Wi-Fi Protected Access (WPA) and Wi-Fi Protected Access II (WPA2) are two security protocols and security certification programs developed by the Wi-Fi Alliance to secure wireless computer networks. The Alliance defined these in response to serious weaknesses researchers had found in the previous system, WEP (Wired Equivalent Privacy).
- Wireless card (support promiscuous mode) – In this tutorial I use ALFA AWUS036H from Amazon.inA flaw in a feature added to Wi-Fi, called Wi-Fi Protected Setup (WPS), allows WPA and WPA2 security to be bypassed and effectively broken in many situations. Many access point they have a Wifi Protected Setup enabled by default (even after we hard reset the access point).
- Access point with WPA2 and WPS enables.
- A linux Kali OS Installed in your PC. If you don’t have it download it now : http://abhi2you.blogspot.com/2014/10/download-kali-linux-operating-system-32.html
Don’t know how to install it??? Visit this link –http://abhi2you.blogspot.com/2014/10/tutorial-how-to-dual-boot-kali-linux.html
Want to use Virtual Box – Download it Now : Click here
Steps to Crack WPA2 Password With Linux Kali :
- Open Linux terminal (CTRL+ALT+T) and type airmon-ng
- The next step we need to stop our wireless monitor mode by running airmon-ng stop wlan0 .
- Now we ready to capture the wireless traffic around us. By running airodump-ng wlan0 our wireless interface will start capturing the data.
From the picture above, we can see many available access point with all the information. In the green box is our victim access point which is my own access point
Information:BSSID (Basic Service Set Identification): the MAC address of access pointPWR: Signal level reported by the card.MB: Maximum speed supported by the AP. If MB = 11, it’s 802.11b, if MB = 22 it’s 802.11b+ and higher rates are 802.11g.ENC: Encryption algorithm in use.CIPHER: The cipher detected. TKIP is typically used with WPA and CCMP is typically used with WPA2.Beacons: Number of announcements packets sent by the AP#Data: Number of captured data packets (if WEP, unique IV count), including data broadcast packets.#/s: Number of data packets per second measure over the last 10 seconds.CH: Channel number (taken from beacon packets).AUTH: The authentication protocol used.ESSID: Shows the wireless network name. The so-called “SSID”, which can be empty if SSID hiding is activated.
From the step 3 above, we can find access point with encryption algorithm WPA2 and note the AP channel number. Now we will find out whether target AP has WPS enabled or not.
The last step is cracking the WPA2 password using reaver.reaver -i <your_interface> -b <wi-fi victim MAC address> –fail-wait=360Because we already get the information from step 3 above, so my command look like this:It took about 4 hours to crack 19 characters WPA2 password (vishnuvalentino.com) from my Kali virtualBox, but it depend with our hardware and wireless card.Conclusions:1) WPA2 security implemented without using the Wi-Fi Protected Setup (WPS) feature are unaffected by the security vulnerability.2) To prevent this attack, just turn off our WPS/QSS feature on our access point. See picture below (I only have the Chinese version)
Notes : This Tutorial Is for education purposes not for practicing it for some rewards please don’t use it for hacking only practice it for lab or training purposes.We are not responsible for anything regarding with this post!!