Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
In the last lecture, 2
2
we've seen to use airodump-ng 3
3
to list all the networks around us 4
4
and display useful information about them. 5
5
Usually, we do this in order 6
6
to see our target network, 7
7
see the signal strength, see how far we are from it 8
8
and then start targeting this target network. 9
9
Now, in this example, 10
10
I'm gonna assume that my target network 11
11
is this one right here. 12
12
This is actually the network 13
13
that my host machine is connected to 14
14
and now that I have my target network, 15
15
and I have some basic information about it, 16
16
let's see how we can run airodump-ng 17
17
against this network only, 18
18
not against all networks. 19
19
And this way, we'll be able 20
20
to gather more information about it. 21
21
So to do this, first of all, 22
22
I'm gonna have to write the name of my program 23
23
which is airodump-ng. 24
24
Then I'm going to specify a specific BSSID 25
25
or a specific MAC address 26
26
for airodump-ng to sniff data from. 27
27
So my target network has a BSSID of this. 28
28
We can see it here under the BSSID. 29
29
So I'm gonna copy it 30
30
and then I'm gonna do --bssid 31
31
and I'm gonna give it the BSSID that I just copied. 32
32
Next, I'm gonna specify a channel 33
33
for airodump-ng to sniff. 34
34
Again, if we look under the Channel column in here, 35
35
we can see my target network 36
36
is on channel two. 37
37
So I'm gonna do --channel 2. 38
38
So now, we're telling airodump-ng 39
39
that I want you to sniff data on channel two 40
40
and only from a network that has this BSSID. 41
41
I'm also going to tell airodump-ng 42
42
that I want you to store all the data 43
43
that you're gonna gather for me in a file. 44
44
So I'm gonna say --write 45
45
and then I'm gonna type a file name 46
46
and let's call this test 47
47
and at the end, as usual, 48
48
I need to give it the name of my wireless adapter 49
49
in monitor mode 50
50
which is mon0 in my case. 51
51
So a very simple command. 52
52
Let's go over it one more time. 53
53
We're doing airodump-ng, 54
54
that's the name of the program that I wanna use. 55
55
I'm telling it that I only want you to sniff data 56
56
from a specific bssid. 57
57
Then I'm giving it the BSSID of my target. 58
58
Then I'm telling it I want you to only sniff data 59
59
from a specific channel 60
60
and I'm giving it the channel 61
61
that I want it to sniff data from, 62
62
again, we can get it from here, it's number two. 63
63
Finally, I'm telling it that I want you 64
64
to write all the data 65
65
that you're gonna capture in a file 66
66
that we're gonna call it test 67
67
and then I'm giving it my wireless adapter 68
68
in monitor mode which is mon0. 69
69
Now, I'm gonna hit Enter. 70
70
And as you can see, unlike the last time, 71
71
airodump-ng is only showing me one network in here. 72
72
This is the network that I wanted it to sniff data on. 73
73
And we can also see, 74
74
we have a completely new section right now. 75
75
So when I run airodump-ng in the previous lecture, 76
76
you've seen I only had the networks in here 77
77
and I had nothing here at the bottom. 78
78
But now, you can see we have more entries in here 79
79
at the second section of networks 80
80
and basically, anything that you see here 81
81
in the second section, 82
82
these are the clients or the devices connected 83
83
to this network. 84
84
So right now, we can see this network 85
85
has three devices connected to it 86
86
and you can see the MAC addresses of these devices 87
87
under the Station. 88
88
So you can see all of these devices 89
89
are connected to the same network. 90
90
So the BSSID is still the same, 91
91
this is the MAC address of the network 92
92
and under the Station, 93
93
we have the different clients or different devices connected 94
94
to this network. 95
95
We can also see the Power, so this is the signal strength 96
96
of each of these devices. 97
97
We can see the speed, 98
98
we can see the amount of data lost, 99
99
we can see the amount of frames or packets 100
100
that we have captured 101
101
and we can see if any of these devices 102
102
are still probing for networks. 103
103
So sometimes, when you run airodump-ng 104
104
against all networks, 105
105
you'd still see the section 106
106
and you'd see that some devices 107
107
are not connected and they're literally trying 108
108
or looking for networks. 109
109
So you'd see the name of the networks 110
110
that they're looking for under the Probe. 111
111
Now, if I hit Control + C, 112
112
airodump-ng will quit, it'll stop working 113
113
but I should have new files in my current working directory 114
114
that contain the data 115
115
that we just captured 'cause remember, 116
116
when we run the command, we use the write option in here 117
117
to store the data in a file called test. 118
118
So if I just do ls to list all the files 119
119
in my current working directory, 120
120
you can see I have four files, 121
121
all of them start with test. 122
122
But they all have different extensions. 123
123
So we have a CSV, we have a netxml, 124
124
we have a cap 125
125
and we have a Kismet.csv. 126
126
Now also notice that airodump-ng 127
127
automatically appended minus 01 128
128
to each of these files. 129
129
So in the future, when you go 130
130
and try to use the capture file, 131
131
make sure you append -01 132
132
to the file name that you specified in the command. 133
133
Now, the main file that we're gonna be using 134
134
is the cap file. 135
135
Again, this file contains the data 136
136
that we captured during the period 137
137
that airodump-ng was working on in here. 138
138
And basically this file should contain everything 139
139
that was sent to and from my target network. 140
140
So it should contain URLs, 141
141
chat messages, usernames, passwords 142
142
or anything that any of these devices did on the internet 143
143
because anything that they have to do 144
144
will have to be sent to the router 145
145
as we've seen before. 146
146
The only problem is if you look at the encryption in here, 147
147
you can see that my target network uses WPA2 encryption. 148
148
So all of the data sent between the router 149
149
and the clients is encrypted. 150
150
So let me show you what I mean. 151
151
I'm gonna use a tool called Wireshark 152
152
to analyze the data 153
153
and don't worry about how to use Wireshark. 154
154
We will talk about it in details later on. 155
155
Right now, I just want to make sure 156
156
that you understand the idea 157
157
that now we're able to capture all these packets, 158
158
the only problem is these packets are encrypted. 159
159
So I'm gonna do wireshark to run Wireshark. 160
160
And then I'm gonna open my capture file, 161
161
so I'm gonna go to File, Open 162
162
and it's already in my root directory, 163
163
so I'm just gonna scroll down 164
164
and select my test-01.cap. 165
165
I'm gonna open it 166
166
and I'll just put this in full screen 167
167
and as you can see, 168
168
if we click on any of these packets, 169
169
you see we really have no useful data. 170
170
You can see everything looks like gibberish 171
171
and we can't read anything 172
172
even though these packets might contain usernames, 173
173
passwords or URLs. 174
174
The only useful thing that we can see here 175
175
is the device manufacturer. 176
176
So we know one of the devices connected to the network 177
177
that has this specific MAC address, 178
178
so it's the one that ends with E8 179
179
and if we go up, we can see that it's this specific device, 180
180
we know now it is an Apple device. 181
181
So it could be an Apple computer, 182
182
it could be an iPhone or an iPad 183
183
and this is actually my MacBook computer 184
184
that is the host machine. 185
185
Again, we can see we also have a device 186
186
that's using a Huawei chip set 187
187
so this can be a phone or it could be the router. 188
188
And if you look at the MAC address here, 189
189
and compare it to the MAC addresses 190
190
that we have here, you can see 191
191
that this is actually under the BSSID 192
192
so this is the MAC address of the router. 193
193
So now we know that the brand 194
194
of my router is Huawei. 195
195
So we can gather more information 196
196
by opening this file in Wireshark 197
197
and we can kinda guess 198
198
what computers are there 199
199
and what operating systems they use 200
200
but this is not detailed enough 201
201
and the main problem with this 202
202
is the fact that the network is using encryption. 203
203
Now, in the next section, 204
204
we're gonna be talking about how to break this encryption 205
205
and once we do, you'll see how we can see the passwords, 206
206
the usernames in plain text 207
207
and you'll also see how we can map all 208
208
of the computers on the same network, 209
209
gather detailed information about them, 210
210
hack into them and do some really, really cool stuff. 211
211
Now, you should guess by everything that I said so far, 212
212
if this network was an open network, 213
213
if it was a network that does not use any passwords, 214
214
then you would have been able 215
215
to actually see all the URLs and everything 216
216
that they do in here. 217
217
But again, if you can't connect to the network 218
218
without a password, 219
219
then you'll automatically be at the post connection section 220
220
and in that section, like I said, 221
221
we're gonna talk about some really, really cool attacks 222
222
that you can do 223
223
once you have the password or once you can connect 224
224
to the network. 225
225
So don't worry about Wireshark for now. 226
226
I just wanted to make sure 227
227
that you understand why encryption is useful 228
228
and why it's used 229
229
and why we can't see much now 230
230
because we don't know the key. 231
231
We will talk about Wireshark and all of that later on 232
232
in the next section.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.