Search:  

 
 
   News
newer
story category FBI's 3-Minute WEP Hack
WEP: Wet cardboard security
(old news - 06:12PM Friday Apr 01 2005)
tags: wireless · security
Out of the million of wireless hotspots in the world, about 70% of them are unprotected, 30% are protected by WEP, and a handful are protected by WPA. Tom's Networking reports on a recent FBI demonstration, in which they broke a 128 bit WEP key in under three minutes. It's not shocking that WEP is vulnerable, but with the release of WEP cracking tools last year, the "protection" it offers has become downright paper thin. (Page 5 offers tips on how to secure your hotspot.)

Related:
  1. Tuesday Morning Links
  2. FBI Gets DS3 Backdoor Into Verizon Wireless Network?
  3. Steal Wi-Fi In Maryland? Face 3 Year Prison Stretch
  4. Cell Phones and VoIP Calls Easy to Hack
  5. Tuesday Morning Links
  6. Friday Evening Links
  7. Using GPUs To Speed Up WPA Hacks
  8. WPA Wi-Fi Encryption Is Partially Cracked
Forums » FBI's 3-Minute WEP Hack
view: topics flat text 
Post a:

snipper_cr

join:2002-01-22
Wheaton, IL
clubs:

Paper thin?

A condom is paper thin and look how much protection THAT offers :-D :P

Anyawys jokes aside, this shouldnt come as too much of a suprise. I mean, how much security can a password protected system really offer? Eventually, someone is going to find a way around it and break in, this as a case.

The major threat are those 70% un protected networks. I know in my room alone, i can pick up 3 networks, only ONE of them is secure. The rest i can log in, view network places, go into the routers admin page (admin/admin logins usually).

WEP needs to be AUTOMATICALLY enabled if we wish to deture major network threats.
--
-Snipper_crDFI Lanparty 875ProB(Chipset water)Intel 2.4 GHzC@3.2(water)Corsar DDR 500@530 (4x256)Radeon 9800XT(Water)Audigy 2ZS PlatAspire 500 Watt PSU2X 160 Maxtor SATA in RAID 0G33Ks rule!

reub2000
Premium
join:2001-12-28
Evanston, IL

Re: Paper thin?

You mean WPA-PSK. I feel safe using a randomly generated string of letters, uppercase letters, and numbers, at least 20 chars long and changed every few months. I get complains, but IMO it better than being hacked.
donaldk
Premium
join:2000-10-19
Thunder Bay, ON

Re: Paper thin?

Fort most people getting WPA-PSK is too much of a pain in the ass to get working on XP... especially the novices.

reub2000
Premium
join:2001-12-28
Evanston, IL

Re: Paper thin?

it is? I haven't had any problems other than mistyped keys. And one would strongly asume that would affect WEP too.

lookma

@optonline.net
see, if the fbi can do it in 3 minutes, think of what a hacker with SKILLZ can do...
andreo

join:2001-03-30
Des Moines, IA

There are also times when the wireless components don't offer WPA. For example: the wireless media kits that are coming out (like Buffalo's new wireless media player) and wired to wireless network bridges. So your left either not enabling protection or adding the flawed WEP protection.
While WEP is better then sticking your network out there for all the world to access, I think the product manufactures should be adding WPA (and the long promised firmware updates, in some cases) to their products.

Tech-2005

@pacbell.n

This is ridiculous ! Don't ever use WEP ! Just use WPA,a long pre-shared key with AES algorithm, and finally add VPN. Then software firewall all the Windows computers with ZA or ZAP and restrict access between all the computers and only allow access to the server.

There are also some million dollar networking tricks to expensively lock down a basic Windows file sharing network to make it mostly unbreakable and some are very obvious if you read them but I will not post them publicly here or they will lose there secrecy and value to all those experienced administrators who currently use them.

Tech-2005

@pacbell.n

Re: Paper thin?

Correction... To "inexpensively" lock down a Windows Network there are a number of tricks you can use. Sorry about the typo mistake.
BobMcLeod

join:2005-04-06
Winnipeg, MB

This is my first posting so my apology if not quite right.

I looked over the the fairly limited overview of the FBI crack
of wep. The article displayed a "key" which actually resembled the stream that would be generated by RC4 which then encrypts or decrypts the frame.

My question is, is the encryption key cracked or the cypher stream?

Thanks to anyone who can shed a little light.

Bob

PICE

@nf.net
OK MAYBE THIS IS TE WRONG PLACE TO POST THIS BUT I NEEDS HELP CRACKING A WEP KEY ANYONE GOT ANY WAYS?

jwersan
R.I.P. Mom, Brian, Ziggy, and RichK1957
Premium
join:2004-12-20
Port Jefferson Station, NY
clubs:
·Optimum Online

What!?!?!?!?

The FBI demonstrated this attack to the computer security professionals at the ISSA meeting in order to show the inadequate protection offered by WEP. It is one thing to read stories of WEP being broken in minutes, but it is shocking to see the attack done right before your eyes. It was fast and simple.

Thankfully, the FBI are the good guys.
I love this comment at the end of the story...

The FBI are good guys????

I don't think so!!!

Bill
Light Up The Halo
Premium,VIP
join:2001-12-09
clubs:

Re: What!?!?!?!?

They are the good guys compared to others who could be cracking your network.
deepblackmag

join:2004-12-27
99999

Re: What!?!?!?!?

wtf bill, they arent the good guys. If they are breaking into your network its probablly to toss u in jail for 10-15 hard time. If the wardrivers do it, its to check their mail. and if the kiddiots do it, its to steal ur credit card (which ur CC company will refund to u)

Out of all of these options, WHO would you like cracking into your network.

ff1324
Everybody Goes Home
Premium
join:2002-08-24
On Four Day

Re: What!?!?!?!?

said by deepblackmag See Profile:

wtf bill, they arent the good guys. If they are breaking into your network its probablly to toss u in jail for 10-15 hard time.
What do you have to hide? They can look at my computers all they want. They'll find firefighting pictures, about a billion pictures of my kid, saved MOHAA games, and emails from my parents, coworkers, and college friends.

Yeah, I've got a lot to hide there....

So, what are you hiding?
--
The funny thing about firemen...night and day they're always firemen

rodoke

join:2003-10-28
Carbondale, IL
·Charter Pipeline

Re: What!?!?!?!?

said by ff1324 See Profile:

What do you have to hide?...
So, what are you hiding?
To the "I'm innocent, why aren't you?" "defense", I'll only say [c]omrade, there are no innocents in a world with the F.B.I. and Carnivore.

RR Conductor
Premium
join:2002-04-02
Redwood Valley, CA
It's called right to privacy

localhost
Premium
join:2005-01-19
Long Beach, CA
clubs:

when your ISP shuts off your internet connection because you have been sending unsolicited emails, then maybe you'll figure out why you need security.
--
»secure-wifi.net -- Wireless maps, searchable database, personalized statistics, and more!

ff1324
Everybody Goes Home
Premium
join:2002-08-24
On Four Day

Re: What!?!?!?!?

I'm not talking about keeping your computer secure. I'm saying, if you have nothing to hide, why the suspiscion of the investigative agencies?
--
The funny thing about firemen...night and day they're always firemen

ICE1

@comcast.net

Re: What!?!?!?!?

We all have something to hide.....our personal information...privacy rights....do I need to say more? I wouldnt want the FBI or any government agency browsing thru my network. Have you forgotten that we are living in a country where you are guilty to proven innocent.

nixen
Rockin' the Boxen
Premium
join:2002-10-04
Alexandria, VA
·Cox HSI
·Speakeasy

Good is a relative term.

In this instance, it was a demonstration of capability. It wasn't charges showing up on your bank statement.

-tom
--
"Some people have morals, standards and ideals about quality, but I'm an American: I couldn't care less." --Tony Pierce (paraphrased)
damox
Premium
join:2002-01-07
Olympia, WA
·Comcast Formerly ..

said by jwersan See Profile:

The FBI are good guys????
I don't think so!!!
Yeah, in this country, unless you're a criminal, or you just happen to be into anarchy, law enforcement is the good guys, unless of course you've been watching too many of those movies where law enforcement is portrayed as the bad guys!
--
DAMOX Proud to be a member of Team Discovery

PL11x15eq165

join:2002-07-05
Ladera Ranch, CA
clubs:

Re: What!?!?!?!?

said by damox See Profile:

Yeah, in this country, unless you're a criminal, or you just happen to be into anarchy, law enforcement is the good guys, unless of course you've been watching too many of those movies where law enforcement is portrayed as the bad guys!
I'm sorry, but my freedoms are much too valuable to protect by faith alone. I'll opt for separation of powers, enforcement of the Bill of Rights, and send a check to the ACLU every year to help me keep an eye on people or orgainizations or government employees who might possibly (and sometimes DO, in fact) cut the corners of my rights as a United States citizen in their enthusiasm to execute the laws of this land. The "only the bad guys have to worry" method of protecting personal rights has been shown to be not sufficient time and time again, throughout history.
--
No .sig, I'm on the patch...
damox
Premium
join:2002-01-07
Olympia, WA
·Comcast Formerly ..

Re: What!?!?!?!?

There's a huge difference between wanting to protecting ones freedoms, and considering law enforcement the "bad guys". I'm all for watch dog groups who work to insure that our rights and freedoms are being protected, but law enforcement is there to protect me from criminals. That is not to say that there are not some criminals who masquerade as law enforcement, and that is not to say that law enforcement is perfect, because obviously there are criminals who hide behind a badge and law enforcement agencies do make mistakes, but overall, law enforcement is for our good, they are not our enemies.
--
DAMOX Proud to be a member of Team Discovery

PL11x15eq165

join:2002-07-05
Ladera Ranch, CA
clubs:

Re: What!?!?!?!?

I can't argue with that, you're right.
--
No .sig, I'm on the patch...
markopoleo

join:2003-04-02
Bonne Terre, MO

No surprise here

Drive 10 miles from my house and you would get hundreds, i mean HUNDREDS of unprotected wireless networks. The scary/funny part? I live in hicksville, usa. :P

They have many funny names, lots of curse words for network names. :P

snipper_cr

join:2002-01-22
Wheaton, IL
clubs:

Re: No surprise here

I still think the most common one ive come accross is:

linksys

or

motorola

Generally if you find one of those its un protected, but not all.

Hell, we were able to get high speed internet while on vacation in florida from a linksys unprotected service... and the people were never home!
--
-Snipper_crDFI Lanparty 875ProB(Chipset water)Intel 2.4 GHzC@3.2(water)Corsar DDR 500@530 (4x256)Radeon 9800XT(Water)Audigy 2ZS PlatAspire 500 Watt PSU2X 160 Maxtor SATA in RAID 0G33Ks rule!
BIGHUSKER

join:2002-01-20
Minneapolis, MN

edit:
April 1st, @06:44PM

Thank God I still only have a wired router

OK, I don't really need a wireless one since there are no laptops in our house, but it's nice to not have to worry about someone getting relatively easy access to my network.

hx02

@12.165.x.x


from:
Matt See Profile
thumbs down from:
Andrew J See Profile

3mins... under *nix

3mins is a bit low, i have done it in an hour under under winblows with minimal network traffic. really the fbi cheated by creating more network traffic by interfering with the network, i prefer to do everything passively

for all you peeps wondering how to hax0r, just look for history here @ bbr and find the article about wep cracking comparisons from a few months ago

btw I use aircrack in XP

»www.cr0.net:8040/code/network/aircrack/

reaver221

join:2003-05-08
Cincinnati, OH

Re: 3mins... under *nix

you are awesome.

pcscdma
Chocobo Chocobo Random Battle
Premium
join:2004-01-14
Winterset, IA
clubs:

Re: 3mins... under *nix

like, tottally!
bradleym

join:2002-08-05
Dunfermline, IL

And yet....

Here's the FBI demonstrating what can happen with improper wireless security practices, while the other 700 government agencies can't secure their wired networks.

nixen
Rockin' the Boxen
Premium
join:2002-10-04
Alexandria, VA
·Cox HSI
·Speakeasy

Re: And yet....

said by bradleym See Profile:

Here's the FBI demonstrating what can happen with improper wireless security practices, while the other 700 government agencies can't secure their wired networks.
Yeah, well... Why should their wireless networks be any different than any of their other computing infrastructure.

-tom
--
"Some people have morals, standards and ideals about quality, but I'm an American: I couldn't care less." --Tony Pierce (paraphrased)
B
Premium,MVM
join:2000-10-28

Re: And yet....

And the Secret Service lets its employees log in as administrator, and can't trust them not to disable government-mandated background applications. (See recent password cracking story.)

-- B
--
In a realm outside causality and function

glmclell

join:2000-10-17
Northwest MI
clubs:
·Charter Pipeline

heh

its good to know a police agency with billions in funding has 'discovered' this flaw and how to exploit it ... I'm sure glad my government is lookin out for me.
--
"Here you go America - you are free to do what we tell you! You are free to do what we tell you!" - Hicks

pv8man999

@sbcglobal.net

Re: heh

well, of course they can crack it in 3 minutes. They problably had a packet generator sending shit loads of packets from point to router. It's easy to do it with that much traffic going through the air.

ICE1

@comcast.net

Dont forget.....

That the NSA is the first agency to receive any new technology before it hits the market. If that agency hasn't found a way to crack and/or monitor activity the new activity, it won't get put on the open market.
Forums » FBI's 3-Minute WEP Hack


Sunday, 23-Nov 04:09:58 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.republican-creole