Re: dwepcrack doesn't
"Tye F. Hammerle" <[email protected]> Wed, 05 Mar 2003 20:12:03 -0600
| Newsgroups | gmane.network.wireless.bsd.airtools |
|---|---|
| Message-ID | <[email protected]> |
After gathering 780mb worth of weak packets over a week and the 0: counter over 400 I've given up on it. Brute force fails as well. Though on an earlier run I was able to brute force it. I was able to finally wrest confirmation from Cisco that they are doing weak iv filtering. They do not advertise it as a feature nor support it. They also don't claim to filter all the weak iv's. Any further info would have to be gotten through an SE or sales manager and probably involve an NDA. I am doing a little experiment with an older 340 series access point and pcmica card to see if that does not have the weak iv filtering. Does anyone know if there is a list or have confirmation of other vendors doing weak iv filtering? Tye h1kari wrote: > Tye, > > It looks like the access point is doing some sort of weak iv filtering > because you're getting a hella lot of duplicates. The numbers with dwepdump > is the total number of packets with weak ivs for the different key bytes, > whereas the numbers in dwepcrack are the number of unique weak ivs (which as > you see are significantly smaller). It might still be possible to crack it, > but you're going to need to collect a lot more packets to get enough unique > weak ivs.. I'll try and build some fast weak iv checking into dwepdump and > such in the next release so it's a little more intuitive. > > I've been able to crack hardware that isn't doing weak iv filtering fairly > fast in both lab and live environments. The iv filtering stuff is tricky, > since I don't know exactly what sort of algorithm the APs and cards are > using to avoid weak ivs. Either way it's really difficult to filter all of > the weak ivs and still have decent network speed and still avoid iv > collisions, so I'm sure there's still some that are sent out. > > I'd be interested to see if you're able to crack it by capturing more > packets. Please let us know if you can get it to work.. > > Thanks, > -h1kari > > > On 2/24/03 17:33, "Tye F. Hammerle" <[email protected]> wrote: > > >>I'm working on cracking wep keys with OpenBSD 3.2 using the bsd-airtools >>package. I've gathered more than enough packets according to what I've >>read yet it seems uncrackable. >> >>I've got a Cisco 340 Access point setup with 40-bit wep (key = >>0101010101 ) no tkip or mic enabled. I have another PC setup with a >>Cisco 350 wireless card. The PC uses a batch file to copy and delete a >>65mb file to a server across the wireless network. It's been running for >>a couple of days now and here's what I've got.; >> >> >>#./dwepdump -w wi0 logfile >> >>* dwepdump v0.2 by h1kari <[email protected]> * >>* Copyright (c) Dachb0den Labs 2002 [http://dachb0den.com] * >> >>starting pcap capture loop... >>device: wi0 >>logfile: logfile >> >>0:6c 1:6589 2:9e5d :: 3183449 >> >> >>According to the above I've got 6c (102 dec) weak packets, well over the >>40 (60 dec) suggested as necessary in the docs. >> >>Now lets see if we can crack it; >> >>#./dwepcrack -w logfile >> >>* dwepcrack v0.4 by h1kari <[email protected]> * >>* Copyright (c) Dachb0den Labs 2002 [http://dachb0den.com] * >> >>reading in captured ivs, snap headers, and samples... done >>total packets: 174324 >> >>calculating ksa probabilities... >>0: 8/768 keys (!) >>1: 2048/131328 keys (!) >>2: 3076/197376 keys (!) >>3: 3076/197120 keys (!) >>4: 5379/328703 keys (!) >> >>(!) insufficient ivs, must have > 60 for each key (!) >>(!) probability of success for each key with (!) < 0.5 (!) >> >>warming up the grinder... >>packet length: 40 >>init vector: 01:03:04 >>default tx key: 0 >> >>progress: ................................................ >> >> >>Yet when I run Dwpecrack, it gets nowhere. I've tried -f 1 through 9. I >>also don't understand the "must have > 60 for each key" what is the n:x >>counter (x) for? I thought that was the weak key counter and I've got 6c >>which is way over the 60. I figure I'm confused. >> >>Before I got this output I ran another capture for about a day getting >>over 20 on (x). Didn't crack. I ran dwepcrack -b and brute forced the >>key in 16 hours. (my laptop is a PII-333) >> >>So, I'm looking to find out what I should be expecting to see for >>numbers from dwepdump. Also, how much of a given is it that once you >>have enough weak keys you can crack the key? Based on what the docs >>tell me and the little I think I have learned, I am getting enough that >>dwepcrack should have cracked the key. >> >>I've read several lists where the people there are saying that there is >>a significant difference between cracking a real live network verses a >>lab test network. Supposedly the real network cracks alot easier. >>Interesting. >> >>Where am I going wrong? > > > _______________________________________________ > Bat mailing list > [email protected] > http://lists.dachb0den.com/mailman/listinfo/bat