Click to See Complete Forum and Search --> : i sniffed a wep encrypted ping
OpticalCarrier
09-19-2002, 08:05 PM
i set up wep and sniffed some pings and both the echo request and the reply popped up in the sniffer and it appeared to be cleartext. Is that normal? i guess its possible the sniffer picks up data from the nic before wep grabs it. its also very possible that i didnt set up wep right. how can i be sure?
JimGeier
09-20-2002, 01:37 PM
I don't think that's normal. WEP should encrypt the pings (since they're within the frame body of 802.11 data frames). What kind of sniffer are you using?
OpticalCarrier
09-20-2002, 02:52 PM
My "Access Point" is an openBSD machine running in hostap mode with a Gemtek WI-311 card.
I have a WinXP machine with a DLINK DWL-650 and Im using Ethereal for a sniffer on the WinXP.
When I sniff IPSec encrypted pings all I see is ESP packets so I guess I didn't set up WEP right on the BSD machine... a wicontrol command says that WEP is active and shows my 13byte hex key and I have that same key plugged into the WinXP machine.
OpticalCarrier
09-20-2002, 09:12 PM
well i guess it was set up right. i changed the key on the winxp machine and it wouldnt do anything until i changed it back.
someone was telling me i had to put hte wireless nic into promiscuous mode to sniff. so maybe if i can find another laptop somewhere i can try it and satisfy my curiousity
JimGeier
09-21-2002, 12:43 PM
Sounds good. If find out anything new, you might want to post your response here. I'm curious of what you find.
wi-fiplanet.com
Copyright 2007 Jupitermedia Corporation All Rights Reserved.