Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
So from the previous lecture, 2
2
we know, in order to crack WEP, 3
3
we need to first capture a large number of packets, 4
4
this means that we'll capture a large number of IVs, 5
5
the IVs, because they are short, 6
6
they will be repeated, 7
7
therefore we'll be able to use a tool called aircrack-ng 8
8
to run statistical attacks 9
9
and crack the WEP key. 10
10
So, we're using airodump-ng to capture the data 11
11
and we've seen how to do this before, 12
12
then we're using aircrack-ng 13
13
to analyze this data and break the key. 14
14
Let's see how to do this in practice. 15
15
So I already have my wireless adapter in monitor mode. 16
16
And it's called mon0. 17
17
I've also already run airodump-ng 18
18
to list all the networks around me 19
19
and as you can see, I have only one network using WEP. 20
20
This is called Test AP3 21
21
and this is my actual network 22
22
that I use every day. 23
23
I've just configured it to use WEP 24
24
to make this lecture. 25
25
The main reason why I'm targeting the network 26
26
that I use daily 27
27
because like I said, for this to work, 28
28
we need to capture a large number of packets 29
29
and therefore we need a busy network, 30
30
a network that gets used constantly 31
31
to capture a large number of packets. 32
32
If the network is idle, 33
33
then the process is a little bit complex 34
34
and I will cover that in the next lecture. 35
35
So for now, let's focus on the simplest form 36
36
which is how to break into a busy network. 37
37
So I'm gonna copy the BSSID of this network. 38
38
And I'm gonna run airodump-ng against this network only. 39
39
So I showed you how to do this before. 40
40
I'm gonna do airodump.ng. 41
41
I'm gonna do --bssid to specify the BSSID of the network. 42
42
Then I'm gonna do --channel 43
43
to specify the channel of the network 44
44
and we can see it's running on number one. 45
45
And I'm gonna do --write 46
46
to store everything that we capture into a file 47
47
and let's call this file basic_wep. 48
48
And then I'm gonna specify my wireless adapter 49
49
in monitor mode which is mon0. 50
50
So we ran this command before 51
51
in the targeted sniffing lecture. 52
52
All we're doing is we're running airodump.ng 53
53
against a specific network with this MAC address, 54
54
with this channel and we're storing everything in a file 55
55
called basic_wep. 56
56
I'm gonna hit Enter 57
57
and as you can see, airodump.ng is working 58
58
against my target network 59
59
and if you notice, 60
60
you'll see the data in here 61
61
is increasing really, really fast. 62
62
So this is something that I told you, 63
63
I'll talk about it later 64
64
when we were talking airodump.ng 65
65
because I didn't want to talk about IVs 66
66
at that early stage. 67
67
So basically what you see under the Data column 68
68
is the number of useful packets 69
69
that contain a different IV 70
70
that we can use in order to crack the key. 71
71
So the higher this number is, 72
72
the more likely we will be able 73
73
to crack the key. 74
74
As you can see, this number is increasing very fast 75
75
because like I said, this is a busy network 76
76
that is being used at the moment 77
77
by my own computers and my own devices. 78
78
If yours isn't increasing fast, 79
79
then don't worry, we will tackle this problem 80
80
in the next lectures. 81
81
So for now, we're capturing a lot of data 82
82
and this should actually be enough 83
83
to crack the key. 84
84
So what I'm gonna do, 85
85
I'm gonna go down to my other terminal in here 86
86
and if we actually list the files, 87
87
you'll see that we have the capture file 88
88
that we specified in the write argument 89
89
and like I said, we're always interested in the .cap file. 90
90
So all we have to do right now 91
91
is do step two in here. 92
92
Run aircrack-ng against the file 93
93
that we captured in order to crack the key. 94
94
So I'm gonna do aircrack.ng 95
95
followed by the file name 96
96
which is basic_wep-01.cap. 97
97
I'm gonna hit Enter. 98
98
And as you can see, 99
99
it's telling us that the key is found. 100
100
So let me cancel this here 101
101
and right now, we can connect 102
102
to the target network which is called Test_AP3 103
103
using this ASCII password, 104
104
so you can literally just copy this and paste it 105
105
or you can connect using this key. 106
106
Now, in some cases, 107
107
you will not see this ASCII password. 108
108
That's why I'm gonna show you how to connect 109
109
using this key right here 110
110
because you'll always get this. 111
111
So I'm gonna copy this. 112
112
And I'm just gonna paste it here. 113
113
You can paste it anywhere in a normal text editor 114
114
or anywhere you want. 115
115
And all you have to do 116
116
is remove the colons 117
117
that we see in here between the numbers. 118
118
So I'm gonna remove this one, 119
119
I'm gonna remove this one, 120
120
this one and this. 121
121
And now, we can just copy this. 122
122
And just to show you, 123
123
I'm actually gonna connect from my host machine. 124
124
You can connect from Kali 125
125
but when we enabled monitor mode, 126
126
we killed a lot of processes 127
127
and sometimes even after you restart these processes, 128
128
getting connecting to your target 129
129
will be a little bit buggy 130
130
so it's best to literally just restart Kali 131
131
and connect again. 132
132
So just to save all of this time, 133
133
I'm going to connect from here. 134
134
I'm just gonna click here, 135
135
I'm gonna connect to Test AP3. 136
136
And I'm going to paste the password. 137
137
So I'm just gonna click on Show the Password 138
138
to show it to you. 139
139
Again, the same password, 140
140
we just remove the colons. 141
141
I'm gonna click on Join. 142
142
And as you can see, we managed to connect 143
143
and we can test this connection 144
144
by going to Google and perfect. 145
145
As you can see, it's working 146
146
and we managed to break the WEP encryption.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.