WEP Quest

Ronald W. Henderson

CTO
UNIVERSAL Technologies, LLC

Copyright © 2003 - 2008 Respective Authors

2005-May-9

This article will demonstrate the weakness associated with the IEEE 802.11b wireless encryption standard called WEP (Wired Equivalent Privacy). The reader will learn how a WEP key for a WEP encrypted wireless network can be cracked.


Table of Contents

Overview/History/Goals
Determining The WEP Key
Gathering The Necessary Equipment
Setting Up The System
Determining The Frequency/Channel Of The Access Point
Capturing Wireless Data Packets
Deciphering the WEP Key
What We've Learned So Far
What Can Be Done With A WEP Key
Removing The WEP Encryption From The Captured Data
Examining Network Data After Removing WEP Encryption
What Else Can Be Done?
Summary
What Has Been Learned
What Should Be Further Investigated
Bibliography

Having a wireless access point in our home, and knowing that 128 bit WEP is subject to being cracked, I've often wondered the following:

Being a developer involved with the Network Security Toolkit project, I knew that I had both the hardware and software to answer this question. Instead of simply running out and answering the question, I decided to take the time and "do it right" with the following goals in mind:

The purpose of this article is not to enable one to break into wireless networks. Instead, the goal of this article is to provide incentive to those making use of wireless networks to do a better job at securing them. It may not be possible to keep a determined and skilled network cracker out of a wireless network, but we should be able to do a better job at slowing them down.