NetStumbler.org Forums

Go Back   NetStumbler.org Forums > Software > Unix/Linux
Register Search Today's Posts Mark Forums Read

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 03-07-2005   #46 (permalink)
KoreK
Banned in DC
 
KoreK's Avatar
 
Join Date: Jul 2004
Posts: 102
It's a bit incorrect. Basic formula is (1-k/n)^n ~ exp(-k) when n is sufficiently large (mathly speaking lim of the left term when n grows to infinity is exp(-k)). In the papers, you get quantities like (253/256)^(256-p-1) (probability the (256-p-1) bytes of the KSA are different from 3 given values), with p=3,... First you approximate the exponent with 256, and you rewrite (1-3/256)^256, which then you approximate with the limit exp(-3).

cf http://mathworld.wolfram.com/ExponentialFunction.html
KoreK is offline  
Old 03-07-2005   #47 (permalink)
Madory
Registered Member
 
Madory's Avatar
 
Join Date: Jan 2005
Posts: 3
Origin of 5%

This makes sense, thanks.

Perhaps it is a case of 6 and one-half-dozen. I got my explanation from "Attacks On RC4 and WEP" by FMS:

"The probability that three locations will not be pointed to by a pseudo random index during the
remaining N - 1 - x rounds is better than ((1-1/N)^N)^3 ~ e^-3 ~ 5%."

((1-1/N)^N)^3
can be reduced to
(e^-1)^3
and finally
e^-3

-OR-

(1-3/N)^N
reduced directly to
e^-3

Anyway, thanks for the general formula - crystal clear now.
Madory is offline  
Old 03-15-2005   #48 (permalink)
noise_gaining
Registered Member
 
Join Date: Mar 2005
Posts: 1
half dozen is six

It's the same. Let M = 3N, then

((1-1/N)^N)^3 = (1-3/M)^M




Quote:
Originally Posted by Madory
This makes sense, thanks.

Perhaps it is a case of 6 and one-half-dozen. I got my explanation from "Attacks On RC4 and WEP" by FMS:

"The probability that three locations will not be pointed to by a pseudo random index during the
remaining N - 1 - x rounds is better than ((1-1/N)^N)^3 ~ e^-3 ~ 5%."

((1-1/N)^N)^3
can be reduced to
(e^-1)^3
and finally
e^-3

-OR-

(1-3/N)^N
reduced directly to
e^-3

Anyway, thanks for the general formula - crystal clear now.

Last edited by noise_gaining : 03-15-2005 at 12:01 PM.
noise_gaining is offline  
Old 03-17-2005   #49 (permalink)
Beep
Registered Member
 
Beep's Avatar
 
Join Date: Mar 2005
Location: Basel - Switzerland
Posts: 1
Question

Quote:
Originally Posted by KoreK
He has to use the wlan-ng patch. I didn't manage to make hostap work.

mfenetre, just a reminder: You need an AP, an associated card, and an injection card using the wlan-ng patched module (Or just associate the wlan-ng card, yank it out, back in, inject, and hope the it hasn't been disassociated). If you don't know where to begin, have a look at the auditor CD, chopchop is included:
http://new.remote-exploit.org/index.php/Auditor_main
Hi KoreK

I use the new Auditor (120305-01) on my HP OmniBook XE2 Laptop. I also use the Orinoco Silver WiFi card.
Is the necessary chopchop patch already installed on the Auditor CD? Must i apply any patches?

I've got the same problem like mfenetre few posts over me.

Thanks

-Beep

PS: Please dont flame me for my (maybe stupid) question... I searched a answer in google, readme's and this forum several hours/days.

PPS: R.E.S.P.E.C.T. to Korek and Devine for her great tools!
Beep is offline  
Old 03-17-2005   #50 (permalink)
sylvain
Wireless Auditor
 
Join Date: Jun 2004
Location: Paris, France
Posts: 175
drivers are already patched in new auditor version..and there is an auditor forum...maybe it's a better place to ask...not sure you really search...probably too lazy
sylvain is offline  
Old 03-17-2005   #51 (permalink)
G8tK33per
Asshole Emeritus
 
G8tK33per's Avatar
 
Join Date: May 2003
Location: S.E. VA.
Posts: 5,868
Quote:
Originally Posted by Beep
Hi KoreK

I use the new Auditor (120305-01) on my HP OmniBook XE2 Laptop. I also use the Orinoco Silver WiFi card.
Is the necessary chopchop patch already installed on the Auditor CD? Must i apply any patches?

I've got the same problem like mfenetre few posts over me.

Thanks

-Beep

PS: Please dont flame me for my (maybe stupid) question... I searched a answer in google, readme's and this forum several hours/days.

PPS: R.E.S.P.E.C.T. to Korek and Devine for her great tools!
OK, which one of you is the chick?
__________________
"Butters, stop being such a pussy."

Sons of Confederate Veterans
G8tK33per is offline  
Old 03-17-2005   #52 (permalink)
sylvain
Wireless Auditor
 
Join Date: Jun 2004
Location: Paris, France
Posts: 175
I can say it is not Devine, I already met him
sylvain is offline  
Old 03-17-2005   #53 (permalink)
KoreK
Banned in DC
 
KoreK's Avatar
 
Join Date: Jul 2004
Posts: 102
Quote:
Originally Posted by G8tK33per
OK, which one of you is the chick?
You need a new pair of stockings , cabin boy?

As for Beep, if you bothered reading my previous posts... And while I am at it, noise_gaining why don't you take a math class...
KoreK is offline  
Old 12-30-2005   #54 (permalink)
Grant
Registered Member
 
Join Date: Dec 2005
Posts: 1
Anyone know why my version won't compile even though the header file it says is missing isn't?
Grant is offline  
Old 12-30-2005   #55 (permalink)
Thorn
Did you do the math?
 
Thorn's Avatar
 
Join Date: Apr 2002
Location: Villa Straylight
Posts: 9,980
Probably the header file isn't in the path. Most often this type of thing occurs because the code's author assumes one particular path, and your system is slightly different.

Try using an explicit path, for example, change:

#include stdio.h

to:

#include /usr/src/stdio.h

(of course the path preceding the header file name would be the required one for your system.)
__________________
Thorn
"You guys'll be chalk outlines without me."
Thorn is offline  
Old 03-21-2007   #56 (permalink)
bigbadbo
Registered Member
 
Join Date: Mar 2007
Posts: 3
idea to crack WEP with chopchop

Hi all

This is my first Post on this site so hang in their with me !.

OK ...

KOREK chopchop theory obtains the Keystream of a particular packet, Idealy from an ARP packet from the AP.

And then we can forge an ARP Packet with packetforge-ng and some other stuff !

However, if we inject our new forge ARP packet, were still only generating as much traffic, according to the size of that ARP (68bits)

How about if you apply that keystream to a much larger packet, for instance ...
a GET packets, thats 400+ bits, this will generate much more traffic leading to a quicker attack

I know packetforge-ng has a custom packet capability, but im unsure how to use it

regards
Kai
bigbadbo is offline  
Old 03-21-2007   #57 (permalink)
Starpoint
Registered Member
 
Starpoint's Avatar
 
Join Date: Apr 2003
Location: Houston
Posts: 2,312
Quote:
Originally Posted by bigbadbo
Hi all

This is my first Post on this site so hang in their with me !.

OK ...

KOREK chopchop theory obtains the Keystream of a particular packet, Idealy from an ARP packet from the AP.

And then we can forge an ARP Packet with packetforge-ng and some other stuff !

However, if we inject our new forge ARP packet, were still only generating as much traffic, according to the size of that ARP (68bits)

How about if you apply that keystream to a much larger packet, for instance ...
a GET packets, thats 400+ bits, this will generate much more traffic leading to a quicker attack

I know packetforge-ng has a custom packet capability, but im unsure how to use it

regards
Kai
And your goal in all this is WHAT?
__________________
Against the run of the mill, static as it seems

We break the surface tension with our wild kinetic dreams
Curves and lines -- of grand designs...


Tonight's movie "Soylent Green" has been brought to you by our sponsor - Waste Management

My mind is like a Steel trap - Rusty and Illegal in most states
Starpoint is offline  
Old 03-21-2007   #58 (permalink)
streaker69
Psychic Amish Stumbler
 
streaker69's Avatar
 
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 11,609
Quote:
Originally Posted by Starpoint
And your goal in all this is WHAT?
Zombie Revival? Discuss the blasé practice of cracking wep?

Where is Devine anyway?
__________________
"One of these days, I'm going to cut you to pieces."

If you're offended by this post, please feel free to report it to one of the many helpful moderators of this forum.

Thank you.
streaker69 is offline  
Old 03-21-2007   #59 (permalink)
Dutch
Humourless EuroMod.
 
Dutch's Avatar
 
Join Date: Mar 2004
Location: City of Mermaids, Denmark
Posts: 6,816
Quote:
Originally Posted by streaker69
Zombie Revival? Discuss the blasé practice of cracking wep?

Where is Devine anyway?
Last I saw him, he was jamming with Elvis at the truckstop orbiting Betelgeuse.

Dutch
__________________
All your answers are belong to Google. SEARCH DAMMIT!
Warning. Warning.
Low C8H10N4O2 level detected. Operator halted....
Dutch is offline  
Old 03-21-2007   #60 (permalink)
ccie4526
My search-fu is weak!
 
ccie4526's Avatar
 
Join Date: Jun 2002
Location: West BFE, Texas
Posts: 410
Quote:
Originally Posted by streaker69
Zombie Revival? Discuss the blasé practice of cracking wep?
Well, Dutch has weighed in on the topic, so I'm guessing it's up to G8t for the two week vacation.
__________________
---
<#include std.disclaimer.h>
AltarThug of Wired and Unwired, The Church of WiFi
http://www.churchofwifi.org
http://www.linuxisforbitches.com
http://www.wigle.net
http://www.kismetwireless.net
ccie4526 is offline  
Closed Thread


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 06:37 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.