Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
In the previous lecture, 2
2
we've seen how easy it is to crack WEP. 3
3
All we had to do is capture enough data 4
4
and then run aircrack-ng to crack the encryption 5
5
and give me the key. 6
6
Now, one problem that we could face 7
7
is if the network is not busy. 8
8
If it's not busy, 9
9
then the number of data 10
10
will be increasing very, very slowly. 11
11
Therefore, we're gonna have to wait 12
12
for a while before we have enough data 13
13
to crack the key. 14
14
So let me show you an example. 15
15
I'm just gonna run airodump-ng here 16
16
and list all the networks around me. 17
17
And you can see I have my test network, 18
18
my Test AP in here, it's using WEP. 19
19
And if you look under the Data, 20
20
you'll see that it's at zero 21
21
and it's not increasing 22
22
and even if it's gonna increase, 23
23
it's gonna increase very, very slowly 24
24
which means that I'm gonna have to be waiting 25
25
for hours before I can crack this network. 26
26
So a solution to this 27
27
is to force the AP to generate new packets with new IVs. 28
28
Now, before doing this, 29
29
we need to associate with this network. 30
30
So what I mean by associate 31
31
is we need to tell this network 32
32
that we want to communicate with it 33
33
because by default, 34
34
access points ignore any requests they get 35
35
unless the device has connected to this network 36
36
or associated with it. 37
37
So don't get this mixed up with connecting. 38
38
We're still unable to connect to the network 39
39
because we need the password to be able to connect 40
40
to the network 41
41
but what we're doing right now 42
42
is literally just telling the target network look, 43
43
I want to communicate with you. 44
44
Don't ignore my requests. 45
45
That's all we're doing. 46
46
So it's something similar to what happens 47
47
when you just click on the network when you want 48
48
to connect to it. 49
49
You still haven't put the password, 50
50
you just telling the target network 51
51
I want to communicate with you, 52
52
please don't ignore me. 53
53
So in this lecture, I'm gonna show you 54
54
how to associate with the target network 55
55
so we can communicate with it 56
56
and in the next lecture, 57
57
I'm gonna show you how once associated, 58
58
we can inject packets into the network 59
59
and force the number of data to increase very, very quickly. 60
60
First, I'm going to run airodump.ng 61
61
against my target network 62
62
which has this BSSID. 63
63
So I'm gonna copy it 64
64
and we're gonna use the exact same command 65
65
that we've been using so far. 66
66
So we're gonna do airodump.ng --bssid 67
67
followed by the MAC address of my target --channel 68
68
followed by the channel 69
69
which my target is running on which is six 70
70
and we're gonna store all of this. 71
71
So we're gonna do --write 72
72
and we'll call this file arpreplay 73
73
because that's the name of the attack. 74
74
And then I'm gonna put my wireless adapter 75
75
in monitor mode which is mon0. 76
76
So a very simple command that we've done before. 77
77
We're using airodump.ng to capture data 78
78
from a network with this MAC address, 79
79
running on this channel, 80
80
we're storing everything in a file called arpreplay. 81
81
I'm gonna hit Enter 82
82
and as you can see, it's running against my target 83
83
and notice the data is increasing really, really slow 84
84
or it's actually not increasing at all right now. 85
85
Now, to associate with this network, 86
86
we're going to use a program called aireplay-ng. 87
87
So we're gonna type aireplay-ng 88
88
followed by --fakeauth 89
89
because we want to do a fake authentication attack. 90
90
We're gonna put zero 91
91
because we only want to do this once. 92
92
We're gonna do -a to specify the MAC address 93
93
of the target network. 94
94
So I'm gonna paste it, I've already copied it. 95
95
Then we're gonna do -h 96
96
to specify the MAC address of my wireless adapter 97
97
and to get the MAC address of my wireless adapter, 98
98
I'm gonna do ifconfig. 99
99
And it's the first 12 digits of the unspec field. 100
100
Usually you'd see it after the ether 101
101
but when you enable monitor mode, 102
102
it'll show up like so. 103
103
So I'm gonna copy this. 104
104
And I'm gonna paste it here. 105
105
And I'm gonna replace the minuses with colons. 106
106
And that's it, it's done. 107
107
And finally, I'm just gonna give the name 108
108
of my wireless adapter in monitor mode. 109
109
So a very simple command. 110
110
We're using aireplay-ng 111
111
which is a tool that can be used 112
112
to run a number of attacks 113
113
and we've seen using this with the de-authentication attack. 114
114
We're telling it that we want 115
115
to run a fake authentication attack. 116
116
We wanna do this once. 117
117
We're giving it the MAC address of my target network 118
118
after the a. 119
119
Then I'm giving it the MAC address of my wireless adapter 120
120
after the h 121
121
an finally, I'm giving it my wireless adapter 122
122
in monitor mode. 123
123
Now before I run this, 124
124
notice in here under the AUTH, we have nothing. 125
125
And we don't have any clients showing up in here 126
126
at the bottom. 127
127
Now, if I hit Enter, 128
128
you can see under the AUTH, 129
129
it's showing up as OPN 130
130
and you can see we have a new client here associated 131
131
with the network. 132
132
If you look in here, 133
133
you'll see this is the MAC address of my target network 134
134
and right here is the MAC address 135
135
of my wireless adapter. 136
136
So right now, I am associated with the target network 137
137
and if I send it anything, 138
138
it's going to accept it 139
139
and it's gonna communicate with me. 140
140
Again, I am not connected to the network, 141
141
I still can't use the internet, 142
142
I'm literally just associated with the network 143
143
so I can communicate with it. 144
144
Now, in the next lecture, 145
145
I'm gonna show you how we can communicate 146
146
with this network in a way 147
147
to force it into generating new packets 148
148
with new IVs which will allow us 149
149
to crack the key very, very quickly.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.