Powered By Blogger

Sunday 12 January 2014

Crack Wi-Fi Password Using Kali Linux

This guide is for penetration testing your own network or someone else's, with permission
using someone elses wifi is theft of service and may or may not  be a criminal offence in your area for security use tor browser For Anon Surfing..!! 
Logan nor anyone from tek syndicate is liable for your actions, you are so proceed with caution!

EDIT; kali linux is now out as logan said on the tek a few weeks back, as kali is built from the same tools by the same team this guide work with both BT5 r3 and kali,

1st step you will need a copy of backtrack 5 so go here http://www.backtrack-linux.org/downloads/

or kali linux from here (guide is same for both) http://www.kali.org/downloads/

and get yourself an iso (32 or 64bit depending on your hardware)

either burn to disc using imgburn http://www.imgburn.com/index.php?act=download

or make a live usb of 4gb + then you can save sessions and not have to start over when you power off, its a good idea as i have had attacks take up to a day and a half (because of weak signal) and with a disc once powered down......

to do this i use this http://www.pendrivelinux.com/universal-usb-installer-easy-as-1-2-3/ itll do windows too....

or as a third option you could run it as a virtual machine with vmware from within windows, but if you do that you HAVE to use a usb wifi dongle because the internal wifi card of laptops gets seen as ethernet by the guest os, dont know why but i have found it to be true - vmware is not freeware, there maybe a trial or cripple ware version available here  http://www.vmware.com/uk/ but i sailed away from the pirate bay with my copy, i wont link directly to it as i may get in trouble from logan but you're a smart guy you can find it ;)
ok so now you have a disc/usb or virtual machine so power on, into BIOS (del,f11,f2 another key depending on hardware) and set it to boot from disc or usb, (not applicable to vm) and lets have some fun!
when the first menu comes up you want default text mode
when the cursor becomes available type "startx" without the quotes and it will boot into a desktop
go to the top of the screen and click on the little black screen to open a teminal (looks like a windows cmd window)
now to find out what wifi adaptor you have
type "airmon-ng" no quotes
if it doesnt list anything then your wifi adaptor is not compatible with bt5 it probably has no promiscuous mode or is lacking driver support but most laptop internal wifi i have found to work and most full size usb dongles do too the tp link tl wn821n works for definate.
the output from that is normally wlan0 but if you have multiple adaptors you will get more options
type "airmon-ng start wlan0"
assuming wlan0 was the output from previous command if not put what the output was for the adaptor you would like to use it will output monitoring enabled on mon0 most times unless you have multiple adaptors
so now we have set our adaptor to monitor the airwaves we can have a snoop at all the available networks 
type "wash -i mon0"
and it will list all available networks signal strength encryption type bssid's and other things, we are looking for networks with wpa2/psk WEP is also dooable and much quicker, but as a security standard it is dead and not in common use any more but if you would like a guide for that too, let me know in the thread and when i have a moment.....
anyway choose your victims bssid and
type "reaver -i mon0 -bBSSIDGOESHERE -vv" 
and it will start running through the all the possible wps set up pins randomly, it maybe that you get ap rate limiting detected, this is where a router recognises that it is getting attacked from all the wrong passwords and stops bt5 from accessing it rfor a set amount of time to combat this youi need to add a delay -d command to the reaver command line so it looks something  like this
"reaver -i mon0 -b21.34.56.23.54 -d20 -vv" 
if ap rate limiting still detected keep increasing the delay by 5 seconds untill you stop tripping the ap rate limit
by using the -vv comand you get more verbose output from the termional wich allows you to see if it is channel hopping or ap rate limiting or whatever and it also lets you see when it gets caught in a loop on a particular password when this happens i press cntrl+c to stop session then up cursor for last command and enter and it picks up where it left off and normally carries on without stuttering on the same password again
after time passes it will output the password and pin number copy both down as if the password is changed you can run the reaver command line again with a -pPINHERE and it will break new password in less than a minit as the pin doesnot change this would look like
"reaver -i mon0 -b23.56.76.45. -p123456 -vv"
the password will get changed if your found on a network you are not supposed to be on wich is why i put that command there as i have had it happen a few times
if this goes on and the network admin is savvy they may stop changing the password and start banning mac addresses from connecting to the router but dont fear!

i use this http://www.technitium.com/ to change my mac address as i have had to deal with this problem before

as a side note, if you are going to jump on a network that isnt yours change your pc name to something not identifiable to you mine is called vm.lineupdate32 as the target network is on virgin media....see?

4 comments:

  1. Hello everyone, my name is Kate and I want to recommend a reliable hacker who helped hack my husband's cell phone remotely.

    Which gave me full access to all his texts and, and now he has nothing to hide from me. If you require his service, contact ghosthacker2351@gmail.com, tell him Kate referred you he'll help.

    ReplyDelete

  2. If you need to hire a real hacker to help spy on your partner's cell phone remotely, change your grades or boost your credit score. Contact this helpline 347.857.7580 or the email address expressfoundations@gmail.com

    ReplyDelete
  3. ARE YOU WILLING TO HIRE THE REAL HACKERS TO GET YOUR CYBER PROBLEMS FIXED WITH SWIFT RESPONSE?
    AND ARE YOU A VICTIM OF THE BINARY OPTION SCAM?
    Solving a problem for which you know there’s an answer is like climbing a mountain with a guide, along a trail someone else has laid.
    You can put a stop to your anxiety and constant fear of you getting ripped off by forgeries. 
    This post is actually for those who are willing to turn their lives around for the better, either financial-wise or relationship-wise or businesses.
    Our primary reason for this development is to ensure that those in need of help don’t get ripped off by forgeries.
    This is a global idea that navigates a newbie to a prominent encounter ( Fully immersed to a degree that the subject in question Is a disorienting worthwhile experience on merits).
    Who are the GlobalHackers?
    We are group of skilled professional hackers driven by passion to make the internet a safer place and render proficient services to those having cyber problems.
    Globalhackers has grown and expanded since it formation over the years due to the experience and professionalism of our management and technical staff. Our strength is based on our ability to bring together active cyber security professionals who individually has acquired enormous exposure in the world of HACKING
    As part of our corporate goals, providing value added services to meet our client needs and requirements has been our sustaining impetus.
    The new development on the Globalhackers platform is to assign to you the right HACKER to deal with your Particular kind of cyber issues depending on the kind of cyber problems you are willing to get fixed.
    Here, you would be refer to a legit professional hacker known for massive skills and security abilities.
    Skilled and trained on
    ▪Social media hacks (facebook, twitter, instagram,snapchat)
    ▪Email hacks
    ▪phone hacks
    ▪bitcoin hacks.
    ▪verified PayPal account hacks
    ▪database hacks
    ▪credit card top up
    ▪university score upgrade
    ▪money transfer
    ▪binary option funds recovery. ( recovered $4,372,063 million)
    The binary option scam is another problem facing the internet today.
    How do you avoid binary option scam and what do you do if you are a victim of the scam.
    Be wary of adverts on the internet and mostly on social media promising high returns from binary options trading. The binary option is one of the highly recorded scam on the internet.This are a form of fixed-odds betting.
    People investor their hard earned funds in the scammers website and at the end, they wouldn't be able to take their profit plus their investment too. The Globalhacks are breeding effort to put an end to these unbearable swindle scheme taking over the intenet and taking a solid step forward to render solution to those affected by the fleece… we have striven to make tenacious effort to relief those who were victims off their traumatic feeling of loss. ( We Are Here To Help Recover Your Stolen Funds).
    Here would be our cybersecurity techniques to retrieving back the victims stolen funds.
    ●The binary broker website would be traced down using a game over peer to peer network via a bug attack,
    The bug network secure an SQL trace on a hiding server, decentralizing it and redirecting the server to a soft plus network. A soft plus network enable varieties of unique web coding languages, Through that process reveals thier hidden networking source, displaying the changed web page made default.
    This unveil the hiding information traceable to track down the scammers and their embezzled central fund reserve system.
    HOW DO YOU STAY AWAY FROM FALSE BUSINESSES ONLINE?
    * Making enquiries for their firm reference number (FRN)
    * Contact details and barter their calls on the switchboard number and also
    * Never make use of the link in a website or an email from the firm propitiating you for an investment.
    For more enquiries and help, contact:
    Info.globalhacks (at) gmail. com
    globalhacktech (at) protonmail. com
    HackerOne©️LLC 2030.

    ReplyDelete
  4. Hey Guys !

    USA Fresh & Verified SSN Leads AVAILABLE with best connectivity
    All Leads have genuine & valid information

    **HEADERS IN LEADS**
    First Name | Last Name | SSN | Dob | DL Number |Address | State | City | Zip | Phone Number | Account Number | Bank Name

    *Price for SSN lead $2
    *You can ask for sample before any deal
    *If anyone buy in bulk, we can negotiate
    *Sampling is just for serious buyers

    ==>ACTIVE & FRESH CC FULLZ ALSO AVAILABLE<==
    ->$5 PER EACH

    ->Hope for the long term deal
    ->Interested buyers will be welcome

    **Contact 24/7**
    Whatsapp > +923172721122
    Email > leads.sellers1212@gmail.com
    Telegram > @leadsupplier
    ICQ > 752822040

    ReplyDelete