[Full-Disclosure] Reading WEP-Key from Win 2000 Network Config

From: Marcel Krause (marcel_k_at_web.de)
Date: 05/18/04

  • Next message: ktabic: "RE: [Full-Disclosure] Support the Sasser-author fund started"
    To: Full Disclosure <full-disclosure@lists.netsys.com>
    Date: Tue, 18 May 2004 23:25:19 +0200
    
    

    Hi!

    I'm just playing around with my wireless LAN config in Windows 2000
    Professional. There is some security dialog where you can enter your
    WEP key in 26 hex digits. You may enter them but not read them because
    they are masked with ***. I have a tool which reads the plaintext of
    such password boxes but in this case it is not applicable because the
    code surrenders as soon as the box receives the focus.

    Solution: enter sobe chars that are not hex digits. You will receive
    an error message. Select a different one of the 4 av/ keys. It will
    be shown in plaintext.

    Is this fresh news? Is it exploitable remotly, meaning without sitting
    in front of the box?

    Yours, Marcel

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: ktabic: "RE: [Full-Disclosure] Support the Sasser-author fund started"

    Relevant Pages

    • RE: V/Scan for Wireless LANs
      ... Just use Airsnort or Kismet to listen and store the ... U.S. Dept of State, Bureau of Diplomatic Security ... Is there a tool he can use to discover the WEP key ...
      (Pen-Test)
    • Re: wep problems
      ... Well, since you're a writer on security, perhaps you can explain why ... have done more than a few dry runs. ... they can crack a WEP key under almost ideal circumstance. ... email messages that were in the capture file. ...
      (alt.internet.wireless)
    • Re: Walmart using WEP
      ... Not a very good security practice. ... I don't see how cracking the WEP key used by their inventory scanners is ... Download FREE whitepaper on how a managed service can ...
      (Pen-Test)
    • WEP attacks based on IV Collisions
      ... kismet sniffer and steadily increasing IV Collisions. ... to actually determine the WEP key if you have zero knowledge about the ... to Decrypt Traffic", if you have a known keystream with one known plaintext, then it looks ...
      (Pen-Test)
    • WEP attacks based on IV Collisions
      ... kismet sniffer and steadily increasing IV Collisions. ... to actually determine the WEP key if you have zero knowledge about the ... to Decrypt Traffic", if you have a known keystream with one known plaintext, then it looks ...
      (Pen-Test)