it is a group project, my group did send me their papers. In each tool they discussed I needed to come with an abstract, intro and conclusion. this is my part
SHORT PAPER TITLE 2
Full Title of the Paper
Author Names
University
Running head: SHORT PAPER TITLE 2
Abstract
Table of Contents Abstract 2 List of Figures 3 List of Tables 3 Heading 1 4 Heading 2 4 Heading 3. 4 Heading 4. 4 Heading 5. 4 Reference list 7 Appendix A 8 Appendix B 10
Figure 1. Example figure body text 6
Figure A1. Example figure appendix 9
Figure A2. Example figure appendix 9
Figure B1. Example figure appendix 10
Table 1 Example table body text 6
Table A1 Example table appendix 9
Aircrack-ng
Aircrack-ng is a hacking tool to crack 802.11 WEP key and WPA/WPA2-PSK key once airodump-ng capture enough data packets (Aircrack-ng, n.d.).
Aircrack-ng WEP key Cracking Methods
The Aircrack-ng cracks WEP key using two methods. The first method is (Pyshkin, Tews, Weinmann) known as PTW approach. The PTW attack is an extend of the Klein attack however it decreases the number of initialization vectors (IVs) needed to decrypt a WEP key. The PTW attack performs a key classification strategy which instead of trying all possible combinations, it chooses a set number of promising keys and continues the RC4 algorithm based on those combinations. Using divergent voting strategies, the hacker can choose the most promising key byte at each decision in the tree to discover the correct key (Aircrack-ng Documentation, n.d.). The PTW Attack has approximately 97% rate of success using only 7x104 packets (Wireless Security Attacks, n.d.). That is due the fact that the PTW attack depends on two phases. The first phase uses enhanced FMS techniques on ARP packets only, if this phase failed to find the key then it will proceed to the second phase which uses all the captured packets. The PTW approach is considered as the default approach. The pro of this approach is that it requires few data packets. On the other hand, the drawback of this approach is that it only can cracks 40 and 104 bit WEP key (Aircrack-ng, n.d.).
The second method is FMS/KoreK method. This method incorporates numerous statistical attacks to find the WEP key and utilize these in combination with brute forcing.
Aircrack-ng also can determine the WEP key using dictionary method.
FMS Attack. In 2001 Fluhrer, Mantin, and Shamir found weakness in IVs uses RC4 encryption that have B+3::ff:X format (where B is the byte of the key to be discovered, ff is the constant 255, and X is beside the point) . By knowing the plaintext in the headers of specific packets for example APR packets we can find the value of B. The FMS Attack has approximately 50% rate of success using only 9x106 packets. (Wireless Security Attacks, n.d.)
KoreK Attack. In 2004, KoreK announce a cracking suite that performs a combination of 17 different attacks. These attacks are divided into 3 groups. The first group recovers the key form the first word of the output from the RC4 algorithm. The second group uses the first word as well as the second word. Finally, the third group which excludes certain values from being a key, instead of guessing the values of the key. The PTW Attack has approximately 97% rate of success using only 3x106 packets. (Wireless Security Attacks, n.d.)
Brute Forcing. Brute force attacks require repeated login attempts using every possible combination of letter, number, and character to guess a certain password (Kaspersky, 2020).
Dictionary Method Attack. Dictionary attacks uses an actual dictionary, but it's contains a shorter list of words that the attacker thinks are most likely to be successful. Commonly used password lists, pet names, movie characters, popular names, and other words can all be part of a dictionary list (Vigliarolo, 2018).
Aircrack-ng WPA/WPA2 keys Cracking Methods
Aircrack-ng uses only the dictionary method to crack WPA/WPA2 keys. Which was previously discussed. A “four-way handshake” is needed as input. For WPA handshakes, a full handshake is composed of four packets. However, aircrack-ng works with just 2 packets. EAPOL packets (2 and 3) or packets (3 and 4) are considered a full handshake (Aircrack-ng Documentation, n.d.).
Limitation of Aircrack-ng
Aircrack-ng tool runs on Linux, Windows, OpenBSD, FreeBSD, as well as Solaris and even eComStation 2. Unfortunately, the Aircrack-ng tool is not well supported on Windows and these operating systems as good as it is on Linux that is due the proprietary nature of the OS and wireless card drivers (“Getting_started [Aircrack-ng],” n.d.).
References
Aircrack-ng. (n.d.). Retrieved July 13, 2020, from https://www.aircrack-ng.org/
Aircrack-ng Documentation. (n.d.). Retrieved July 12, 2020, from http://www2.aircrack-ng.org/hiexpo/aircrack-ng_book_v1.pdf
Fluhrer, S., Mantin, I., & Shamir, A. (2001, August). Weaknesses in the key scheduling algorithm of RC4. In International Workshop on Selected Areas in Cryptography (pp. 1-24). Springer, Berlin, Heidelberg.
Getting_started [Aircrack-ng]. (n.d.). Retrieved July 12, 2020, from https://www.aircrack-ng.org/doku.php?id=getting_started
Kaspersky. (2020, March 31). What’s a Brute Force Attack? Retrieved July 12, 2020, from https://www.kaspersky.com/resource-center/definitions/brute-force-attack
Vigliarolo, B. (2018, December 17). Brute force and dictionary attacks: A cheat sheet. Retrieved July 12, 2020, from https://www.techrepublic.com/article/brute-force-and-dictionary-attacks-a-cheat-sheet/
Wireless Security Attacks. (n.d.). Retrieved July 12, 2020, from https://wirelessnetworkssecurity.blogspot.com/2013/01/wireless-security-attacks.html