Re: WEP Encryption Detection
h1kari <[email protected]> Tue, 16 Jul 2002 21:28:46 -0700
| Newsgroups | gmane.network.wireless.bsd.airtools |
|---|---|
| Message-ID | <B95A408E.AF54%[email protected]> |
Ben, First of all, run dstumbler with the monitor mode enabled: # dstumbler wi0 -o If the wireless network shows up with a red 'w' flag it means it's weped. If the network is running 40-bit with multiple keys and dstumbler picks up traffic that's using keys 2-4 the red 'w' will change to a red '4' which indicates that the network is most likely running 40-bit (since 104-bit networks only allow the use of 1 key). Dstumbler will also indicate which key the nodes are using in the node view (by hitting 'o' to toggle node view) by replacing the red 'w' with the corresponding key (1-3) that they're using. Basically, if you see a '4' it almost guarantees they're running 40-bit, if you see a 'w' it means it could be either. Well, that's the best way I've found of figuring out if a network is running 40-bit.. There might be some better methods but I haven't been able to find them. Also, if you're doing analysis of a wireless network that's running without beacon packets/probe requests (i.e. adhoc \wout management packets) you can determine if they're running wep by examining if the packets have iv and key id fields set (as oppose to a straight snap header after the 802.11b headers) by seeing if the first couple bytes are set to 0xaa. It also probably wouldn't be too difficult to determine if you're looking at an ip header or just encrypted jibba-jabbah. Happy hunting, -h1kari P.S. Btw, I'm back from vacation so I'm gonna start working more on integrating everything better. Sorry if some things are broken atm. On 7/16/02 10:51 AM, "[email protected]" <[email protected]> wrote: > Hi all, > I've successfully set up a system. > CPQ M300 > OpenBSD 3.1-current (thank you jsyn) > Linksys WPC11 (v2.5) - Prism 2.5 chipset > > 1. How can I detect if the network traffic is using WEP or is being sent > clear-text? > > 2. If it is detected is there any way of determining what level of > encryption is being used (40bit vs 104bit) without actually breaking the > encryption? > > -benh > > _______________________________________________ > Bat mailing list > [email protected] > http://lists.dachb0den.com/mailman/listinfo/bat > -- David Hulton <[email protected]> Senior Researcher, Dachb0den Labs http://www.dachb0den.com