Wednesday 20 April 2016

WIFI HACKING : CRACKING WPS USING REAVER

Hello my rookies, Welcome back. :)

Today I will show how to crack WPS enabled wifi networks. In this attack we exploit the vulnerability in the WPS protocol which was original implemented for the ease of users.

So, Let's get started.

WHAT IS WPS & HOW IT WORKS?

WPS is the abbreviated form of WIFI PROTECTED SETUP. It is used to authenticate clients without them having to enter the  pass phrase. WPS authentication can take place via two methods :-

1. Push Button
2. Pin Entry

We exploit the pin entry method in which the user enters an 8 digit pin(which is numeric) rather than the pre shared key. The pin verification takes place in two steps. Firstly, the first 4 digits are verified and the acknowledgment of this is sent back to the client, if the first 4 digits are successfully verified then only the next 4 digits are verified. so, in a way our work here is even more simplified because we dont have to find an 8 digit pin rather two 4 digit pins,which decreases the number of test cases significantly. Total number of test cases :-

10^4  + 10^3 = 11000

Second term is 10^3 because of the last four digits the last, i.e. , the 8 digit is the checksum of the first 7 digits.

As you can see the number of test cases which we have to run through to find the correct pin are much less than the case when we were trying to crack a WPA/WPA2 protected AP using aircrack-ng suite by bruteforcing the 4-way handshake to get the password, because the password can range from anywhere  between 8 to 63 characters long.

Enough with the theory part. Let's get started now.

STEP #1

First of all get your wireless interface in monitor mode :-
airmon-ng check kill
airmon-ng start interface_name
if you don't know your wireless interface you can use ifconfig to find the name of your interface.(wlan1 in my case)



As you can see the in the second last line of the second image monitor mode is enabled on wlan1mon in my case.

STEP #2

Find a target for yourself, we will use wash to find all the WPS enabled APs in our proximity :-

wash -i monitor_mode_interface_name

This will give you a list of all the WPS enabled APs in your proximity. Select one go to next step.

wash -i wlan1mon 
in my case

STEP #3

Last step, fire up reaver and let this beast do its work :-

reaver -b BSSID_of_AP -i interface_name -vv


NOTE :- 

If you are not receiving M5/M7 OR receiving timeout error try playing with the values of the (Increase The Values, Below is an example) :-
  • T -> used to set the M5/M7 timeout period, default value is 0.20 (Must be less then 1.0)
  • t -> set the receive time out period, default value is 5.
Example with changed values : -

reaver -b XX:XX:XX:XX:XX:XX -i wlan1mon -p -t 8 -T 0.9 -vv
That's it Guys, Stay tuned for more tutorials.
Stay anonymous, Hack The World. \m/

12 comments :
Write comments
  1. Should you ever require the services of a hacker, i implore you to try your very best to hire only professionals. . i was able to hire the services of an elite, asides the fact that i was provided a permanent solution to the service he rendered me, but he gave a very efficient customer experience. he carried me along with every process and didnt leave me in the dark. (cyberblasst@gmail.com) is the only trusted hacker i can boldly recommend, he helped me hack into his phone and social media accounts and the whole thing was exposed at a little cost. I and my friends have used him quite a number of times and he never disappoints.........

    ReplyDelete
    Replies
    1. ARE YOU A VICTIM OF FALSE HACKERS & BANK LOAN SCAM⁉️

      We have been having recent complains from individuals about how they lost money 💵 to SPAMMERS who call themselves HACKERS or BANK LOAN OFFERS. They are all over the internet sharing false testimonies. Please do not fall for their lies for this is just a way to LURE you to them.

      They say lies in the likes of such-:
      ▪️Bitcoin Auctioning ▪️Western Union Hack
      ▪️Blank Credit Card ▪️Clearing Criminal Records
      ▪️Loan Offers. ▪️Bank Account Loading
      ▪️Changing University Grades & so on.
      These are all lies and you shouldn’t fall for them.

      🏵GLOBAL PLUGGERS🏵 is here to help you Recover all your Money 💵 that you have been Ripped of.
      WHO ARE GLOBAL PLUGGERS⁉️
      We are a group of Computer💻 Experts who are memebers of the “HACKERONE” Forum. We have dedicated ourselves to help Victims of these SCAM(s) recover all the Money that has been taken falsely from them.

      If you have been a victim of thes Thieves, then you need to contact us as soon as possible so you can get your money back.
      Email-: globalpluggers@gmail.com
      No. +1 (808) 600 0773 ( Number also available on WhatsApp)

      Note:
      Please know that we do not charge you for Fund Recovery Service, Our Funds Recovery Service is to help and so it’s Free.

      We also provide Legit Hacking Services such as-:
      🔸Phone Hacking/Cloning
      🔸Email Hacking & Password Recovery
      🔸Social Media Hacking & Passowrd Recovery
      🔸Deleted Files Recovery 🔸Mobil Tracking
      🔸Virus detection & Elimination.

      Contact-:
      Email globalpluggers@gmail.com
      No. +1 (808) 600 0773 (number also available on WhatsApp)








      Delete
    2. CRYPTO ACCOUNT TAKEOVER (ATO) FAKE INVESTMENT & OTHER TROUBLESHOOT. As Bitcoin reaches all-time highs, and continues to go through price action swings, it has been attracting a lot of attention. As unknowing, new supporters of Bitcoin enter the cryptocurrency craze, this has presented ideal opportunities for Bitcoin scams to occur. Every day investors are getting scammed by old and new tactics. It’s important to note that although Bitcoin itself is not a scam, attacks are on the rise and they are costing individuals, businesses, and organizations significant financial and damage that are often difficult to recover quickly. When it comes to Binary Options, there are quite people who have been taken for a ride by a Brokers and at a result of this many have lost a large amount of money to Fake Binary Option Scammers this bring Investors down to a Zero point financially.

      D-hackers is a multinational equipped Hackers come together as a team to track down & to recover whatever that has being stolen from you from the most difficult internet SCAMMERS. NOTE!! We've received countless heartbreaking reports of notorious cyber scammers and we’ve successful recover them back.

      contact us on
      1⃣Binary Recovery.
      2⃣Files Recovery
      3⃣School Grades Change & Exam Questions
      4⃣Password Bypass / Recovery
      5⃣Malware Removal / Criminal Record Expunge
      6⃣Blank ATM Card
      7⃣Social Media Hack
      8⃣Remote Mobile Monitoring & Hacking
      9⃣ Credit Repair
      🔟Private Key Reset

      Relate whatever it is to City Center Of Binary Option Service & allow us give you positive result with our hacking skills. Visit our BLOG page Dhackerspot.com
      Email 📩 binaryoptionservice01@gmail.com pointekhack@gmail.com cyberhackertap@gmail.com we Guarantee you up to %85
      REMEMBER YOUR HAPPINESS

      Delete
  2. ★COMPOSITE HACKS★

    If Truly you Are In Need Of A PROFESSIONAL LEGIT HACKER Who Will Get Your Job Done Efficiently With Swift Response, Congratulations, You Have Met the Right HACKERS.

    ★ WHO ARE COMPOSITE HACKS???
    • We are a Team Of Professional HACKERS , a product of the coming together of Legit Hackers from the Dark-Web, (pentaguard,CyberBerkut, RedHack , Black Hat, White Hack ) we have been existing for over 12years, our system is a veryStrong and decentralized command structure that operates on ideas and directives.

    ★ JOB GUARANTEE:
     • Frankly speaking, I always give a 100% guarantee on any job we are been asked to do, because we have always been successful in Almost all our jobs for over 12years and our clients can testify to that .To hack any thing needs time though, but we can provide a swift response to your job depending on how fast and urgent you need it.Time also depends on what exactly you want to hack and how serious you are. Enough time with social engineering is required for hacking. So if you want to bind us in a short time, then just don't contact us because We can't hack within 30minutes,*sorry*.Basically, time depends on your luck. If its good luck, then it is possible to hack within 30minutes but, if it is in the other way round, it would take few hours. I have seen FAKE HACKERS claiming they can hack in 30min, 20min , but there is no REAL HACKER who can say this (AVOID THEM).
    Please Note : we have only one contact email : compositehacks@gmail.com

    We will be happy to have you join over 2000 satisfied clients around the world to use our services.

    ★ OUR HACKING CAPABILITIES:
    There are so many Reasons why people need to hire a hacker, It might be to Hack a Websites to deface , retrieve information, edit information or give you admin access Some people might need us for Hacking any smart phone giving you access to all activities onthe phone like , text messages , call logs , Social media Apps and other informations.Some might need to Hack a Facebook , gmail, yahoomail, Instagram , twitter and every other social network Accounts, Some might need to Hack into Court's Database to Clear criminal records.However we can also Hack into school's websites (server) to change grades without any trace, Also Some Individuals might want to Track someone else's Location probably for investigation cases.
       All these Are what we can get Done withing few hours.

    ★ SOME OTHER SPECIAL SERVICES WE OFFER:
    ★ Bank Accounts Loading.
    ★ Credit Cards Loading
    ★ One Vanilla Cards Loading ($100 cards and above)
    ★ Sales Of HACKED/PROGRAMMED Cards (ATM & CC)

    ★ You can also contact us for other Cyber Attacks And Hijackings, we do almost All.

    ★Contact Us for Your Desired Service Via: compositehacks@gmail.com

    ★We Treat Every Request With Utmost Confidentiality★

    ReplyDelete
  3. Hi can I call u or text u can u give me ur number because I want to ask u something

    ReplyDelete
  4. Hack Ethics is a Trusted Certified Binary Options Recovery Expert and a Reliable Hacker/Organization. Also render any desired hacking services which includes ROMANCE SCAMS, CHANGE OF ANY SCORE GRADES and other HACKING SERVICES. These are happy again client's recovery reviews that was recently helped to put smiles back on their faces after been cheated and scammed of their hard earned money - (Kylie Ford) "I was scammed and scammed and scammed again. I invested with four binary companies and lost all of my investments totalling £750,000 Then I contacted a special someone who offered me help – who specializes in binary recovery and every other hacking services (Hack Ethics). By the end of it all I was able to recover all of my money including my savings and profits. My husband is not around anymore and I have an 8 year old son with learning difficulties. The pressure of being a single, working mother with a child who needs so much additional attention and support became overwhelming for me. I also felt too traumatized to trust anyone else and I was very afraid, Thanks to HACKETHICS008@GMAIL.COM or WICKR - recoverygenius who deserved my trust by helping me get every penny I lost. He has been incredibly helpful and supportive and also very understanding about all of my fear and concerns he helped recover all of my funds back within 48 HOURS . I really hope that others do not have to go through what I did, and I wish that I had realized before. I hope my story might help others to not be fooled the way that I was. He can also render any desired hacking services ,Romance Scams,Change of School Grades and so on.'' (Sarah Richards) - I appreciate Hack Ethics for helping me recover my stolen funds $110,000 from Binary Brokers and Fake Hackers within 48 hours. Contact him or Skype for any desired Hacking Services.It was like a miracle within 48 hours and now I feel free like a bird. It was sweet and smooth from the start, withdrawals were easy and consistent until it gets to a point I started to be denied withdrawals and that was how I lost all money, I couldn't get my investment amount back not talk of the bonuses. I contacted several lawyers but it was all waste of time and money, they couldn't render an inch of help. God so good to my old self and family, I later met with a certified binary options recovery expert (Hack Ethics) who helped me recover my money within 48 hours from the brokers, it was worth it to pay him 20%" I appreciate HACKETHICS008@GMAIL.COM so much. Contact for ANY DESIRED HACKING SERVICES.'

    ReplyDelete
  5. ETHICAL REVOLUTION HACKER...How bad is your grade?..Have you ever wanted to change your grades and you had contacted many hackers to
    render this service but cannot guarantee a safe exploit for your school systems.. Fear no more, we at ETHICAL REVOLUTION HACKER comes to network exploit and software penetration we are the very best out there. We have all hacking materials and tools to penetrate any system and deliver a 100 percent success to our client.Privacy and safety of our client is our ultmost priority. .
    Our service includes
    +Upgrade University Grades
    +Facebook,Instagram, Twitter, Whatsapp, Line, Skype Hack
    +Delete unwanted online Pictures and Videos on any website
    +Remove Criminal Records
    +Hack bank accounts
    +Apps hacking
    +Mastercard, Paypal, Bitcoin, WU, Money Gram with untraceable credit on it etc.We are part of a team consisting of highly efficient developers and hackers.
    +Upgrade University Grades
    +Facebook, Instagram, Twitter, Whatsapp, Line, Skype Hack
    +Delete unwanted online Pictures and Videos on any website
    +Remove Criminal Records
    +Hack bank accounts
    +Apps hacking
    +Mastercard, Paypal, Bitcoin, WU, Money Gram with untraceable credit on it etc.
    We have 100% records from our client as well as highest repeat hire rate. our work speak for ourselves, we provide a perfect software solution to all clients.
    We believe in mutual growing with client and hence we work as a technology partner and consultant for our clients.
    Contact us ON WEBPAGE ethicalrevolutionhacker.strikingly.com AND revolutionhacker.protonmail.ch

    Reply

    ReplyDelete
  6. Guys it no longer questionable when it comes to (HACKING). I am good in what I do Hacking

    *Facebook Hacking Tricks
    * Database Hacking
    * G-mail/AOL/Yahoomail/ Inbox Hacks
    *Control Device Remotely Hack
    *University Grade Upgraded
    *Wiping of Credit Cards/ Increase Credit Cards Hacks
    *Western Union & Money Gram Hacks
    *Loan Transfer
    *Blank ATM Card
    *Recover your lost Btcoin password

    All you need do just Email:- pointekhack@gmail.com and your job shall be done with %100✓ guarantee

    ReplyDelete
  7. Hola chicos,
    ¿Alguna vez has necesitado un experto en piratería? ¿Alguna vez has querido hackear la cuenta de correo de alguien? RECUPERAR CUENTAS PERDIDAS, grado escolar, ¿aumentar puntaje de crédito?
    Básicamente, creo que no todos tenemos que enfrentar todo este engaño y las mentiras de nuestro cónyuge en un caso mío. Cuando me enfermé y me cansé de todas las mentiras y engaños, tuve que contactar a un amigo mío para que me contactara. Uno de los mejores hackers en los estados.
    Luego conocí a Herbert West. Me salvó de las mentiras de mi infiel marido al piratear su teléfono. En caso de que necesite ayuda para piratear cualquier teléfono o cuenta u otros trabajos, póngase en contacto con él (cyberhackspy01@GMAIL.COM). Número: +1 (518) -217-5690.
    Él te ayudará

    ReplyDelete
  8. Hack Ethics is a Verified Experienced Binary Options Recovery Specialist and Professional Hacker that provides the experience, intelligence, expertise in Asset Recovery and successfully solve ANY DESIRED HACKING SERVICES YOU WANT with ease.

    People have lost their hard earned money through this BINARY OPTIONS TRADINGS, yet they would go to meet FAKE HACKERS who are also scammers unknowingly to help them recover their money and they would end up losing more money in the process. These Scammers also tend to put Fake Testimonies out there just to steal more from you by giving you False hope. I understand how heartbreaking it is to be a BINARY OPTIONS SCAM VICTIM after you've been promised your fortune by Binary Companies and then they ignore your Emails or Calls after stealing from you.  I'm taking every step to render solution to those innocent people affected and help them get every penny they lost.  CONTACT  EMAIL  -  HACKETHICS008@GMAIL.COM 
       REPOSTING MY ARTICLE ON EVERY PLATFORM AND FORUM TO HELP VICTIMS OUT THERE. 

    ReplyDelete
  9. I know of a group of private investigators who can help you with they are also hackers but prefer to be called private investigators They can help with your bitcoin issues and your clients will be happy doing business with you,they can also help yo with your bad credit score,hacking into phones,binary recovery,wiping criminal records,increase school score, stolen files in your office or school,blank atm etc. Just name it and you will live a better life
    whatsapp +1 (984) 733-3673
    Premiumhackservices@gmail.com

    ReplyDelete
  10. hi everyone kindly reach out to (ethan spy world) they are the best when it comes to online hacking, they helped me in the past when i did suspect my partner was cheating on me , and I find this very helpful, so I strongly recommend anyone to this group for any issues related to hack, do reach out through web @: (ethanspyworld.com)
    best in getting this done

    ReplyDelete