Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Now that we have associated 2
2
with our target network, 3
3
we can start communicating with it, and it won't ignore us. 4
4
So now we can go and start injecting packets 5
5
into the traffic to force the access point 6
6
to generate new packets with new IVs. 7
7
This will increase the number of data 8
8
really, really quickly, allowing us 9
9
to crack WEP networks in minutes, 10
10
even if the network was not busy, 11
11
like the one that we are targeting right now. 12
12
Now, there are a number of ways to do this, 13
13
but in this course, I'm going to explain 14
14
the most reliable method 15
15
which is using an ARP request replay attack. 16
16
I actually explain other methods 17
17
in my network hacking course, 18
18
but they are a little bit more complex 19
19
and have less success rate. 20
20
So this is the most reliable method 21
21
and it should work against most networks 22
22
if you have a good signal and a good wireless adapter. 23
23
So the idea behind this method is 24
24
to wait for an ARP packet, 25
25
and I'll talk about ARP in more details later on. 26
26
So for now, just think of it as a special type of a packet 27
27
that we're gonna be waiting on. 28
28
Once this packet is sent in the network, 29
29
we're going to capture it and retransmit it. 30
30
Once we do this, the router is forced 31
31
to generate a new packet with a new IV. 32
32
So by repeating this process, we will be forcing the router 33
33
to continuously generate new packets with new IVs. 34
34
Then once we have enough data, once we have enough IVs, 35
35
we can run aircrack-ng, 36
36
exactly as we seen before and crack the key. 37
37
So let me show you how to do this in practice. 38
38
Now, as you can see, 39
39
I'm already running airodump-ng against my target network. 40
40
And I have already associated with it 41
41
as shown in the previous lecture. 42
42
So the only thing that's left right now 43
43
is to run the ARP replay attack 44
44
in order to inject packets into the traffic, 45
45
and force the router to generate new packets 46
46
and increase the number of data. 47
47
To do that, we're gonna use aireplay-ng again. 48
48
And the command is actually gonna be very similar 49
49
to this command right here. 50
50
So I'm actually gonna copy all of this because I'm lazy, 51
51
and I'm gonna clear this, and paste the command here. 52
52
Now, there are only a few things that I need to modify. 53
53
First of all, I don't want to run 54
54
a fake authentication attack, 55
55
so I'm gonna remove all of this, 56
56
and I want to run an ARP replay attack. 57
57
Also, this attack does not take a number, 58
58
so I'm gonna remove this number. 59
59
And I'm also gonna replace the a with b, and we're done. 60
60
So if you look at it, you'll see it's actually very similar 61
61
to this command right here. 62
62
We're using aireplay-ng, 63
63
but instead of doing a fake authentication attack, 64
64
we're doing an ARP replay attack, 65
65
we're giving it the MAC address of my target network 66
66
after the b instead of the a. 67
67
Then we're giving it the MAC address 68
68
of my wireless adapter after the h, 69
69
which is identical to this. 70
70
And then we're giving it 71
71
my wireless adapter in monitor mode. 72
72
Now, I'm actually gonna associate again, before I do that, 73
73
and then I'm gonna hit Enter here. 74
74
And what's happening right now is 75
75
my wireless adapter is waiting for an ARP packet, 76
76
once there is an ARP packet transmitted in this network, 77
77
it's gonna capture it, and it's going to retransmit it. 78
78
Once it does that, the access point will be forced 79
79
to generate a new packet with a new IV, 80
80
and we'll keep doing this, forcing the access point 81
81
to continually generate new packets with new IVs. 82
82
So you should just wait for it right now, 83
83
we're literally just waiting for an ARP packets 84
84
to be sent in the air. 85
85
And as you can see, the number of data 86
86
is increasing now very, very quickly, which means 87
87
that we actually managed to capture an ARP packet. 88
88
This ARP packet got retransmitted, forced the router 89
89
to generate a new packet with a new IV, 90
90
and we are continually doing this process, 91
91
forcing the router to generate new packets with new IVs. 92
92
So right now we can go ahead and run aircrack-ng, 93
93
to crack this network, and before I do that, 94
94
I'll actually just associate one more time. 95
95
And then I'm gonna do aircrack-ng, 96
96
and give it the name of the file 97
97
which we're storing the data in, 98
98
which is called arpreplay-01.cap. 99
99
So I'm gonna hit Enter, 100
100
and you'll notice the cracking process right now 101
101
will actually require more data packets. 102
102
The reason for this is, 103
103
I've actually modified the settings of this network, 104
104
so that it uses 128 bit key, 105
105
because in WEP, you can either use a 64 bit or 128 bit key, 106
106
and obviously, the 128 key is longer. 107
107
Therefore, I actually modified the key length 108
108
for this lecture to make sure it's the longest key possible. 109
109
And as you can see, we still managed to get it 110
110
within about 47,000 packets. 111
111
We have the key right here in ASCII, 112
112
and we have the key in here in hex, 113
113
where we can use after we remove the colons. 114
114
So perfect, now we managed to crack the target network, 115
115
it was idle as you could see, 116
116
the was no data being sent, and we managed to do this 117
117
by forcing the target access point 118
118
to generate new packets with new IVs.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.