NetStumbler.org Forums

Go Back   NetStumbler.org Forums > Software > Unix/Linux
Register Search Today's Posts Mark Forums Read

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 07-29-2004   #1 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
(Aircrack)Yet another WEP cracking tool for Linux

Hey folks,

I'm glad to announce the first release of aircrack - a program similar to David Hulton's dwepcrack and TopoLB's weplab.

The source can be downloaded at http://www.cr0.net:8040/code/network/ - any feedback will be greatly appreciated.

-- Christophe

Last edited by devine : 07-30-2004 at 04:03 AM.
devine is offline  
Old 08-11-2004   #2 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
aircrack 1.1 released

From the freshmeat announcement -


Quote:
This release adds multi-processor support, improves the fudge calculation algorithm, and fixes a major bug in the BSSID check code. It also introduces a new tool (aireplay) that can be used to generate traffic on a WEP-encrypted wireless LAN without knowing the key, thereby reducing the amount of time needed to gather a sufficient number of encrypted data packets.
devine is offline  
Old 08-11-2004   #3 (permalink)
kleptophobiac
Registered Member
 
Join Date: Sep 2002
Posts: 310
generates more traffic on the network.... I'll have to check that one out!
kleptophobiac is offline  
Old 08-11-2004   #4 (permalink)
KoreK
Banned in DC
 
KoreK's Avatar
 
Join Date: Jul 2004
Posts: 102
Devine, check out my post (the one with the little demo) in the Mac OS section. You might find it interesting
KoreK is offline  
Old 08-12-2004   #5 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
Thumbs up

Quote:
Originally Posted by KoreK
Devine, check out my post (the one with the little demo) in the Mac OS section. You might find it interesting
Indeed! The new attacks you've developped look awesome, and I'm generating some stats right now for each keybyte of different keys in order to see what may be the best attack strategy. This could lead to a very fast WEP cracking tool.
devine is offline  
Old 08-12-2004   #6 (permalink)
sylvain
Wireless Auditor
 
Join Date: Jun 2004
Location: Paris, France
Posts: 175
do you know if your tool is compliant with aironet cisco card ?

it seems to the case..one great thing that weplab can not do is to select the bssid of the network !!

Last edited by sylvain : 08-12-2004 at 07:58 AM.
sylvain is offline  
Old 08-12-2004   #7 (permalink)
sylvain
Wireless Auditor
 
Join Date: Jun 2004
Location: Paris, France
Posts: 175
Quote:
Originally Posted by devine
Indeed! The new attacks you've developped look awesome, and I'm generating some stats right now for each keybyte of different keys in order to see what may be the best attack strategy. This could lead to a very fast WEP cracking tool.

do you plan to develop this WEP cracking tool
sylvain is offline  
Old 08-12-2004   #8 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
Quote:
Originally Posted by sylvain
do you know if your tool is compliant with aironet cisco card ?
airodump should be compatible with any wireless card that can be put in Monitor mode. At the moment it has only been tested with Prism2 cards, but I intend to borrow some Orinoco/Aironet/PrismGT/Atheros cards to make sure it works ok with those chipsets.

AFAIK aircrack works with any 802.11 pcap file.

aireplay is, at the moment, only compatible with Prism2 cards using the patched HostAP driver.
devine is offline  
Old 08-12-2004   #9 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
Quote:
Originally Posted by sylvain
do you plan to develop this WEP cracking tool
Sure, actually that's what I'm doing right now
devine is offline  
Old 08-12-2004   #10 (permalink)
sylvain
Wireless Auditor
 
Join Date: Jun 2004
Location: Paris, France
Posts: 175
you are right aircrack is working with pcap file generated with kismet/aironet

do you plan to develop aireplay for other cards than Prism2 ?
sylvain is offline  
Old 08-12-2004   #11 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
Quote:
Originally Posted by sylvain
you are right aircrack is working with pcap file generated with kismet/aironet

do you plan to develop aireplay for other cards than Prism2 ?
Yep, once I get a hold on the aforementioned cards I'll try to see which ones can be used for WEP packets re-injection. Could take a few weeks though, if not months.
devine is offline  
Old 08-12-2004   #12 (permalink)
sylvain
Wireless Auditor
 
Join Date: Jun 2004
Location: Paris, France
Posts: 175
that will be a good idea to add aironet as cisco cards are often used by professional auditors...
sylvain is offline  
Old 08-12-2004   #13 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
Quote:
Originally Posted by devine
Sure, actually that's what I'm doing right now
Ok, I've just finished implementing KoreK's attacks into the development version of aircrack. The preliminary results are very good - I've been able to crack in less than one minute a 104-bit WEP key with as few as 800k unique IVs; the previous version of aircrack fails with so few IVs.
devine is offline  
Old 08-13-2004   #14 (permalink)
sylvain
Wireless Auditor
 
Join Date: Jun 2004
Location: Paris, France
Posts: 175
can you send me the development version ?

en fait on va pouvoir le faire en français aussi ;-)
sylvain is offline  
Old 08-13-2004   #15 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
Quote:
Originally Posted by sylvain
can you send me the development version ?

en fait on va pouvoir le faire en français aussi ;-)
I'd rather stick with english, as most people here don't speak french ;-)

You can download a patch that implements the KoreK attacks at [deleted]

The results I have so far are astounding; if lucky, aircrack can now recover a 104-bit WEP key with only 500k IVs in about 5 minutes. With 1M IVs the key is found almost instantly . This is a huge improvement from the standard FMS attack, and it leaves other tools such as airsnort dead in the water

post-edit: patch no longer present on the web server so removed the url.

Last edited by devine : 09-01-2004 at 08:17 AM.
devine is offline  
Closed Thread


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 11:04 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.