Link

Join Probux to get paid for clicking on links!!

Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Wednesday, August 14, 2013

Hack Network Security Key

Hacking WEP Network with Backtrack 5

          This tutorial will show you how to hack a WEP network. Its relatively easy to hack a WEP(Wired Equivalent Privacy) network than a WPA/WPA2 network. That's the reason, most people choose WPA/WPA2 to secure their wireless network. However, if you want to hack a WEP network, this tutorial will be teaching you how to do it. It takes from 30 mins to 3 hrs to hack a WEP network depending on the signal strength of the network you're trying to hack. I have posted tutorial for hacking a WPA/WPA2 secured wireless network in my previous post.

Lets get Hacking

        First you will need to have a Wireless Network Adapter supporting packet injection. Download Backtrack and create a Live USB/DVD. Then, boot Backtrack.

Open a Terminal. Type in:
iwconfig

        This command will show all the available interfaces in your PC. Note the interface name of your wireless network adapter. Generally it is named "wlan0". A wireless network adapter can be operated in two modes. One is the normal mode that you normally use for surfing the net. The next mode is the Monitor mode that we will be using for hacking. In monitor mode, we monitor all the available access points in the location and interfere their packets. Now lets put our network adapter to Monitor mode. For that type in:
airmon-ng start wlan0


      After this command, our network adapter will be in monitor mode and the interface name is changed to "mon0". Note this that in monitor mode, your interface name will be "mon0" not "wlan0".
    After enabling the monitor mode, we now search for access points in the location. For this, type in:
 
airodump-ng mon0


        This command will monitor all the available networks in your area. And it also show many information about the access points that we'll need for later commands like the channel no. ,bssid,etc. After running airodump-ng, wait till your victim (WEP network) appears. After that, hit Ctrl + C to stop airodump-ng. 
          Note the channel no. and bssid of your victim. Now you need to capture the packets from the access point. Type in:

airodump-ng -c (channel no. of victim) --bssid (bssid of victim) -w (capture file name) mon0


       The above command will start capturing packets from the access point you are targeting. The captured packets are saved in the caputre file (.cap). We will use this capture file to crack the password. After entering the above command, note the amount of Data that is being received. All we have to do is wait for the Data to reach about 10000 to 20000. The data rate may be slow because your network adapter is not associated with the access point. So we use "Fake Authentication" to authenticate and associate with the access point. Keep airodump-ng  running, capturing data. Open a new terminal and Type:
aireplay-ng -1 0 -a (bssid of victim) mon0

         This command will start a Fake Authentication with the victim's access point. On success, it will show "Association successful". Sometimes, this attack may not be successful. If so, try moving nearer to the access point and use your luck the next time. Once you're associated with your victim's access point, you send an ARP Request.
Type:
aireplay-ng -3 -b (bssid of victim) mon0


          This command sends an ARP Request to the victim. An ARP Request starts a type of network communication request between two computers. If your request is acknowledged, ACK signals are received. If your ARP Request is acknowledged, you will notice that the Data received will increase rapidly. Once the data reaches 5000, start aircrack-ng. First, look up what's the name of your capture file. For that, open a new terminal, type "ls" and hit enter. And note the name of your capture file.

Type:
aircrack-ng (capture file name.cap)

           Once you enter this command, it will start testing keys. Depending on the password strength of the victims' access point, it will require more packets (data) from the access point. Generally, aircrack-ng can surely crack the password if you obtain 25000 IVs (packets) from the access point. Just start aircrack-ng after receiving 5000 IVs. Even if it fails to crack password at 5000 IVs, the attack will auto-start after receiving 10000 IVs. It will keep on attacking until the password is cracked.

       Once it cracks the password, it will show "Key Found![victims' password]". Remove all the ":" from the key, and now you have the password. Cheers!!
    So, this is how you hack a WEP network using Backtrack 5. Please leave a Comment, rate and share my post guys!! And if you have any problem, please ask freely in the comment section below.

Thanks!!





 

Friday, August 9, 2013

Compatible Wireless Network Adapters for Backtrack 5

       

 Compatible Wireless Network Adapters for Backtrack 5

       Backtrack is popular open source Linux distribution used by most of the security professionals for network security. Security Professionals use it for checking the loop-holes in their network and cover those holes. Backtrack can also be used for hacking a wireless network. It has all the essential tools for hacking a WEP/WPA/WPA2 network (airodump-ng,aircrack-ng,etc). A wireless network can be hacked directly from the windows but for that you need to be willing to spend thousands of cash for an AirPcap Tx/Nx adapter. We use Backtrack instead of Windows also because Windows does not have patched drivers that support injection. So it is relatively easy and very cheap to use Backtrack by booting a live USB/DVD. The most important thing here is to make sure that your wireless network adapter supports monitor mode and packet injection.
       A wireless network adapter can be used in two modes: Normal mode and Monitor mode. Normal mode is what you normally use your network adapter for connecting to a network and surfing the internet. Monitor mode is a different mode in which the network adapter monitors all the access points (networks) in the area and intercepts its packets (i.e packet injection). So, it is a must that your network adapter should support monitor mode.
       Not all network adapters support packet injection or monitor mode. For laptops, there is an in-built wireless network adapter(mostly). You're lucky if your in-built network adapter supports packet injection. But you do not need to worry; you can still purchase a cheap external USB Wireless network adapter that is capable of packet injection. The following in-built network adapters support packet injection and are compatible with Backtrack 5:
  • Broadcom Corporation BCM4321 abgn rev 03
  • Broadcom Corporation BCM4322 abgn
  • Atheros AR5008,AR5009,AR92xx
  • Atheros AR9380,AR9382,AR9390
  • Atheros AR9485
  • Dell Wireless 1505,1510,1515,1520,1530
  • Dell Wireless 1702
  • Intel 3945ABG
  • Intel 4956/5xxx
  • Internal Intel Corporation PRO/Wireless 3945ABG
 These are the tested Wireless Network adapters that support packet injection. You may find many other network adapters online. Just Google it! Or simply test the compatibility of your in-built wireless adapter or external USB wireless adapter in Backtrack 5. For that, click on this link: http://keep-it-sim.blogspot.com/testing

     Now coming on to the USB wireless network adapters, there is a wide of variety of Wireless USB network adapters available in the market (brands like Digicom,TP-LINK,NetGear,D-Link,Alfa,etc). Out of them, some of the best Wireless USB Network adapters are listed below:


  • ALFA AWUS036H 1000mW Long-Range with Realtek RTL8187L
  • D-Link DWA-160 v.B2
  • D-Link DWA-182
  • Edimax EW-7733UnD
  • Linksys WUSB600N
  • NetGear WN111 v2
  • NetGear WNDA 3100 v1
  • NetGear WNDA 3100 v2
  • TP-Link TL-WDN3200
  • TP-Link TL-WN721N and TP-Link WN722N
  • TP-Link TL-WN821 N v1,v2 and v3
  • TP-Link TL-WN822N v1 and v2
       These are some of the adapters that will support packet injection. Out of them, ALFA AWUS036H is supposed to be the best for hacking and other purposes. But, its hardly available in markets in Nepal. The easily available adapters in market in Nepal are D-Link DWA,TP-Link TL-WDN3200, TP-Link TL-WN721N, TP-Link TL-WN722N and TP-Link TL-822. You can purchase them at Computer Bazaar in Putalisadak or shops in New Road and costs around Rs. 800 to Rs. 2000. The one I use is TP-Link WN722N 150Mbps High-Gain adapter and its pretty good adapter. And i purchased it for only Rs. 1200 at Computer Bazaar. Adapters from NetGear is also a good choice but its not easily available in Nepal. You will need to search from shop to shop and its quite tedious. So, TP-Link adapters is the easy option.
The Packet injection test can also be done on the Wireless USB Network Adapters, so if you already own a USB adapter, just give it a little test. Click on the link:

Pictures of the Working Wireless USB Network Adapters

Edimax EW-7733UnD

D-Link DWA 160

TP-Link TL-WN 721N
TP-Link TL-WN822N



TP-Link TL-WN722N
NetGear Wn111 v2

LinkSys WUSB600N

 

   If you have problems regarding compatibility of your wireless card, comment in the comment section below. Feel free to comment :)





Testing Compatibility of Wireless Network Adapter

Testing Compatibility of Wireless Network Adapter

      If you already own a USB wireless network adapter, its wise to just give it a little test for its compatibility. It may save some of your money.

       For this, connect your USB adapter to your PC (don't need to do anything for testing the in-built adapters). Then, boot Backtrack 5. After you've booted up Backtrack 5, open a Terminal and type:                                                       
                                                                         iwconfig



      This command lets you see all the interfaces available in your PC, including your wireless network interface. As in the snapshot, the wireless network interface name is wlan0 (Mostly it is wlan0, but it is dependent of network adapter.If a different name appears for your adapter, use that name). Interface name is wlan0 and its currently working in Normal Mode. Inorder to test its capability of packet injection, we need to operate it in Monitor mode.

Type:

airmon-ng


        This command will show all of your wireless network interfaces. As in snapshot above its showing wlan0.

Type:

airmon-ng start wlan0



       This command will put your adapter in Monitor mode.(If your interface name is other than wlan0, type that name instead of wlan0 in above command) Now that your adapter is in Monitor mode, your interface name will now be changed to mon0. From here onwards, you will now use mon0 wherever you will have to put your interface name.
           Now that you have put you adapter in Monitor mode, the final command lets you see the injection capability.

Type:

aireplay-ng -9 mon0




         In the snapshot, it is clearly showing that "Injection is Working". If your adapter does not support injection, it will show some other messages saying "ARP injection not supported" or something like that.

So this is how you test the compatibility of your wireless network adapter. If you have problems regarding anything, feel free to ask in the comment section below. Thanks!