All language subtitles for 5. Cracking WPA & WPA2 Using a Wordlist Attack

af Afrikaans
ak Akan
sq Albanian
am Amharic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1 1

Now from the previous lectures, 2

2

we learned in order to crack WPA or WPA2, 3

3

we need to first capture the handshake. 4

4

And second, have a wordlist, 5

5

which contains a number of passwords 6

6

that we're going to try, and hopefully, 7

7

one of them will be the password for the target network. 8

8

So right now I have both of these components, 9

9

and we are ready to go and crack the password. 10

10

To do this, Aircrack-ng is going to unpack the handshake 11

11

and extract the useful information. 12

12

The MIC right here, or the message integrity code, 13

13

is what's used by the access point 14

14

to verify whether a password is correct or not. 15

15

So, it's gonna separate this and put it to the side, 16

16

and then it's going to use all 17

17

of the other information right here, 18

18

combined with the first password from the wordlist 19

19

to generate an MIC, another message integrity code. 20

20

And then, it's going to compare this MIC 21

21

to the one that's already in the handshake. 22

22

If the MIC generated using this information 23

23

plus the first password is the same, 24

24

then the password used to generate this MIC 25

25

is the password for the network. 26

26

Otherwise, this password is wrong, 27

27

and it'll move to the next password. 28

28

Again, it'll do the same, it'll use all of this information, 29

29

combined with this password, generate a new MIC, 30

30

compare this new MIC to the one 31

31

that's already in the handshake. 32

32

If it's correct, then this is the password. 33

33

If it's not, then it's gonna move onto the next password. 34

34

And it'll keep doing this through all of the passwords 35

35

in my wordlist. 36

36

If any of them generates the right MIC, 37

37

then this is the password for the network. 38

38

Otherwise, we won't be able to get the password. 39

39

That's why the success of this attack really depends 40

40

on your wordlist. 41

41

So, let's see how to do this in practice. 42

42

Right now I have my wordlist right here, 43

43

it's called test.txt. 44

44

And I've actually manually added my password 45

45

to the end of the list right here. 46

46

Just so that when I run the wordlist against the handshake, 47

47

I will actually find the password, 48

48

because the wordlist did not contain my password by default. 49

49

I also have the handshake file right here, 50

50

as you can see. 51

51

And all of this is in my Home directory, 52

52

which is my root directory. 53

53

So if I do L-S in here, you'll see I have the wordlist, 54

54

and the handshake file. 55

55

So, we're ready to run Aircrack-ng. 56

56

So we're gonna type the name of the program as usual, 57

57

followed by the name of my capture file, 58

58

which is wpa_handshake.01.cap. 59

59

So, so far it's identical to the way 60

60

that we used to use it with WEP. 61

61

The only difference right now, 62

62

because this is a WPA2 network, 63

63

we have to specify a wordlist with a dash W option. 64

64

And the name of my wordlist is test.txt. 65

65

So very, very simple. 66

66

Aircrack is the name of my program. 67

67

Wpa_handshake.01.cap is the name of the file 68

68

that contain my handshake. 69

69

And I'm using dash W to specify my wordlist file. 70

70

I'm gonna hit Enter. 71

71

And as you can see, now Aircrack-ng 72

72

is running through the wordlist, 73

73

testing each word in the wordlist one by one, 74

74

as shown in this diagram. 75

75

Calculated an MIC based on this information 76

76

and the wordlist. 77

77

And then, if the MIC is correct, it's going to tell me 78

78

that this is the password. 79

79

Now the speed of this depends on your processor, 80

80

and the size of your wordlist file. 81

81

So if you have a huge file, obviously, 82

82

it will take you longer time. 83

83

There are also online services that you can try 84

84

where you upload the handshake, 85

85

and they have huge wordlists and they have super computers 86

86

to run through these wordlists and try 87

87

to give you the password. 88

88

Unfortunately, I can't share their links with you, 89

89

but you can easily find them on Google 90

90

if you search for them. 91

91

And, perfect! 92

92

As you can see, we managed to find the key, 93

93

it's telling us the key is found, 94

94

and this is the key to the network. 95

95

And this is the correct key because as you know, 96

96

this is the same key that we got 97

97

when we exploited the WPS feature. 98

98

So now we can go ahead and connect to the network, 99

99

and we'll be able to run all of the cool stuff 100

100

that I'm gonna teach you 101

101

in the Post-Connection Attack section. 102

102

Now this is the only practical way known so far 103

103

to crack WPA and WPA2 keys. 104

104

There are methods to speed up this process 105

105

so you can use the GPU for cracking, 106

106

because it's much faster than the CPU. 107

107

That's if you have a GPU. 108

108

You can also use rainbow tables, 109

109

you can also pipe the wordlist 110

110

as it's being created in Crunch to Aircrack-ng. 111

111

This way you can create bigger wordlists 112

112

without using any storage on your computer. 113

113

There are also methods, 114

114

so that you can pause your cracking process, 115

115

and then come back after awhile 116

116

without losing your progress, 117

117

but the main idea's the same. 118

118

The only way right now to crack WPA and WPA2 119

119

is through a wordlist attack. 120

120

You can use social engineering, however, 121

121

to get the password using an evil twin attack, 122

122

where you trick one of the users to give you the password. 123

123

This is actually all covered 124

124

in my Advanced Network Hacking course. 125

125

The cracking using the GPU, pipe in Crunch to Aircrack-ng, 126

126

getting the password using an evil twin attack, 127

127

and much more advanced network hacking techniques. 128

128

If you are interested in that, 129

129

then I highly recommend you have a look 130

130

on my Advanced Network Hacking course. 131

131

Check out the bonus lecture of this course, 132

132

the last lecture of this course. 133

133

It contains links to all of my other courses, 134

134

and a comparison between them.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.