NetStumbler.org Forums

Go Back   NetStumbler.org Forums > Software > Unix/Linux
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 01-16-2005   #1 (permalink)
opr__
Registered Member
 
Join Date: Sep 2004
Posts: 1
weplab/aircrack

Hi all,

here is my problem:
I have a wifi protected with WEP 128 bits key for testing. I first dumped about 300k packets with Kismet using regular traffic (ftp-data). Here is the output of the statistics with weplab:

# ./weplab -a ../Kismet-Jan-15-2005-1.dump
weplab - Wep Key Cracker Wep Key Cracker (v0.1.3).
Jose Ignacio Sanchez Martin - Topo[LB] <topolb@users.sourceforge.net>


Statistics for packets that belong to [00:05:5D:5C:21:9A]
- Total valid packets read: 321344
- Total packets read: 321344
- Total unique IV read: 321344
- Total truncated packets read: 0
- Total non-data packets read: 0
- Total FF checksum packets read: 0

The next day, I again dumped traffic but now using 'ping -f' to generate as much traffic as fast as possible on the wireless. The statistics output of weplab:

# ./weplab -a ../Kismet-Jan-16-2005-1.dump
weplab - Wep Key Cracker Wep Key Cracker (v0.1.3).
Jose Ignacio Sanchez Martin - Topo[LB] <topolb@users.sourceforge.net>


Statistics for packets that belong to [00:05:5D:5C:21:9A]
- Total valid packets read: 277546
- Total packets read: 277546
- Total unique IV read: 277546
- Total truncated packets read: 0
- Total non-data packets read: 0
- Total FF checksum packets read: 0

Now, I both ran weplab and aircrack (with default fudge factor) and even after 9 hours, the key of the first dump could not be found. When I ran weplab and aircrack on the second dump, he cracked it within 5 minutes. How is this possible? The first dump has even more unique IV's than the second dump ... anyone has a reasonable explanation for this?

btw, does anyone know a tool which can replay packets on the wifi interface on BSD? Because most of the tools like aireplay and chopchop use the netpacket interface which is nonexistant on BSD. I did manage to get weplab (only the cracking, not dumping of packets) and aircrack (again, only aircrack and 802ether, not dumping) working on OpenBSD.

regards

Last edited by opr__ : 01-16-2005 at 09:59 AM.
opr__ is offline   Reply With Quote
Old 01-17-2005   #2 (permalink)
grcore
Member at large
 
grcore's Avatar
 
Join Date: Aug 2004
Posts: 121
Quote:
Originally Posted by opr__
Now, I both ran weplab and aircrack (with default fudge factor) and even after 9 hours, the key of the first dump could not be found. When I ran weplab and aircrack on the second dump, he cracked it within 5 minutes. How is this possible? The first dump has even more unique IV's than the second dump ... anyone has a reasonable explanation for this?
It's not always a matter of how many IVs you collect. There is some luck involved. Depending on the distribution of IVs, the number of keys that need to be tried can vary. In my tests, it the number of IVs collected has varied from as little as 80k and as high as 800k to discover a 64bit key. Most of the time the key is found somewhere in the 100-200krange.

g
grcore is offline   Reply With Quote
Old 01-19-2005   #3 (permalink)
rjdenver
Registered Member
 
rjdenver's Avatar
 
Join Date: Nov 2004
Posts: 110
Quote:
Originally Posted by grcore
It's not always a matter of how many IVs you collect. There is some luck involved. Depending on the distribution of IVs, the number of keys that need to be tried can vary. In my tests, it the number of IVs collected has varied from as little as 80k and as high as 800k to discover a 64bit key. Most of the time the key is found somewhere in the 100-200krange.

g
Just to add some stats to that, I got my first test of my 64bit key to crack with 100k IVs in about 5 seconds. I tried my 128bit key with 100k packets, and after about 5 hours gave up and made 100k more packets. With the 200k, it cracked in 3 hours.

I notice my actiontec also has a 256bit key. Maybe that's next.

Rj
rjdenver is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 07:09 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.