![]() |
|
|||||||
| Register | Search | Today's Posts | Mark Forums Read |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#17 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Here's the procedure:
Quote:
|
|
|
|
|
|
#19 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
![]() I just fixed a bug in my implementation of KoreK's attack #6 which prevented some false posivites from being rejected. I also improved the fudging code quite a bit. The new patch (to be applied against stock 1.1) is at [deleted] Now that attack #6 is working, the results are even better: with 500k IVs, there's a ~60% chance the WEP key will be found; and with 1000k IVs there a ~95% probability you'll succeed in cracking the key ![]() post-edit: patch no longer present on the web server so removed the url. Last edited by devine : 09-01-2004 at 08:16 AM. |
|
|
|
|
|
#20 (permalink) | |
|
Registered Member
Join Date: Apr 2004
Posts: 17
|
Quote:
![]() PS: 1 million wasn't enough -> "no luck, sorry", now trying 1,5 million packets..... key found ![]() Last edited by firefighter99 : 08-14-2004 at 03:14 PM. |
|
|
|
|
|
#21 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
It's true that sometimes you can have bad luck, in that case more packets or some deeper fudging is required. |
|
|
|
|
|
#23 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
Your work is very impressive, did you consider writing a whitepaper or something about the WEP attacks you've developed ? Especially regarding each attack stability & probability of success, and the theory behind it.post-edit: did some more testing with wep_gen and chopper, got mindblowing results - managed to crack a 104-bit WEP key with as few as 100k IVs !! This stuff is unbelievable ![]() Last edited by devine : 08-16-2004 at 03:10 PM. |
|
|
|
|
|
#27 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
BTW, aircrack 1.2 with the full set of KoreK's attacks has just been released, grab it at http://www.cr0.net:8040/code/network/ |
|
|
|
|
|
#28 (permalink) |
|
KB1JQO - Packin' Heat
Join Date: May 2002
Location: Worcester, MA
Posts: 517
|
Looks interesting.
Based on the example in the README, it looks like this relies on a very low number of weak IVs, which is very interesting.
Gonna try this on the engineering lab later this week. ![]()
__________________
-A.G.- |
|
|
|
|
#29 (permalink) |
|
Registered Member
Join Date: Jul 2004
Posts: 13
|
Works Great - But What Changed Since the Patch
I patched version 1.1 yesterday with the KoreK patch posted here and was able to crack the 104 bit WEP key with the following results:
2.2 Million IVs - 13 seconds 1.2 Million IVs - 52 seconds 500K IVs - 8 seconds Using the newest version, 1.2, released today with the same capture files I was only able to crack the WEP key using 2.2 Million IVs. All data was captured using kismet. What changed from yesterday's patch to release 1.2? |
|
|
|
|
#30 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
|
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|