
Open a Terminal (Ctr-Alt-T in Ubuntu) and execute this command sudo iwlist wlan0 scanning This command prints out a long list of all networks with their detailed information.

I just choose one of them, for example the “EasyBox-F1xxxx” giving me a good signal. Some of SSID names were changed but some of them are default and I can easily recognize which one is an EasyBox router. So here is a snapshot of all available wireless networks around me. Almost of my neighbors are simple persons, they order DSL lines, install the hardwares and let all settings like they were from factory.

As you can see the algorithm is pretty simple, it just takes the MAC address of router, makes some computations with base changing, xor,plus Therefore all we have to do is get the MAC address of victim, make a copy of the algorithm ourselves and then generate the default WLAN password. Therefore like other patents, the complete description of algorithm was simply exposed on internet (if you can read German). This default password was generated by a algorithm and this algorithm was patented. That means if someone is using default settings of EasyBox, you can get his WLAN password easily and then access his network.

Last week I’ve read small news on c’t magazine saying that the default password of EasyBox router used for Vodafone, Telecom, Arcor in Germany was hacked by Sebastian Petters.
