Re: dwepcrack

h1kari <[email protected]> Wed, 26 Jun 2002 13:00:38 -0700
Newsgroups gmane.network.wireless.bsd.airtools
Message-ID <B93F6B76.A74A%[email protected]>
Robbo,

Yeah,.. wepcrack.pl doesn't use any brute force techniques for fudging the
probabilities. When I originally looked into it, it looked like it was
mainly for proof-of-concept. Another main diff between wepcrack.pl (and
airsnort/etc) and dwepcrack is that dwepcrack utilizes a lot more weak ivs
that they don't catch. If you look at
http://www.dachb0den.com/projects/bsd-airtools/wepexp.txt it outlines the
methods to make use of almost all of the weak ivs instead of just the ones
collected with the baseline attack. This results in reducing the amount of
packets you need to collect in order to crack the key. The results really
vary, but with my testing with airsnort, I found it usually took around 4
million - 6 million packets, whereas with dwepcrack I could recover a key in
around 1 million - 2 million packets.

-h1kari


On 6/26/02 12:37 PM, "Scott Robson" <[email protected]> wrote:

> Using the wepcrack software on sourceforge (I forget who the author/s
> are) you can generate a series of "weak ivs" than can then be used to
> test the cracking software against. I often found the software could not
> accurately crack a number of keys I gave it. It may be some keys require
> more weak ivs than the authors predict. I don't know much about the
> performance of dwepcrack though.
> 
> Robbo
> 
> On Wednesday, June 26, 2002, at 03:27 PM, h1kari wrote:
> 
>> Doug,
>> 
>> Make sure you're collecting enough weak iv's. You should have at least
>> 20
>> for all of the key bytes in order to crack it in a timely manner. If you
>> have enough, try running with different fudge (-f <num>) values starting
>> from 1, this specifies how far dwepcrack will search for the key in the
>> probabilities tables. If you aren't collecting enough weak ivs, I'm
>> guessing
>> that one of your wireless cards is running a driver that blocks out
>> some of
>> the weak ivs or does the funky iv repeating stuff. If you're still
>> having
>> problems, post more info to the list so we can try and figure out what's
>> going on.
>> 
>> -h1kari
>> 
>> 
>> On 6/26/02 7:40 AM, "Doug Marzano" <[email protected]> wrote:
>> 
>>> I have captured over 2 million packets with dwepdump. The access point
>>> and
>>> mobile UNIT are both setup for WEP with 128 key encryption.
>>> 
>>> I ran it through dwepcrack... and did not recover the key
>>> 
>>> what options should I set on dwepdump and dwepcrack.
>>> 
>>> 
>>> -doug
>>> 
>>> _________________________________________________________________
>>> Join the world’s largest e-mail service with MSN Hotmail.
>>> http://www.hotmail.com
>>> 
>>> _______________________________________________
>>> Bat mailing list
>>> [email protected]
>>> http://lists.dachb0den.com/mailman/listinfo/bat
>>> 
>> 
>> --
>> David Hulton <[email protected]>
>> Senior Researcher, Dachb0den Labs
>> http://www.dachb0den.com
>> 
>> _______________________________________________
>> Bat mailing list
>> [email protected]
>> http://lists.dachb0den.com/mailman/listinfo/bat
>> 
> 
> _______________________________________________
> Bat mailing list
> [email protected]
> http://lists.dachb0den.com/mailman/listinfo/bat
> 

-- 
David Hulton <[email protected]>
Senior Researcher, Dachb0den Labs
http://www.dachb0den.com