RE: how i can hack WPA - CCMP,WPA- TKIP? 05-19-2014, 10:18 AM
#8
(05-19-2014, 08:59 AM)HomeSen Wrote: Basically, cracking WPA(2) under Windows works as follows:
- Run Wireshark with your WiFi being set to promiscious mode
- Capture the full initial 4-way-handshake (since this is the only traffic that gets encrypted by the WPA-PSK) and save the capture file in "pcap format".
- Get a decent dictionary (since aircrack-ng only allows dictionary attacks against WPA). You can safely strip out every (pass)word in the dictionary that is shorter than 8 characters, since the WPA-PSK has to be 8-64 characters long.
- Download aircrack-ng (there is a Windows version of it with [due to OS restrictions] limited functionality. but we only need the cracker, anyways). I'd recommend using the 1.x beta release, since performance had increased by a lot, when switching from 0.9 to 1.x
- Feed your saved capture file and the dictionary into aircrack-ng
- depending on the size of your dictionary (and if it contains the WPA-key), you need to be very patient, until it found the key
Since Windows (same applies to MacOS X, by the way) doesn't allow packet injection (without specialized hardware), you need to be lucky to get a client logging in to the WPA-protected WiFi. If you were on Linux, you would only need a client that is already connected, since you could then inject a DEAUTH packet "into the air", so that the client simply reconnects.
But since all this is "academical" (right?), you can just make a second client connect to your WPA-protected WiFi and sniff the connection phase.
If you are lucky, and have a supported WiFi-NIC, you can even only use the aircrack-ng suite to perform the actions, since some NICs are capable of operating in monitor-mode under Windows (check the "Supported by airodump for Windows" column for your WiFi chipset): http://www.aircrack-ng.org/doku.php?id=c...ty_drivers
Thank you! I will try it out.
Hope it's work with me..
Thank you again.



![[+]](https://sinister.li/images/modern/collapse_collapsed.png)