EvilZone

Hacking and Security => Tutorials => : iTpHo3NiX November 26, 2010, 06:35:30 AM

: Hacking WEP with Backtrack4 Final and Airoscript
: iTpHo3NiX November 26, 2010, 06:35:30 AM
///////////////////////////////////////////////////////////////////////////////////////
Title: Hacking WEP with Backtrack4 Final and Airoscript
Paper by: iTpHo3NiX
///////////////////////////////////////////////////////////////////////////////////////

NOTE
When cracking the network from the screenshots, I had permission from my neighbor to pen test their wireless encryption and to write this paper. It is illegal to hack wireless networks without encryption, however if you would like to help secure your neighbors network (as I did and help him set up a MAC filter after this with a WPA2 encryption). Then take a look and show them this. Also hopefully this will also educate you in wireless security.

Method
The simplest way (and a good way to show potential customers how easy it is to actually hack their wireless networks) to hack a WEP encrypted network is using Backtrack4 Final with Airoscript. Airoscript utilizes the aircrack-ng suite to automate WEP/WPA hacking (although WPA, best thing to do is use it to capture the handshake file, go offsite and use John the Ripper to bruteforce, or cowpatty to run a dictionary attack against the handshake file).

Devices Used

Hint
With the final release of Backtrack4 there seems to be an error with Airoscript (just a very slight one) that requires you to navigate to the tmp directory after scan and change the extention of dump-01.cvs to dump-01.txt for airoscript to recognize the dump file to select which network you would like to attack.

The Process

Step One
Open the KDE Start Menu (after loading the desktop using startx) and navigate to "Backtrack-->Raido Network Analysis-->80211-->Cracking-->Airoscript"

(http://i51.tinypic.com/feq8op.jpg)

Step Two
Select your screen resolution (I chose 4)

Step Three
Select your wireless device. In most cases its wlan0, however since I'm using my Linksys WUSB54GC its going to be wlan1 and when prompted to put device into monitor mode, select "y" for yes.

(http://i56.tinypic.com/2lmt9qr.jpg)

Step Four
Now you are at the main Airoscript page to select your options. Now normally option 9 which will go through the first three steps is not working out of the box with the final live cd (unless updated to the latest airoscript and the latest aircrack-ng suite) so we are manually going to go through the steps (however its still just as simple) So lets select option 1 to scan.

(http://i56.tinypic.com/1zdryih.jpg)

Step Five
The next page asks you if you would like to apply a filter, since this is a paper on WEP cracking then I am going to select a filter for WEP (option 3) then to select whether you want it to scan on a specific channel or to scan all channels (via Channle Hopping or option 1)

(http://i56.tinypic.com/102kpiw.jpg)

This will open up a new window that is now scanning for targets

(http://i52.tinypic.com/30aqo0j.jpg)

Step Six
Once you've picked up a few networks and have a target you would like to attack (I would note the BSSID and the ESSID with multiple options so you go after ther proper network. Close the scanning window. Now as I stated before unless you have an updated Airoscript/aircrack-ng you will need to go to the temp folder and rename the dump-01.cvs to dump-01.txt To do this simply open Konqueror (right next to the KDE start menu) Click on "Home Folder" you will be in /root and then you will want to go up a folder to just / go into the tmp folder then go into the tmp.RANDOMCHARACTOR folder right click on dump-01.cvs and click rename, then change the extention to dump-01.txt and you can now close Konqueror and continue with Airoscript.

Step Seven
Now we select option 2 to simply select our target then you have a numbered list to select which network you would like to attack

(http://i55.tinypic.com/a3jk0o.jpg)

Step Eight
Now I choose option 1 to select the associated client

(http://i53.tinypic.com/2vk0yva.jpg)

Step Nine
Now we go for the attack so choose option 3, now this can vary for everyone, I personally choose option 1 which is a Fake authorization without user input (no need to select packets, a more automated attack)

(http://i56.tinypic.com/fo3vrq.jpg)

Which will open up the following windows

(http://i54.tinypic.com/qpicep.jpg)

Now I also like to run another attack at the same time, so select option 3 again, however this time I choose option 7 which is an ARP Replay which is again automatic so no user interaction.

Now its a waiting game and you will be having a window like this

(http://i56.tinypic.com/24m9n5k.jpg)

Now this is just personal preference, you can start the cracking as soon as you get at least 1 ACK, however I like to wait until I get at least 100,000+ ACKs (usually 200,000+)

Step 10
Now its time for the actual cracking (option 4) So you select option 4, then option 1 at the following screen for a PTW crack and soon you will have the WEP encryption key like this

(http://i55.tinypic.com/f2vnr5.jpg)

Tutorial by iTpHo3NiX of EvilZone.org This is for educational purposes ONLY and is not to be abused. Hopefully this will pursued people to change their wireless configuration to run a MAC filter with WPA2 to help their internet to not be stolen.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: shijinmrx January 15, 2011, 03:58:55 PM
i know its illegal to hack to a network n use it without there permissions..
But i hacked one of my friends wep networks.we had a bet for 50$..the problem is that when i connect..it is showing limited connectivity. when i looked upon the status..the default gateway appears to b 0.0.0.0..
so i thnk its not connected to the Router(it also shows unidentified network)..Please help me..
How to find the ip adress of the router..i can no way acess his computer or router...
i used bactrack to find WEP Key..
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: ande January 15, 2011, 04:23:28 PM
i know its illegal to hack to a network n use it without there permissions..
But i hacked one of my friends wep networks.we had a bet for 50$..the problem is that when i connect..it is showing limited connectivity. when i looked upon the status..the default gateway appears to b 0.0.0.0..
so i thnk its not connected to the Router(it also shows unidentified network)..Please help me..
How to find the ip adress of the router..i can no way acess his computer or router...
i used bactrack to find WEP Key..

Tried the default ones? :P 10.0.0.1 | 192.168.0.1

If those does not work, do a range scan on 10.0. and 192.168. and you should get something.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: a12danrulz January 16, 2011, 11:20:43 PM
This is one HELL of a tut man! Time to hack into my own wifi network. Quick question though. Could this be done from VMware? I have mine set to share my laptops network and it's never asked for a password eventhough Im getting Internet from it and it shows up when I scan. Would I have to disconnect my laptop from the network first?
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: FuyuKitsune January 17, 2011, 03:37:08 AM
This is one HELL of a tut man! Time to hack into my own wifi network. Quick question though. Could this be done from VMware? I have mine set to share my laptops network and it's never asked for a password eventhough Im getting Internet from it and it shows up when I scan. Would I have to disconnect my laptop from the network first?
It should work from a VM. I know that VirtualBox puts the NIC in monitor mode to create a virtual card, I'm not so sure how VMware does it.


Really nice tut. I should get that USB wifi adapter, my stupid card doesn't support monitor/promiscuous without finding some old Linux drivers.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: a12danrulz January 17, 2011, 03:12:55 PM
Yeah I meant virtualbox. I hate autocorrect sometimes.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: iTpHo3NiX January 18, 2011, 02:42:51 AM
It should work from a VM. I know that VirtualBox puts the NIC in monitor mode to create a virtual card, I'm not so sure how VMware does it.


Really nice tut. I should get that USB wifi adapter, my stupid card doesn't support monitor/promiscuous without finding some old Linux drivers.

http://www.newegg.com/Product/Product.aspx?Item=N82E16833124187&nm_mc=OTC-Froogle&cm_mmc=OTC-Froogle-_-Network+-+Wireless+Adapters-_-Linksys-_-33124187 (http://www.newegg.com/Product/Product.aspx?Item=N82E16833124187&nm_mc=OTC-Froogle&cm_mmc=OTC-Froogle-_-Network+-+Wireless+Adapters-_-Linksys-_-33124187)

;-) I love my card, works like a champ
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: Ghat c0mrade2 March 01, 2011, 04:39:44 PM
u copy/paste it
try to put the source next time  ;)
http://myhackingway.blogspot.com/2011/02/hacking-wep-with-backtrack4-final-and.html (http://myhackingway.blogspot.com/2011/02/hacking-wep-with-backtrack4-final-and.html)

btw nice tut
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: ande March 01, 2011, 04:54:32 PM
u copy/paste it
try to put the source next time  ;)
http://myhackingway.blogspot.com/2011/02/hacking-wep-with-backtrack4-final-and.html (http://myhackingway.blogspot.com/2011/02/hacking-wep-with-backtrack4-final-and.html)

btw nice tut

I highly doubt that.

Hacking WEP with Backtrack4 Final and Airoscript
« on: November 26, 2010, 06:35:30 am »

Saturday, February 12, 2011
Hacking WEP with Backtrack4 Final and Airoscript
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: iTpHo3NiX March 01, 2011, 11:50:29 PM
Lol I copy and pasted my own tut lol. I even posted this on the OLD evilzone!

http://evilzone.org/archive/new/tutorials/hacking-wep-with-backtrack-4-final-and-airoscript/ (http://evilzone.org/archive/new/tutorials/hacking-wep-with-backtrack-4-final-and-airoscript/)

Hacking WEP with Backtrack 4 Final and Airoscript
« on: March 31, 2010, 04:12:13 am »

I posted that almost a year ago. They copy and pasted off of me :P

So thank you try again
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: Satan911 March 02, 2011, 01:10:06 AM
I shall try it later today (If my backtrack live USB still works). This and easy tut.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: LucaBrassi June 19, 2011, 07:34:32 PM
Can anyone give an updated source to download backtrack4 with airoscript because the links don't work and I could not find it when I searched with Google.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: Kulverstukas June 19, 2011, 07:51:17 PM
Use BackTrack5 instead. You can get it here: http://www.backtrack-linux.org/downloads/ (http://www.backtrack-linux.org/downloads/)
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: noob June 20, 2011, 12:41:03 AM
Why dont do it more easy(Gerix is a part of Backtrack 4-5):
(http://4.bp.blogspot.com/-DfJAgCGWeHo/TdqQAohtQiI/AAAAAAAAAME/HmCVwktdCR8/s1600/STEP%2B8.JPG)
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: ande June 20, 2011, 12:53:40 AM
Why dont do it more easy(Gerix is a part of Backtrack 4-5):
(http://4.bp.blogspot.com/-DfJAgCGWeHo/TdqQAohtQiI/AAAAAAAAAME/HmCVwktdCR8/s1600/STEP%2B8.JPG)


Come on, don't encourage click n hack software. Its just gay
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: Stackprotector June 20, 2011, 01:03:34 AM
Come on, don't encourage click n hack software. Its just gay
mehehe,    cheat engine in toolbar says enough ;)
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: noob June 20, 2011, 03:16:08 PM
@ande

well its a best choise when your laptop baterry is limited on 45 min and you must keep your laptop on a windows to hack your neighbour :)

But who wana know more about it there is Wireless Lan Security Megaprime serial on security tube by vivek ;)
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: noob June 20, 2011, 03:18:16 PM
mehehe,    cheat engine in toolbar says enough ;)

not my screen,type gerix in search pictures :P
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: Axalto September 25, 2011, 04:21:28 PM
Sorry for probably being an entire n00b, but I use backtrack 5 and I cant find the tool.


[edit] Nevermind, found out how.


For those who wonder how:
1. Download airoscript from the airoscript google site
2. Navigate to where the .tar.gz is and use tar to unpack it
3. Navigate (using shell) to the unpacked folder and type "make"
Now you can type airoscript in shell to start it.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: fl4sh January 10, 2012, 03:57:49 AM
Worked fine but, will this work on WPA and WPA2?
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: Kulverstukas January 10, 2012, 07:28:23 AM
Cracking WPA is whole different procedure - very hard. Not talking about WPE2...
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: ande January 10, 2012, 02:37:12 PM
Cracking WPA is whole different procedure - very hard. Not talking about WPE2...

Only way doing it is by brute force iirc?
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: Z3R0 January 10, 2012, 03:05:48 PM
Only way doing it is by brute force iirc?
I guess yeah, brute forcing is the only method. I don't think there are any crypto-attacks on AES that are higher than 128-bit. I guess one could do a generic bruteforce (ssid + key). However, I've also heard of forcing the client to reinitiate its session, capturing the pre-shared key, and bruteforcing that. I'm definitely not an expert on the subject, but I haven't really heard of anything other than brute force methods, although I have heard of different vectors of which to brute force.

EDIT: This was in reference to cracking WPA/WPA2 networks.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: _moon January 12, 2012, 12:33:40 AM
aircrack-ng (http://www.aircrack-ng.org/) can can crack WPA using pre-shared key (PSK).


More information (http://www.aircrack-ng.org/doku.php?id=aircrack-ng).
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: iAmLuFFy January 16, 2012, 08:52:22 AM
Only way doing it is by brute force iirc?

 isn't dictionary attack work sometimes....?
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: ande January 16, 2012, 02:23:26 PM
isn't dictionary attack work sometimes....?

That would still be bruteforce
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: AnTiHer0 February 10, 2012, 05:38:22 AM

 isn't dictionary attack work sometimes....?

A dictionary attack won't work for most things. You are just hoping your prey is stupid enough to have a very basic password.

Also, for the whole mac address security thing...not that secure. Pretty simple to get around actually. You can sniff out mac addresses on a wifi network, then you can spoof your mac address. However most people won't do this, so it is a good step up.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: _otter_ February 18, 2012, 03:31:40 PM
hmmmm i really cant find aeroscript link to download it.... i use backtrack 5 and i have aircrack which is same even better than aeroscript but problem is that i cant find and good turtorial for it.
or mb i can but my problem is that i cant turn off mon0!
can someone help?
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: Z3R0 February 20, 2012, 04:05:11 PM
hmmmm i really cant find aeroscript link to download it.... i use backtrack 5 and i have aircrack which is same even better than aeroscript but problem is that i cant find and good turtorial for it.
or mb i can but my problem is that i cant turn off mon0!
can someone help?
Even though it would be infinitely easier for me to tell you the command, I cannot cope mentally with the idea of giving a handout for something like this. I'll point you in the right direction though. Look in the linux man-pages about how to use "ifconfig"

Just a side note to all the other new guys, learn how to use your respective operating systems before you attempt any kind of hacking. What good is having a bicycle if you don't know how to ride it? Same idea here. Also, aeroscript is fantastic. I'm an extremely huge fan of mdk3.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: _otter_ February 20, 2012, 10:33:41 PM
ty very much  ;)
i did everything u said to me and now i can access to WEP my neighbor  :)
i learn fast. sorry for my mb nooby question to u but sometimes i really need a help

p.s. sorry for my bad English :-[
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: locolopez515 February 21, 2012, 01:58:49 AM
Is there a tutorial on this on video format? and what program should i download to do this, any links will be appreciated and I know this is illegal I'm not using it for the wrong purpose :D Pls and thank you
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: PiZZ4 February 22, 2012, 06:17:25 AM
Crack WEP:
:
http://lifehacker.com/5305094/how-to-crack-a-wi+fi-networks-wep-password-with-backtrack
Crack WPA:
:
http://lifehacker.com/5873407/how-to-crack-a-wi+fi-networks-wpa-password-with-reaver
Videos:
:
http://www.securitytube.net/
Videos are fun to watch but reading about the subject, either it be an book on cracking WEP passwords or an article about sql injection, will help in your learning process. Take it from someone who's been there before.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: iTpHo3NiX April 26, 2012, 12:49:12 AM
: ande
Come on, don't encourage click n hack software. Its just gay
Airoscript is pretty much click n hack, just not click just enter a few numbers and press enter :P

Yes there is Gerix as well as other GUI front-ends for aircrack-ng and I've used most of them, however I find airoscript easier to use as well as simple, yet effective.

Also for those of you who WANT airoscript its not that hard...

:
svn co http://trac.aircrack-ng.org/svn/trunk/ aircrack-ng
It will download the latest aircrack, as well as airoscript which is in the scripts directory or just google...

http://code.google.com/p/airoscript/
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: Z3R0 April 26, 2012, 09:27:30 AM
Airoscript is pretty much click n hack, just not click just enter a few numbers and press enter :P
As much as I agree with you on this, writing your own tools is not a simple task to undertake. I do think that in the name of research, I would recommend someone to use these tools to understand the attacks and how they work, and from there start writing their own code. As we all know, the aircrack suite as a whole actually takes some thought and planning to perform an attack. There are more noob friendly tools for cracking WEP...for example, the ultimate tool in click n' hack softwarez...wesside-ng.
: Re: Hacking WEP with Backtrack4 Final and Airoscript
: iTpHo3NiX April 26, 2012, 06:07:57 PM
As much as I agree with you on this, writing your own tools is not a simple task to undertake. I do think that in the name of research, I would recommend someone to use these tools to understand the attacks and how they work, and from there start writing their own code. As we all know, the aircrack suite as a whole actually takes some thought and planning to perform an attack. There are more noob friendly tools for cracking WEP...for example, the ultimate tool in click n' hack softwarez...wesside-ng.

Wesside-ng is an auto-magic tool which incorporates a number of techniques to seamlessly obtain a WEP key in minutes. It first identifies a network, then proceeds to associate with it, obtain PRGA (pseudo random generation algorithm) xor data, determine the network IP scheme, reinject ARP requests and finally determine the WEP key. All this is done without your intervention.

lol you do have a point there :P But the GUIz man, teh guiz!!

http://code.google.com/p/aircrackgui-m4/

lol tbh I've never used a gui for aircrack, ever since backtrack 3 beta I've used airoscript and back when I was using backtrack 2 I did it manually.

HOWEVER, my intention when I wrote up this paper (like back in 2009-2010) was to show the vulnerabilities in WEP security. The point was to show that by pressing a few numbers, anyone can hack their WEP network. Then once on their network the damage that could be done. I do believe that people should know what the commands of the aircrack suite, but honestly I havent used it by its self in so long, all it takes is for me to run airoscript.