Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Now from the previous lectures, 2
2
we learned in order to crack WPA or WPA2, 3
3
we need to first capture the handshake. 4
4
And second, have a wordlist, 5
5
which contains a number of passwords 6
6
that we're going to try, and hopefully, 7
7
one of them will be the password for the target network. 8
8
So right now I have both of these components, 9
9
and we are ready to go and crack the password. 10
10
To do this, Aircrack-ng is going to unpack the handshake 11
11
and extract the useful information. 12
12
The MIC right here, or the message integrity code, 13
13
is what's used by the access point 14
14
to verify whether a password is correct or not. 15
15
So, it's gonna separate this and put it to the side, 16
16
and then it's going to use all 17
17
of the other information right here, 18
18
combined with the first password from the wordlist 19
19
to generate an MIC, another message integrity code. 20
20
And then, it's going to compare this MIC 21
21
to the one that's already in the handshake. 22
22
If the MIC generated using this information 23
23
plus the first password is the same, 24
24
then the password used to generate this MIC 25
25
is the password for the network. 26
26
Otherwise, this password is wrong, 27
27
and it'll move to the next password. 28
28
Again, it'll do the same, it'll use all of this information, 29
29
combined with this password, generate a new MIC, 30
30
compare this new MIC to the one 31
31
that's already in the handshake. 32
32
If it's correct, then this is the password. 33
33
If it's not, then it's gonna move onto the next password. 34
34
And it'll keep doing this through all of the passwords 35
35
in my wordlist. 36
36
If any of them generates the right MIC, 37
37
then this is the password for the network. 38
38
Otherwise, we won't be able to get the password. 39
39
That's why the success of this attack really depends 40
40
on your wordlist. 41
41
So, let's see how to do this in practice. 42
42
Right now I have my wordlist right here, 43
43
it's called test.txt. 44
44
And I've actually manually added my password 45
45
to the end of the list right here. 46
46
Just so that when I run the wordlist against the handshake, 47
47
I will actually find the password, 48
48
because the wordlist did not contain my password by default. 49
49
I also have the handshake file right here, 50
50
as you can see. 51
51
And all of this is in my Home directory, 52
52
which is my root directory. 53
53
So if I do L-S in here, you'll see I have the wordlist, 54
54
and the handshake file. 55
55
So, we're ready to run Aircrack-ng. 56
56
So we're gonna type the name of the program as usual, 57
57
followed by the name of my capture file, 58
58
which is wpa_handshake.01.cap. 59
59
So, so far it's identical to the way 60
60
that we used to use it with WEP. 61
61
The only difference right now, 62
62
because this is a WPA2 network, 63
63
we have to specify a wordlist with a dash W option. 64
64
And the name of my wordlist is test.txt. 65
65
So very, very simple. 66
66
Aircrack is the name of my program. 67
67
Wpa_handshake.01.cap is the name of the file 68
68
that contain my handshake. 69
69
And I'm using dash W to specify my wordlist file. 70
70
I'm gonna hit Enter. 71
71
And as you can see, now Aircrack-ng 72
72
is running through the wordlist, 73
73
testing each word in the wordlist one by one, 74
74
as shown in this diagram. 75
75
Calculated an MIC based on this information 76
76
and the wordlist. 77
77
And then, if the MIC is correct, it's going to tell me 78
78
that this is the password. 79
79
Now the speed of this depends on your processor, 80
80
and the size of your wordlist file. 81
81
So if you have a huge file, obviously, 82
82
it will take you longer time. 83
83
There are also online services that you can try 84
84
where you upload the handshake, 85
85
and they have huge wordlists and they have super computers 86
86
to run through these wordlists and try 87
87
to give you the password. 88
88
Unfortunately, I can't share their links with you, 89
89
but you can easily find them on Google 90
90
if you search for them. 91
91
And, perfect! 92
92
As you can see, we managed to find the key, 93
93
it's telling us the key is found, 94
94
and this is the key to the network. 95
95
And this is the correct key because as you know, 96
96
this is the same key that we got 97
97
when we exploited the WPS feature. 98
98
So now we can go ahead and connect to the network, 99
99
and we'll be able to run all of the cool stuff 100
100
that I'm gonna teach you 101
101
in the Post-Connection Attack section. 102
102
Now this is the only practical way known so far 103
103
to crack WPA and WPA2 keys. 104
104
There are methods to speed up this process 105
105
so you can use the GPU for cracking, 106
106
because it's much faster than the CPU. 107
107
That's if you have a GPU. 108
108
You can also use rainbow tables, 109
109
you can also pipe the wordlist 110
110
as it's being created in Crunch to Aircrack-ng. 111
111
This way you can create bigger wordlists 112
112
without using any storage on your computer. 113
113
There are also methods, 114
114
so that you can pause your cracking process, 115
115
and then come back after awhile 116
116
without losing your progress, 117
117
but the main idea's the same. 118
118
The only way right now to crack WPA and WPA2 119
119
is through a wordlist attack. 120
120
You can use social engineering, however, 121
121
to get the password using an evil twin attack, 122
122
where you trick one of the users to give you the password. 123
123
This is actually all covered 124
124
in my Advanced Network Hacking course. 125
125
The cracking using the GPU, pipe in Crunch to Aircrack-ng, 126
126
getting the password using an evil twin attack, 127
127
and much more advanced network hacking techniques. 128
128
If you are interested in that, 129
129
then I highly recommend you have a look 130
130
on my Advanced Network Hacking course. 131
131
Check out the bonus lecture of this course, 132
132
the last lecture of this course. 133
133
It contains links to all of my other courses, 134
134
and a comparison between them.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.