RE: Testing WEP Key on pcap dump

From: Jerry Shenk (jshenk_at_decommunications.com)
Date: 04/22/04

  • Next message: Jeremiah Cornelius: "RE: MBSA scanner"
    To: <pen-test@securityfocus.com>
    Date: Wed, 21 Apr 2004 21:13:55 -0400
    
    

    There is a decrypt utility that comes with Airsnort that will do that.
    I believe the latest version of kismet will also decrypt data when it's
    given a WEP key. It can also pull in a dump file so it seems like that
    should work too but I haven't do it that way.

    -----Original Message-----
    From: Jason Ostrom [mailto:jpo@pobox.com]
    Sent: Wednesday, April 21, 2004 12:42 PM
    To: pen-test@securityfocus.com
    Subject: Testing WEP Key on pcap dump

    Does anyone know of a quick method or automated tool for accomplishing
    the following:
    I have a pcap dump using Kismet Wireless sniffer on a BSSID using
    128-bit WEP encryption. If I think I know the 26 character HEX WEP
    key, is there a way to easily decrypt all of the traffic for a
    specific BSSID based on input of this WEP key, and then display the
    decrypted pcap output in Ethereal? Or another way of seeing if this
    WEP key is able to decrypt from the pcap dump for that specific BSSID?

    Jason

    ------------------------------------------------------------------------
    ------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545
    off
    any course! All of our class sizes are guaranteed to be 10 students or
    less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of
    in-the-field
    pen testing experience in our state of the art hacking lab. Master the
    skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ------------------------------------------------------------------------
    -------

    ------------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    -------------------------------------------------------------------------------


  • Next message: Jeremiah Cornelius: "RE: MBSA scanner"

    Relevant Pages

    • Re: Testing WEP Key on pcap dump
      ... >> I have a pcap dump using Kismet Wireless sniffer on a BSSID using ... >> specific BSSID based on input of this WEP key, ... >> WEP key is able to decrypt from the pcap dump for that specific BSSID? ...
      (Pen-Test)
    • Re: WEP key wrong and static IP address setting
      ... ~> a mismatched WEP key ... ... I see that the card is logging a decrypt ... the "wrong" WEP key. ... See 802.11-1999 sec. 8.2.3 for how the incoming frame is decrypted in WEP. ...
      (alt.internet.wireless)
    • Re: WEP key wrong and static IP address setting
      ... I see that the card is logging a decrypt ... ~ What did the wrong encrypted packet come from? ... the "wrong" WEP key. ... If the calculated ICV does not match the ICV received in the frame, ...
      (alt.internet.wireless)
    • Re: WEP key wrong and static IP address setting
      ... I see that the card is logging a decrypt ... ~ What did the wrong encrypted packet come from? ... the "wrong" WEP key. ... I wonder when it is happening, what packets will send to the station ...
      (alt.internet.wireless)