Thursday, July 09, 2020
WEP Cracking, FBI Style

Arrow Image How to crack WEP like the feds, in 3 mins.


-By BluMoose

Okay, before we begin, I give you BluMoose´s fun facts on WEP.


-WEP stands for Wired Equivalent Privacy
-WEP is used to secure wireless networks from eavesdroppers
-WEP usually takes hours to crack

WEP has always been a long and tedious job, untill recently, when two FBI agents demonstrated how it´s possible to crack WEP in under 4 minutes (3 to be exact).

Here is how they did it:

1. Run Kismet to find your target network. Get the SSID and the channel.
2. Run Airodump and start capturing data.
3. With Aireplay, start replaying a packet on the target network. (You can find a ‘good packet’ by looking at the BSSID MAC on Kismet and comparing it to the captured packet’s BSSID MAC).
4. Watch as Airodump goes crazy with new IVs. Thanks to Aireplay.
5. Stop Airodump when you have about 1,000 IVs.
6. Run Aircrack on the captured file.
7. You should see the WEP key infront of you now.



Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system.
It is designed for Linux.

You can download it at
A windows version can be downloaded at

-Aircrack (Includes Airodump, Aireplay, Aircrack and optional Airdecap for decrypting WEP/WPA capture files)

Aircrack is the 802.11 WEP and WPA-PSK keys cracking program that can recover this keys once enough encrypted packets have been captured with airodump.

Airdecap is used to decrypt WEP/WPA capture files.

Airmon can be used to configure the wireless card.

Aireplay is used to inject frames.

Airodump is used for packet capturing of raw 802.11 frames and is particularly suitable for collecting WEP IVs (initialization vectors) for the intent of using them with aircrack-ng.

Download the whole suit at

Av fun and enjoy,



-The_Flash-on July 22 2006 - 15:12:12
Dang! Facts have never been so fun since your last article! Great article dude
tancurromon July 22 2006 - 16:04:14
dont flames, but is that not a skiddy way of doing it?
system_meltdownon July 22 2006 - 18:48:02
How would you do it then tancurrom?
regiton July 22 2006 - 19:25:30
great artical, i like how it sais exactly step by step how to do it. it should be great for anyone thats new to wardriving Smile
BluMooseon July 22 2006 - 20:47:36
Lol nicely said system Smile Hows it skiddy? Im not saying "download this program and press the 'hack' button", im telling u how the feds do it. Its okay to use other programs, its not like ur gonna go n code everything u use...
a-hackon July 22 2006 - 20:51:12
Great article 10/10; skiddy?
hack4uon July 22 2006 - 21:46:09
nice.. seems similar to my extended article on the same thing in the zine. aong with my video Smile
BluMooseon July 22 2006 - 21:53:45
Didnt read that article, srry if its on the same thing. Found out bout it on Whitedust... i think.
Darth_Pengoon July 23 2006 - 10:11:41
HM Lucky you gave credit cause I was about to flame you I read this on digg about 2 weeks ago its a great article Wink and basically..its not the skiddish way of doing it.. unless you can hijack wep packets with your mind and decrypt them.. go for it
moonaguyon August 01 2006 - 22:20:24
Awesome article, ive always wondered and easy way to do it, and there it is! sweet work man
BluMooseon August 02 2006 - 09:51:40
Lol dont credit me, all I did was say how the FBI do it xD
paranoiahaxon May 12 2007 - 22:41:30
sorry, but i find that BS that it can be done in 3 minutes. Seriously, I've NEVER had that result before. Also, for newbies, you may wanna include a little bit about running the program, and the command lines used.
paranoiahaxon May 12 2007 - 22:43:31
sorry to double post, but apart from what i just said, it was a decent article, outlining the things needed.
LanceUppercuton June 03 2007 - 21:21:54
You need to make sure you're utilizing the newest version of Aircrack (Aircrack-ptw) This is the only version that will crack WEP in under 3 minutes.
darkinfiniteon April 05 2008 - 07:30:59
Very cool.
Mtutnidon October 07 2010 - 16:40:12
Not a bad article. I understand why tancurrom thinks it's skiddy article. You did not go into detail of what actually happens when you do each step, but that was not what this article was about...
