Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 29 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow WEP cracking, how to ping router?
EH-Net
May 25, 2013, 01:28:41 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: WEP cracking, how to ping router?  (Read 15976 times)
0 Members and 1 Guest are viewing this topic.
duffman984
Newbie
*
Offline Offline

Posts: 7


View Profile
« on: January 09, 2009, 10:37:00 AM »

I've learned a lot about cracking WEP keys and have all of my software and hardware configured to do it properly. I'm looking for a way to ping a router that I am not connected/authenticated to. I can see the AP and actually know the key since I set it up but I want to treat this like I know nothing about it.

Is there a way to get the WAN address easily. I've tried AiroPeek and OmniPeek as well as Nessus but I haven't messed with them long enough to really figure it out. I can get the MAC for the AP by using NetStumbler but can't get a host to ping to create traffic.
Logged
jimbob
Guest
« Reply #1 on: January 09, 2009, 01:39:37 PM »

Hi,
If you want to know the network addresses being used on a WEP network you can decrypt some captured packets using the key. Both Kismet and Wireshark support entry of WEP keys to view the decrypted data.

You won't be able to 'ping' the router until you're on the network i.e. have you card set up with the correct essid, channel, WEP key etc. It's the same as if you're on a wired network. You can create a ping packet without having an IP address and inject this onto the network, but you might not see the reply.

Regards,
Jimbob
Logged
duffman984
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #2 on: January 09, 2009, 05:09:38 PM »

Is there a way to speed up the process of capturing packets and IVs? I used my internal card and connected to the network and sent an ICMP ping flood which really sped up the process and I got about 500,000 IVs in under 5 minutes which made cracking the key almost effortless.

I of course want to pentest this so without any clients on this AP can I speed the process up without being connected?
Logged
Vertigo
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #3 on: January 12, 2009, 06:09:32 AM »

Is there a way to speed up the process of capturing packets and IVs? I used my internal card and connected to the network and sent an ICMP ping flood which really sped up the process and I got about 500,000 IVs in under 5 minutes which made cracking the key almost effortless.

I of course want to pentest this so without any clients on this AP can I speed the process up without being connected?

i heve a expierence to crack deiferent WEP protected connections: Open, Shared key.  My best choice to collect enough IV's(40 000-90 000) is one:
arp request replay attack with :
aireplay-ng -3 - b bssid_mac_address -h 00:11:22:33:44:55 ath0
Logged
Kev
Sr. Member
****
Offline Offline

Posts: 428


View Profile
« Reply #4 on: January 12, 2009, 11:46:12 AM »

The aircrack-ng site has all the answers you need. Pinging your router is really only good for a proof of concept and not really practical and certainly not very stealth. Aircrack has what you need to inject the proper packets.
Logged
duffman984
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #5 on: January 12, 2009, 10:19:10 PM »

The aircrack-ng site has all the answers you need. Pinging your router is really only good for a proof of concept and not really practical and certainly not very stealth. Aircrack has what you need to inject the proper packets.

Good suggestion. I found the info you are talking about so I'll read up on it and give it a try. Thanks!
Logged
Soolari
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #6 on: March 07, 2009, 08:51:28 AM »

Do..This kismet and wireshark wrk on windows cause i need 2 use it..anybDy plz
Logged
NickFnord
Full Member
***
Offline Offline

Posts: 117



View Profile WWW
« Reply #7 on: March 07, 2009, 11:08:44 AM »

*clears voice*

Stand back everyone, I'm going to attempt to communicate with him.

do0d u liek need to l3rn hw 2 serch da web n stuff.  haxoring ait summing dat u can jus rely on other ppl 2 hld ur hand until u lern u got ta do sum wrk urself.
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #8 on: March 07, 2009, 11:38:04 AM »

*clears voice*

Stand back everyone, I'm going to attempt to communicate with him.

do0d u liek need to l3rn hw 2 serch da web n stuff.  haxoring ait summing dat u can jus rely on other ppl 2 hld ur hand until u lern u got ta do sum wrk urself.

LOL!
Logged

~~~~~~~~~~~~~~
Ketchup
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #9 on: March 07, 2009, 04:54:08 PM »

Do..This kismet and wireshark wrk on windows cause i need 2 use it..anybDy plz
Definitely sounds like a question to type in to Google.
Logged

eCPPT, GCIH, OSCP, OSWP
Soolari
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #10 on: March 12, 2009, 08:14:35 PM »

Hey guyz i saw a wireless in my schl that iz security enabled plz hw do i bypass that hlp..Any1
Logged
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 928



View Profile WWW
« Reply #11 on: March 13, 2009, 06:49:58 AM »

Hey guyz i saw a wireless in my schl that iz security enabled plz hw do i bypass that hlp..Any1
Simple, ask the network admin for the security keys.
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #12 on: March 18, 2009, 08:13:43 AM »

Hey guyz i saw a wireless in my schl that iz security enabled plz hw do i bypass that hlp..Any1
Simple, ask the network admin for the security keys.

Easy, huh?   Wink 

Soolari, I might add for you - this site is ethicalhacker.net.  Keyword, 'ethical.'  While we can all remember times where we've seen access points in places, and thinking, 'what if I could just crack that, for fun or whatever?' to say you've seen 'a wireless in my schl that iz security enabled plz hw do i bypass that hlp' leads me to believe you have neither asked for, nor have a true need for, permission to access it.  I don't think you'll find much support or advice from us, when your intentions aren't for the right reasons.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
munkeyfreenix .batcat
Newbie
*
Offline Offline

Posts: 11



View Profile
« Reply #13 on: April 03, 2009, 01:49:16 AM »

if you want to know how to use a program, read everything you can find about it (on their website, their forums, and so on), then when it still doesn't work, post half your /etc and a dmesg or two. it is actually a whole lot more entertaining/engaging that way. and posting that you have imaginings of penetrating networks unauthorized online, not such a good idea.

besides, whats the point in cracking a password if you can just ask for it? err...

letting your school's administrator know if the network is unnecessarily at risk could be good, if you're intending to learn the tools/skills to offer that service. but if you're not willing to do some research (and learn linux), good luck with aircrack...
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.1 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.