Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Okay, now that we know 2
2
what WPS is and how it can be used 3
3
to recover the password for WPA and WPA2 networks, 4
4
let's see how to do that in practice. 5
5
So right here I have my Kali machine. 6
6
I've already enabled monitor mode 7
7
on my wireless adapter on 10. 8
8
Now, usually we use airodump-ng 9
9
to see all the networks around us. 10
10
But right now, we want to see the networks 11
11
that have WPS enabled 12
12
but because like I said it's just a feature 13
13
and people can turn this feature off, 14
14
so first of all, I'm gonna use a tool called wash 15
15
to display all the networks around me 16
16
that have WPS enabled. 17
17
So we're gonna do wash --interface 18
18
and give it my interface in monitor mode 19
19
which is mon0. 20
20
So all we're doing is wash is the name of the tool, 21
21
interface to give it the interface 22
22
and mon0 is my wireless adapter in monitor mode. 23
23
If I hit Enter now, 24
24
you'll see it'll list my network straight away. 25
25
Now, I pressed Control + C to cancel this, 26
26
similar to airodump-ng 27
27
because it'll keep running 28
28
unless you cancel it. 29
29
And you can see this is my target network. 30
30
It's called Test_AP. 31
31
It's giving us the vendor 32
32
of the hardware used in this network 33
33
in this access point. 34
34
The Lck tell us whether WPS is locked or not 35
35
because sometimes WPS locks 36
36
after a number failed attempts. 37
37
So right now this says no, 38
38
which means that we can actually go ahead 39
39
and try to guess the PIN. 40
40
It's giving us the version of WPS, it's using version one. 41
41
The signal strength is in here. 42
42
The channel and the BSSID. 43
43
Now, I explained the meaning of all these things before 44
44
in my airodump-ng lecture 45
45
so I'm not gonna talk about them now. 46
46
If you forgot the meaning of any of these terms, 47
47
please go back to the airodump-ng lecture. 48
48
Now, this network actually uses WPA2, 49
49
so just to confirm this to you, 50
50
if I go here to my host machine 51
51
and just try to connect to it, 52
52
you'll see that it's telling me 53
53
that this uses a WPA2 password. 54
54
But like I said, we don't care 55
55
if it's WPA or WPA2 56
56
because we're gonna be exploiting a features 57
57
in these encryptions which is the WPS feature. 58
58
So now that we know our target network uses WPS, 59
59
there's a good chance that this attack will work against it. 60
60
The only reason it might fail 61
61
is if the target uses PBC 62
62
or push button authentication. 63
63
Like I said, if the target uses PBC, 64
64
then it will refuse all the PINs 65
65
unless the button is pressed on the router 66
66
and therefore this attack will fail. 67
67
The only way to know is to literally try this attack 68
68
and see if it works. 69
69
So I'm gonna copy the MAC address of this network 70
70
or the BSSID 71
71
and the first thing that I'm gonna do, 72
72
similar to what we did with WEP, 73
73
I'm going to associate with the target network 74
74
using a fake authentication attack. 75
75
So basically I'll be saying I want 76
76
to communicate with you, 77
77
please don't ignore me 78
78
so that when I run the attack, 79
79
the network will start accepting the PINs 80
80
and not ignore me. 81
81
So to associate, we're gonna use the exact same command 82
82
that we used when we did it with WEP. 83
83
So we're gonna use aireplay.ng. 84
84
We're gonna tell it I want to run 85
85
a fake authentication attack. 86
86
We're gonna give it the delay, 87
87
so this is the time to wait 88
88
between association attempts. 89
89
Previously we set it to zero 90
90
and we had to do this manually every now and then. 91
91
Right now I'm gonna set it to 30 92
92
so that we associate 93
93
with the target network every 30 seconds. 94
94
Then I'm gonna do -a to give it the MAC address 95
95
of my target and -h 96
96
to give it the MAC address of my wireless adapter 97
97
in monitor mode 98
98
and we see that we can get this by doing ifconfig. 99
99
And copy it from here. 100
100
We said it's the first 12 digits. 101
101
And I'll just replace the minus with the colon. 102
102
And finally, I'm gonna give it the name 103
103
of my wireless adapter in monitor mode which is mon0. 104
104
So I explained this in details before. 105
105
That's why I did it quickly. 106
106
If you don't remember how I did this, 107
107
please go back to the fake authentication attack lecture. 108
108
So the command is ready now, 109
109
but I'm not gonna execute it. 110
110
I'm gonna go down to the bottom terminal 111
111
and run Reaver which is the program 112
112
that will boot first the PIN for me 113
113
and only then I will associate with the target 114
114
because otherwise, aireplay.ng will fail 115
115
to associate with my network. 116
116
So I'm gonna move to this terminal right here, 117
117
I'm gonna clear the screen. 118
118
And we're gonna run Reaver which is the program 119
119
that's going to boot first the PIN, 120
120
so it's gonna try every possible PIN 121
121
until it get the right PIN. 122
122
Once it has the right PIN, 123
123
it'll use it to compute the actual WPA key. 124
124
So using Reaver is very, very simple. 125
125
It's very similar to everything 126
126
we've been doing so far. 127
127
So first of all, we have to type the program name 128
128
which is reaver. 129
129
Then I'm gonna do --bssid to give it the MAC address 130
130
of my target network. 131
131
So I'm just gonna paste it. 132
132
Then I'm gonna do --channel. 133
133
And give it the channel of the target network 134
134
which is one. 135
135
Then we're gonna do --interface 136
136
and give it my wireless adapter 137
137
in monitor mode which is mon0. 138
138
So a very, very simple command. 139
139
We're using Reaver, this is the name of the program 140
140
that'll do the brute forcing for us 141
141
and give us the key. 142
142
We're giving it the bssid, the MAC address of my target. 143
143
We're doing --channel to give it the channel 144
144
that my target is running on 145
145
and we're doing --interface to give it the name 146
146
of my wireless adapter in monitor mode. 147
147
I'm also gonna add two more options. 148
148
I'm gonna add --vvv to show us 149
149
as much information as possible. 150
150
This is really helpful. 151
151
If it fails or things go wrong, 152
152
we'll be able to know what's happening, 153
153
why things are going wrong. 154
154
And I'm also gonna do --no-associate 155
155
to tell Reaver not to associate with the target network 156
156
because we're already manually doing that in here. 157
157
So Reaver can automatically do this step right here for you 158
158
but I've seen that it fails a lot. 159
159
Therefore it's actually better 160
160
to do it ourselves manually here 161
161
and then tell Reaver not to associate. 162
162
So now I'm gonna hit Enter 163
163
to get Reaver to work. 164
164
And I'm gonna go up to the top terminal 165
165
and I'm gonna hit Enter to associate 166
166
with the target network telling it, 167
167
please don't ignore us so that Reaver at the bottom here 168
168
can brute force the PIN 169
169
and try every possible PIN 170
170
until we get the correct PIN 171
171
which we'll use to get the password. 172
172
Now, as you can see, right now I'm getting an error 173
173
and this is actually a bug 174
174
with the latest versions of Reaver. 175
175
So if you get this bug, 176
176
this means they still haven't fixed it 177
177
in the latest version. 178
178
So it's better to go back and use an older version. 179
179
I'm gonna include an older version 180
180
that works perfectly in the resources of this lecture 181
181
so you can access it from the top left of the lecture. 182
182
If you tried Reaver and got this error right here, 183
183
then go ahead and download this older version. 184
184
Right now I already have it in my downloads right here, 185
185
so you can see I'm in Home, Downloads 186
186
and I have it right here called Reaver. 187
187
So what I'm gonna do is I'm gonna clear this again 188
188
and I'm gonna navigate to my Downloads so cd Downloads. 189
189
I'm gonna list and you can see we have it right here. 190
190
Now, it's already in green for me 191
191
but for you, you'd wanna change the permissions 192
192
of this file to an executable 193
193
so you'll have to do chmod +x reaver. 194
194
This will make it an executable. 195
195
Once it is an executable, 196
196
you can run it by doing ./ followed by its name, so reaver. 197
197
Then you can do the exact same command 198
198
exactly like I just did it with the one 199
199
that comes pre-installed in Kali. 200
200
So I'm actually just gonna go back 201
201
to what I had and I'm just gonna go 202
202
to the start of the command 203
203
and put ./ 204
204
so when we put the ./ 205
205
we're basically running the file 206
206
that is in the current working directory. 207
207
We're running this, we're not running the normal Reaver file 208
208
that is pre-installed in Kali. 209
209
Then we're using all of the options exactly the same way 210
210
that we were using it with the built-in one. 211
211
I'm gonna hit Enter. 212
212
And as you can see, right now Reaver 213
213
is trying the PIN 1234567. 214
214
And perfect. 215
215
You can see the PIN was actually 12345670. 216
216
So it's a simple PIN. 217
217
It actually came with the PIN 218
218
so I didn't manually set this PIN. 219
219
My router came from the factory with WPS enabled 220
220
with this PIN. 221
221
So like I said, this tool works 222
222
but again, not against all routers. 223
223
From that, it was able to discover the WPA key 224
224
which is UAURWSXR 225
225
and the name of the router is Test AP. 226
226
So I can literally go ahead 227
227
and connect with this password 228
228
and I'll be able to connect to the network 229
229
and see and decrypt all of the packets sent in the air.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.