Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
The first encryption 2
2
that we'll learn how to break is called WEP, 3
3
or Wired Equivalent Privacy. 4
4
This is an old encryption, that can be easily broken. 5
5
The reason why I'm still covering it in this course, 6
6
is first of all, because like I said, it's very simple, 7
7
so it's a good starting point. 8
8
Also, it's still used sometimes in some networks. 9
9
Therefore, you can't really call yourself a hacker, 10
10
and then if you see a network that uses WEP, 11
11
you'll get stuck, 12
12
and you won't even be able to break into it. 13
13
So in this lecture, I'm gonna explain how WEP works, 14
14
and what's the weakness that we can use to break it. 15
15
And in the next lecture, 16
16
you'll see how we can use this weakness 17
17
in order to break WEP and get the key 18
18
for any network that uses WEP. 19
19
So basically, WEP uses an algorithm called RC4 20
20
to encrypt its the data. 21
21
So the way this works is basically, 22
22
if a client wants to send something to the router, 23
23
and let's say it wants to send this text, 24
24
data to send to the router, 25
25
it will first encrypt this using a key. 26
26
Therefore this normal text will be converted into gibberish 27
27
as you can see here. 28
28
This encrypted packet will be sent into the air, 29
29
so if a hacker captures this packet as we seen before, 30
30
if we open this packet, 31
31
we'll see that it's full of gibberish. 32
32
Even though it actually contains useful information, 33
33
we won't be able to read it because it's encrypted. 34
34
The access point will receive this encrypted packet, 35
35
and it will be able to transform it 36
36
back to its original form because it has the key. 37
37
Therefore, it'll actually be able to read the contents 38
38
which is, data to send to the router. 39
39
The same happens if the router 40
40
wants to send something back to the client, 41
41
it will first encrypt it using a key, 42
42
send it to the client, 43
43
the client will be able to decrypt it 44
44
because it has the key. 45
45
So the concept is always the same, 46
46
the transmitter encrypts the data using a key, 47
47
sends it to the receiver, 48
48
the receiver is able to decrypt it, 49
49
because it also has the key, therefore, 50
50
anybody who captures the packet in the middle, 51
51
they will get the packet, 52
52
but they won't be able to see the contents 53
53
because they do not have the key. 54
54
So the algorithm and the way RC4 works is actually fine, 55
55
the problem is with the way 56
56
that WEP implement this algorithm. 57
57
And to understand it, 58
58
let's zoom in a little bit more on each step. 59
59
So going back to the first step, 60
60
we have the client trying to send data to the router, 61
61
and the data that wants to send is, 62
62
data to send to the router. 63
63
So in order to encrypt this, 64
64
WEP tries to generate a unique key for each packet. 65
65
So literally each packet that's sent into the air, 66
66
it tries to create a new unique key for it, to do that, 67
67
it generates a random 24 bit initialization vector. 68
68
The initialization vector is then added to the password 69
69
of the network to the actual key 70
70
that people use to connect to the network. 71
71
This generates a key stream, 72
72
and then this key stream is used to encrypt this packet 73
73
and transform it into gibberish. 74
74
So basically, we have the key stream 75
75
plus the data that we need to encrypt, 76
76
gives us the gibberish, 77
77
and then the gibberish is sent into the air. 78
78
But before sending this into the air, 79
79
WEP will also append the initialization vector. 80
80
This is the 24 bit random number that I said it creates 81
81
in order to make sure that each packet has a unique key. 82
82
The reason why it adds the initialization vector 83
83
to the packet is because 84
84
once the router receives this packet, 85
85
it needs to be able to decrypt it, 86
86
and to decrypt it, it needs the key and the IV. 87
87
But the router already has the key, 88
88
so there is no need to send that. 89
89
Therefore we just need to send it the IV. 90
90
So when the router receives the packet, it has the IV, 91
91
it has the password or the key, 92
92
so it can generate a key stream 93
93
and then use that key stream to transform this gibberish 94
94
into its original form and read the packet. 95
95
So if you think about what I said, 96
96
you can probably guess what the weakness is. 97
97
Basically, the IV is sent in plain text, 98
98
so if you look at this, 99
99
you can see the packet content is encrypted, 100
100
so if someone captures this packet, 101
101
they won't be able to read this, 102
102
but they will be able to read the IV in plain text. 103
103
Also, the size of the IV is only 24 bits. 104
104
Now considering the huge amount of traffic 105
105
that can be generated on a Wi-Fi network, 106
106
this number is not big enough, 107
107
and the IVs will start getting repeated in a busy network. 108
108
This makes WEP vulnerable to statistical attacks, 109
109
so we can use a tool called Aircrack-ng 110
110
to determine the key stream, 111
111
once we have enough repeated IVs. 112
112
And from that it will also be able to crack WEP, 113
113
and give us the key to the network.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.