Time for action – bypassing Shared Authentication
Bypassing Shared Authentication is a bit more challenging than previous exercises, so follow the steps carefully.
Let us first set up Shared Authentication for our Wireless Lab network. I have done this on my access point by setting the Security Mode as WEP and Authentication as Shared Key:
Let us now connect a legitimate client to this network using the shared key we have set in step 1.
In order to bypass Shared Key Authentication, we will first start sniffing packets between the access point and its clients. However, we would also like to log the entire shared authentication exchange. To do this we use
airodump-ng
using the commandairodump-ng mon0 -c 11 --bssid 00:21:91:D2:8E:25 -w keystream
. The-w
option which is new here, requestsairodump-ng
to store the packets in a file whose name is prefixed with the word "keystream". On a side note, it might be a good idea to store different sessions of packet captures in different files. This allows...