The Fragmentation Attack in Practice
Andrea Bittau · 2005
The 802.11 encryption standard Wired Equivalent Privacy (WEP) is still widely used today despite the numerous discussions on its insecurity. Al-though WEP definitely faces serious security prob-lems, there is no single tool which will recover any WEP key with minimal effort from the user and in a very short amount of time. In this paper, we present a mechanism which al-lows an attacker to send arbitrary data on a WEP network after having eavesdropped a single data packet. Many common WEP attacks require gath-ering large amounts of data before they may be performed whereas ours requires only one, making it much quicker and more practical. We implemented a fully automatic version of this attack which enables even non technical peo-ple to perform it and recover a key without effort and in a relatively short period. Hopefully this will induce people to abandon WEP as their wireless security solution—it is no longer the case that only skilled and patient attackers may recover the key in practice. 1