Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Now, if WPS is disabled 2
2
on your target network, 3
3
or if it's enabled, but configured 4
4
to use push button or PBC, 5
5
then the method that I showed you in the previous lecture 6
6
will not work. 7
7
Therefore, you will have to go 8
8
and crack the actual WPA or WPA2 encryption. 9
9
And like I said, when these encryptions were designed, 10
10
the developers knew about the weaknesses in WEP 11
11
and they made sure 12
12
that they properly fixed these weaknesses. 13
13
They actually did a pretty good job at this. 14
14
Therefore, we cannot use the same method used in WEP 15
15
to crack WPA and WPA2. 16
16
So in WPA2, the keys are unique, they're temporary, 17
17
they much longer than what they were in WEP. 18
18
Therefore, the packets sent 19
19
in the air contained no information 20
20
that is useful for us. 21
21
So it doesn't matter even if we capture one million packets, 22
22
we can't use them to crack the key. 23
23
The only packets that contain useful information 24
24
are the handshake packets. 25
25
These are four packets transferred between a client 26
26
and the router when the client connects to the network. 27
27
So in this lecture, 28
28
I'm gonna show you how to capture these packets 29
29
and in the next lectures, 30
30
we'll see how to use them to crack the WPA 31
31
or WPA2 key. 32
32
First of all, as usual, 33
33
you'd wanna run airodump-ng 34
34
against all the networks around you. 35
35
I've already done that 36
36
and as you can see, this is my target right here. 37
37
It's using WPA2. 38
38
And this is the MAC address. 39
39
I'm gonna copy it. 40
40
And the first thing we'll do is just run airodump-ng 41
41
on this network and store the data in a file, 42
42
exactly the wame way that we used to do with WEP. 43
43
So we're just gonna do airodump-ng --bssid 44
44
and give it the BSSID of my target. 45
45
-channel and give it the channel of my target 46
46
which is one. 47
47
-write to specify a file name 48
48
to store all the data that we're gonna capture in. 49
49
And let's call this wpa_handshake 50
50
because we're gonna capture the handshake. 51
51
And finally, we're gonna give it my wireless adapter 52
52
in monitor mode 53
53
which is mon0. 54
54
So a very simple command. 55
55
We've done this multiple times by now. 56
56
We're using airodump-ng. 57
57
We're giving it the MAC address of my target 58
58
after the BSSID, I'm giving it --channel 59
59
to specify the channel of my target. 60
60
I'm using --write to store all the data in a file. 61
61
This file will contain everything 62
62
that we capture so if we capture the handshake, 63
63
it'll be in this file. 64
64
And finally, I'm giving it the name of my wireless adapter 65
65
in monitor mode. 66
66
So now I'm gonna hit Enter 67
67
and as you can see, airodump-ng is working 68
68
against my target network 69
69
and right now, all we have to do 70
70
is literally sit down and wait 71
71
for the handshake to be captured. 72
72
Like I said, the handshake is sent 73
73
when a client connects to the network 74
74
so we'll literally have to sit down 75
75
and wait until a new client connect to the network. 76
76
Once a new client connects, 77
77
we will capture the handshake 78
78
and you will see in here airodump telling us 79
79
that the handshake has been captured. 80
80
Alternatively, we can use something 81
81
that we learned before 82
82
which is a deauthentication attack. 83
83
We know using that attack, 84
84
we can disconnect a client from the network 85
85
so we can do this for a very short period of time. 86
86
We can disconnect this client from the network. 87
87
He will automatically connect once we stop the attack. 88
88
Therefore, when he automatically connects, 89
89
the handshake will be sent in the air 90
90
and we will be able to capture it. 91
91
This way we will not have to sit down 92
92
and wait for someone to voluntarily connect 93
93
to the network. 94
94
So we've seen how to do this before 95
95
and it's gonna be exactly the same command 96
96
as we did it before. 97
97
We used aireplay-ng. 98
98
We did --deauth. 99
99
Then we specified a really large number of packets 100
100
to keep the client disconnected for a long period of time. 101
101
This time, I'm gonna set this to four 102
102
to only send four deauthentication packets. 103
103
This way, my client will be disconnected 104
104
for a very short period of time. 105
105
They won't even feel that they got disconnected 106
106
but this is enough for the handshake 107
107
to be sent because they will be disconnected, 108
108
they will automatically connect 109
109
and when they do that, 110
110
we will capture the handshake. 111
111
Now, the next argument we wanna set 112
112
is the MAC address of my target. 113
113
So we're gonna do -a followed by the MAC address 114
114
of my target. 115
115
Then we're gonna do -c followed by the MAC address 116
116
of the client that we want to disconnect. 117
117
So it's this client right here. 118
118
I'm gonna copy, paste it here 119
119
and finally, we're gonna give it the name 120
120
of my wireless adapter in monitor mode 121
121
which is mon0. 122
122
And we are done. 123
123
Again, I've spent a full lecture on this command 124
124
explaining what a deauthentication attack is 125
125
so if it's a bit confusing, 126
126
please go back and revise that lecture. 127
127
Basically all we're doing is we're using aireplay-ng 128
128
to run a deauthentication attack 129
129
to disconnect this device 130
130
for a very short period of time. 131
131
That's why I'm setting this to only number four. 132
132
Then I'm using -a to specify the MAC address of my target, 133
133
c to specify the MAC address of the client connected 134
134
to this network 135
135
and then I'm giving it my wireless adapter in monitor mode. 136
136
Now I'm gonna hit Enter 137
137
and keep an eye on this side right here. 138
138
You'll see the handshake will be captured in here. 139
139
So I'm gonna hit Enter. 140
140
Deauthentication packets are being sent 141
141
and perfect, as you can see, 142
142
once the client connected again, 143
143
we receive the handshake. 144
144
So now we can quit airodump-ng. 145
145
So Control + C because we have the handshake now. 146
146
It is stored in the file 147
147
that we set after the right option 148
148
which is called wpa_handshake 149
149
and in the next lecture, I'll show you how this handshake 150
150
can be used to get the key for the network.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.