=\"m\">1<\/span>.0 Mb\/s <span class=\"m\">2462<\/span> MHz 11b -34dBm signal antenna <span class=\"m\">3<\/span> IP <span class=\"m\">192<\/span>.168.200.1.21 &gt; <span class=\"m\">192<\/span>.168.200.102.50504: Flags <span class=\"o\">[<\/span>P.<span class=\"o\">]<\/span>, seq <span class=\"m\">1<\/span>:21, ack <span class=\"m\">0<\/span>, win <span class=\"m\">2896<\/span>, options <span class=\"o\">[<\/span>nop,nop,TS val <span class=\"m\">194874<\/span> ecr <span class=\"m\">35416851<\/span><span class=\"o\">]<\/span>, length <span class=\"m\">20<\/span>: FTP: <span class=\"m\">220<\/span> <span class=\"o\">(<\/span>vsFTPd <span class=\"m\">2<\/span>.0.7<span class=\"o\">)<\/span>\r\nE..Hv.@.@..-.......f...H.<span class=\"o\">[<\/span>.....<span class=\"p\">;<\/span>...P.P.....\r\n...:..k.220 <span class=\"o\">(<\/span>vsFTPd <span class=\"m\">2<\/span>.0.7<span class=\"o\">)<\/span>\r\n...e\r\n    :\r\n<span class=\"m\">01<\/span>:26:05.791087 <span class=\"m\">2462<\/span> MHz 11n -39dBm signal antenna <span class=\"m\">3<\/span> <span class=\"m\">72<\/span>.2 Mb\/s MCS <span class=\"m\">7<\/span> <span class=\"m\">20<\/span> MHz s\r\nhort GI mixed IP <span class=\"m\">192<\/span>.168.200.102.50396 &gt; <span class=\"m\">192<\/span>.168.200.1.21: Flags <span class=\"o\">[<\/span>P.<span class=\"o\">]<\/span>, seq <span class=\"m\">1<\/span>:\r\n<span class=\"m\">12<\/span>, ack <span class=\"m\">20<\/span>, win <span class=\"m\">115<\/span>, options <span class=\"o\">[<\/span>nop,nop,TS val <span class=\"m\">35410347<\/span> ecr <span class=\"m\">178581<\/span><span class=\"o\">]<\/span>, length <span class=\"m\">11<\/span>:\r\n FTP: USER root\r\nE..?O.@.@..z...f.............wu....s    ......\r\n..Q.....USER root\r\n...2\r\n    :\r\n<span class=\"m\">01<\/span>:26:05.792197 <span class=\"m\">2462<\/span> MHz 11n -41dBm signal antenna <span class=\"m\">3<\/span> <span class=\"m\">72<\/span>.2 Mb\/s MCS <span class=\"m\">7<\/span> <span class=\"m\">20<\/span> MHz s\r\nhort GI mixed IP <span class=\"m\">192<\/span>.168.200.1.21 &gt; <span class=\"m\">192<\/span>.168.200.102.50396: Flags <span class=\"o\">[<\/span>P.<span class=\"o\">]<\/span>, seq <span class=\"m\">20<\/span>\r\n:54, ack <span class=\"m\">12<\/span>, win <span class=\"m\">2896<\/span>, options <span class=\"o\">[<\/span>nop,nop,TS val <span class=\"m\">178613<\/span> ecr <span class=\"m\">35410347<\/span><span class=\"o\">]<\/span>, length <span class=\"m\">34<\/span>: FTP: <span class=\"m\">331<\/span> Please specify the password.\r\nE..V.b@.@.<span class=\"se\">\\.<\/span>.......f.....wu........P<span class=\"sb\">`<\/span>......\r\n......Q.331 Please specify the password.\r\nu<span class=\"sb\">`<\/span>a.\r\n    :\r\n<span class=\"m\">01<\/span>:27:11.238673 <span class=\"m\">2462<\/span> MHz 11n -40dBm signal antenna <span class=\"m\">3<\/span> <span class=\"m\">72<\/span>.2 Mb\/s MCS <span class=\"m\">7<\/span> <span class=\"m\">20<\/span> MHz short GI mixed IP <span class=\"m\">192<\/span>.168.200.102.50504 &gt; <span class=\"m\">192<\/span>.168.200.1.21: Flags <span class=\"o\">[<\/span>P.<span class=\"o\">]<\/span>, seq <span class=\"m\">11<\/span>:23, ack <span class=\"m\">55<\/span>, win <span class=\"m\">115<\/span>, options <span class=\"o\">[<\/span>nop,nop,TS val <span class=\"m\">35416878<\/span> ecr <span class=\"m\">194908<\/span><span class=\"o\">]<\/span>, length <span class=\"m\">12<\/span>: FTP: PASS pqiap\r\nE..@.@@.@.\/....f.....H.....F.<span class=\"o\">[<\/span>.<span class=\"p\">&amp;<\/span>...s.......\r\n..k....<span class=\"se\">\\P<\/span>ASS pqiap\r\n.5.Z\r\n<\/pre>\n<\/div>\n<p>FTP\u63a5\u7d9a\u3067<code>root:pqiap<\/code>\u306e\u3088\u3046\u3067\u3059\uff0e<\/p>\n<h3 id=\"_5\">\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u3092\u623b\u3059<\/h3>\n<div class=\"codehilite\">\n<pre><span><\/span>sudo iw dev mon0 del\r\nsudo iw phy phy0 interface add wls1 type managed\r\n<\/pre>\n<\/div>\n<h2 id=\"ftp\">ftp\u63a5\u7d9a\u3092\u8a66\u3057\u3066\u307f\u308b<\/h2>\n<div class=\"codehilite\">\n<pre><span><\/span>$ nc <span class=\"m\">192<\/span>.168.200.1 <span class=\"m\">21<\/span>\r\n<span class=\"m\">220<\/span> <span class=\"o\">(<\/span>vsFTPd <span class=\"m\">2<\/span>.0.7<span class=\"o\">)<\/span>\r\nuser root\r\n<span class=\"m\">331<\/span> Please specify the password.\r\npass pqiap\r\n<span class=\"m\">230<\/span> Login successful.\r\n<\/pre>\n<\/div>\n<h2 id=\"telnet\">telnet\u3092\u8a66\u3057\u3066\u307f\u308b<\/h2>\n<div class=\"codehilite\">\n<pre><span><\/span>$ nc <span class=\"m\">192<\/span>.168.200.1 <span class=\"m\">23<\/span>\r\n\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd!\ufffd\ufffd\ufffd\ufffd<span class=\"o\">(<\/span>none<span class=\"o\">)<\/span> login: \r\n\r\n<span class=\"o\">(<\/span>none<span class=\"o\">)<\/span> login: root\r\nroot\r\nPassword: pqiap\r\n\r\n\r\n\r\nBusyBox v1.01 <span class=\"o\">(<\/span><span class=\"m\">2013<\/span>.01.03-08:27+0000<span class=\"o\">)<\/span> Built-in shell <span class=\"o\">(<\/span>ash<span class=\"o\">)<\/span>\r\nEnter <span class=\"s1\">&#39;help&#39;<\/span> <span class=\"k\">for<\/span> a list of built-in commands.\r\n\r\n~ <span class=\"c1\"># uname -a<\/span>\r\nuname -a\r\nLinux <span class=\"o\">(<\/span>none<span class=\"o\">)<\/span> <span class=\"m\">2<\/span>.6.31.AirPen_V0.1.22-g5eca71a <span class=\"c1\">#319 Thu Jan 3 16:27:02 CST 2013 mips unknown<\/span>\r\n<\/pre>\n<\/div>\n<p>\u3068\u3044\u3046\u3053\u3068\u3067\u4e2d\u306b\u5165\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f :)<\/p>\n<p><iframe style=\"width:120px;height:240px;\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\" frameborder=\"0\" src=\"\/\/rcm-fe.amazon-adsystem.com\/e\/cm?lt1=_blank&#038;bc1=000000&#038;IS2=1&#038;bg1=FFFFFF&#038;fc1=000000&#038;lc1=0000FF&#038;t=matokensmeme-22&#038;o=9&#038;p=8&#038;l=as4&#038;m=amazon&#038;f=ifr&#038;ref=as_ss_li_til&#038;asins=B00BNAST0O&#038;linkId=968bee59571b4cc0ddf0d4aa3bfc07a4\"><\/iframe><iframe style=\"width:120px;height:240px;\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\" frameborder=\"0\" src=\"\/\/rcm-fe.amazon-adsystem.com\/e\/cm?lt1=_blank&#038;bc1=000000&#038;IS2=1&#038;bg1=FFFFFF&#038;fc1=000000&#038;lc1=0000FF&#038;t=matokensmeme-22&#038;o=9&#038;p=8&#038;l=as4&#038;m=amazon&#038;f=ifr&#038;ref=as_ss_li_til&#038;asins=B06WLGMNGH&#038;linkId=b1c14afd87ee7d29083e994d708937bb\"><\/iframe><iframe style=\"width:120px;height:240px;\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\" frameborder=\"0\" src=\"\/\/rcm-fe.amazon-adsystem.com\/e\/cm?lt1=_blank&#038;bc1=000000&#038;IS2=1&#038;bg1=FFFFFF&#038;fc1=000000&#038;lc1=0000FF&#038;t=matokensmeme-22&#038;o=9&#038;p=8&#038;l=as4&#038;m=amazon&#038;f=ifr&#038;ref=as_ss_li_til&#038;asins=4864940029&#038;linkId=9dd7e4bd7bda22597012913ad879c70f\"><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u9001\u6599\u8fbc\u307f500\u5186\u3060\u3063\u305f\u306e\u3067\u30dd\u30c1\u3063\u3066\u3057\u307e\u3044\u307e\u3057\u305f\uff0eX200\u306e\u30b8\u30e3\u30f3\u30af\u4ee5\u6765\u306e\u30b3\u306e\u624b\u306e\u8cb7\u3044\u7269\uff0e \u300cPQI Air Pen\u300dLinux\u642d\u8f09\u3067telnet\u3067\u304d\u308b\u30ef\u30a4\u30e4\u30ec\u30b9\u30a2\u30af\u30bb\u30b9\u30dd\u30a4\u30f3\u30c8\u304c500\u5186 \u3061\u3087\u3063\u3068\u53e4\u3044\u3082\u306e\u3067\u3059\u304cftp\/t [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"webmentions_disabled_pings":false,"webmentions_disabled":false,"activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":4,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"","footnotes":""},"categories":[6],"tags":[206,204,205],"class_list":["post-1548","post","type-post","status-publish","format-standard","hentry","category-linux","tag-packet-capture","tag-pqi-air-pen","tag-tcpdump"],"_links":{"self":[{"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/posts\/1548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/comments?post=1548"}],"version-history":[{"count":0,"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/posts\/1548\/revisions"}],"wp:attachment":[{"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/media?parent=1548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/categories?post=1548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/tags?post=1548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}