Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial Cracking WPA/WPA2 with Reaver. filter_list
Author
Message
RE: Cracking WPA/WPA2 with Reaver. #11
(12-15-2015, 07:02 PM)zombiefied Wrote:

                                    Cracking WPA and WPA2 with Reaver
What you need:

  1. A computer with a *nix Operating system.
  2. A wireless c@rd that supports monitor mode.
  3. aircrack-ng
  4. Reaver
  5. Some spare time


Okay, so first of all you want to put your wireless c@rd into monitor mode. This can by typing  

Code:
sudo ifconfig wlan0 down

Code:
sudo iwconfig wlan0 mode monitor

Code:
sudo ifconfig wlan0 up
into your terminal. Most network c@rds call themselves wlan0, if your c@rd goes by another name, replace wlan0 with its name.

Our c@rd is now in monitor mode, and it is called mon0. We are going to look for networks with WPS enabled, so type

Code:
wash -i mon0
into your terminal, after a while you can stop the scan with ctrl+c.  If you see a Access Point with no under "WPS locked", write down the bssid.

Now we are going to start bruteforcing the WPS key! Type

Code:
reaver -i mon0 -c 1 -b (BSSID of AP) -vv

This will probably take quite a while, it usually takes between 2 to 8 hours so have patience.

When this is finished, it will show you the WPS key and the WPA password! Enjoy your newly cracked network connection!

Excuse my leetspeak, apparently i'm typing spam words.


Will try soon gotta get linx on one of my laptops

Reply

RE: Cracking WPA/WPA2 with Reaver. #12
Too bad, My NIC does not support this. Thanks anyway.

Reply

RE: Cracking WPA/WPA2 with Reaver. #13
I just scanned near my house yesterday. Found 5/6 WPS-enabled and 1 with good old WEP security.
Pay respects to the malformed SYN packet.

Reply

RE: Cracking WPA/WPA2 with Reaver. #14
To contribute to the thread.

Before going through the painstakingly slow process of bruteforce, you should always see if the network is vulnerable to a pixie attack first. This only takes 3-5 seconds to crack or fail so might as well give it a go.

Otherwise,
If you need a cheap NIC to support reaver or bully. Look into the TL-WN722N. Usually sells for around $12 and has out of the box support for monitor mode and packet injection.

If your target network detects intrusion or failed attempts and employs a locking mechanism, look into a script called revdk3 or Wps-slaughter (requires more than 1 NIC, 4-5 of them for best results) to potentially flood and force the router to unlock itself, allowing for more pin attempts. Specially useful for routers that use exponential locking delays after failed attempts.

Also, you might consider using something other than wash to scan for wps enabled networks as it doesn't give much information on what mode wps is set to. Push button connect or Display only for example. You would be wasting your time trying to bruteforce wps networks configured in this way. Use "Airodump-ng --wps wlan0" instead.

Goodluck!!

[Image: XN4b1eZ.gif]
(This post was last modified: 03-22-2017, 03:18 AM by ApatheticEuphoria. Edit Reason: Boredom really. )
The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
[Image: ouxiEMk.png]

Reply

RE: Cracking WPA/WPA2 with Reaver. #15
there's alot of people who don't know how to protect them from bunch of hackers Biggrin Biggrin

Reply

RE: Cracking WPA/WPA2 with Reaver. #16
(03-04-2017, 02:28 PM)xssinj Wrote: Too bad, My NIC does not support this.

You can always get a USB external NIC.

They're very cheap nowadays- particularly from a computer swap meet.
[Image: AD83g1A.png]

Reply