‏إظهار الرسائل ذات التسميات Wi-Fi Hacking. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Wi-Fi Hacking. إظهار كافة الرسائل

الخميس، 8 يناير 2015

Hack WiFi Account From Phishing Attack With WifiPhisher Tool



Hack WiFi Account From Phishing Attack With WifiPhisher Tool ..

Wifiphisher is a security tool that mounts fast automated phishing attacks against WiFi networks in order to obtain secret passphrases and other credentials. It is a social engineering attack that unlike other methods it does not include any brute forcing. It is an easy way for obtaining credentials from captive portals and third party login pages or WPA/WPA2 secret passphrases.

From the victim's perspective, the attack makes use in three phases:

1. Victim is being deauthenticated from her access point. 
Wifiphisher continuously jams all of the target access point's wifi devices within range by sending deauth packets to the client from the access point, to the access point from the client, and to the broadcast address as well.

2. Victim joins a rogue access point. 
Wifiphisher sniffs the area and copies the target access point's settings. It then creates a rogue wireless access point that is modeled on the target. It also sets up a NAT/DHCP server and forwards the right ports. Consequently, because of the jamming, clients will start connecting to the rogue access point. After this phase, the victim is MiTMed.

3. Victim is being served a realistic router config-looking page. 
Wifiphisher employs a minimal web server that responds to HTTP & HTTPS requests. As soon as the victim requests a page from the Internet, wifiphisher will respond with a realistic fake page that asks for credentials, for example one that asks WPA password confirmation due to a router firmware upgrade.

Requirements
1. Kali Linux.
2. Two wireless network interfaces, one capable of injection.

For Usage

Short formLong formExplanation
-mmaximumChoose the maximum number of clients to deauth. List of clients
will be emptied and repopulated after hitting the limit. Example: -m 5
-nnoupdateDo not clear the deauth list when the maximum (-m) number of client/AP combos is reached. Must be used in conjunction with -m. Example: -m 10 -n
-ttimeintervalChoose the time interval between packets being sent. Default is as fast as possible. If you see scapy errors like 'no buffer space'
try: -t .00001
-ppacketsChoose the number of packets to send in each deauth burst. Default value is 1; 1 packet to the client and 1 packet to the AP. Send 2 deauth packets to the client and 2 deauth packets to the AP: -p 2
-ddirectedonlySkip the deauthentication packets to the broadcast address of the access points and only send them to client/AP pairs
-aaccesspointEnter the MAC address of a specific access point to target
-jIjamminginterfaceChoose the interface for jamming. By default script will find the
most powerful interface and starts monitor mode on it.
-aIapinterfaceChoose the interface for the fake AP. By default script will find
the second most powerful interface and starts monitor mode on it.
Wifiphisher works on Kali Linux and is licensed under the MIT license

Download now

الخميس، 29 مايو 2014

MOSCRACK Perl Application Tool For Cracking WPA Keys


Moscrack Multifarious On-demand Systems Cracker is a Perl application designed to facilitate cracking WPA keys in parallel on a group of computers.

This is accomplished by use of either Mosix clustering software, SSH or RSH access to a number of nodes. With Moscrack's new plugin framework, hash cracking has become possible. SHA256/512, DES, MD5 and Blowfish Unix password hashes can all be processed with the Dehasher Moscrack plugin.

Some of Moscrack's features:

  • Basic API allows remote monitoring
  • Automatic and dynamic configuration of nodes
  • Live CD/USB enables boot and forget dynamic node configuration
  • Can be extended by use of plugins
  • Uses aircrack-ng (including 1.2 Beta) by default
  • CUDA/OpenCL support via Pyrit plugin
  • CUDA support via aircrack-ng-cuda (untested)
  • Does not require an agent/daemon on nodes
  • Can crack/compare SHA256/512, DES, MD5 and blowfish hashes via Dehasher plugin
  • Checkpoint and resume
  • Easily supports a large number of nodes
  • Desgined to run for long periods of time
  • Doesn't exit on errors/failures when possible
  • Supports mixed OS/protocol configurations
  • Supports SSH, RSH, Mosix for node connectivity
  • Effectively handles mixed fast and slow nodes or links
  • Architecture independent
  • Supports Mosix clustering software
  • Supports all popular operating systems as processing nodes
  • Node prioritization based on speed
  • Nodes can be added/removed/modified while Moscrack is running
  • Failed/bad node throttling
  • Hung node detection
  • Reprocessing of data on error
  • Automatic performance analysis and tuning
  • Intercepts INT and TERM signals for clean handling
  • Very verbose, doesn't hide anything, logs agressively
  • Includes a "top" like status viewer
  • Includes CGI web status viewer
  • Includes an optional basic X11 GUI

الأربعاء، 16 أبريل 2014

Hack Wi-Fi With The Same SSID To Create Fake Access Point


Hack Wi-Fi With The Same SSID To Create Fake Access point. Security researcher N B Sri Harsha's  has shared this trick with us. 
"Hello friends I Share My One Of My findings trick In WIFI Network.

I Have Found This Vulnerability In My  College Network  ,  We have 70 Rooms In  Our  College  , Every Room Has a Router  , All Routers Are Connected To A Switch  ,  When I Tried To Connect  To A Router It Was Showing Only 1 AP ,  Rather Than Showing 70 AP's , ( For Both Smartphones And lappies) 

This Made Me To Think Something Evil , What will happen If i Started A  Wifi  Hotspot With The Same SSID  :D :D , 

Ya this Worked , Who Are Near To Me  Will Connect To My Wifi , *If  He Was Connecting For The First Time * ,  Between I Have Put The Same password as that of my college WiFi password , 

But This is Something Social Engg , To make him To Connect Him For The First time :/ , I don't Like It

Then i Got A New Idea  , Why  I Should Not Try In  Public  Open Networks

There Are Many Public Places Which Gives Open Wifi Hotspot . like kfc ,starbucks , pizzhut ...etc

 So I Have Tested  This Vulnerability With Two Android Devices  and Windows 8 lappy


- I Created A Open Hotspot  With Same SSID  In Both Devices

- I Opened My Lappy And  It Was Only Showing One SSID

- When I Tried To Connect , It Was Connecting To The Wifi Hotspot Which is Near

- So if  in a public place , if the attacker starts a fake access point with same SSID , The Victim Who Is Near To Attacker hotspot , Will Be Connected To The Attacker's AP ,  The Attacker Can Now Sniff The Packets

I Have Checked This Vulnerability  In Laptops And Smartphones  , Both Are Vulnerable.
So Every Traffic Will be Sent To Your Access Point So you Can Do Man In The Middle Attack.
This Video Will Help You  In How To Create An Fake AP and Capture traffic


The Script used In The Video :- link So I Will Be Going To Make A Full Demonstration Video On This After My Exams , probably in the end of this month.

Thanks For Viewing :)"

About the Author: 
N B Sri Harsha's, if you have any details regarding this contact here :- nekkantisriharsha@gmail.com or facebook.com/nbLORDS