Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Wireless arrow Wireless How To arrow How To Crack WPA / WPA2
How To Crack WPA / WPA2 Print E-mail
Brandon Teska   
January 15, 2008

Active Attack

Using the information we gathered with Kismet during the recon step, we can target associated clients of a certain AP with forged deauthentication packets, which should cause the client to disassociate from the AP. We then listen for the reassociation and subsequent authentication. This is a little trickier and also detectable, since we're sending out packets. But it's much quicker than waiting for a genuine association (in most cases).

After identifying our target AP with associated clients, we need to set up the wireless hardware for packet injection. The aircrack suite has a little bash script to do just that.

First bring down the managed VAP (Virtual Access Point) with:

airmon-ng stop ath0

Bringing down the managed interface
Click to enlarge image

Figure 2: Bringing down the managed interface

Next, start up a VAP in "Monitor" mode:

airmon-ng start wifi0

Creating a monitor mode interface
Click to enlarge image

Figure 3: Creating a monitor mode interface

Now we need to simultaneously deauthenticate a client and capture the resulting reauthentication. Open up two terminal windows. Start airodump-ng in one terminal:

General Form:

airodump-ng -w capture_file_prefix --channel channel_number interface

Example:

airodump-ng -w cap --channel 6 ath0

airodump-ng, up and running
Click to enlarge image

Figure 4: airodump-ng, up and running
NOTE!Note:
You can check which interface is in monitor mode by using iwconfig.

Next, run the deathentication attack with aireplay-ng in the other terminal:

General Form:

aireplay-ng --deauth 1 -a MAC_of_AP -c MAC_of_client interface

Example:

aireplay-ng --deauth 1 -a 00:18:E7:02:4C:E6 -c 00:13:CE:21:54:14 ath0

A successfully sent deathentication packet
Click to enlarge image

Figure 5: A successfully sent deathentication packet

If all goes well, the client should be deauthenticated from the AP and will usually reauthenticate. I like to keep the number of deauthentication packets sent to a minimum (one, in this case). This helps keep you under the radar, since programs like Kismet can detect deauthentication floods.

If the deauthentication was successful, airodump-ng displays a notification of the captured reauthentication event (boxed in red in Figure 6).

Successful WPA handshake capture
Click to enlarge image

Figure 6: Successful WPA handshake capture


Tags: Hacking, How To, WiFi, WPA,

Related Articles:

The Feds can own your WLAN too
WEP Cracking...Reloaded
How To Crack WEP - Part 1: Setup & Network Recon
How To Crack WEP - Part 2: Performing the Crack
WPA Cracked in 15 minutes
 

Most Read

 
 

Over At The Forums

New firmware 2.1.0
see also http://forum.qnap.com/viewtopic.php?f=142&t=10052 i had already the beta's running with also iscsi. Many more features are there.

Your thoughts about QNAP TS-109 II
I'm at the point where DVD backups for my photos,mp3 is taken too much of my time. I'm thinking of using the TS-109 II to...

OpenWRT not working as wireless repeater bridge on Netgear WGR614L
Hi , I have flashed my wgr614l with openwrt firmware . I have tested it for wireless client bridge mode and it is working fine but I...

OpenWRT working as wireless client bridge on Netgear WGR614L
Hi everybody , I have flashed my Netgear WGR614L with openwrt firmware and have tested it for client bridge mode . It is working grt .......

DIY or buy used?
Hi everybody, I am looking for a new NAS solution for my office. 1. SITUATION I use with video files and animations a lot. The big video...

Slideshows

NETGEAR ReadyNAS Pro Western Digital ShareSpace QNAP TS-509 Pro D-Link DNS-343 4-Bay Network Storage Enclosure Thecus N3200 RAID 5 NAS D-Link DIR-628 RangeBooster N Dual Band Router More

Win This!

Enter to Win!

You could win a Trendnet TEW-633GR Wireless N Gigabit Router and two TEW-621PC 300Mbps Wireless N-Draft PC Cards

Learn How!

 

Ldr:0.00158286094666, Rct:0.00561189651489, Sky:0.0073139667511, Tlink:0.0831799507141, TopPG:0.0832498073578, GQV:0.0833768844604 seconds to load.