|
|
|
|
|
by unbelievr
3668 days ago
|
|
There are quite a lot of guides out there on sites like hackforums I reckon. The search keywords are "aircrack-ng WPA". In short terms, you need to sniff the 4-way handshake between a legitimate client and the AP it connects to. This can sometimes be forced by spoofing a "deauth" (disconnect) packet from the client, but requires support in the chipset for your wlan-card. (Injection and monitor mode). Once you have the handshake, your options are either aircrack-ng, hashcat or other password cracking tools. Some of these have a crazy amount of options and possibilities for cracking, and getting to know them can increase your success rate by a lot. However, the easiest way these days is to exploit WPS in the AP. Look up Reaver and Pixiewps. |
|