Penetration Testing mailing list archives

Cracking WEP and WPA keys


From: Eduardo Espina <eduardomx () gmail com>
Date: Tue, 13 Dec 2005 09:55:30 -0600



I cracked my own WEP a few months ago, I just needed to collect about 800,000
IVs with airodump, then ran aircrack and I got the key in less than one second.
(104 bit WEP) By the way, i collected the whole traffic in 2 hours.

It doesn't just depend on the number of collected IVs, but the weak IVs and your
hardware. My frist try was using a 3Com Card, but I wasn't collecting enough
IVs, then I tried with a Prism2 Intersil card and it was done.

You should give it more time to the airodump stage than to the aircrack one.

Greetings,
Eduardo.

--
Eduardo Espina Garcia <eespina () seguridad unam mx>
Departamento de Seguridad en Computo - UNAM-CERT DGSCA, UNAM
http://www.seguridad.unam.mx  Tel.: 5622-8169  Fax: 5622-8043
GPG Key Fingerprint: "8E86 932F C364 03BE 39B8  3F9D D27E 438A 3C6A 750F"
"No matter how hard you try to keep your secret, it's a universal
law that sooner or later it will be discovered."

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 

Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: