I have demonstrated many ways to hack Wi-Fi here on Null Byte, including cracking WEP and WPA2 passwords and creating an Evil Twin and Rogue AP.
A few years back, Alex Long demonstrated how to use Reaver to hack the WPS PIN on those systems with old firmware and WPS enabled. Recently, a new WPS-hacking tool has appeared on the market and is included in our Kali hacking distribution. It's name, appropriately, is Bully.
Why WPS Is So Vulnerable
WPS stands for Wi-Fi Protected Setup and was designed to make setting a secure AP simpler for the average homeowner. First introduced in 2006, by 2011 it was discovered that it had a serious design flaw. The WPS PIN could be brute-forced rather simply.With only 7 unknown digits in the PIN, there are just 9,999,999 possibilities, and most systems can attempt that many combinations in a few hours. Once the WPS PIN is discovered, the user can use that PIN to find the WPA2 preshared key (password). Since a brute-force attack against a WPA2 protected AP can take hours to days, if this feature is enabled on the AP and not upgraded, it can be a much faster route to getting the PSK.
The Keys to Success
It's important to note, though, that new APs no longer have this vulnerability. This attack will only work on APs sold during that window of 2006 and early 2012. Since many families keep their APs for many years, there are still many of these vulnerable ones around.If you aren't familiar with wireless hacking, I strongly suggest that you read my introduction on the Aircrack-ng suite of tools. In addition, make certain that you have an Aircrack-ng compatible wireless card, otherwise this will simply be an exercise in frustration.
Step 1: Fire Up Kali
Let's start by firing our favorite hacking Linux distribution, Kali. Then open a terminal that looks like this:To make certain we have some wireless connections and their designation, we can type:
- kali > iwconfig
Step 2: Put Your Wi-Fi Adapter in Monitor Mode
The next step is to put your Wi-Fi adapter in monitor mode. This is similar to promiscuous mode on a wired connection. In other words, it enables us to see all the packets passing through the air past our wireless adapter. We can use one of the tools from the Aircrack-ng suite, Airmon-ng, to accomplish this task.- kali > airmon-ng start wlan0
- kali > airdump-ng mon0
Step 3: Use Airdump-Ng to Get the Necessary Info
Finally, all we need to do is to put this info into our Bully command.- kali > bully mon0 -b 00:25:9C:97:4F:48 -e Mandela2 -c 9
- mon0 is the name of the wireless adapter in monitor mode.
- --b 00:25:9C:97:4F:48 is the BSSID of the vulnerable AP.
- -e Mandela2 is the SSID of the AP.
- -c 9 is the channel the AP is broadcasting on.
Super bro you teach as a internal structure of earth
ReplyDeleteI was scammed by cityinvestgp, I got a message from a trader on my Instagram and told me about how high their profit after investing was, I decided to invest in the online trade but they kept asking for more money including withdrawal fee and it was until then I realized I was being scammed. I couldn't let go because I invested my savings as at that time. I had to make a research on how I could recover my funds from them and I came across the website REMOTESPYTECH (@) GMAIL COM after so many searches. I read several good reviews about the website from various scam victims they have helped and I decided to contact the website admin for help.
DeleteI was opportune to get my money back from the scam brokers through the help of the website recovery professional, they recovered my investments for me with all the profits I was entitled to within two weeks of contacting them. You can write REMOTESPYTECH (@) gmailcom for help too if you a victim of any kind of scam
They are experts at dealing with online scam and assisting victims in receiving reimbursement, tracking down digital fingerprints, cyber analysis and thorough investigation.
They offer other services such as
Phone cloning ( catching, monitoring and tracking a suspected cheating spouse )
Website hack
Boost of credit scores
Clearing of criminal records
Fixes bad debts etc
Contact them now!!!
REMOTESPYTECH (@) GMAIL, COM
WhatsApp: +56 9 3129 3092
Regards
Excellent Review
I was scammed by cityinvestgp, I got a message from a trader on my Instagram and told me about how high their profit after investing was, I decided to invest in the online trade but they kept asking for more money including withdrawal fee and it was until then I realized I was being scammed. I couldn't let go because I invested my savings as at that time. I had to make a research on how I could recover my funds from them and I came across the website REMOTESPYTECH (@) GMAIL COM after so many searches. I read several good reviews about the website from various scam victims they have helped and I decided to contact the website admin for help.
ReplyDeleteI was opportune to get my money back from the scam brokers through the help of the website recovery professional, they recovered my investments for me with all the profits I was entitled to within two weeks of contacting them. You can write REMOTESPYTECH (@) gmailcom for help too if you a victim of any kind of scam
They are experts at dealing with online scam and assisting victims in receiving reimbursement, tracking down digital fingerprints, cyber analysis and thorough investigation.
They offer other services such as
Phone cloning ( catching, monitoring and tracking a suspected cheating spouse )
Website hack
Boost of credit scores
Clearing of criminal records
Fixes bad debts etc
Contact them now!!!
REMOTESPYTECH (@) GMAIL, COM
WhatsApp: +56 9 3129 3092
Regards