Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Now before leaving this section and moving 2
2
to the gaining access section where I'm gonna teach you 3
3
how to break the different encryptions and gain access 4
4
to networks, I want to spend one more lecture talking about 5
5
a really useful attack that still falls under the 6
6
pre-connection attacks under this section. 7
7
The attack that I want to talk about, 8
8
is the de-authentication attack. 9
9
This attack allow us to disconnect any device, 10
10
from any network, before connecting to any of these networks 11
11
and without the need to know the password for the network. 12
12
To do this, we're going to pretend to be the client 13
13
that we want to disconnect, by changing our MAC address 14
14
to the MAC address of that client, and tell the router 15
15
that I want to disconnect from you. 16
16
Then, we're going to pretend to be the router, again, 17
17
by changing our MAC address to the router's MAC address 18
18
and tell the client that you're requested 19
19
to be disconnected, so I'm going to disconnect you. 20
20
This will allow us to successfully disconnect, 21
21
or de-authenticate any client from any network. 22
22
Now, we're actually not going to do this manually, 23
23
we're gonna use a tool called aireplay-ng to do that. 24
24
From the previous lecture, we know that this MAC 25
25
address right here, belongs to an Apple computer, and like 26
26
I said, this Apple computer is actually my computer 27
27
right here. 28
28
And, as you can see, this host machine is connected to this 29
29
network right here, which is the same as the one that you 30
30
see in here, and it actually has internet access. 31
31
So, if I just look for test, you'll see that I'm connected 32
32
and I can look for things, I can use google. 33
33
So, I have a proper working internet connection. 34
34
Now, we're gonna come back here, and we're gonna use a tool 35
35
called aireplay-ng, to launch the de-authentication attack, 36
36
and disconnect this MAC computer from the internet. 37
37
So, we're gonna type the name of the program, which is 38
38
aireplay-ng, we're gonna tell it that I want to run 39
39
a de-authentication attack, then, I'm gonna give it 40
40
the number of de-authentication packets that I want to send. 41
41
So, I'm gonna give it a really large number, so that 42
42
it keeps sending these packets to both the router, 43
43
and the target device, therefore, I'll disconnect my target 44
44
device for a very long period of time, and the only way 45
45
to get it back to connect is to hit Control + C and quit 46
46
aireplay-ng. 47
47
Next, I'm gonna give aireplay-ng the MAC address 48
48
of my target network. 49
49
So, I'm gonna do -a and give it the MAC address, which 50
50
I'm gonna copy from here. 51
51
Then, I'm gonna use -c to give it the MAC address of the 52
52
client that I want to disconnect. 53
53
And, the client that I want to disconnect is this client 54
54
right here, which is the Apple computer like we said. 55
55
So, I'm gonna copy it, and paste it here. 56
56
And finally, 57
57
I'm gonna give it the name of my wireless adapter in 58
58
monitor mode, and in my case it's called mon zero. 59
59
So, a very, very simple command. 60
60
We're typing aireplay-ng, this is the name of the program 61
61
that we're going to use, we're doing --deauth to tell 62
62
aireplay-ng that I want to run a de-authentication attack, 63
63
I'm givin' it a really large number of packets, so that it 64
64
keeps sending the de-authentication packets 65
65
to both the router and the client, and keep the client 66
66
disconnected, I'm using -a to specify the MAC address of the 67
67
target router, or the target access point, then I'm using -c 68
68
to specify the MAC address of the client. 69
69
Finally, I'm givin' it mon zero, which is the name 70
70
of my wireless adapter in monitor mode. 71
71
Now, you can run this command like this, and in most cases 72
72
it would work, but in very rare cases, this command will 73
73
fail unless airodump-ng is running against the target 74
74
network. 75
75
So, what I'm gonna do now is, I'm gonna go back to my 76
76
first terminal in here, and I'm going to run airodump-ng 77
77
using the command that we seen before, and I don't want 78
78
to write anything to our file, so I'm going to remove the 79
79
write argument. 80
80
So, I'm just doin' a normal airodump-ng command. 81
81
I'm literally just givin' it the BSSID of my target network, 82
82
and I'm givin' it the target channel, and then I'm just 83
83
gonna hit Enter. 84
84
We seen how to do this, we spent a full lecture on it, 85
85
that's why I did it really quick. 86
86
And then I'm gonna go back to the command that we wrote 87
87
so far, and I'm gonna hit Enter. 88
88
Now, as you can see, aireplay-ng it's telling me that it's 89
89
sending the de-authentication packets, and if we go back 90
90
here and look up, you can see that I actually lost 91
91
my connection, and I'm trying to connect back. 92
92
So, obviously if I try to look for anything, so let's say 93
93
test 2, you'll see I'll get stuck and nothing will load 94
94
for me. 95
95
So, the only way for me to connect back is, if I go back 96
96
here, if I quit this by doing Control+C, quit this again, 97
97
and now my machine should be able to connect back, 98
98
and restore its connection. 99
99
This is actually very,very handy in so many ways. 100
100
It's very useful in social engineering cases, 101
101
where you could disconnect clients from the target network, 102
102
and then call the user and pretend to be, a person from the 103
103
IT Department and ask them to install a virus or a backdoor, 104
104
telling them that this would fix their issue. 105
105
You could also set, create other fake access point and get 106
106
them to connect to the fake access point, and then start 107
107
spying on them, from that access point. 108
108
And, we'll see how to do that later on in the course. 109
109
And, you can also use this to capture the handshake, 110
110
which is what happened in here, actually. 111
111
And, this is vital when it comes to WPA cracking and we'll 112
112
talk about this once we get to the WPA cracking section. 113
113
So, like I said, this is a small attack that can be used as 114
114
a plug into other attacks to make other attacks possible.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.