How to Crack a Wi-Fi Network’s WEP Password with BackTrack


How to Crack a Wi-Fi Network’s WEP Password with BackTrack

You already know that if you want to lock down your Wi-Fi network, you should opt for WPA encryption because WEP is easy to crack. But did you know how easy? Take a look.
Note: This post demonstrates how to crack WEP passwords, an older and less often used network security protocol. If the network you want to crack is using the more popular WPA encryption, see our guide to cracking a Wi-Fi network's WPA password with Reaver instead.
Today we're going to run down, step-by-step, how to crack a Wi-Fi network with WEP security turned on. But first, a word: Knowledge is power, but power doesn't mean you should be a jerk, or do anything illegal. Knowing how to pick a lock doesn't make you a thief. Consider this post educational, or a proof-of-concept intellectual exercise.
Dozens of tutorials on how to crack WEP are already all over the internet using this method. Seriously—Google it. This ain't what you'd call "news." But what is surprising is that someone like me, with minimal networking experience, can get this done with free software and a cheap Wi-Fi adapter. Here's how it goes.

What You'll Need

How to Crack a Wi-Fi Network's WEP Password with BackTrackUnless you're a computer security and networking ninja, chances are you don't have all the tools on hand to get this job done. Here's what you'll need:
  • A compatible wireless adapter—This is the biggest requirement. You'll need a wireless adapter that's capable of packet injection, and chances are the one in your computer is not. After consulting with my friendly neighborhood security expert, I purchased an Alfa AWUS050NH USB adapter, pictured here, and it set me back about $50 on Amazon. Update: Don't do what I did. Get the Alfa AWUS036H, not the US050NH, instead. 
  • A BackTrack Live CD. Download yourself a copy of the CD and burn it, or load it up in VMware to get started.
  • A nearby WEP-enabled Wi-Fi network. The signal should be strong and ideally people are using it, connecting and disconnecting their devices from it. The more use it gets while you collect the data you need to run your crack, the better your chances of success.
  • Patience with the command line. This is an ten-step process that requires typing in long, arcane commands and waiting around for your Wi-Fi card to collect data in order to crack the password. Like the doctor said to the short person, be a little patient.

Crack That WEP

To crack WEP, you'll need to launch Konsole, BackTrack's built-in command line. It's right there on the taskbar in the lower left corner, second button to the right. Now, the commands.
First run the following to get a list of your network interfaces:
airmon-ng
The only one I've got there is labeled ra0. Yours may be different; take note of the label and write it down. From here on in, substitute it in everywhere a command includes (interface).
Now, run the following four commands. See the output that I got for them in the screenshot below.

airmon-ng stop (interface)
ifconfig (interface) down
macchanger --mac 00:11:22:33:44:55 (interface)
airmon-ng start (interface)
How to Crack a Wi-Fi Network's WEP Password with BackTrackIf you don't get the same results from these commands as pictured here, most likely your network adapter won't work with this particular crack. If you do, you've successfully "faked" a new MAC address on your network interface, 00:11:22:33:44:55.
Now it's time to pick your network. Run:
airodump-ng (interface)
To see a list of wireless networks around you. When you see the one you want, hit Ctrl+C to stop the list. Highlight the row pertaining to the network of interest, and take note of two things: its BSSID and its channel (in the column labeled CH), as pictured below. Obviously the network you want to crack should have WEP encryption (in the ENC) column, not WPA or anything else.
How to Crack a Wi-Fi Network's WEP Password with BackTrackLike I said, hit Ctrl+C to stop this listing. (I had to do this once or twice to find the network I was looking for.) Once you've got it, highlight the BSSID and copy it to your clipboard for reuse in the upcoming commands.
Now we're going to watch what's going on with that network you chose and capture that information to a file. Run:
airodump-ng -c (channel) -w (file name) --bssid (bssid) (interface)
Where (channel) is your network's channel, and (bssid) is the BSSID you just copied to clipboard. You can use the Shift+Insert key combination to paste it into the command. Enter anything descriptive for (file name). I chose "yoyo," which is the network's name I'm cracking.
How to Crack a Wi-Fi Network's WEP Password with BackTrack
You'll get output like what's in the window in the background pictured below. Leave that one be. Open a new Konsole window in the foreground, and enter this command:
aireplay-ng -1 0 -a (bssid) -h 00:11:22:33:44:55 -e (essid) (interface)
Here the ESSID is the access point's SSID name, which in my case is yoyo. What you want to get after this command is the reassuring "Association successful" message with that smiley face.
How to Crack a Wi-Fi Network's WEP Password with BackTrack
You're almost there. Now it's time for:
aireplay-ng -3 -b (bssid) -h 00:11:22:33:44:55 (interface)
Here we're creating router traffic to capture more throughput faster to speed up our crack. After a few minutes, that front window will start going crazy with read/write packets. (Also, I was unable to surf the web with the yoyo network on a separate computer while this was going on.) Here's the part where you might have to grab yourself a cup of coffee or take a walk. Basically you want to wait until enough data has been collected to run your crack. Watch the number in the "#Data" column—you want it to go above 10,000. (Pictured below it's only at 854.)
Depending on the power of your network (mine is inexplicably low at -32 in that screenshot, even though the yoyo AP was in the same room as my adapter), this process could take some time. Wait until that #Data goes over 10k, though—because the crack won't work if it doesn't. In fact, you may need more than 10k, though that seems to be a working threshold for many.
How to Crack a Wi-Fi Network's WEP Password with BackTrack
Once you've collected enough data, it's the moment of truth. Launch a third Konsole window and run the following to crack that data you've collected:
aircrack-ng -b (bssid) (file name-01.cap)
Here the filename should be whatever you entered above for (file name). You can browse to your Home directory to see it; it's the one with .cap as the extension.
If you didn't get enough data, aircrack will fail and tell you to try again with more. If it succeeds, it will look like this:
The WEP key appears next to "KEY FOUND." Drop the colons and enter it to log onto the network.


Problems Along the Way

With this article I set out to prove that cracking WEP is a relatively "easy" process for someone determined and willing to get the hardware and software going. I still think that's true, but unlike the guy in the video below, I had several difficulties along the way. In fact, you'll notice that the last screenshot up there doesn't look like the others—it's because it's not mine. Even though the AP which I was cracking was my own and in the same room as my Alfa, the power reading on the signal was always around -30, and so the data collection was very slow, and BackTrack would consistently crash before it was complete. After about half a dozen attempts (and trying BackTrack on both my Mac and PC, as a live CD and a virtual machine), I still haven't captured enough data for aircrack to decrypt the key.
So while this process is easy in theory, your mileage may vary depending on your hardware, proximity to the AP point, and the way the planets are aligned. Oh yeah, and if you're on deadline—Murphy's Law almost guarantees it won't work if you're on deadline.

11 comments:


  1. best hacker contact elizabethjone146@gmail.com
    WhatsApp +18573255825
    Do you need a hacker to hack into your cheating ass account or do you want us to hack into the following account such as.
    1-facebook hack
    2-gmail hack
    3-whatsapp hack
    4-website hack
    5-tracking calls
    6-online hacking lectures
    7-phone clone
    8-online records changes
    9-retrival of hacked social media account

    10 ATM merchine hack/password from any Email Address.
    11 Get any password from any Facebook, Twitter or Instagram account.
    12 Cell phone hacking (whatsapp, viber, line, wechat, etc)
    13 Grades changes (institutes and universities)
    14 Websites hacking, pentesting.
    15 IP addresses and people tracking.
    16 Hacking courses and classes.
    17 blank ATM CARD.
    contact elizabethjone146@gmail.com
    WhatsApp +18572012269

    ReplyDelete
  2. My name is Alice and I just want to give a quick review and introduce you to LANX CREDIT SOLUTION, I must tell you that I was skeptical at first about this Company when they told me they’ll remove all the derogatory items in my report, and give me a better FICO. Believe me, giving in to their offer is the best decision I have made in a while, my FICO went from low 485 to a high 780 and my husband’s score went from 612 to 800. We did all they asked us to do and delivered as promised. They removed late payments, some charge offs, eviction and collections. We are still amazed at how awesome this company is. Call them on (310) 879 2541 or email them at LANXCREDITSOLUTION@GMAIL.COM. You also will testify…

    ReplyDelete
  3. Hello there, I have been reading a lot about these credit repair companies and it reminded me of the great job Lanx Credit Solution did for me earlier this year, apparently my fico is still at 765 after 6 months of working with them. Before I contested them my score was as low as 530, had loads of negative items and credit card debts and a Judgement. They helped me tidy it up really good and added some trade lines in it. They are really good at it. Here is their contact just in case in require such service LANXCREDITSOLUTION@GMAIL.COM / +1 (310) 879 2541. Thanks and have a great day.

    ReplyDelete
  4. Do you want a quick, genuine and permanent credit repair? then contact LANX CREDIT SOLUTION via LANXCREDITSOLUTION@GMAIL.COM / call or text (310) 879 2541. I had couple of collections and late payments plus my son’s student loans and some charge offs. My credit score was at the low 560 and needed to get approved for mortgage loan but was denied several times. A colleague told me about this people and how they fixed her credit in 10 days. I was moved so I contacted them on the 2nd OCT 2020 and they fixed my credit before 2 weeks. My score was increased to 790s and the negatives cleared. They promised that the repair is permanent. Big Shout out to them.

    ReplyDelete
  5. Truthfully, taking the decision of contacting a credit repair company was not an easy one, I desperately needed a home, I couldn’t get one due to the evictions and Late payments on my credit, with a very low FICO, I was frustrated and had no choice but try one. Luckily for my I read some very good reviews on LANX CREDIT SOLUTION and decided to contact them. I have never been happier, my FICO was increased to 750 and the late payments and evictions were taken off my report. Superb service I must say!!! You can reach them on LANXCREDITSOLUTION@GMAIL.COM or (310) 879 2541. thanks

    ReplyDelete
  6. Hi people, I encourage you to contact LANX CREDIT SOLUTION, they did me a huge favor and repaired my credit for a reasonable fee, there precision is excellent, they have all my trust and I am referring everyone with credit issues to them. Imagine erasing 12 hard inquiries, collections, charge off and eviction in less than 5 days. They went further in boosting my FICO score to 780 across the bureaus. I qualified for a home loan due to my perfect credit. Awesome, tell them Mateo Rolly referred you. Here is their LANXCREDITSOLUTION@GMAIL.COM/+1 (310) 879 2541]. Their services are excellent and they are always available.

    ReplyDelete
  7. I urgently needed a home loan but could not qualify for one due to my poor credit, I had a very low FICO and I had some inquiries, late payments and repos on my credit report, I really needed to fix my credit so I could get a home for my family. I confided in a friend and he was kind enough to introduce me to LANX CREDIT SOLUTION, they were able to fix my credit and add some positive trade lines to my credit, with a clean credit and a FICO of 782. Writing this review because I just got the loan I’ve been looking for. You can get through to them via
    PHONE: (310) 879 2541
    Email: LANXCREDITSOLUTION@GMAIL.COM
    Thank you for your time.

    ReplyDelete
  8. I had a poor credit which was largely due to identity theft, I needed a loan to finance my business but could not get one because my credit was not just good enough, after trying everything things went from bad to worse, the more I disputed the lower my credit score went. This continued till a Pal introduced me to Lanx Credit Solution. I explained my position and they assured me that they could help me put things in order by fixing my credit and increasing my score. They kept their words, I am still in awe. I now have a credit score of 782, all the negative items that bedeviled my credit were removed finally. It was good one. Get to them on Lanxcreditsolution@gmail.com, text/call (214) 888 9709.

    ReplyDelete
  9. The benefits of having a good credit can never be over emphasized, as a young Adult I made lots of mistakes and I’ve been paying for them ever since. As a divorcee with 4 kids living with a poor credit was not easy, I needed a mortgage loan because I needed a better home for my kids and I, I had an eviction, 4 hard inquiries, late payments and huge credit card debts. It wasn’t funny at all because I suffered a great deal. The good news is a credit repair company known as Lanx Credit Solution ensure that I was able to live my life to the fullest, they helped me improve my credit, removed all the negative and derogatory items, gave me a very high FICO score of 750. I will leave their contact here so you also can benefit from their excellent work LANXCREDITSOLUTION@GMAIL.COM and (214) 888 9709…

    ReplyDelete
  10. Always prayed to be able to afford my needs, I had everything going well till I lost my job and things went south, the pandemic made things worse, the situation dealt with my report and my FICO score became too low, I could get a home, I had late payments, liens and inquiries on my report. I took a cue from a friend whom had similar issues but was helped by Lanx Credit Solution and contacted them, it didn’t even take 2 weeks and I got everything back, they removed all derogatory items and increased my FICO score to 780 now with a very good credit things are beginning to look up for me and my family. You can get them on [LANXCREDITSOLUTION@GMAIL.COM (214) 888 9709]. Tell them Avery referred you.

    ReplyDelete
  11. Ellie Jones told me about Lanx Credit Solution and how they helped her increase her Fico and improve her credit, at first it was difficult to believe but I had pressing credit concerns that I needed to clear up I had foreclosure, evictions, late payments and some debts. It was like my life was over because I could not do anything about it, she persuaded me and I had to let them handle it. This review is as a proof that they are really good at what they do. My credit score sits at 760, and the evictions, late payments, and foreclosure on my credit reports are gone, my debts were also cleared. I appreciate their job and I would like you to contact them on LANXCREDITSOLUTION@GMAIL.COM or (214) 888 9709. It really was worth it.

    ReplyDelete

Page List

Powered by Blogger.

Copyright © / Ayush's Desk

Template by : Urang-kurai / powered by :blogger