Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Wireless arrow Wireless How To arrow How To Crack WPA / WPA2
How To Crack WPA / WPA2 Print E-mail
Brandon Teska   
January 15, 2008

Introduction

Previously, we showed you how to secure your wireless with industrial strength RADIUS authentication via WPA-Enterprise. It turns out that there's a little back-story there. So, in traditional Tarentino fashion, now that we've already seen the ending, let's back up to the beginning: cracking WPA-PSK.

Wi-Fi Protected Access (WPA) was created to solve the gaping security flaws that plagued WEP. Perhaps the most predominant flaw in WEP is that the key is not hashed, but concatenated to the IV, allowing completely passive compromise of the network. With WEP, you can literally sit in your car listening for packets on a network. Once you have captured enough of them, you can extract the key and connect to the network.

WPA solves this problem by rotating the key on a per-packet basis, which renders the above method useless. However, nothing is perfectly secure, and WPA-PSK is particularly vulnerable during client association, during which the hashed network key is exchanged and validated in a "four-way handshake".

The Wi-Fi Alliance, creators of WPA, were aware of this vulnerability and took precautions accordingly. Instead of concatenating the key in the IV (the weakness of WEP), WPA hashes they key using the wireless access point's SSID as a salt. The benefits of this are two-fold.

First, this prevents the statistical key grabbing techniques that broke WEP by transmitting the key as a hash (cyphertext). It also makes hash precomputation via a technique similar to Rainbow Tables more difficult because the SSID is used as a salt for the hash. WPA-PSK even imposes a eight character minimum on PSK passphrases, making bruteforce attacks less feasible.

So, like virtually all security modalities, the weakness comes down to the passphrase. WPA-PSK is particularly susceptible to dictionary attacks against weak passphrases. In this How To, we'll show you how to crack weak WPA-PSK implementations and give you some tips for setting up a secure WPA-PSK AP for your SOHO.

NOTE!Warnings:
  • Accessing or attempting to access a network other than your own (or have permissions to use) is illegal.
  • SmallNetBuilder, Pudai LLC, and I are not responsible in any way for damages resulting from the use or misuse of information in this article.

NOTE!Note: The techniques described in this article can be used on networks secured by WPA-PSK or WPA2-PSK. References to "WPA" may be read "WPA/WPA2".


Tags: Hacking, How To, WiFi, WPA,

Related Articles:

The Feds can own your WLAN too
WEP Cracking...Reloaded
How To Crack WEP - Part 1: Setup & Network Recon
How To Crack WEP - Part 2: Performing the Crack
WPA Cracked in 15 minutes
 

Most Read

 
 

Slideshows

Western Digital My Book World Edition II (white bar) Buffalo TeraStation III Linksys WET610N Wireless-N Ethernet Bridge with Dual-Band NETGEAR ReadyNAS Vault Buffalo Linkstation Pro XHL LaCie Network Space More

Over At The Forums

Are STBC mandatory for 802.11n?
STBC for those who don't know are "Space Time Block Code" the feature of 802.11n that is supposed to extend the range to infinity and...

Definitely clueless..Please help!
Hey there. First let me tell you that I am really NOT technically savvy. I mean I can follow instructions (I was able to connect...

good laptop card to use w/WZR-HP-G300NH?
Going to order a Buffalo WZR-HP-G300NH wireless router. Was looking for advice on a laptop card (32 bit cardbus card) for my gf's laptop (Inspiron...

Best way to sync NASs directly (not through computers)
I just finished reading Kevin's "How To Back Up Offsite for Free with rsync" article and it was pretty useful *but* it dealt with doing...

Wirless NIC and Vista64.
I've lately noticed frequent packet loss and connection drop from my desktop in my usual doings (gaming & web browsing). I thought this connection was...

Go Shopping with PriceGrabber

Get Email Updates

Enter your email address:

Delivered by FeedBurner once a day

 
 

Ldr:0.00154209136963, Rct:0.00542688369751, Sky:0.00673890113831, Tlink:0.0834069252014, TopPG:0.0834729671478, GQV:0.0835950374603 seconds to load.