Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
OK, now that we know what the bloops is and how it can be used to recover the password for a WPA and
WPA two networks, let's see how to do that in practice.
So right here I have my curling machine, I've already enabled monitor mode on my wireless adapter on
one zero.
Now usually we use aero dump energy to see all the networks around us.
But right now we want to see the networks that have the enabled.
But because, like I said, it's just a feature and people can turn this feature off.
So first of all, I'm going to use a tool called Wash.
To display all the networks around me that have enabled, so we're going to do wash dash dash interface
and give it my interface in monitor mode, which is more on zero.
So all we're doing is wash is the name of the tool interface to give it the interface, and one zero
is my wireless adapter in miter mode.
If I hit enter now, you'll see it'll list my network straight away.
Now I press control City Council this similar to dump and because it'll keep running unless you cancel
it.
And you can see this is my target network.
It's called Test app.
It's given us the vendor of the hardware used in this network.
And this access point, the LC key, tell us whether WPC is locked or not, because sometimes WPC logs
after a number of failed attempts.
So right now, this is no which means that we can actually go ahead and try to guess the pin.
It's given us the version of the it's using version one.
The signal strength is in here, the channel on the backside.
Now I explained the meaning of all of these things before in my A-roads lecture, so I'm not going to
talk about them now.
If you forgot the meaning of any of these terms, please go back to the Arrow Dump and G Lecture.
Now, this network actually uses WPA, too, so just to confirm this to you, if I go here to my host
machine and just try to connect to it.
You'll see that instilled in me that this uses a WPA to password, but like I said, we don't care if
it's WPA or WPA two because we're going to be exploiting a feature in these inscriptions, which is
the WPA feature.
So now that we know our target network uses the.
There's a good chance that this attack will work against it.
The only reason it might fail is if the target uses PPC or push button authentication.
Like I said, if the target uses PPC, then it will refuse all the pins unless the button is pressed
on the router and therefore this attack will fail.
The only way to know is to literally try this attack and see if it works.
So I'm going to copy the Mac address of this network or the society.
And the first thing that I'm going to do, similar to what we did with the Blue EP, I'm going to associate
with the target network using a fake authentication attack.
So basically, I'll be saying I want to communicate with you.
Please don't ignore me.
So that when I run the attack, the network will start accepting the pins and not ignore me.
So to associate, we're going to use the exact same command that we used when we did it with W EP.
So we're going to use airplay and we're going to tell it.
I want to run a fake authentication attack.
We're going to give it the delay.
So this is the time to wait between association attempts.
Previously, we set it to zero and we had to do this manually every now and then.
Right now, I'm going to set it to 30 so that we associate with the target network every 30 seconds.
Then I'm going to do a Dash eight to give it the Mac address of my target and Dash H to give it the
Mac address of my wireless adapter in monitor mode.
And we see that we can get this by doing ifconfig.
And copy it from here, we said it's the first 12 digits.
And I'll just replace the minus with the column.
And finally, I'm going to give it the name of my wireless adapter in monitor mode, which is my zero.
So I explained this in details before.
That's why I did it quickly.
If you don't remember how I did this.
Please go back to the fake authentication attack lecture.
So the command is ready now, but I'm not going to execute it.
I'm going to go down to the bottom terminal and run river, which is the program that will brute force
the pin for me, and only then I will associate with the target because otherwise a Triple-A energy
will fail to associate with my network.
So I'm going to move to this terminal right here.
I'm going to clear the screen.
And we're going to run River, which is the program that's going to brute force the pin, so it's going
to try every possible pin until it get the right pin.
Once it has the right pin, it will use it to compute the actual WPA key.
So using river is very, very simple.
It's very similar to everything we've been doing so far.
So first of all, we have to type the program name, which is the river.
Then I'm going to do a dash dash beside to give it the Mac address of my target network.
So I'm just going to paste it.
Then I'm going to do a Dash Dash channel.
And give it the channel of the target network, which is one.
Then we're going to do a Dash Dash interface and give it my wireless adapter innovator mode, which
is than zero.
So a very, very simple command we're using reverse, this is the name of the program that will do the
brute force thing for us and give us the key.
We're giving it the best ideas, the Mac address of my target.
We're doing that channel to give it the channel.
That's my target is running on.
And we're doing Dash Dash interface to give it the name of my wireless adapter in monitor mode.
I'm also going to add two more options.
I'm going to add Dash V to show us as much information as possible.
This is really helpful if it fails or things go wrong.
We'll be able to know what's happening, why things are going wrong, and I'm also going to do a dash
dash.
No associate.
To tell the river not to associate with the target network because we're already manually doing that
in here.
So River can automatically do this, tap right here for you.
But I've seen that it's fills a lot.
Therefore, it's actually better to do it ourselves manually here and then tell the river not to associate.
So now I'm going to hit enter to get the river to walk, and I'm going to go up to the top terminal
and I'm going to to enter to associate with the target network telling it Please don't ignore us so
that river at the bottom here can brute force the pin and try every possible pin until we get the correct
pin, which we'll use to get the password.
And as you can see right now, River is trying.
The PIN one two three four five six seven.
Aren't perfect.
You can see the pin was actually one two three four five six seven zero, so it's a simple pin.
It actually came with this pin.
So I it's manually set this pin.
My writer came from the factory with the GPS enabled with this pin.
So like I said, this still works, but again, not against old rafters.
From that, it was able to discover the WPA key, which is you are you are W6 or and the name of the
writer is Test AP.
So it can literally go ahead and connect with this password.
And I'll be able to connect to the network and see and decrypt all of the packets sent in the air.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.