Re: dwepcrack _works_

h1kari <[email protected]> Sat, 26 Oct 2002 18:33:32 -0700
Newsgroups gmane.network.wireless.bsd.airtools
Message-ID <B9E0907C.ED07%[email protected]>
Alan,

That's really interesting.. It should have been a lot faster with the
cracking, is your hardware filtering weak ivs? Also, often times it's better
to crack with a smaller amount of packets because most of the time involves
reading and sorting the packets. dwepcrack in cvs has some patches for 3d
searches that reduces the loading time a lot.

Also, I recently managed to put together a couple techniques of making
encrypted wireless networks generate traffic by injecting certain types of
captured encrypted packets. With this method an attacker can easily crack
almost any wep encrypted wireless network in around 30 min. I'm aiming to
have a bunch of new wep tools as well as a full re-code of dstumbler out
before HiverCon. I'm planning on moving everything over to straight monitor
mode and abandoning all of the scan mode stuff and make dstumbler into more
of an analysis/injection/attack console gui.

If anyone wants to try out the traffic generation tool I'm working on (and
are running openbsd 3.2 and willing to patch your kernel), send me an email
off list and I'll forward you a copy,

Cheers,
-h1kari


On 10/23/02 5:58 PM, "Alan B. Clegg" <[email protected]> wrote:

> Just wanted everyone to know that I cracked a 40 bit WEP key during the
> last week.
> 
> Things to note:
> 
> Collector ran for 6 days collecting (3.6million) packets.
> Cracker ran for just under 96 hours on a 1Ghz Pentium III.
> Fudge factor of 4 was required.
> 
> --SNIP--
> 
>>> dwepcrack -w -f 4 DATA_FILE
> 
> * dwepcrack v0.4 by h1kari <[email protected]> *
> * Copyright (c) Dachb0den Labs 2002 [http://dachb0den.com] *
> 
> reading in captured ivs, snap headers, and samples... done
> total packets: 3606603
> 
> calculating ksa probabilities...
> 0: 85/768 keys
> 1: 44677/131328 keys
> 2: 67325/197376 keys
> 3: 67262/197120 keys
> 4: 112546/328703 keys
> 
> warming up the grinder...
> packet length: 42
> init vector: f0:17:6a
> default tx key: 0
> 
> [..... lots and lots of dots .......]
> 
> wep keys successfully cracked!
> 0: XX:XX:XX:XX:XX *
> done.
> 
> --SNIP--
> 
> The key was proven to work.
> 
> Bravo, all!
> 
> AlanC

-- 
David Hulton <[email protected]>
Senior Researcher, Dachb0den Labs
http://www.dachb0den.com