Zune Forum
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
February 09, 2010, 09:06:07 AM


Login with username, password and session length


Pages: [1] 2 3   Go Down
  Print  
Author Topic: Zune WIFI Packet Capture  (Read 14891 times)
0 Members and 1 Guest are viewing this topic.
Albinotux
Grunt of the ZS Army
*
Offline Offline

Posts: 8



View Profile
« on: November 15, 2006, 07:26:02 PM »

Attached is a packet I was able to sniff when I tried looking for other Zunes. As you can see my zune name and current song are being sent.

The attached can be opened with Wireshark (http://www.wireshark.org/)

After you download the packet, change the extension to .pcap

Code:
Ôò¡          (   i   QYm8²H à   Ã    P   Pò€  úuT²)®OÜåð3–=    d 2   ‚„‹–Œ˜° * 2$H`l
 ÃÅ¾ Pò%Sõ   p’ Albinotux                        Tu
 úuTHawthorne Heights 'Apparently Hover Boards Don't Work On Water (As "A Day In The Life")'       
Logged
100rubs
King of Zunes
****
Offline Offline

Posts: 140



View Profile
« Reply #1 on: December 06, 2006, 04:47:00 PM »

I analyzed your packet and also some of my own packets that I was able to sniff. Both our mac addresses start with 00:17:fa which according to this website belongs to Microsoft Corporation.

   http://coffer.com/mac_find/

I wish I had 2 zunes so I could see which packets are sent while exchanging files. Anybody out there with access to two Zunes? I used the demo version of this program:

   http://www.tamos.com/products/commwifi/
Logged
equate975
Full Zune
**
Offline Offline

Posts: 10


View Profile
« Reply #2 on: December 06, 2006, 08:36:08 PM »

I have been playing with wifi too, I am not sure how the zune filters out other zunes to connect with. Do you think they would just go for a MS MAC? Seems to easy...

An initial broadcast packet would be a lot more helpful I think, I haven't gotten around to capturing any yet though
Logged
Albinotux
Grunt of the ZS Army
*
Offline Offline

Posts: 8



View Profile
« Reply #3 on: December 06, 2006, 08:46:57 PM »

I have been playing with wifi too, I am not sure how the zune filters out other zunes to connect with. Do you think they would just go for a MS MAC? Seems to easy...

An initial broadcast packet would be a lot more helpful I think, I haven't gotten around to capturing any yet though

That is what is attached to this thread.
Logged
Bohlio
Zune Sovereign Ruler
*****
Offline Offline

Posts: 2109



View Profile
« Reply #4 on: December 06, 2006, 09:02:19 PM »

wow this is completely foreign to me Cheesy
but no need to explain, just keep doing what your doing and figure out something cool with the Wi-Fi! Tongue
Logged

http://www.pandora.com/ - Discover your Music

Bailouts = Fail
Phlag
Full Zune
**
Offline Offline

Posts: 10


View Profile
« Reply #5 on: December 08, 2006, 05:45:50 PM »

I messed around with Wifi sniffing with a friend, and we found out a couple basic things. Song and picture transfers are done with WPA encryption, so we weren't able to analyze that traffic - and no one probably will be able to until someone modifies the Zune's firmware to not do file transfers with WPA, or until the WPA key is figured out. And, assuming that Microsoft is using a complex key (which they surely are), cracking it is probably unfeasible. But all Zunes must be using the same key, and maybe it's possible to analyze the contents of the harddrive or firmware to derive it.

We were able to capture and edit packets that the Zune broadcasts to populate the "Community list", and re-send them from our computers. So, I captured the packet he was sending, edited both his user name and the song he was listening to, turned off his Zune, and sent the modified packet to my Zune. And, easy as that that, apparently the user "Bill Gates" was listening to "Abcdefghijlkmnop."

Edit: I just read the thread on Zuneboards, and holy God Mys Videl is arrogant. And wrong, as far as I can tell. A google search for "implied MAC address" yielded NO relevant search results, and it's very clear from sniffing the Wifi traffic that it has a MAC address.


Edit 2: More developments. My friend and I have basically broken down the Zune broadcast packet.
0x0000   50 00 A2 00 00 17 FA 00-2E EF 00 17 FA 03 B2 CF   P.¢...ú..ï..ú.²Ï
0x0010   AA 08 A1 C6 87 B4 30 02-DE 1F BF 00 00 00 00 00   Âª.¡Æ‡´0.Þ.¿.....
0x0020   64 00 32 00 00 00 01 08-82 84 8B 96 8C 98 B0 12   d.2.....‚„‹–Œ˜°.
0x0030   03 01 0B 2A 01 02 32 04-24 48 60 6C 06 02 0A 00   ...*..2.$H`l....
0x0040   DD 9E 00 50 F2 06 25 12-53 F5 02 00 00 00 70 01   ÃÅ¾.Pò.%.Sõ....p.
0x0050   92 00 70 64 68 61 72 74-00 00 00 00 00 00 00 00   â€™.pdhart........
0x0060   00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00   ................
0x0070   00 00 11 05 00 02 B2 CF-03 0A 00 17 FA 03 B2 CF   ......²Ï....ú.²Ï
0x0080   39 31 2E 37 00 65 65 64-20 59 6F 75 20 42 6C 61   91.7.eed You Bla
0x0090   63 6B 20 45 6D 70 65 72-6F 72 21 20 27 30 39 2D   ck Emperor! '09-
0x00A0   31 35 2D 30 30 20 28 50-61 72 74 20 4F 6E 65 29   15-00 (Part One)
0x00B0   27 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00   '...............
0x00C0   00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00   ................
0x00D0   00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00   ................

0x0000      05-10 is the destination MAC
0x0000      11-16 is the source MAC address
0x0050       03-   
0x0070        -02 is the Zune name (31 characters). A hex value of 00 signals the end of the name and ignores any remaining data within this range.
0x0070      06    is the status flag (00: simple, 01: song, 02: radio, 03: video, 04: pictures, 05: basic, 06: busy, 07+: offline) *
0x0070      11-16 is a repeat of the source MAC address
0x0080      01-
0x00D0        -16 is the title. A hex value of 00 signals the end of the title and ignores any remaining data.

* These flags determine what is shown to nearby Zune users in the 'Community.' When set to 00, it just shows [title]. When set to 01, 'listening to [title]'. When set to 02, 'listening to radio [title] FM'. When set to 03, 'watching [title]'. When set to 04, 'Viewing Pictures'. When set to 05, it just says 'Online' for when online status is set to basic. When set to 06, 'Busy'. When set to 07 or above, 'Offline'.

In the above example, a Zune with the MAC address 00:17:FA:00:2E:EF is receiving the packet sent by a Zune with MAC address 00:17:FA:03:B2:CF.  The Zune name for the sender is 'pdhart' and the receiving Zune displays pdhart's status as 'listening to radio 91.7 FM'. The "eed You Black Emperor..." is left over from what song pdhart was listening to before. New titles are inserted over the old ones. Because it is preceeded by the hex value 00, "eed You Black Emperor..." is ignored.
« Last Edit: December 08, 2006, 08:05:58 PM by Phlag » Logged
KainXS
Zune Freak
***
Offline Offline

Posts: 89


View Profile
« Reply #6 on: December 09, 2006, 08:45:13 PM »

i wonder if we can use psp's to rebroadcast this

i'll try it later
Logged
A_Str8
King of Zunes
****
Offline Offline

Posts: 236



View Profile WWW
« Reply #7 on: December 09, 2006, 09:45:39 PM »

is the 3x3 drm added on send or on recieve?
Are there any common file transfer protocols used for sending files between wi-fi devices or WindowsCE devices?
« Last Edit: December 09, 2006, 09:49:24 PM by A_Str8 » Logged

www.AhdChild.com/zune - Music and wallpapers for your Zune
www.AhdChild.com - My main site with some more music for your Zune
XMike14x
I see dead people.
Zune Sovereign Ruler
*****
Offline Offline

Posts: 1130


TeamZuneBadA$$'es HQ Mod Global Command


View Profile WWW
« Reply #8 on: December 27, 2006, 06:54:34 PM »

Bump, lets work on this guys!
Logged

Michael.
________________________________________
Proud indirect owner of a funeral home. Serving the community since 2008.
________________________________________

Ignorance truly is bliss.
zune
Guest
« Reply #9 on: December 27, 2006, 08:42:21 PM »

I own 2 zunes but I lent one to a family member, wont get it back till Jan 3.  At that point I can start sniffing packets.

I analyzed your packet and also some of my own packets that I was able to sniff. Both our mac addresses start with 00:17:fa which according to this website belongs to Microsoft Corporation.

   http://coffer.com/mac_find/

I wish I had 2 zunes so I could see which packets are sent while exchanging files. Anybody out there with access to two Zunes? I used the demo version of this program:

   http://www.tamos.com/products/commwifi/
Logged
XMike14x
I see dead people.
Zune Sovereign Ruler
*****
Offline Offline

Posts: 1130


TeamZuneBadA$$'es HQ Mod Global Command


View Profile WWW
« Reply #10 on: December 28, 2006, 11:55:34 PM »

Oh please! That would rock!
Logged

Michael.
________________________________________
Proud indirect owner of a funeral home. Serving the community since 2008.
________________________________________

Ignorance truly is bliss.
Bohlio
Zune Sovereign Ruler
*****
Offline Offline

Posts: 2109



View Profile
« Reply #11 on: December 29, 2006, 09:54:20 PM »

Hey you guys that are doing this, is your #1 priority using this to hack the 3x3 or something else?
Logged

http://www.pandora.com/ - Discover your Music

Bailouts = Fail
XMike14x
I see dead people.
Zune Sovereign Ruler
*****
Offline Offline

Posts: 1130


TeamZuneBadA$$'es HQ Mod Global Command


View Profile WWW
« Reply #12 on: December 30, 2006, 01:37:51 AM »

Yeah, and maybe syncing with the computer. This can have enormous possibilities.
 
Logged

Michael.
________________________________________
Proud indirect owner of a funeral home. Serving the community since 2008.
________________________________________

Ignorance truly is bliss.
ZackP
Guest
« Reply #13 on: December 30, 2006, 12:44:35 PM »

Wow gl guys.
Logged
ScrewApple
Zune Freak
***
Offline Offline

Posts: 80


View Profile
« Reply #14 on: December 30, 2006, 03:44:34 PM »

What would a traffic sniffer help you do in all of this?? As I am aware you have two zunes in a house and you are sending songs and pictures to the other zune while capturing the traffic on the sniffer from the packets being sent from zune to network to other zune. How would this help anyone advance in some wifi hax0rz??
« Last Edit: December 30, 2006, 03:48:35 PM by ScrewApple » Logged


Get your own Gamercard Sig.
pspahn
Zune Freak
***
Offline Offline

Posts: 89


View Profile
« Reply #15 on: December 31, 2006, 06:05:55 AM »

by capturing the packets, you can do a number of things.

1. You can decipher the contents of the packet, and determine simple things like syntax and complex things like security keys.
2. You can change the contents of the packet, to do things you want it to.
3. You can upload Bette Midler songs to your enemy's Zune.
Logged
etx
Grunt of the ZS Army
*
Offline Offline

Posts: 3


View Profile
« Reply #16 on: January 03, 2007, 09:50:10 AM »

Good stuff guys. I wish I had two Zunes to mess with. It would be fun to fire up a compiler and see if we can't send a mp3 to the zune flagged as a picture to see how it handles it.
Logged
Repoman
King of Zunes
****
Offline Offline

Posts: 236


who stole my ritalin


View Profile
« Reply #17 on: January 03, 2007, 10:39:50 AM »

I have 2 but have not even the faintest idea what you are doing so .... Embarrassed
Logged

Pages: [1] 2 3   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM
Page created in 0.176 seconds with 24 queries.