Crack Wep With No Clients

This tutorial walks you though a very simple case to crack a WEP key. It is intended to build your basic skills and get you familiar with the concepts.


  • It assumes you have a working wireless card with drivers already patched for injection. The basic concept behind this tutorial is using aireplay-ng replay an ARP packet to generate new unique IVs. In turn, aircrack-ng uses the new unique IVs to crack the WEP key.


    It is important to understand what an ARP packet is. Although this tutorial does not cover all the steps, it does attempt to provide much more detailed examples of the steps to actually crack a WEP key plus explain the reason and background of each step. It is recommended that you experiment with your home wireless access point to get familiar with these ideas and techniques.

    If you do not own a particular access point, please remember to get permission from the owner prior to playing with it. Please send me any constructive feedback, positive or negative. Additional troubleshooting ideas and tips are especially welcome. You are using drivers patched for injection. You are physically close enough to send and receive access point packets.

    Remember that just because you can receive packets from the access point does not mean you may will be able to transmit packets to the AP. The wireless card strength is typically less then the AP strength. So you have to be physically close enough for your transmitted packets to reach and be received by the AP. There is at least one wired or wireless client connected to the network and they are active.

    The reason is that this tutorial depends on receiving at least one ARP request packet and if there are no active clients then there will never be any ARP request packets. If you use a different version then some of the common options may have to be changed.

    Ensure all of the above assumptions are true, otherwise the advice that follows will not work. You should gather the equivalent information for the network you will be working on. Then just change the values in the examples below to the specific network. Normal network traffic does not typically generate these IVs very quickly. Theoretically, if you are patient, you can gather sufficient IVs to crack the WEP key by simply listening to the network traffic and saving them.

    Since none of us are patient, we use a technique called injection to speed up the process. This allows us to capture a large number of IVs in a short period of time. Once we have captured a large number of IVs, we can use them to determine the WEP key. The purpose of this step is to put your card into what is called monitor mode.

    Monitor mode is mode whereby your card can listen to every packet in the air. By hearing every packet, we can later select some for injection.

    Note: this procedure is different for non-Atheros cards. You must have your wireless card locked to the AP channel for the following steps in this tutorial to work correctly. This is because the madwifi-ng drivers are being used. For other drivers, use the wireless interface name.

    In the response above, you can see that ath0 is in monitor mode, on the 2. 452GHz frequency which is channel 9 and the Access Point shows the MAC address of your wireless card.

