Wednesday, October 19, 2016

deltaxflux/fluxion - WiFi (WPA/WPA2) Hacking without Brute Force

https://github.com/deltaxflux/fluxion

http://www.ehacking.net/2016/10/wifi-wpawpa2-hacking-without-brute-force.html?utm_source=twitterfeed&utm_medium=linkedin+company+page&utm_campaign=Feed%3A+ehacking+%28Ehacking-+Your+Way+To+The+World+Of+IT+Security%29

How it works

  • Scan the networks.
  • Capture a handshake (can't be used without a valid handshake, it's necessary to verify the password)
  • Use WEB Interface *
  • Launch a FakeAP instance to imitate the original access point
  • Spawns a MDK3 process, which deauthenticates all users connected to the target network, so they can be lured to connect to the FakeAP and enter the WPA password.
  • A fake DNS server is launched in order to capture all DNS requests and redirect them to the host running the script
  • A captive portal is launched in order to serve a page, which prompts the user to enter their WPA password
  • Each submitted password is verified by the handshake captured earlier
  • The attack will automatically terminate, as soon as a correct password is submitted

2 comments: