0% found this document useful (1 vote)
800 views4 pages

5 Steps Wifi Hacking - Cracking WPA2 Password: Requirements

This document provides a 5-step process for hacking WPA2 WiFi passwords. Step 1 involves preparing the wireless card by putting it in monitor mode. Step 2 stops any existing monitor mode. Step 3 uses airodump-ng to capture wireless traffic and find target access points. Step 4 checks if the target access point has WPS enabled using wash. Step 5 cracks the WPA2 password using reaver if WPS is enabled. The summary outlines the key steps and tools used to hack WPA2 passwords by exploiting the WPS vulnerability.

Uploaded by

rana
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (1 vote)
800 views4 pages

5 Steps Wifi Hacking - Cracking WPA2 Password: Requirements

This document provides a 5-step process for hacking WPA2 WiFi passwords. Step 1 involves preparing the wireless card by putting it in monitor mode. Step 2 stops any existing monitor mode. Step 3 uses airodump-ng to capture wireless traffic and find target access points. Step 4 checks if the target access point has WPS enabled using wash. Step 5 cracks the WPA2 password using reaver if WPS is enabled. The summary outlines the key steps and tools used to hack WPA2 passwords by exploiting the WPS vulnerability.

Uploaded by

rana
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
You are on page 1/ 4

5 Steps Wifi Hacking Cracking WPA2 Password

Wi-Fi Protected Access (WPA) and Wi-Fi Protected Access II (WPA2) are two security protocols and security certification programs developed by the Wi-Fi Alliance to secure
wireless computer networks. The Alliance defined these in response to serious weaknesses researchers had found in the previous system, WEP (Wired Equivalent Privacy)
A flaw in a feature added to Wi-Fi, called Wi-Fi Protected Setup (WPS), allows WPA and WPA2 security to be bypassed and effectively broken in many situations. Many access
point they have a Wifi Protected Setup enabled by default (even after we hard reset the access point).
Requirements:
1. Wireless card (support promiscuous mode)
In this tutorial I use ALFA AWUS036H from Amazon.

2. Access point with WPA2 and WPS enables

5 Steps Wifi Hacking Cracking WPA2 Password:


1. Open our terminal (CTRL+ALT+T) and type airmon-ng (view tips and tricks how to create keyboard shortcut on kali linux)

this command will lists our wireless card that attached with our system.
2. The next step we need to stop our wireless monitor mode by running airmon-ng stop wlan0

3. Now we ready to capture the wireless traffic around us. By running airodump-ng wlan0 our
wireless interface will start capturing the data .

From the picture above, we can see many available access point with all the
information. In the green box is our victim access point which is my own access

point
Information:
BSSID (Basic Service Set Identification): the MAC address of access point
PWR: Signal level reported by the card.
Beacons: Number of announcements packets sent by the AP

#Data: Number of captured data packets (if WEP, unique IV count), including data broadcast packets.
#/s: Number of data packets per second measure over the last 10 seconds.
CH: Channel number (taken from beacon packets).
MB: Maximum speed supported by the AP. If MB = 11, it's 802.11b, if MB = 22 it's 802.11b+ and higher rates are
802.11g.
ENC: Encryption algorithm in use.
CIPHER: The cipher detected. TKIP is typically used with WPA and CCMP is typically used with WPA2.
AUTH: The authentication protocol used.
ESSID: Shows the wireless network name. The so-called SSID, which can be empty if SSID hiding is activated.

4. From the step 3 above, we can find access point with encryption algorithm WPA2 and note
the AP channel number. Now we will find out whether target AP has WPS enabled or not.
wash -i wlan0 -c 8 -C -s

if the WPS Locked status is No, then we ready to crack and move to step 5.
5. The last step is cracking the WPA2 password using reaver.
reaver -i <your_interface> -b <wi-fi victim MAC address> fail-wait=360

Because we already get the information from step 3 above, so my command look like
this:
reaver -i wlan0 -b E0:05:C5:5A:26:94 fail-wait=360

it took about 5 hours to crack 19 characters WPA2 password (vishnuvalentino.com) from my Kali virtualBox, but it depend with our hardware and wireless card.
Conclusions:
1. WPA and WPA2 security implemented without using the Wi-Fi Protected Setup (WPS) feature are unaffected by the security vulnerability.
- See more at: http://www.hacking-tutorial.com/hacking-tutorial/wifi-hacking-cracking-wpa2-password/#sthash.84dLWhxN.dpuf

You might also like