Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 37 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow WEP Cracking
EH-Net
May 20, 2013, 11:29:01 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: WEP Cracking  (Read 7842 times)
0 Members and 1 Guest are viewing this topic.
eth3real
Sr. Member
****
Offline Offline

Posts: 309



View Profile WWW
« on: November 16, 2011, 10:53:01 AM »

Hi Everyone,

I know it's an old subject, but if anyone is in the US, in the Jacksonville, FL area, come to the Jacksonville Linux Users Group tonight. I'm doing a presentation on the security flaws of the WEP protocol, and demonstrate how easy it is to subvert. Details and slides at the link below:

http://www.hacksonville.com/?p=134

Thanks!  Grin
Logged

Put that in your pipe and grep it!
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #1 on: November 16, 2011, 11:26:49 AM »

I can't make it, but if you run in to anyone still using WEP, please slap them for me.   Grin
Logged

Poking at security since 1986.  +++ATH
eth3real
Sr. Member
****
Offline Offline

Posts: 309



View Profile WWW
« Reply #2 on: November 16, 2011, 11:40:06 AM »

+1 rance
Unfortunately, I still see WEP networks all over the place. Sad
Logged

Put that in your pipe and grep it!
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 208



View Profile
« Reply #3 on: November 16, 2011, 01:39:40 PM »

See them all the time.  If we're doing a wireless assessment and the client is in a dense area (tall building, office park, etc) we'll find at least half a dozen WEP APs from various other companies that share the facility.  Heaven help you if the client's building is downtown near apartments.  Not only do you have to bust out the directionals in order to make sure those APs are not inside the client's area, you also need to explain to them why the raw outputs you include in your work papers show AP names like "I [blanked] your sister" and "I have a giraffe [male genitalia]". 
Logged

CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
eth3real
Sr. Member
****
Offline Offline

Posts: 309



View Profile WWW
« Reply #4 on: November 17, 2011, 01:36:36 PM »

My presentation went really well, I got a lot of positive feedback. This was my first presentation, by the way. Grin

pseud0, I'm curious now. Do outside wifi networks affect a pentest at all? I know you would be looking for rogue APs internally, but I'm curious about outside networks. I also got to show off a homemade directional antenna at my presentation, pretty cool stuff.

rance, nobody would admit to still using WEP. Tongue
Logged

Put that in your pipe and grep it!
3xban
Hero Member
*****
Offline Offline

Posts: 605


View Profile WWW
« Reply #5 on: November 17, 2011, 02:55:19 PM »

There are alot of vendor products that use WEP for Scan guns.  I have a few of those were I am and it drives me batty.  Thankfully if you compromise them you won't get much and you won't get on the main network.  But still, c'mon vendors get with it! 
Logged

Certs: GCWN
(@)Dewser
lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #6 on: November 17, 2011, 03:18:28 PM »

There are alot of vendor products that use WEP for Scan guns.  I have a few of those were I am and it drives me batty.  Thankfully if you compromise them you won't get much and you won't get on the main network.  But still, c'mon vendors get with it! 

I was fighting this battle for awhile until we had another problem with our scan guns and I convinced my boss to upgrade the scan guns rather than just replacing them with used ones.
Logged

GSEC, eCPPT, Sec+
eth3real
Sr. Member
****
Offline Offline

Posts: 309



View Profile WWW
« Reply #7 on: November 17, 2011, 06:50:23 PM »

What's even worse is wireless security cameras that use WEP. Shocked
Logged

Put that in your pipe and grep it!
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 208



View Profile
« Reply #8 on: November 18, 2011, 08:13:41 AM »

The only really significant problem we run into with the "outside" APs is proving that they are "outside".  If you're looking for rogue access points it can get really difficult to figure out what might actually be on the client network and what is actually sitting at the law firm the floor above or the hedge fund the floor below.  The secondary risk for finding open access points outside of the client network is that employees might connect to it so that they can visit internet sites that are blocked by the corporate network.  They can get infected and then reconnect to the corporate network and cause a breach. 
Logged

CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
3xban
Hero Member
*****
Offline Offline

Posts: 605


View Profile WWW
« Reply #9 on: November 18, 2011, 08:14:25 AM »

What's even worse is wireless security cameras that use WEP. Shocked

No those are great  Wink

Over at BsidesDE this past weekend there was a talk by InfoSecJanitor that was really cool and scary.  Many manufacturers of cars, appliances and electronics are continuing to use WiFi based communications for various services.  WiFi light bulbs, tire pressure censors, Refrigerators able to call in parts servicing for you.  Freaky stuff!  
Logged

Certs: GCWN
(@)Dewser
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.066 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.