Re: WEP Encryption Detection

h1kari <[email protected]> Tue, 16 Jul 2002 21:28:46 -0700
Newsgroups gmane.network.wireless.bsd.airtools
Message-ID <B95A408E.AF54%[email protected]>
Ben,

First of all, run dstumbler with the monitor mode enabled:

# dstumbler wi0 -o

If the wireless network shows up with a red 'w' flag it means it's weped. If
the network is running 40-bit with multiple keys and dstumbler picks up
traffic that's using keys 2-4 the red 'w' will change to a red '4' which
indicates that the network is most likely running 40-bit (since 104-bit
networks only allow the use of 1 key). Dstumbler will also indicate which
key the nodes are using in the node view (by hitting 'o' to toggle node
view) by replacing the red 'w' with the corresponding key (1-3) that they're
using. Basically, if you see a '4' it almost guarantees they're running
40-bit, if you see a 'w' it means it could be either.

Well, that's the best way I've found of figuring out if a network is running
40-bit.. There might be some better methods but I haven't been able to find
them. 

Also, if you're doing analysis of a wireless network that's running without
beacon packets/probe requests (i.e. adhoc \wout management packets) you can
determine if they're running wep by examining if the packets have iv and key
id fields set (as oppose to a straight snap header after the 802.11b
headers) by seeing if the first couple bytes are set to 0xaa. It also
probably wouldn't be too difficult to determine if you're looking at an ip
header or just encrypted jibba-jabbah.

Happy hunting,
-h1kari

P.S. Btw, I'm back from vacation so I'm gonna start working more on
integrating everything better. Sorry if some things are broken atm.


On 7/16/02 10:51 AM, "[email protected]"
<[email protected]> wrote:

> Hi all,
> I've successfully set up a system.
> CPQ M300
> OpenBSD 3.1-current (thank you jsyn)
> Linksys WPC11 (v2.5)  - Prism 2.5 chipset
> 
> 1. How can I detect if the network traffic is using WEP or is being sent
> clear-text?
> 
> 2. If it is detected is there any way of determining what level of
> encryption is being used (40bit vs 104bit) without actually breaking the
> encryption?
> 
> -benh
> 
> _______________________________________________
> Bat mailing list
> [email protected]
> http://lists.dachb0den.com/mailman/listinfo/bat
> 

-- 
David Hulton <[email protected]>
Senior Researcher, Dachb0den Labs
http://www.dachb0den.com