Wifi Hacking

tags: #presentation, #hacking


WiFi Bandwidth


WiFi Standards


WEP

60 bit or 128 bit encryption key = IV (initialization vector) = RC4 key
Vulnerability in the IVs being reused
Guaranteed compromise with 5 mins capture


WEP hacking

Wifi Hacking-1.jpg

  1. interface monitor mode with airmon-ng

Wifi Hacking-2.jpg
2. capture WEP AP packets, check for roughly 5000 IVs


Wifi Hacking-3.jpg
3. crack with aircrack-ng


WPA/WPA2

Vulnerability lies in the handshake packets
The handshake packets can be captured and bruteforced


Steps

  1. Monitor mode on interface
  2. capture packets from AP
  3. De-auth the connected clients, force handshake
  4. Crack handshake with wordlist

WPS

WPS Pin = 8 digit number (fixed)


Steps

  1. Monitor mode on interface
  2. use reaver, start bruteforcing pins
  3. Using pin to recover current password

Other Wireless Attacks


Tools