A Method of Attacking WEP2 When IVs Are Generated from a Little-Endian Counter
Cao Xiu-ying · Dianzi xuebao · 2004
WEP2 protocol does not specify how the IVs are generated.However,in practice,the method of generating IVs from a counter is commonly used.When the IVs are generated from a little-endian counter,we present a cracking method which can recover the first 24 bits of WEP2's secret key in two steps,by observing the ciphered frames with special form transferred in the network.At the first step,we can recover the second and third bytes of the secret key,and at the second step we can get the first key byte.Then on this basis,by using the IV Weakness cracking method,the total 128 bits of WEP2's secret key can be recovered.The method and principle of this attack are represented in detail,and the simulation results are also given.