Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Wireless arrow Wireless How To arrow How To Crack WEP - Part 2: Performing the Crack
How To Crack WEP - Part 2: Performing the Crack Print E-mail
Humphrey Cheung   
May 18, 2005

Introduction

This article has been superceeded by How to Crack WEP...Reloaded.

In Part 1 of How to Crack WEP, we showed the basic approach to WEP cracking, configured a practice target WLAN and configured both sniffing and attack computers. We also introduced the Auditor Security Collection and used Kismet to find in-range wireless LANs.

In this article, we will describe how to use additional tools found on the Auditor CD to capture traffic and use it to crack a WEP key. We'll also describe how to use deauthentication and packet replay attacks to stimulate the generation of wireless traffic that is a key element of reducing the time it takes to perform a WEP key crack.

Before we get started, however, let us make a few points that may save some readers the time and effort of trying these techniques:

  • To successfully follow this How To, you need basic familiarity with networking terminology and principles. You should know how to ping, open a Windows Command Prompt, enter command lines and know your way around the Windows networking properties screens. Basic familiarity with Linux will be helpful too.

  • These procedures assume the use of specific wireless hardware described in Part 1. They will not work with other hardware types without modification.

  • These procedures assume that the target WLAN has at least one client associated with an AP or wireless router. They will not work with an AP that has no associated clients.

  • This tutorial is based on the Auditor version released April 2005. Future versions could make this attack easier or harder. In addition, some of the commands shown are Auditor-specific scripts that don't exist (but can easily be made) in other Linux distributions.

  • Accessing anyone else's network other than your own without the network owner's consent is illegal. SmallNetBuilder, Pudai, LLC and the author do not condone or approve of illegal use of this tutorial in any way

Also note that it is possible to perform WEP cracking using only one computer. But we have chosen to use two to more clearly illustrate the process and avoid some of the complications caused by using a single computer.

The four main tools used in this article are airodump, void11, aireplay and aircrack, which are included on the Auditor Security Collection CD:

  • Airodump scans the wireless network for packets and captures these packets into files
  • Void11 will deauthenticate computers from a wireless access point, which will force them to reassociate to the AP, creating an ARP request
  • Aireplay takes this ARP request and resends it to the AP, spoofing the ARP request from the valid wireless client
  • Finally, aircrack will take the capture files generated by airodump and extract the WEP key

From your scanning with Kismet as described in Part 1, you should have written down the following four pieces of information:

  • MAC Address of the wireless Access Point (AP)
  • MAC Address of the "Target" computer
  • WEP key used
  • Wi-Fi channel used

In the following procedures, we will call our laptops, Auditor-A and Auditor-B and call the target computer Target. Let's get started.



Tags: Hacking, How To, WEP, WiFi,

Related Articles:

The Feds can own your WLAN too
How To Crack WEP - Part 1: Setup & Network Recon
WEP Cracking...Reloaded
How To Crack WPA / WPA2
Auditor Security Collection CD reviewed
 

Most Read

 
 

Slideshows

Western Digital My Book World Edition II (white bar) Buffalo TeraStation III Linksys WET610N Wireless-N Ethernet Bridge with Dual-Band NETGEAR ReadyNAS Vault Buffalo Linkstation Pro XHL LaCie Network Space More

Over At The Forums

NAS, Gigabit, TCP window size
Hi All, This could be a very stupid question...but... When looking to achieve max transfer speeds to a NAS, can the TCP window size of the *sending*...

Are STBC mandatory for 802.11n?
STBC for those who don't know are "Space Time Block Code" the feature of 802.11n that is supposed to extend the range to infinity and...

Definitely clueless..Please help!
Hey there. First let me tell you that I am really NOT technically savvy. I mean I can follow instructions (I was able to connect...

good laptop card to use w/WZR-HP-G300NH?
Going to order a Buffalo WZR-HP-G300NH wireless router. Was looking for advice on a laptop card (32 bit cardbus card) for my gf's laptop (Inspiron...

Best way to sync NASs directly (not through computers)
I just finished reading Kevin's "How To Back Up Offsite for Free with rsync" article and it was pretty useful *but* it dealt with doing...

Go Shopping with PriceGrabber

Get Email Updates

Enter your email address:

Delivered by FeedBurner once a day

 
 

Ldr:0.00168204307556, Rct:0.00579881668091, Sky:0.00713396072388, Tlink:0.0866639614105, TopPG:0.0867259502411, GQV:0.0868558883667 seconds to load.