Beruflich Dokumente
Kultur Dokumente
FOLLOW US
ClementsAutoInsuranceWorldwidePolicyMade
ForYou
HOW TO
M ost of you lot would be aware what WPA/WPA2 is so I won't bang on about the encryption or protocols a great deal. In short WPA and WPA2
both have a maximum of 256bit encrypted with a maximum of 64 characters in the password. The encryption is really only 64bit but x 4 because
of the way the authentication functions as a 4 way handshake.
Before starting with oclHashcat. I would suggest to test for a WPS/Wifi Protected Setup' using Reaver and more recently the Pixie-dust method as it
can effectively crunch the 11,000 WPS pins and extract the WPA pre shared key a lot faster than a complex WPA/WPA2 password. If WPS is secure
I would suggest to then move onto WPA/WPA2 this method or the Evil twin method that clones the AP.
Download
FreeDownloadunzipper.com
The tool Hashcat has been around for sometime and is CPU based, oclHashcat makes use of modern GPU processors and makes use of its physics
abilities to crack most modern encrypted user/pass hashes.
Step 1
Once airodump-ng is busy, Pop up another terminal and send deauthentication packets towards the desired access point and connected device so
it will disconnect and have to reconnect to the AP and capture the 4 way handshake with aireplay-ng, You can also just leave airodump-ng to
capture the handshakes passively without spraying out deauthentication packets with aireplay-ng and over time it will capture handshake/s but
generally takes a little longer and end up with a larger capture file. This aireplay-ng command can fail, You may need to do it a few times for it to
function as it should. Just keep in mind with aireplay-ng the -a switch is for AP/wifi mac address, -b is for the wifi mac address of a device
connected to that AP.
WONDERHOWTO GADGET HACKS NEXT REALITY INVISIVERSE DRIVERLESS NULL BYTE
https://nullbyte.wonderhowto.com/howto/bruteforcewpawpa2viagpu0170474/ 1/5
6/21/2017 BruteForceWPA/WPA2viaGPUNullByte::WonderHowTo
#~:$wifite -wpa
or
#~:$fern-wifi-cracker
or
#~:$gerix-wifi-cracker-ng
FreeDownload
ConvertWordToPDFwithFileConvertor.fileconvertor.org
Step 2
If your using windows, You could effectively capture a WPA handshake with a Android phone app and a Alfa RTL8187L wifi adapter. The
oclHashcat site has a page you can upload upto 5mb wpa.cap files and then download the back file back as a .hccap
Step 3
The -m switch is for hash type, We can easliy find the information needed for using the -m switch with WPA. This can easily be done with
other hashes MD5 etc.
STEP 4 - Here we will make use of oclHashcat/Hashcat. It is a versitile tool set and can be used with or without a wordlist. It can create wordlists
on the go without slowing down and storring massive dictionary files.
There many wordlists that can be found on the web, But why store them in files when oclHashcat creates them on the fly. Another thing to keep in
mind about wordlists, Not all wordlists you find online will be created for WPA/WPA2 as they need to start a 8 characters in length.
Download
https://nullbyte.wonderhowto.com/howto/bruteforcewpawpa2viagpu0170474/ 2/5
6/21/2017 BruteForceWPA/WPA2viaGPUNullByte::WonderHowTo
Download FOLLOW US
FreeDownloadunzipper.com
Step 4
Note - A modern GPU such as R9290x at full speed can munch through 180,000 WPA attempts per second. This can vary depending a small
amount depending on drivers at the time. This can be corrected with the -u switch to get full speed. The -u switch ends with amount of RAM on
the gpu. For me my AMD R( is 4096mb. For eg. -u 4096.
With wordlist the results will vary depending on the strength of your GPU and if the password is in your list at all. It flys through small lists, You
can make a list.txt of compile wordlist/or hashes of the same type and pipe that into the command.
or
Step 5
?l = abcdefghijklmnopqrstuvwxyz
?u = ABCDEFGHIJKLMNOPQRSTUVWXYZ
?d = 0123456789
?s = !"#$%&'()+,-./:;??@\^`{|}~
:
?l?l?l?l?l?l?l?l = a-z, 8 Characters in length.
InstantGrammarChecker
GrammarlyMakesSureEverythingYouTypeIsEffectiveAndMistake
Free.TryNow!grammarly.com
Lets just say you password is 12345678. You can use the custom mask option ?d?d?d?d?d?d?d?d
Note- For a mask/Brute-force options you will need to use the -a 3 switch.
The Hybrid options gel well also, It jumbles wordlist with masks or brute force methods.
Attack modes:
WONDERHOWTOGADGET HACKS NEXT REALITY INVISIVERSE DRIVERLESS NULL BYTE
https://nullbyte.wonderhowto.com/howto/bruteforcewpawpa2viagpu0170474/ 3/5
6/21/2017 BruteForceWPA/WPA2viaGPUNullByte::WonderHowTo
0 = Straight
1 = Combination
FOLLOW US
3 = Brute-force
6 = Hybrid dict + mask
7 = Hybrid mask + dict
Summary
This tool does it's slowest work when put up against WPA/WPA2 because of the 4 way handshake slowing it down. It does extremely well with
other hash types For eg Md5 is cracked at 10million attempts per second and NTLM is a bit faster than Md5. The oclHashcat website has some
more in depth .info.
Related
2 Comments
TANG XIAO
1 YEAR AGO 1
i have also heard that pyrit use gpu to crack the same
REPLY
D3ATHR3A13R
1 YEAR AGO 1
REPLY
YOU
LOGIN TO COMMENT
https://nullbyte.wonderhowto.com/howto/bruteforcewpawpa2viagpu0170474/ 4/5
6/21/2017 BruteForceWPA/WPA2viaGPUNullByte::WonderHowTo
FOLLOW US
InstantGrammar
Checker
GrammarlyMakesSure
EverythingYouTypeIsEffective
AndMistakeFree.TryNow!
Grammarly
HOT LATEST
HOW TO
RSAConference
RSAConferenceSingapore...
ConnectWithInfoSecPros&EnhanceYourSkills.
RegisterNow!
HOW TO
https://nullbyte.wonderhowto.com/howto/bruteforcewpawpa2viagpu0170474/ 5/5