All language subtitles for 2. Hacking WPA & WPA2 Without a Wordlist

af Afrikaans
ak Akan
sq Albanian
am Amharic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1 1

Okay, now that we know 2

2

what WPS is and how it can be used 3

3

to recover the password for WPA and WPA2 networks, 4

4

let's see how to do that in practice. 5

5

So right here I have my Kali machine. 6

6

I've already enabled monitor mode 7

7

on my wireless adapter on 10. 8

8

Now, usually we use airodump-ng 9

9

to see all the networks around us. 10

10

But right now, we want to see the networks 11

11

that have WPS enabled 12

12

but because like I said it's just a feature 13

13

and people can turn this feature off, 14

14

so first of all, I'm gonna use a tool called wash 15

15

to display all the networks around me 16

16

that have WPS enabled. 17

17

So we're gonna do wash --interface 18

18

and give it my interface in monitor mode 19

19

which is mon0. 20

20

So all we're doing is wash is the name of the tool, 21

21

interface to give it the interface 22

22

and mon0 is my wireless adapter in monitor mode. 23

23

If I hit Enter now, 24

24

you'll see it'll list my network straight away. 25

25

Now, I pressed Control + C to cancel this, 26

26

similar to airodump-ng 27

27

because it'll keep running 28

28

unless you cancel it. 29

29

And you can see this is my target network. 30

30

It's called Test_AP. 31

31

It's giving us the vendor 32

32

of the hardware used in this network 33

33

in this access point. 34

34

The Lck tell us whether WPS is locked or not 35

35

because sometimes WPS locks 36

36

after a number failed attempts. 37

37

So right now this says no, 38

38

which means that we can actually go ahead 39

39

and try to guess the PIN. 40

40

It's giving us the version of WPS, it's using version one. 41

41

The signal strength is in here. 42

42

The channel and the BSSID. 43

43

Now, I explained the meaning of all these things before 44

44

in my airodump-ng lecture 45

45

so I'm not gonna talk about them now. 46

46

If you forgot the meaning of any of these terms, 47

47

please go back to the airodump-ng lecture. 48

48

Now, this network actually uses WPA2, 49

49

so just to confirm this to you, 50

50

if I go here to my host machine 51

51

and just try to connect to it, 52

52

you'll see that it's telling me 53

53

that this uses a WPA2 password. 54

54

But like I said, we don't care 55

55

if it's WPA or WPA2 56

56

because we're gonna be exploiting a features 57

57

in these encryptions which is the WPS feature. 58

58

So now that we know our target network uses WPS, 59

59

there's a good chance that this attack will work against it. 60

60

The only reason it might fail 61

61

is if the target uses PBC 62

62

or push button authentication. 63

63

Like I said, if the target uses PBC, 64

64

then it will refuse all the PINs 65

65

unless the button is pressed on the router 66

66

and therefore this attack will fail. 67

67

The only way to know is to literally try this attack 68

68

and see if it works. 69

69

So I'm gonna copy the MAC address of this network 70

70

or the BSSID 71

71

and the first thing that I'm gonna do, 72

72

similar to what we did with WEP, 73

73

I'm going to associate with the target network 74

74

using a fake authentication attack. 75

75

So basically I'll be saying I want 76

76

to communicate with you, 77

77

please don't ignore me 78

78

so that when I run the attack, 79

79

the network will start accepting the PINs 80

80

and not ignore me. 81

81

So to associate, we're gonna use the exact same command 82

82

that we used when we did it with WEP. 83

83

So we're gonna use aireplay.ng. 84

84

We're gonna tell it I want to run 85

85

a fake authentication attack. 86

86

We're gonna give it the delay, 87

87

so this is the time to wait 88

88

between association attempts. 89

89

Previously we set it to zero 90

90

and we had to do this manually every now and then. 91

91

Right now I'm gonna set it to 30 92

92

so that we associate 93

93

with the target network every 30 seconds. 94

94

Then I'm gonna do -a to give it the MAC address 95

95

of my target and -h 96

96

to give it the MAC address of my wireless adapter 97

97

in monitor mode 98

98

and we see that we can get this by doing ifconfig. 99

99

And copy it from here. 100

100

We said it's the first 12 digits. 101

101

And I'll just replace the minus with the colon. 102

102

And finally, I'm gonna give it the name 103

103

of my wireless adapter in monitor mode which is mon0. 104

104

So I explained this in details before. 105

105

That's why I did it quickly. 106

106

If you don't remember how I did this, 107

107

please go back to the fake authentication attack lecture. 108

108

So the command is ready now, 109

109

but I'm not gonna execute it. 110

110

I'm gonna go down to the bottom terminal 111

111

and run Reaver which is the program 112

112

that will boot first the PIN for me 113

113

and only then I will associate with the target 114

114

because otherwise, aireplay.ng will fail 115

115

to associate with my network. 116

116

So I'm gonna move to this terminal right here, 117

117

I'm gonna clear the screen. 118

118

And we're gonna run Reaver which is the program 119

119

that's going to boot first the PIN, 120

120

so it's gonna try every possible PIN 121

121

until it get the right PIN. 122

122

Once it has the right PIN, 123

123

it'll use it to compute the actual WPA key. 124

124

So using Reaver is very, very simple. 125

125

It's very similar to everything 126

126

we've been doing so far. 127

127

So first of all, we have to type the program name 128

128

which is reaver. 129

129

Then I'm gonna do --bssid to give it the MAC address 130

130

of my target network. 131

131

So I'm just gonna paste it. 132

132

Then I'm gonna do --channel. 133

133

And give it the channel of the target network 134

134

which is one. 135

135

Then we're gonna do --interface 136

136

and give it my wireless adapter 137

137

in monitor mode which is mon0. 138

138

So a very, very simple command. 139

139

We're using Reaver, this is the name of the program 140

140

that'll do the brute forcing for us 141

141

and give us the key. 142

142

We're giving it the bssid, the MAC address of my target. 143

143

We're doing --channel to give it the channel 144

144

that my target is running on 145

145

and we're doing --interface to give it the name 146

146

of my wireless adapter in monitor mode. 147

147

I'm also gonna add two more options. 148

148

I'm gonna add --vvv to show us 149

149

as much information as possible. 150

150

This is really helpful. 151

151

If it fails or things go wrong, 152

152

we'll be able to know what's happening, 153

153

why things are going wrong. 154

154

And I'm also gonna do --no-associate 155

155

to tell Reaver not to associate with the target network 156

156

because we're already manually doing that in here. 157

157

So Reaver can automatically do this step right here for you 158

158

but I've seen that it fails a lot. 159

159

Therefore it's actually better 160

160

to do it ourselves manually here 161

161

and then tell Reaver not to associate. 162

162

So now I'm gonna hit Enter 163

163

to get Reaver to work. 164

164

And I'm gonna go up to the top terminal 165

165

and I'm gonna hit Enter to associate 166

166

with the target network telling it, 167

167

please don't ignore us so that Reaver at the bottom here 168

168

can brute force the PIN 169

169

and try every possible PIN 170

170

until we get the correct PIN 171

171

which we'll use to get the password. 172

172

Now, as you can see, right now I'm getting an error 173

173

and this is actually a bug 174

174

with the latest versions of Reaver. 175

175

So if you get this bug, 176

176

this means they still haven't fixed it 177

177

in the latest version. 178

178

So it's better to go back and use an older version. 179

179

I'm gonna include an older version 180

180

that works perfectly in the resources of this lecture 181

181

so you can access it from the top left of the lecture. 182

182

If you tried Reaver and got this error right here, 183

183

then go ahead and download this older version. 184

184

Right now I already have it in my downloads right here, 185

185

so you can see I'm in Home, Downloads 186

186

and I have it right here called Reaver. 187

187

So what I'm gonna do is I'm gonna clear this again 188

188

and I'm gonna navigate to my Downloads so cd Downloads. 189

189

I'm gonna list and you can see we have it right here. 190

190

Now, it's already in green for me 191

191

but for you, you'd wanna change the permissions 192

192

of this file to an executable 193

193

so you'll have to do chmod +x reaver. 194

194

This will make it an executable. 195

195

Once it is an executable, 196

196

you can run it by doing ./ followed by its name, so reaver. 197

197

Then you can do the exact same command 198

198

exactly like I just did it with the one 199

199

that comes pre-installed in Kali. 200

200

So I'm actually just gonna go back 201

201

to what I had and I'm just gonna go 202

202

to the start of the command 203

203

and put ./ 204

204

so when we put the ./ 205

205

we're basically running the file 206

206

that is in the current working directory. 207

207

We're running this, we're not running the normal Reaver file 208

208

that is pre-installed in Kali. 209

209

Then we're using all of the options exactly the same way 210

210

that we were using it with the built-in one. 211

211

I'm gonna hit Enter. 212

212

And as you can see, right now Reaver 213

213

is trying the PIN 1234567. 214

214

And perfect. 215

215

You can see the PIN was actually 12345670. 216

216

So it's a simple PIN. 217

217

It actually came with the PIN 218

218

so I didn't manually set this PIN. 219

219

My router came from the factory with WPS enabled 220

220

with this PIN. 221

221

So like I said, this tool works 222

222

but again, not against all routers. 223

223

From that, it was able to discover the WPA key 224

224

which is UAURWSXR 225

225

and the name of the router is Test AP. 226

226

So I can literally go ahead 227

227

and connect with this password 228

228

and I'll be able to connect to the network 229

229

and see and decrypt all of the packets sent in the air.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.