Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > Cracking WEP in less than 60 seconds

Reply
Thread Tools Display Modes

Cracking WEP in less than 60 seconds

 
 
Jeff Liebermann
Guest
Posts: n/a

 
      04-16-2007, 05:59 AM
How to crack WEP in less than 60 seconds.
<http://eprint.iacr.org/2007/120.pdf>
Actually, it typically takes about 3-10 seconds to recover the WEP
key.
<http://www.cdc.informatik.tu-darmstadt.de/aircrack-ptw/>
I built it and ran it under Umbutu 6.10 using capture files from
airdump-ng. Works fairly well on the neighborhood assortment of older
PBI/SBC/at&t supplied 2Wire wireless routers that default to WEP
encryption even though they are capeable of doing WPA and WPA2.
However, it failed on an access point with custom tweaked firmware
designed to discourage ARP injection, re-injetion, and flooding as
airdump-ng could not get the required number of ARP replies in a
reasonable amount of time.

Moral: WEP really sucks. Use WPA or WPA2 instead.

--
Jeff Liebermann (E-Mail Removed)
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558
 
Reply With Quote
 
 
 
 
Axel Hammerschmidt
Guest
Posts: n/a

 
      04-16-2007, 08:41 AM
Jeff Liebermann <(E-Mail Removed)> wrote:

<snip>

> <http://www.cdc.informatik.tu-darmstadt.de/aircrack-ptw/>


<snip>

> However, it failed on an access point with custom tweaked firmware
> designed to discourage ARP injection, re-injetion, and flooding as
> airdump-ng could not get the required number of ARP replies in a
> reasonable amount of time.


According to the tu-darmstadt site their software can't crack 256bit WEP
either.

BTW it's a statistical test: using less than 40.000 frames in 50 pct of
all cases.

A 50 pct crtitical region (or 50 pct significance level) is quite large
(small) in statistical tests. Levels are usually set to 90 - 95 pct (10
- 5 pct). Using those values will (probably) result in the usual time
taken to crack WEP.
 
Reply With Quote
 
F8BOE
Guest
Posts: n/a

 
      04-16-2007, 04:58 PM
Jeff Liebermann trolled:

> How to crack WEP in less than 60 seconds.
> <http://eprint.iacr.org/2007/120.pdf>
> Actually, it typically takes about 3-10 seconds to recover the WEP
> key.
> <http://www.cdc.informatik.tu-darmstadt.de/aircrack-ptw/>
> I built it and ran it under Umbutu 6.10 using capture files from
> airdump-ng. Works fairly well on the neighborhood assortment of older
> PBI/SBC/at&t supplied 2Wire wireless routers that default to WEP
> encryption even though they are capeable of doing WPA and WPA2.
> However, it failed on an access point with custom tweaked firmware
> designed to discourage ARP injection, re-injetion, and flooding as
> airdump-ng could not get the required number of ARP replies in a
> reasonable amount of time.
>
> Moral: WEP really sucks. Use WPA or WPA2 instead.
>


256 or 512 bits WEP?
So try to crack mine. Ho ho ho!
 
Reply With Quote
 
Jeff Liebermann
Guest
Posts: n/a

 
      04-16-2007, 06:18 PM
F8BOE <(E-Mail Removed)> hath wroth:

>Jeff Liebermann trolled:
>
>> How to crack WEP in less than 60 seconds.
>> <http://eprint.iacr.org/2007/120.pdf>
>> Actually, it typically takes about 3-10 seconds to recover the WEP
>> key.
>> <http://www.cdc.informatik.tu-darmstadt.de/aircrack-ptw/>
>> I built it and ran it under Umbutu 6.10 using capture files from
>> airdump-ng. Works fairly well on the neighborhood assortment of older
>> PBI/SBC/at&t supplied 2Wire wireless routers that default to WEP
>> encryption even though they are capeable of doing WPA and WPA2.
>> However, it failed on an access point with custom tweaked firmware
>> designed to discourage ARP injection, re-injetion, and flooding as
>> airdump-ng could not get the required number of ARP replies in a
>> reasonable amount of time.
>>
>> Moral: WEP really sucks. Use WPA or WPA2 instead.


>256 or 512 bits WEP?
>So try to crack mine. Ho ho ho!


<http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy>
"Key size is not the only major security limitation in WEP. Cracking a
longer key requires interception of more packets, but there are active
attacks that stimulate the necessary traffic. There are other
weaknesses in WEP, including the possibility of IV collisions and
altered packets, that are not helped at all by a longer key. See
stream cipher attack."


--
Jeff Liebermann (E-Mail Removed)
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558
 
Reply With Quote
 
John Navas
Guest
Posts: n/a

 
      04-17-2007, 04:11 AM
On Mon, 16 Apr 2007 18:58:18 +0200, F8BOE <(E-Mail Removed)> wrote in
<4623ab29$0$6092$(E-Mail Removed)>:

>Jeff Liebermann trolled:


>> Moral: WEP really sucks. Use WPA or WPA2 instead.

>
>256 or 512 bits WEP?
>So try to crack mine. Ho ho ho!


Misplaced confidence is a fast track to insecurity.

--
Best regards, FAQ for Wireless Internet: <http://Wireless.wikia.com>
John Navas FAQ for Wi-Fi: <http://wireless.wikia.com/wiki/Wi-Fi>
Wi-Fi How To: <http://wireless.wikia.com/wiki/Wi-Fi_HowTo>
Fixes to Wi-Fi Problems: <http://wireless.wikia.com/wiki/Wi-Fi_Fixes>
 
Reply With Quote
 
Eric Parker
Guest
Posts: n/a

 
      04-17-2007, 07:51 AM

"John Navas" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> On Mon, 16 Apr 2007 18:58:18 +0200, F8BOE <(E-Mail Removed)> wrote
> in
> <4623ab29$0$6092$(E-Mail Removed)>:
>
> Misplaced confidence is a fast track to insecurity.
>



Are you sure about that John ?

;-)

Eric

--
Remove the dross to contact me directly


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Permanently change default Windows 2003 ping timeout value from 2 seconds to 3 seconds philbo30 Windows Networking 5 08-30-2007 06:13 AM
Cracking WEP and WPA DarkPhoenix Wireless Internet 1 07-01-2007 02:57 AM
Cracking WPA-PSK d11@anywhere.com Wireless Internet 16 03-14-2006 04:41 PM
DoS cracking quesiton. Kevin Brown Wireless Internet 4 02-08-2006 01:30 AM
Cracking WEP Kimball K Kinnison Broadband 122 01-13-2005 10:51 AM



1 2 3 4 5 6 7 8 9 10 11