2016-08-06

Aircrack Basics for Wi-Fi Sheep Hunters

AIRCRACK BASICS
By: @donds https://hackvault.blogspot.com

The instructions below are strictly for research and educational purposes only.  Please setup a test lab, it is illegal to hack an AP without permission.

The steps below might not work, but it does work most of the time. It works very well when a client is connected to the AP, but of course you can fake that also.

TIPS: Change your monitoring interface's MAC address for anonymity and to make is easy to remember: Example 11:22:33:44:55:66  - Use MACCHANGER.

Let’s start AirCrackin’

PHASE 1
-OPEN A TERMINAL WINDOW (Terminal 1)
1. Set the interface to monitor mode:
 airmon-ng start [interface]
2. To recon the airwaves use airodump-ng:
 airodump-ng [interface] 
3. Select a victim and take note of the SSID, channel and mac address.
4. Stop airodump-ng, then restart it with the write option to start catching the IVs.  
airodump-ng -c [channel] -w [filename] [interface]
-LEAVE Terminal 1 PROCESS RUNNING

PHASE 2
-OPEN A SECOND TERMINAL WINDOW (Terminal 2)
5. Inject some "care packages" to generate IV's. Get creative! Take your pick.

NOTE: To test the subjects' ability for packet injection, use the following code.  You are looking for a 100% injection result.  aireplay-ng -9 -e [vic ssid] -a [vic mac] [interface]

Fake Associations for the victim AP
            aireplay-ng -1 0 -e [vic ssid] -a [vic mac] -h [your mac] [interface]
OR use this for picky Access Points 
            aireplay-ng -1 6000 -o 1 -q 10 e [vic ssid] -a [vic mac] -h [your mac] [interface]

You have to get a successful association before you can continue. Your ARP request replay packets will not generate any initialization vectors (IVs) if you are not associated with the AP.

Send out ARP request replay modes
            aireplay-ng -3 -b [vic mac] -h [your mac] [interface]

-LEAVE Terminal 2 PROCESS RUNNING

PHASE 3
-OPEN A THIRD TERMINAL WINDOW (Terminal 3)
6. Start cracking -aircrack-ng [filename] pick the vic SSID then go.  You can also use the FMS/Korek method by adding -K on the code above. 

You will need approx. 250,000 IV's for a 64 bit key, 1.5M IVs for a 128 bit key.

For the PTW method, you'll need 20,000 packets for 64bit and 40,000 packets for 128bits.

2016-07-02

PHV Equipment Check for DEFCON 24 [revised 201:10:40]

08/10/2016 UPDATE: This post also appeared in the Wall of Sheep blog ->> CLICK HERE

They say not to bring any electronic devices at DEFCON!? .... what's the fun in that? Well, your mother also said not to get in a strange car with a stranger... UBER, anyone?

It’s time to prep your gear for the Packet Hacking Village (PHV) at DEFCON 24. Although, the PHV staff will have some gear for you to use, I highly recommend to bring your own "FOR DEFCON USE ONLY" gear.

For the Wall of Sheep and Wi-Fi Sheep Hunt you'll need a laptop with wired and wireless sniffing capabilities. I spent about $200 for a used laptop from eBay. Also, invested on an Alpha wireless USB card from Amazon, load Kali on the laptop and you're basically good to go. Most tools you'll need are already included in Kali.  The PHV staff can help you refine your setup and config depending on what event you want to try out.

For Sheep City, you can use the same laptop you plan to use for WOS and WIFISH.  But it will require a bit more creativity and possibly a visit to the vendor area or Fry's.  Prep for Bluetooth, ZigBee, IrDa, RF...etc. Be ready for anything.

Packet Detective runs like a classroom format. IMHO, this is a "MUST DO" event at PHV. PHV will have laptops setup for PD Agent trainees to use... Yes, you don't have to bring your own laptop to participate.  This is a very popular event and laptops are limited. Sign up early.

Wi-Fi Sheep Hunt will also have a sign-up sheet for the gear use this year. You can use your own equipment to join the RF Sheep Hunt and code breaking fun.  There will also be a couple of laptops for players to use, if you're to chicken to use yours, but only for limited time slots. 

Capture the Packet has produced Black Badge winners at DEFCON. If you're just prepping now, you're already behind... you get my drift.

If you're asking which one to do first, I'd say do it all! But if it's your first ever visit at PHV, here's the order of events I'd suggest..

1. Packet Detective

2. Wall of Sheep
3. WiFi Sheep Hunt
4. Sheep City
5. Capture The Packet

Don't forget about the PHV Speaker Workshops which are excellent that it's almost always standing room only, no equipment required... well, maybe at least a pen and paper. PHV is also an excellent spot if you just want to hangout. Drop by and check out our DJs at the WOSDJCO... it will be hard to miss them -> required equipment = a drink in hand.  
...