NetStumbler.org Forums

Go Back   NetStumbler.org Forums > Software > Unix/Linux
Register Search Today's Posts Mark Forums Read

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 11-12-2004   #211 (permalink)
msure
Registered Member
 
Join Date: Sep 2004
Posts: 1
Hi all.A question,is there any way if having wep to find thepassphrase ?

Last edited by msure : 11-13-2004 at 07:11 PM. Reason: -
msure is offline  
Old 11-13-2004   #212 (permalink)
madjerk
Registered Member
 
Join Date: May 2004
Posts: 5
Hi,

I'm running airodump/aircrack on an orinoco oem without problems, really good work But I have problems with a prism based pci card. I'm using the hostap driver version 0.2.4. When I start airodump, I just get the status bar (essid etc.) but nothing else. The cursor runs from left to right, that's all. I have to terminate airodump with ctrl+c. Then I get a segmentation fault.
I set the monitor mode as follows:
iwconfig wlan0 mode Monitor channel 9
iwpriv wlan0 monitor_type 1

Capturing with kismet works fine. So I don't think the driver or the firmware is the reason. Any ideas?

Thanks in advance.
madjerk
madjerk is offline  
Old 11-15-2004   #213 (permalink)
Basilisk
Registered Member
 
Join Date: Nov 2004
Posts: 1
aircrack & wepcrack

I've been testing various WEP cracking tools -- set up an AP and a few laptops to move traffic while one sniffs. I've seen excellent results from wepcrack -- cracks a 64-bit WEP key in under a second -- with or without a word list. Aircrack seems much slower -- takes 10 minutes or more (this is all using over a packetfile of over 10k packets).

Is anyone familiar enough with the these two to understand why wepcrack seems so much faster?

Haven't been able to get wepattack to work poperly to see how it compares.
Basilisk is offline  
Old 11-15-2004   #214 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
Aircrack seems much slower -- takes 10 minutes or more (this is all using over a packetfile of over 10k packets).

You can't crack WEP using a statistical attack with so few packets. For 64-bit WEP you'll need around 100k IVs. Otherwise you're doing it by brute force.
devine is offline  
Old 11-22-2004   #215 (permalink)
_watcher
Registered Member
 
Join Date: Oct 2004
Posts: 6
Packet Injecting.

Hey Devine. Just wanted to tell you again that I think your program is amazing. I was able to get a key in a matter of 30 minutes or so. (The guy was moving tons of traffic through the network.)

My question for you though is... packet injecting. I've been testing this out but can't seem to get any IV's to generate from using this. Maybe i'm just not using it correctly. What is a good packet injecting program for linux? Packit is pretty cool, that's what i've been using.

What kind of packet do you have to inject to generate iv's? I've tried ARP and TCP. Bah, help me out man!
_watcher is offline  
Old 12-03-2004   #216 (permalink)
_watcher
Registered Member
 
Join Date: Oct 2004
Posts: 6
Question Aircrack.. New version?

Hey Devine. When is the next aircrack expected to be out? Also, do you plan on making a version of aireplay compatible with the wlan drivers?

-w
_watcher is offline  
Old 12-03-2004   #217 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
When is the next aircrack expected to be out?

I can't give a precise release date. Hopefully before 2006.
devine is offline  
Old 12-06-2004   #218 (permalink)
oLie
Registered Member
 
Join Date: Dec 2004
Posts: 2
hello,

i'm using aircrack for windows (ver2.1) and i want to know if aircrack can find a 128bits WEP key ?

because all i see about aircrack is it can crack a 40bits / 102 (or maybe104) wep key !

Thx


oLie - Paris
oLie is offline  
Old 12-08-2004   #219 (permalink)
madjerk
Registered Member
 
Join Date: May 2004
Posts: 5
Hi,

104 bit shared key + 24 bit iv = 128 bit wep key.
Therefore 128 bit actually means 104 bit.

madjerk
madjerk is offline  
Old 12-08-2004   #220 (permalink)
oLie
Registered Member
 
Join Date: Dec 2004
Posts: 2
'lo,

thx for the answer.

it was a bit stupid to ask you with this question because first: if i had read the read-me file, the answer of me Q were in it

And two because the day of my Q, i've try it on my AP (128bits) and he find the key after 7sec of search and 2hours of capture (1000000 IVs, imagine i was downloading a 1Go file from pc-to-pc in my lan !! lol)

anyway, thx
oLie is offline  
Old 12-10-2004   #221 (permalink)
Ricochet25x
Registered Member
 
Join Date: Dec 2004
Posts: 1
Very Newb question (Aircrack related)

I'm trying to get Aircrack to get me a WEP but am clueless as to where to begin? Please help. Thanks in advance.
Ricochet25x is offline  
Old 12-11-2004   #222 (permalink)
itsnotme
Dumbass checker
 
itsnotme's Avatar
 
Join Date: Sep 2002
Location: Somewhere below Lake Ontario
Posts: 1,076
May I suggest you use google.com or the search button up there.

Either one will give you veritable results.

(there! I've used my word of the day! )
itsnotme is offline  
Old 12-22-2004   #223 (permalink)
Deftronic
Registered Member
 
Join Date: Dec 2004
Posts: 1
Using airodump the normal way. Not creating traffic and no packet injection. As software using Slackware 10.1 and not patched hostap drivers. As hardware Senao prism 2.5 with two pigtails.

The setup gave me in the first hour 64975 IVs with around 200k of packets. Two days later I'm around the 1000k of packets and still 64975 IVs. Is this normal. Can anyone tell me what the prob could be?
Deftronic is offline  
Old 12-22-2004   #224 (permalink)
renderman
Drunken Stumbler
 
renderman's Avatar
 
Join Date: Jun 2002
Location: Anywhere but Utah
Posts: 1,803
Odd behaviour

Just trying to crack a test setup here at the office.

AP is a WRT54G, latest firmware, and a client was a Linksys Wireless B webcam, also latest firmware (lotsa traffic)

Setup for 128 Bit WEP, Captured varying amounts of packets and ran the crack.

2 Interesting things I noticed:

1. When Airodump is collecting packets, it says that the packets it is collecting are WPA encoded (I am sure they are WEP only)

2. 100K, 250K, 600K packets: No amount seems to get past the 12th KB in the crack. (I know it's not an exact science)

I'm curious if anyone else has noticed this, or if the newer firmwares are doing something tricky.
renderman is offline  
Old 12-22-2004   #225 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
1. When Airodump is collecting packets, it says that the packets it is collecting are WPA encoded (I am sure they are WEP only)

Yeah. known bug.

2. 100K, 250K, 600K packets: No amount seems to get past the 12th KB in the crack. (I know it's not an exact science)

128 bit WEP = 3 bytes IV + 13 bytes key. Aircrack actually computes votes for the 13th keybyte but the info disappears just after being printed.

Deftronic: it is normal, you're capturing beacons (unencrypted frames sent by the AP to make itself known).
devine is offline  
Closed Thread


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 01:42 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.