How to Crack a With Reaver

Embed Size (px)

Citation preview

  • 8/10/2019 How to Crack a With Reaver

    1/4

    How to Crack a Wi-Fi Networks WPA Password with Reaver

    A new, free, open-source tool called Reaver exploits a security hole in wireless routers andcan crack most routers current passwords with relative ease. Heres how to crack a WPA orWPA password, step !y step, with Reaver"and how to protect your network a#ainst Reaverattacks.

    What Youll Need

    $ou dont have to !e a networkin# wi%ard to use Reaver, the command-line tool that does theheavy liftin#, and if youve #ot a !lank &'&, a computer with compati!le Wi-(i, and a fewhours on your hands, youve #ot !asically all youll need. )here are a num!er of ways youcould set up Reaver, !ut here are the specific re*uirements for this #uide+

    The BackTrack 5 Live !"

    ack)rackis a !oota!le inux distri!ution thats filled to the !rim with network testin# tools,

    and while its not strictly re*uired to use Reaver, its the easiest approach for most users.&ownload the ive &'& from ack)racks download pa#e and !urn it to a &'&. $ou canalternately download a virtual machine ima#e if youre usin# 'ware, !ut if you dont knowwhat 'ware is, /ust stick with the ive &'&. As of this writin#, that means you shouldselect ack)rack 0 R1 from the Release drop-down, select 2nome, 3- or 45-!it dependin#on your 6P7 8if you dont know which you have, 3 is a safe !et9, :;< for ima#e, and thendownload the :; section how WP; creates the securityhole that makes WPA crackin# possi!le.

    A little $atie%ce"

    )his is a 5-step process, and while its not terri!ly difficult to crack a WPA password withReaver, its a !rute-force attack, which means your computer will !e testin# a num!er ofdifferent com!inations of cracks on your router !efore it finds the ri#ht one. When : tested it,Reaver took rou#hly .0 hours to successfully crack my password. )he Reaver home pa#esu##ests it can take anywhere from 5-1? hours. $our milea#e may vary.

    Lets (et Cracki%

    At this point you should have ack)rack !urned to a &'&, and you should have your laptophandy.

    )te$ *+ Boot i%to BackTrack

    http://www.backtrack-linux.org/http://www.backtrack-linux.org/
  • 8/10/2019 How to Crack a With Reaver

    2/4

    )o !oot into ack)rack, /ust put the &'& in your drive and !oot your machine from the disc.82oo#le around if you dont know anythin# a!out live 6&s@&'&s and need help with this

    part.9 &urin# the !oot process, ack)rack will prompt you to to choose the !oot mode. ;elect=ack)rack )ext &efault oot )ext ode> and press Bnter.

    Bventually ack)rack will !oot to a command line prompt. When youve reached the prompt,type startx and press Bnter. ack)rack will !oot into its #raphical interface.

    )te$ ,+ %stall Reaver

    Reaver has !een added to the !leedin# ed#e version of ack)rack, !ut its not yetincorporated with the live &'&, so as of this writin#, you need to install Reaver !efore

    proceedin#. 8Bventually, Reaver will simply !e incorporated with ack)rack !y default.9 )oinstall Reaver, youll first need to connect to a Wi-(i network that you have the password to.

    6lick Applications C :nternet C Wicd Detwork ana#er;elect your network and click 6onnect, enter your password if necessary, click

  • 8/10/2019 How to Crack a With Reaver

    3/4

    root@root:~# air5on-ng start wlan0

    )his command will output the name of monitor mode interface, which youll also want tomake note of. ost likely, itll !e mon?. ake note of that.

    (ind the ;;:& of the router you want to crack+ astly, you need to #et the uni*ue identifierof the router youre attemptin# to crack so that you can point Reaver in the ri#ht direction. )odo this, execute the followin# command+

    root@root:~# airodu5p-ng wlan0

    8Dote+ :f airodump-n# wlan? doesnt work for you, you may want to try the monitor interfaceinstead"e.#., airodump-n# mon?.9

    $oull see a list of the wireless networks in ran#e"itll look somethin# like the screenshot!elow+

    9 Elapsed: )s 202-0*-20 *:2* ;/ handsha7e:

    00:): 4eacons #ata? #s 9 %4 E19 9IE6

    /A E""I

    00:0B:

  • 8/10/2019 How to Crack a With Reaver

    4/4

    A /ew i#$orta%t /actors to co%sider+

    Reaver worked exactly as advertised in my test, !ut it wont necessarily work on all routers8see more !elow9. Also, the router youre crackin# needs to have a relatively stron# si#nal, soif youre hardly in ran#e of a router, youll likely experience pro!lems, and Reaver may notwork. )hrou#hout the process, Reaver would sometimes experience a timeout, sometimes #etlocked in a loop tryin# the same P:D repeatedly, and so on. : /ust let it keep on runnin#, andkept it close to the router, and eventually it worked its way throu#h.

    Also of note, you can also pause your pro#ress at any time !y pressin# 6trlF6 while Reaver isrunnin#. )his will *uit the process, !ut Reaver will save any pro#ress so that next time yourun the command, you can pick up where you left off-as lon# as you dont shut down yourcomputer 8which, if youre runnin# off a live &'&, will reset everythin#9.

    How Reaver Works

    Dow that youve seen how to use Reaver, lets take a *uick overview of how Reaver works.)he tool takes advanta#e of a vulnera!ility in somethin# called Wi-(i Protected ;etup, orWP;. :ts a feature that exists on many routers, intended to provide an easy setup process, andits tied to a P:D thats hard-coded into the device. Reaver exploits a flaw in these P:DsI theresult is that, with enou#h time, it can reveal your WPA or WPA password.

    How to Protect Yoursel/ A2ai%st Reaver Attacks

    ;ince the vulnera!ility lies in the implementation of WP;, your network should !e safe if you

    can simply turn off WP; 8or, even !etter, if your router doesnt support it in the first place9.7nfortunately, as 2alla#her points out as Ars, even with WP; manually turned off throu#h hisrouters settin#s, Reaver was still a!le to crack his password.

    ;o thats kind of a !ummer. $ou may still want to try disa!lin# WP; on your router if youcan, and test it a#ainst Reaver to see if it helps.

    $ou could also set up A6 address filterin# on your router 8which only allows specificallywhitelisted devices to connect to your network9, !ut a sufficiently savvy hacker could detectthe A6 address of a whitelisted device and use A6 address spoofin# to imitate thatcomputer.

    &ou!le !ummer. ;o what will workJ

    : have the open-source router firmware &&-WR) installed on my router and : was una!le touse Reaver to crack its password. As it turns out, &&-WR) does not support WP;, so theresyet another reason to love the free router-!ooster. :f thats #ot you interested in &&-WR),check their supported devices list to see if your routers supported. :ts a #ood securityup#rade, and &&-WR) can also do cool thin#s like monitor your internet usa#e, set up anetwork hard drive, act as a whole-house ad !locker, !oost the ran#e of your Wi-(i network,and more. :t essentially turns your K4? router into a K4?? router.