Remote Exploit Forums

Go Back   Remote Exploit Forums > Specialist Topics > Wireless


Wireless Specific topics related to the attack & defense of wireless systems

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 09-24-2009, 03:19 PM
New Member
 
Join Date: Sep 2009
Posts: 1
Default aircrack-ng failed, 150,000 IVs

I have been attempting to retrieve the WEP password from my own AP using aircrack installed on a linux OS (Slax).

My card is the intel wifi 5100, i believe i have patched the drivers correctly as all injection tests are working.

I successfully retrieve many IVs at around 500/s when injecting, but the problem arises when i run aircrack-ng on the file with just over 150,000 IVs. The attempt always fails.

I am only using a 64 bit key, and i've read that it should require far less than this when using the PTW attack.

Is there a possibility that i am not collecting the correct IVs?

Apologies if this is a simple question that has already been answered, but i have not found any threads through my searches.

Any help would be greatly appreciated.
Reply With Quote
  #2 (permalink)  
Old 09-24-2009, 10:56 PM
Junior Member
 
Join Date: Jan 2009
Posts: 18
Default

Thats wierd....It should work from what you are telling me. Try increasing the fudge factor a little. Technically you shouldnt have to but thats all i can think of. If nothing else turn it way up over night and see what happens...

its the -f <#> function. Default is -f 2 i believe. So this is what it would look like:
aircrack-ng -f 6 file.cap

EDIT: oh, make sure when you are running airodump-ng you have all the setting like --bssid and --channel set to filter out unwanted junk. You might have a bunch of random .ivs which would be hard to crack
__________________
---- ____........../''\.....__...____
----/___../\../.../__\...|_.../___
----___/ /..\/.../......\.|__..___/

Last edited by snaes; 09-24-2009 at 10:58 PM.
Reply With Quote
  #3 (permalink)  
Old 09-24-2009, 11:05 PM
Snayler's Avatar
Senior Member
 
Join Date: Jul 2009
Location: World
Posts: 360
Default

In aircrack-ng site, it says that there are some routers that inject some fake IV's to fool aircrack. Maybe it is your case? Try to read some more about it. If memory serves me, the aircrack team created a workaround for this.
Reply With Quote
  #4 (permalink)  
Old 09-27-2009, 01:48 PM
Nick_the_Greek's Avatar
Senior Member
 
Join Date: Jul 2009
Location: Greece
Posts: 124
Default

Quote:
Originally Posted by mostofmonty View Post
..... using aircrack installed on a linux OS (Slax).
This isn't an Slax or Aicrack-ng forum.
__________________
The quieter you become....
Reply With Quote
  #5 (permalink)  
Old 10-31-2009, 03:24 AM
_DoS_'s Avatar
Junior Member
 
Join Date: Oct 2009
Posts: 11
Default

It`s not a aircrack forum but BT has the aircrack suit so it deserves help i think ..

I have the same card and its working just fine with me (difrence is that am using BT4 ) .. In what you are telling if you had patched the drivers ok and you got injection working (as you say,you capture 500#/s) then you should have no problem. Maybe the problem is with Slax or with the router like Snayler said.

I have seen a case that aircrack didnt find the key with 3.000.000 packets from an AP, but the next day it found it from just 2000 packets (the same AP).

Post the commands that you are using may be of some help, but at the end from my expirience i sugesst to download and try Backtrack becouse it works flowless with intel 5100 with the right update.

Regards
Reply With Quote
  #6 (permalink)  
Old 10-31-2009, 03:58 AM
vvpalin's Avatar
Senior Member
 
Join Date: Apr 2009
Location: all.ur.base
Posts: 417
Default

wow .. blind leading the blind

Quote:
150,000 IVs
Is about 100,000 more than what you need fyi, and you do realize in older versions of aircrack you need to specify the keylength rite ????
__________________
Using backtrack for the first time is like being 10 years old again with the keys to a Ferrari.
Reply With Quote
  #7 (permalink)  
Old 11-09-2009, 09:45 PM
_DoS_'s Avatar
Junior Member
 
Join Date: Oct 2009
Posts: 11
Default

Quote:
Originally Posted by vvpalin View Post
wow .. blind leading the blind



Is about 100,000 more than what you need fyi, and you do realize in older versions of aircrack you need to specify the keylength rite ????
The point was that sometimes you just dont get the right ivs that aircrack needs..You can collect an infinite number of Iv`s and still you`ll be unable to crack the key.

And mostofmonty did you stoped airodump-ng before trying to crack the .cap file ?
__________________
If you wait to do everything until you are sure it`s right, you`ll probably never do much of anything.
Reply With Quote
  #8 (permalink)  
Old 11-11-2009, 03:48 AM
Just burned his ISO
 
Join Date: Sep 2008
Posts: 4
Default

Quote:
Is there a possibility that i am not collecting the correct IVs?
Maybe a stupid question, but can you/are you using ARP request replay?

The other modes will take ALOT of ivs.
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:31 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2