Re: dwepcrack
h1kari <[email protected]> Wed, 26 Jun 2002 13:00:38 -0700
| Newsgroups | gmane.network.wireless.bsd.airtools |
|---|---|
| Message-ID | <B93F6B76.A74A%[email protected]> |
Robbo, Yeah,.. wepcrack.pl doesn't use any brute force techniques for fudging the probabilities. When I originally looked into it, it looked like it was mainly for proof-of-concept. Another main diff between wepcrack.pl (and airsnort/etc) and dwepcrack is that dwepcrack utilizes a lot more weak ivs that they don't catch. If you look at http://www.dachb0den.com/projects/bsd-airtools/wepexp.txt it outlines the methods to make use of almost all of the weak ivs instead of just the ones collected with the baseline attack. This results in reducing the amount of packets you need to collect in order to crack the key. The results really vary, but with my testing with airsnort, I found it usually took around 4 million - 6 million packets, whereas with dwepcrack I could recover a key in around 1 million - 2 million packets. -h1kari On 6/26/02 12:37 PM, "Scott Robson" <[email protected]> wrote: > Using the wepcrack software on sourceforge (I forget who the author/s > are) you can generate a series of "weak ivs" than can then be used to > test the cracking software against. I often found the software could not > accurately crack a number of keys I gave it. It may be some keys require > more weak ivs than the authors predict. I don't know much about the > performance of dwepcrack though. > > Robbo > > On Wednesday, June 26, 2002, at 03:27 PM, h1kari wrote: > >> Doug, >> >> Make sure you're collecting enough weak iv's. You should have at least >> 20 >> for all of the key bytes in order to crack it in a timely manner. If you >> have enough, try running with different fudge (-f <num>) values starting >> from 1, this specifies how far dwepcrack will search for the key in the >> probabilities tables. If you aren't collecting enough weak ivs, I'm >> guessing >> that one of your wireless cards is running a driver that blocks out >> some of >> the weak ivs or does the funky iv repeating stuff. If you're still >> having >> problems, post more info to the list so we can try and figure out what's >> going on. >> >> -h1kari >> >> >> On 6/26/02 7:40 AM, "Doug Marzano" <[email protected]> wrote: >> >>> I have captured over 2 million packets with dwepdump. The access point >>> and >>> mobile UNIT are both setup for WEP with 128 key encryption. >>> >>> I ran it through dwepcrack... and did not recover the key >>> >>> what options should I set on dwepdump and dwepcrack. >>> >>> >>> -doug >>> >>> _________________________________________________________________ >>> Join the worlds largest e-mail service with MSN Hotmail. >>> http://www.hotmail.com >>> >>> _______________________________________________ >>> Bat mailing list >>> [email protected] >>> http://lists.dachb0den.com/mailman/listinfo/bat >>> >> >> -- >> David Hulton <[email protected]> >> Senior Researcher, Dachb0den Labs >> http://www.dachb0den.com >> >> _______________________________________________ >> Bat mailing list >> [email protected] >> http://lists.dachb0den.com/mailman/listinfo/bat >> > > _______________________________________________ > Bat mailing list > [email protected] > http://lists.dachb0den.com/mailman/listinfo/bat > -- David Hulton <[email protected]> Senior Researcher, Dachb0den Labs http://www.dachb0den.com