SecurityTubeBeta
Watch ... Learn ... Contribute
securitytube home
programming videos
tools videos
basics videos
fun
divider
upload video on SecurityTube
rss feed for SecurityTube

AireplayNG (Part 5)

 

ARP is the most suitable packet for replaying in encrypted medium. ARP is a fixed size packet so even if encryption is applied, with the help of simple length filters ARP can be found out. Another important criterion for selecting the packet is, for the selected packet someone should respond. ARP passes that criterion as well. Aireplay-NG provides the ARP-replay attack separately. In arpreplay attack you have to apply proper filter options so that the intended ARPs can be filtered properly and aireply will keep on injecting these ARP packets. You should start airodump-NG in the background to capture the ARP responses for cracking the WEP key.

Chop-chop attack can decrypt the WEP data packet without knowing the key. This attack cannot reveal the WEP key, but merely find the plaintext. This attack might not be successful on all kinds of APs, as, if AP drops shorter packets than 60 bytes then this attack can fail. In this attack, aireplay keeps on replacing the byte content from 00 to ff and notes the response from the AP. When the AP replays the packet on the wireless side successfully, it freezes that byte and moves on to next byte. For speeding up the process, aireplay-ng replaces the destination address with some multicast address which is a function of the byte content.

With the help of Fragmentation attack airelay-ng finds the key stream for the packet.

This video explains the arpreplay, chop-chop attack ad fragmentation attack vectors. Along with the demonstration of how to use the attack, this video also talks about the importance of these attacks in cracking the WEP key.

Enable Javascript or Download Flash Playe if you see this!

AireplayNG is a part of AircrackNG suite of products and is used for re-injecting wireless 802.11 frames on to the specified channel. The main aim of aireplay-NG is to generate large amount of traffic so that it can be used later for cracking the WEP or WPA-PSK keys with the help of aircrack-NG. The input to Aireplay-NG will be either the pcap file which needs to be injected or the interface name, as aireplay-NG is even capable of capturing packets on the wireless interface.

 
Related Videos from: AircrackNG Suite of Wireless Tools (Part 2)
divider
You are Viewing this Video Now!
1691 views
414 views
746 views
731 views
378 views

Links

1. Aireplay-ng Homepage

2. Aireplay-ng Download

3. Aireplay-ng Linux man page

 
Author
Amit-Vartak

Amit Vartak, 27 is working in wired and wireless security fields since last 3-4 years. His current area of interest includes IEEE 802.11 (Wi-Fi) suite of protocols, vulnerabilities in these protocols and countermeasure for those vulnerabilities. Working on cutting edge tools and technology always keeps him busy. He has contributed from concept level to final prototyping for the presentations in Defcon 2007 (The Emperor Has No Cloak - WEP Cloaking Exposed) and Toorcon 2007 (Caffe latte attack). He holds 2 patents with USPTO (current status: Patent Pending) and a few papers in IEEE journals on wireless protocol vulnerabilities. Prior to this, he was working on MEMS (Micro Electro Mechanical Systems) and has published a few papers in SPIE and ICMAT. (Yeah… kindda orthogonal fields… but technology really doesn’t limit the talent :) He did his masters in Electrical Engineering from one of the premier institutes in India, Indian Institute of Technology, Bombay (IIT-Bombay) and his under graduation, from University of Mumbai in Electronics and Telecommunication Engineering. He is currently working with AirTight Networks Inc. as a team lead in technology group since last 3 years.You can get in touch with him at amitcv[at]gmail[dot]com

 
©2007 Freak Labs