Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Wireless arrow Wireless How To arrow How To Crack WEP - Part 2: Performing the Crack
How To Crack WEP - Part 2: Performing the Crack Print E-mail
Humphrey Cheung   
May 18, 2005

Starting from scratch

In real-life, someone trying to break into a wireless network usually would have to obtain the information needed (MAC address of the AP and Target PC and wireless channel). Professionals who do penetration testing of networks describe this attack as a "Zero Knowledge" attack, for obvious reasons. If the attacker already has all the information needed, that's called a "Full Knowledge" attack, which is nowhere near as challenging! We'll assume that we know nothing and describe how to get the information we need.

Finding the MAC Address of the AP with Kismet

Navigating Kismet

Figure 1: Navigating Kismet
(click image to enlarge)

Finding the MAC Address of the AP is extremely easy with either Kismet or Netstumbler. Start Auditor-A with its Wi-Fi card and Auditor CD inserted. Once Auditor is up, start Kismet, just like you did in Part 1, and you will see a list of APs. Type s and then c to sort the APs by channel and using the arrow keys, move the highlight bar to your target AP's SSID. Then hit the Enter key. This will bring up a detailed screen (Figure 2) that will show the selected AP's SSID, MAC address and channel. Voila! "Zero knowledge" has been transformed into almost all the information needed to run a WEP crack.

Kismet easily finds the SSID, Channel and MAC address

Figure 2: Kismet easily finds the SSID, Channel and MAC address
(click image to enlarge)

Tip! Tip: Some "security professionals" suggest cloaking your SSID / disabling SSID broadcasts. While this will defeat a Netstumbler scan, Kismet will easily detect "cloaked" SSIDs. Kismet captures more network information than Netstumbler and can find AP SSID's by following conversations between associated clients and the AP.

Finding the MAC Address of the Client

We need one last piece of information to begin our cracking - the MAC address of a wireless client associated to the AP of our Target WLAN. Go back to Kismet and type q to quit out of the details menu. The highlight bar should still be on your AP, if it isn't, then use the arrow keys again. Typing shift-C will bring up a list of clients. The MAC addresses are listed on the left side (Figure 3).

Client MAC address found by Kismet

Figure 3: Client MAC address found by Kismet
(click image to enlarge)

If you don't see the MAC address of the TARGET computer, check to make sure it's on and associated with the Target AP (boot the TARGET into Windows, have it connect to the AP and start browsing the web). In about 10-30 seconds, you should see the MAC address of the TARGET computer pop up in Kismet. A prudent cracker would probably record all the client MAC addresses found so as not to be thwarted if a client isn't present when the time comes to start the cracking process.



Tags: Hacking, How To, WEP, WiFi,

Related Articles:

The Feds can own your WLAN too
WEP Cracking...Reloaded
How To Crack WEP - Part 1: Setup & Network Recon
How To Crack WPA / WPA2
Auditor Security Collection CD reviewed
 

Most Read

 
 

Over At The Forums

Question on Lightning Protection for Networks
Here's a little background on the situation. I have FIOS with Verizon supplied Router. My network consists of 4 Desktops, a few laptops (connected wireless)...

Qnap TS409 Pro or Netgear ReadyNas NV+ for home server?
I have narrowed down my choices for a home server to a 4-bay Qnap TS409 Pro or a Netgear ReadyNas NV+. The home server would be...

Wireless Setup for Bed and Breakfast
Thanks in advance for any suggestions. I have a bed and breakfast with 8 rooms in two buildings and have used Linksys WRT54G (old versions with...

Dlink (DIR-655) and VOIP problem
Hello, I can't get a Siemens C450IP VOIP phone working together with a DIR-655. The phone is working without a problem on a USRobotics USR5463 using...

Mini-ITX NAS build
I'm currently looking for some ideas on a fast NAS motherboard at home. Looking into a Mini-ITX because of size and low power. Some requirements...

Slideshows

Western Digital ShareSpace QNAP TS-509 Pro D-Link DNS-343 4-Bay Network Storage Enclosure Thecus N3200 RAID 5 NAS D-Link DIR-628 RangeBooster N Dual Band Router Adtran NetVanta 3120 More

Win This!

Enter to Win!

You could win a Promise NetStor NS2300N NAS.

Learn How!

 

Ldr:0.0014431476593, Rct:0.00542998313904, Sky:0.00725507736206, Tlink:0.0838761329651, TopPG:0.0839440822601, GQV:0.0840981006622 seconds to load.