Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Now in this video I'd like to cover a configuration that might be used on the target router that could
make a crack in it a little bit different.
Now as we know WEP is very rare to see now anyway and this configuration is actually really really rare.
And most routers don't even supported it is a bit different to crack it though.
And usually people get confused when they see it and won't even know what to do.
But it's actually kind of easier to crack this type of configuration than the normal web configuration.
What I want to talk about is if the target router does not use open authentication.
So we've seen in all the previous videos the first step was to do a fake authentication attack.
We changed the auth and arrow dump ngi to open in this case the router can be configured to use a shared
key authentication.
So I have my router settings page here and I can see that I changed the setting here required.
And what this basically does is it prevents anybody from even associate it with the router if they don't
know the key.
So usually routers use open authentication which basically means anybody can associate with the router.
And then the router will check if you have the right password if you have the right key.
If you do they let you connect.
If you don't they won't let you to connect.
So they actually allow you to associate and they'll communicate with you if a shared key is used then
the router will not even allow you to associate unless you encrypt a challenge for it and send it to
it.
You won't even be able to associate with the router if you don't have this shared key.
Let me show you an example here.
So I'm just going to do first of all Aradigm engineman Zero to see all the networks around us
and you can see that I have this network which I configured for this class and it's called S-K a test
AP.
So it's right on channel 1 and I'm going to copy its MAC address and we're going to run aero dump ngi
against this network only We're going to give the VSS ID the channel
and we're going to store the data to our file and we'll call the file as a test and then I'm going to
put my wireless card in monitor mode which is Monsey.
So it's the same command that we've always been do and don't Bengie the B side.
SS idea of the target the channel and we're right in a file We're going to hit enter and this is going
to run against our target only.
And now I'm just going to come in and do a fake authentication just to show you what happens in S-K
networks.
So we're going to do a fake authentication exactly like we did it before.
So it's going to be airplay and fake Auth. and we're going to put zero.
And then we're going to do minus a put the mac address of the router and then I'm going to do minor
each and put my own MAC address which is now i'm doing all this real quick because you should know all
of this by now because we covered that in previous lectures my own MAC address is 0 0 0 see a 2 8 2
9 8.
Then we're going to put our wireless card in monitor mode which is than zero.
So again same command that we always use for the fake authentication we're going to do play ngi fake
RS 0 target MAC address my MAC address.
I'm going to hit enter
so I'm going to Control-C this so you can see that we have S-K here under the auth instead of open.
And that means we can't really do all the attacks that we did previously.
The three methods the three injection methods that we spoke about previously the way to fake authenticate
yourself with S-K networks is you'll have to authenticate one of the connectors clients in here.
So you actually need.
You have to have a client connect to the network you're going to have to be authenticated.
Once you do that Aradigm ngi will capture NSK.
You can see that I have a broken S-K here but if you do that properly you will get a normal Eskay and
then he'll use that file with the minus y option to fake authenticate yourself to associate with the
network.
And then he can do all the attacks that he spoke about in the previous lectures the three methods.
The thing is that's a bit too complicated and there is two better methods to do that because as I said
if you want to associate and the target network uses K.A. the network has to have a connected client
has to have at least one connected client.
So based on that fact there's actually better ways to crack that network and I'm going to show you the
first method right now and that is use in an AARP replay attack.
So let me close this first
and I'm going to clear this and I'm actually going to stop this and clear it and run the attack again
because I want to show you that you actually don't even need to run a fake authentication for this.
So we're just going to name them something else we're going to call it as a test too and we're going
to launch or don't punji.
And as you can see right here you don't have authentication or anything on this network right now.
And what I'm going to do is I'm going to do and peer play attack.
So we spoke about that and we actually did it in a previous lecture.
The only difference is when we did it we did a fake authentication and we associate it with the network
and then we use the replay attack based on our mac address so we played packets from our computer and
injected them in the router.
And this lecture because we actually have a client when we did it in previous lectures there was no
clients connected so we had to associate our client showed up in here and then we used our client Mac
address to replay one of the AARP packets and we managed to increase the number of data rapidly that
way.
What we're going to do today is because we already have a connected client.
We're going to use this connect to the client in our replay attack and this method will work against
both normal networks and against the network the web networks that use as a.
So this attack is going to be exactly the same as they are pure play attack that we did.
The only difference is we're going to use the MAC address of a connected client and instead of my own
MAC address.
So the cabal is going to be air flanged AARP or play then we're going to do minus Beith and we're going
to give it the MAC address of the target network then we're going to do minor stage.
And instead of giving it my own MAC address like we did in previous videos I'm going to use the MAC
address of one of the connected clients which is this one
then I'm going to put my wireless card in monitor mode which is zero and we're ready to go.
So again we're using airplanes.
We're doing our pure play attack exactly like we did before.
We're specifying the target network after the minus bit.
And then we were specifying the MAC address of a connected client this time instead of specifying my
own MAC address so I'm going to hit enter and all this is going to do is it's going to wait or appropriate
a packet and once it captures one of them it's going to injected into traffic more and when it's going
to do that it's actually relying on disconnected the client and it's injecting it as if this packet
is coming from this connected client.
And as you can see the number of data is increasing very very fast right now and I can just run track
ngi on the side and I should be able to crack the password.
So again I'm going to run this like we did before.
And we named the file Eskay test.
And we named it to and we have to append the minus 0 1 because the arrow dump entry does that automatically
and that's going to be a dot com But again a hit Enter
now I'm going to stop this.
As you can see we managed to get the key.
Now we can use this we just remove these dots from it and connect to the target network and we'll be
able to connect to it.
So again this method works on both normal web networks and the ones that use shared key authentication
or Eskay.
The only thing that it requires is an existing connected client to the network.
So it's not a client less cracking method.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.