RE: V/Scan for Wireless LANs

From: David Nester (david_at_icrew.org)
Date: 07/18/03

  • Next message: Whiteside, Larry [contractor]: "RE: V/Scan for Wireless LANs"
    To: "Ian Chilvers" <Ian.Chilvers@prolateral.com>, <pen-test@securityfocus.com>
    Date: Fri, 18 Jul 2003 11:53:21 -0500
    
    

    This is a pretty good page.....

            http://www.astalavista.com/library/wlan/wlansecurity.htm

    David

    -----Original Message-----
    From: Ian Chilvers [mailto:Ian.Chilvers@prolateral.com]
    Sent: Friday, July 18, 2003 7:19 AM
    To: pen-test@securityfocus.com
    Subject: V/Scan for Wireless LANs

    Hi all

    We've been asked to perform a vulnerability assessment for a company that
    has a Wireless LAN. The W/LAN is running WEP with a random key generated,
    rather than a dictionary word.

    Are there any tools out there that can brute force a WEP.

    Take this example. A person parks the car in the car park and sniffs the
    air waves with a product like NetStumbler. He discovers the W/LAN but with
    WEP.

    Is there a tool he can use to discover the WEP key (possible by brute force)

    If there isn't such a tool, how does this sound for an idea.

    Run a app that starts at binary 0's and counts upto 128bits of 1's
    For each sequence listen to see if there are any sensible packets or even
    send out a DHCP discover request to see if you get a reply. This would then
    possibly give you the WEP key.

    Any comments

    Ian....

    ---------------------------------------------------------------------------
    KaVaDo is the first and only company that provides a complete and an
    integrated suite of Web application security products, allowing you to:
     - assess your entire Web environment with a Scanner,
     - automatically set positive security policies for real-time protection,
       and
     - maintain such policies at the Application Firewall without compromising
    busines performance.

    For more information on KaVaDo and to download a FREE white paper on Web
    applications - security policy automation, please visit:
    http://www.kavado.com/ad.htm
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    KaVaDo is the first and only company that provides a complete and an
    integrated suite of Web application security products, allowing you to:
     - assess your entire Web environment with a Scanner,
     - automatically set positive security policies for real-time protection,
       and
     - maintain such policies at the Application Firewall without compromising busines performance.
     
    For more information on KaVaDo and to download a FREE white paper on Web applications - security policy automation, please visit:
    http://www.kavado.com/ad.htm
    ----------------------------------------------------------------------------


  • Next message: Whiteside, Larry [contractor]: "RE: V/Scan for Wireless LANs"

    Relevant Pages

    • RE: V/Scan for Wireless LANs
      ... I broke WEP in 7 hours by forcing new IVs. ... - automatically set positive security policies for real-time protection, ... For more information on KaVaDo and to download a FREE white paper on Web ...
      (Pen-Test)
    • RE: V/Scan for Wireless LANs
      ... WEPCrack was the first to crack WEP, but Airsnort seems to be a bit more user friendly. ... - automatically set positive security policies for real-time protection, ... For more information on KaVaDo and to download a FREE white paper on Web applications - security policy automation, ...
      (Pen-Test)
    • RE: Know such a webs server tool?
      ... integrated suite of Web application security products, ... automatically set positive security policies ... For more information on KaVaDo and to download a FREE white paper on Web ...
      (Pen-Test)
    • RE: V/Scan for Wireless LANs
      ... WEPCrack was the first to crack WEP, but Airsnort seems to be a bit more user friendly. ... - automatically set positive security policies for real-time protection, ... For more information on KaVaDo and to download a FREE white paper on Web applications - security policy automation, ...
      (Pen-Test)
    • RE: V/Scan for Wireless LANs
      ... Just use Airsnort or Kismet to listen and store the ... U.S. Dept of State, Bureau of Diplomatic Security ... Is there a tool he can use to discover the WEP key ...
      (Pen-Test)