All language subtitles for 5. ARP Request Replay Attack

af Afrikaans
ak Akan
sq Albanian
am Amharic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1 1

Now that we have associated 2

2

with our target network, 3

3

we can start communicating with it, and it won't ignore us. 4

4

So now we can go and start injecting packets 5

5

into the traffic to force the access point 6

6

to generate new packets with new IVs. 7

7

This will increase the number of data 8

8

really, really quickly, allowing us 9

9

to crack WEP networks in minutes, 10

10

even if the network was not busy, 11

11

like the one that we are targeting right now. 12

12

Now, there are a number of ways to do this, 13

13

but in this course, I'm going to explain 14

14

the most reliable method 15

15

which is using an ARP request replay attack. 16

16

I actually explain other methods 17

17

in my network hacking course, 18

18

but they are a little bit more complex 19

19

and have less success rate. 20

20

So this is the most reliable method 21

21

and it should work against most networks 22

22

if you have a good signal and a good wireless adapter. 23

23

So the idea behind this method is 24

24

to wait for an ARP packet, 25

25

and I'll talk about ARP in more details later on. 26

26

So for now, just think of it as a special type of a packet 27

27

that we're gonna be waiting on. 28

28

Once this packet is sent in the network, 29

29

we're going to capture it and retransmit it. 30

30

Once we do this, the router is forced 31

31

to generate a new packet with a new IV. 32

32

So by repeating this process, we will be forcing the router 33

33

to continuously generate new packets with new IVs. 34

34

Then once we have enough data, once we have enough IVs, 35

35

we can run aircrack-ng, 36

36

exactly as we seen before and crack the key. 37

37

So let me show you how to do this in practice. 38

38

Now, as you can see, 39

39

I'm already running airodump-ng against my target network. 40

40

And I have already associated with it 41

41

as shown in the previous lecture. 42

42

So the only thing that's left right now 43

43

is to run the ARP replay attack 44

44

in order to inject packets into the traffic, 45

45

and force the router to generate new packets 46

46

and increase the number of data. 47

47

To do that, we're gonna use aireplay-ng again. 48

48

And the command is actually gonna be very similar 49

49

to this command right here. 50

50

So I'm actually gonna copy all of this because I'm lazy, 51

51

and I'm gonna clear this, and paste the command here. 52

52

Now, there are only a few things that I need to modify. 53

53

First of all, I don't want to run 54

54

a fake authentication attack, 55

55

so I'm gonna remove all of this, 56

56

and I want to run an ARP replay attack. 57

57

Also, this attack does not take a number, 58

58

so I'm gonna remove this number. 59

59

And I'm also gonna replace the a with b, and we're done. 60

60

So if you look at it, you'll see it's actually very similar 61

61

to this command right here. 62

62

We're using aireplay-ng, 63

63

but instead of doing a fake authentication attack, 64

64

we're doing an ARP replay attack, 65

65

we're giving it the MAC address of my target network 66

66

after the b instead of the a. 67

67

Then we're giving it the MAC address 68

68

of my wireless adapter after the h, 69

69

which is identical to this. 70

70

And then we're giving it 71

71

my wireless adapter in monitor mode. 72

72

Now, I'm actually gonna associate again, before I do that, 73

73

and then I'm gonna hit Enter here. 74

74

And what's happening right now is 75

75

my wireless adapter is waiting for an ARP packet, 76

76

once there is an ARP packet transmitted in this network, 77

77

it's gonna capture it, and it's going to retransmit it. 78

78

Once it does that, the access point will be forced 79

79

to generate a new packet with a new IV, 80

80

and we'll keep doing this, forcing the access point 81

81

to continually generate new packets with new IVs. 82

82

So you should just wait for it right now, 83

83

we're literally just waiting for an ARP packets 84

84

to be sent in the air. 85

85

And as you can see, the number of data 86

86

is increasing now very, very quickly, which means 87

87

that we actually managed to capture an ARP packet. 88

88

This ARP packet got retransmitted, forced the router 89

89

to generate a new packet with a new IV, 90

90

and we are continually doing this process, 91

91

forcing the router to generate new packets with new IVs. 92

92

So right now we can go ahead and run aircrack-ng, 93

93

to crack this network, and before I do that, 94

94

I'll actually just associate one more time. 95

95

And then I'm gonna do aircrack-ng, 96

96

and give it the name of the file 97

97

which we're storing the data in, 98

98

which is called arpreplay-01.cap. 99

99

So I'm gonna hit Enter, 100

100

and you'll notice the cracking process right now 101

101

will actually require more data packets. 102

102

The reason for this is, 103

103

I've actually modified the settings of this network, 104

104

so that it uses 128 bit key, 105

105

because in WEP, you can either use a 64 bit or 128 bit key, 106

106

and obviously, the 128 key is longer. 107

107

Therefore, I actually modified the key length 108

108

for this lecture to make sure it's the longest key possible. 109

109

And as you can see, we still managed to get it 110

110

within about 47,000 packets. 111

111

We have the key right here in ASCII, 112

112

and we have the key in here in hex, 113

113

where we can use after we remove the colons. 114

114

So perfect, now we managed to crack the target network, 115

115

it was idle as you could see, 116

116

the was no data being sent, and we managed to do this 117

117

by forcing the target access point 118

118

to generate new packets with new IVs.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.