<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: TC7 day 1 &#8211; The fragmentation attack in practice</title>
	<atom:link href="http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 15:59:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: aw</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11753</link>
		<dc:creator><![CDATA[aw]]></dc:creator>
		<pubDate>Wed, 24 Oct 2007 08:08:07 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11753</guid>
		<description><![CDATA[@coreUK&lt;br&gt;Sometimes its for backwards compatibility.  If there were a way to put my 802.11B only devices (2 pocket PCs print server and a few other things) on an isolated part of my network for internet only, I would because I wouldn&#039;t mind going N or WPA-PSK and all that]]></description>
		<content:encoded><![CDATA[<p>@coreUK<br />Sometimes its for backwards compatibility.  If there were a way to put my 802.11B only devices (2 pocket PCs print server and a few other things) on an isolated part of my network for internet only, I would because I wouldn&#8217;t mind going N or WPA-PSK and all that</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: coreUK</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11752</link>
		<dc:creator><![CDATA[coreUK]]></dc:creator>
		<pubDate>Sun, 12 Aug 2007 18:49:58 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11752</guid>
		<description><![CDATA[Lots of people still use WEP.(dunno why, ignorance i guess) the worrying thing is....... well known high st banks in the heart of London are still using WEP.&lt;br&gt;oh and BTW 5 mins doesn&#039;t impress me, my record stands at 3min 28secs for 104 bit WEP.&lt;br&gt;i love those crappy bthomehubs!! ;-)]]></description>
		<content:encoded><![CDATA[<p>Lots of people still use WEP.(dunno why, ignorance i guess) the worrying thing is&#8230;&#8230;. well known high st banks in the heart of London are still using WEP.<br />oh and BTW 5 mins doesn&#8217;t impress me, my record stands at 3min 28secs for 104 bit WEP.<br />i love those crappy bthomehubs!! ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sorbo</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11744</link>
		<dc:creator><![CDATA[sorbo]]></dc:creator>
		<pubDate>Wed, 21 Sep 2005 00:29:33 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11744</guid>
		<description><![CDATA[http://darkircop.org/frag-0.1.tgz

if you launch it without args it will send arps [no internet host required].  I personally prefer inet flood.  If you&#039;re paranoid, you can spoof the inet ip while flooding...]]></description>
		<content:encoded><![CDATA[<p><a href="http://darkircop.org/frag-0.1.tgz" rel="nofollow">http://darkircop.org/frag-0.1.tgz</a></p>
<p>if you launch it without args it will send arps [no internet host required].  I personally prefer inet flood.  If you&#8217;re paranoid, you can spoof the inet ip while flooding&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amber</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11743</link>
		<dc:creator><![CDATA[Amber]]></dc:creator>
		<pubDate>Mon, 19 Sep 2005 09:27:30 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11743</guid>
		<description><![CDATA[You have given me a very interesting insight. Now I am looking forward to trying it out. Thanks buddy!]]></description>
		<content:encoded><![CDATA[<p>You have given me a very interesting insight. Now I am looking forward to trying it out. Thanks buddy!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gbag</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11745</link>
		<dc:creator><![CDATA[gbag]]></dc:creator>
		<pubDate>Sun, 18 Sep 2005 18:01:30 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11745</guid>
		<description><![CDATA[I used to be really interested in this stuff but this is over sensationalised...

There are still only a few ways to crack WEP and all require lots (at least 10000 packets) of data to work reasonably.

Weak keys (airsnort) are old-hat and all modern 802.11 devices avoid them. Aircrack and the new breed use roughly 17 statistical anomolies to improve on the brute force chance of a guessing a key. Their technique isn&#039;t perfect but it does work suprisingly well.

The ARP attack involved waiting for a packet that was the same length as an ARP packet and replaying it to the network. If it was an ARP packet, it would cause the remote host to send an ARP response packet with a unique IV. This can be done repeatedly to get the required 10000-100000 packets for WEP cracking, at which time you run aircrack.

His is just another variation where he injects traffic from the internet to get enough packets to break WEP.

It won&#039;t work if the AP is behind a firewall or NAT router. It won&#039;t work if he can&#039;t determine the networks IP range.

I think he&#039;s combining another attack where you decode the contents of a single packet by sending increasingly longer dummy packets into the network and decode the packet contents one byte at a time. After that you have an IP for the internal network and you can use that to launch an Internet-initiated flood.

I&#039;m pretty sure it would still be better to use the ARP attack over this method, if only because this method requires a host on the Internet which is going to have to flood something, setting off all sorts of alarm bells and big flashing lights.

Who the hell uses WEP anyway these days?]]></description>
		<content:encoded><![CDATA[<p>I used to be really interested in this stuff but this is over sensationalised&#8230;</p>
<p>There are still only a few ways to crack WEP and all require lots (at least 10000 packets) of data to work reasonably.</p>
<p>Weak keys (airsnort) are old-hat and all modern 802.11 devices avoid them. Aircrack and the new breed use roughly 17 statistical anomolies to improve on the brute force chance of a guessing a key. Their technique isn&#8217;t perfect but it does work suprisingly well.</p>
<p>The ARP attack involved waiting for a packet that was the same length as an ARP packet and replaying it to the network. If it was an ARP packet, it would cause the remote host to send an ARP response packet with a unique IV. This can be done repeatedly to get the required 10000-100000 packets for WEP cracking, at which time you run aircrack.</p>
<p>His is just another variation where he injects traffic from the internet to get enough packets to break WEP.</p>
<p>It won&#8217;t work if the AP is behind a firewall or NAT router. It won&#8217;t work if he can&#8217;t determine the networks IP range.</p>
<p>I think he&#8217;s combining another attack where you decode the contents of a single packet by sending increasingly longer dummy packets into the network and decode the packet contents one byte at a time. After that you have an IP for the internal network and you can use that to launch an Internet-initiated flood.</p>
<p>I&#8217;m pretty sure it would still be better to use the ARP attack over this method, if only because this method requires a host on the Internet which is going to have to flood something, setting off all sorts of alarm bells and big flashing lights.</p>
<p>Who the hell uses WEP anyway these days?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brandon</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11746</link>
		<dc:creator><![CDATA[Brandon]]></dc:creator>
		<pubDate>Sun, 18 Sep 2005 09:47:21 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11746</guid>
		<description><![CDATA[yeah...where is it?]]></description>
		<content:encoded><![CDATA[<p>yeah&#8230;where is it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gouki</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11748</link>
		<dc:creator><![CDATA[Gouki]]></dc:creator>
		<pubDate>Sun, 18 Sep 2005 08:57:25 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11748</guid>
		<description><![CDATA[I was searching o his site, but didnt find it.

How do we get it? *nux only right?

cya guys!]]></description>
		<content:encoded><![CDATA[<p>I was searching o his site, but didnt find it.</p>
<p>How do we get it? *nux only right?</p>
<p>cya guys!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gouki</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11747</link>
		<dc:creator><![CDATA[Gouki]]></dc:creator>
		<pubDate>Sun, 18 Sep 2005 08:56:27 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11747</guid>
		<description><![CDATA[I was searching o his site, but didnt find it.

How do we get it? *nux only right?

cya guys!]]></description>
		<content:encoded><![CDATA[<p>I was searching o his site, but didnt find it.</p>
<p>How do we get it? *nux only right?</p>
<p>cya guys!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: k00zk0</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11751</link>
		<dc:creator><![CDATA[k00zk0]]></dc:creator>
		<pubDate>Sun, 18 Sep 2005 08:43:53 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11751</guid>
		<description><![CDATA[Well...where can we get this automated WEP cracking app?]]></description>
		<content:encoded><![CDATA[<p>Well&#8230;where can we get this automated WEP cracking app?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brandon</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11750</link>
		<dc:creator><![CDATA[Brandon]]></dc:creator>
		<pubDate>Sun, 18 Sep 2005 08:27:45 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11750</guid>
		<description><![CDATA[This some crazy biznatch! Automated WEP cracking  under 5 mins...wow. Its not really cracking anymore. It takes 5 minutes to get connected sometimes...]]></description>
		<content:encoded><![CDATA[<p>This some crazy biznatch! Automated WEP cracking  under 5 mins&#8230;wow. Its not really cracking anymore. It takes 5 minutes to get connected sometimes&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CDE</title>
		<link>http://hackaday.com/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/comment-page-1/#comment-11749</link>
		<dc:creator><![CDATA[CDE]]></dc:creator>
		<pubDate>Sun, 18 Sep 2005 07:22:44 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2005/09/17/tc7-day-1-the-fragmentation-attack-in-practice/#comment-11749</guid>
		<description><![CDATA[Is this the Arp Spoofing linked on the security section of the site? Any way to get a real translation, ie non Bablefish?]]></description>
		<content:encoded><![CDATA[<p>Is this the Arp Spoofing linked on the security section of the site? Any way to get a real translation, ie non Bablefish?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

