Aircrack

Imagine a world without WiFi. We would still be using long wires of ethernet cables to connect to the internet.

Crack WPA/WPA2 Wi-Fi Routers with Airodump-ng and Aircrack-ng/Hashcat. This is a brief walk-through tutorial that illustrates how to crack Wi-Fi networks that are s ecured using weak passwords. Aircrack-ng is a network software suite consisting of a detector, packet sniffer, WEP and WPA/WPA2-PSK cracker and analysis tool for 802.11 wireless LANs. It works with any wireless network interface controller whose driver supports raw monitoring mode and can sniff 802.11a, 802.11b and 802.11g traffic. Aircrack-ng is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured. It implements the standard FMS attack along with some optimizations like KoreK attacks, as well as the all-new PTW attack.

Aircrack is a suite of tools for 802.11a/b/g WEP and WPA cracking. It implements the best known cracking algorithms to recover wireless keys once enough encrypted packets have been gathered. Aircrack-ng is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured. The application works by implementing the standard FMS attack along with some optimizations such as KoreK attacks, as well as the PTW attack.

There is no debate about how much easier WiFi has made our lives. Now we can connect to the internet at coffee shops, subway stations, and almost anywhere we go.

However, WiFi is also a vulnerable network compared to the ethernet. Unless it is properly secured, it's easy to perform man-in-the-middle attacks using tools like Wireshark.

For example, if you are connected to a Starbucks network, anyone connected to that network can look at every other person’s network traffic.

Unless you use a VPN or the website uses HTTPS, your data (including passwords and credit card details) will be visible to the entire network.

If you are working for a company, chances are they use a WiFi network, too. Have you wondered how secure it is? Do you know if someone in the parking lot is connected to your network and capturing your company’s confidential data?

With tools like Wireshark and Aircrack, you can perform security audits of your WiFi networks. While Wireshark can help you watch what is happening on your network, Aircrack is more of an offensive tool that lets you attack and gain access to WiFi networks.

Thinking like an attacker has always been the best way to defend against a network. By learning how to work with Aircrack, you will be able to understand the exact steps an attacker would take to gain access to your network. You can then perform security audits of your own network to make sure it is not vulnerable.

A quick sidenote: I am in no way encouraging the use of illegal offensive tools. This tutorial is purely educational and is meant to help you defend your networks better.

Before we look at Aircrack in detail, here are a few terms you should know.

  • Access Point — The WiFi network that you want to connect to.
  • SSID — The name of the access point. For example, “Starbucks”.
  • Pcap file — Packet capture file. Contains captured packets on a network. The common format for tools including Wireshark and Nessus.
  • Wired Equivalent Privacy (WEP) — Security algorithm for wireless networks.
  • Wi-Fi Protected Access (WPA & WPA2) — Stronger security algorithm compared to WEP.
  • IEEE 802.11 — Wireless Local Area Network (LAN) protocol.
  • Monitor mode — Capturing the network packets in the air without connecting to a router or access point.

I recently wrote a post on the top 100 terms you should know as a penetration tester. You can check it out if you are interested.

What is Aircrack-NG?

Aircrack is a software suite that helps you attack and defend wireless networks.

Aircrack is not a single tool, but a whole collection of tools, each of which performs a specific function. These tools include a detector, packet sniffer, WEP/WPA cracker, and so on.

The main purpose of Aircrack is to capture the packets and read the hashes out of them in order to crack the passwords. Aircrack supports almost all the latest wireless interfaces.

Aircrack is open-source, and can work on Linux, FreeBSD, macOS, OpenBSD, and Windows platforms.

The ‘NG’ in Aircrack-ng stands for “new generation”. Aircrack-ng is an updated version of an older tool called Aircrack. Aircrack also comes pre-installed in Kali Linux.

WiFi Adapter

Before we start working with Aircrack, you will need a WiFi adapter. Aircrack only works with a wireless network interface controller whose driver supports raw monitoring mode and can sniff 802.11a, 802.11b, and 802.11g traffic.

Typical wifi adapters (usually built-in with your computer) don't have the ability to monitor traffic from other networks. You can only use them to connect to a WiFi access point.

With an Aircrack compatible wifi adapter, you can enable the ‘monitor mode’ with which you can sniff traffic from networks you are not connected to. You can then use that captured data to crack the password of that network.

Check out the list of WiFi adapters that are compatible with Kali Linux here.

Aircrack Tools

Now that you know what you can do with Aircrack, let’s look at each of its tools.

Airmon-ng

Airmon-ng is a script that puts your network interface card into monitor mode. Once this is enabled, you should be able to capture network packets without needing to connect or authenticate with an access point.

You can use the command airmon-ng to list the network interfaces and airmon-ng start <interface name> to start an interface in monitor mode.

In the above example, you can see that the network interface wlan0 has been turned into wlan0mon — meaning the monitor mode has been enabled for it.

AircrackAircrack

Airodump-ng

Airodump-ng is a packet capture utility that captures and saves raw data packets for further analysis. If you have a GPS receiver connected to your computer, airodump-ng can fetch the coordinates of the access points as well.

After enabling monitor mode using airmon-ng, you can start capturing packets using airodump. Running the command airodump-ng will list the available access points. The ESSID (or SSID) is the name of the wireless network.

Aircrack-ng

Once you have captured enough packets using airodump-ng, you can crack the key using aircrack-ng. Aircrack uses statistical, brute force, and dictionary attacks to break the WEP / WPA key.

It is important to note that you need enough packets in order to crack the key. Also, aircrack-ng uses sophisticated algorithms to crack the keys from the network packets.

If you are interested in learning more about how Aircrack does this, this would be a good starting point.

Aireplay-ng

Aireplay-ng is used to create artificial traffic on a wireless network. Aireplay can either capture traffic from a live network or use the packets from an existing Pcap file to inject it into a network.

With aireplay-ng, you can perform attacks such as fake authentication, packet injection, caffe-latte attack, and so on.

The Cafe Latte attack allows you to obtain a WEP key from a client device. You can do this by capturing an ARP packet from the client, manipulating it, and then sending it back to the client.

The client will then generate a packet that can be captured by airodump-ng. Finally, aircrack-ng can be used to crack the WEP key form that modified packet.

Aircrack

Airbase-ng

Airbase-ng is used to convert an attacker’s computer into a rogue access point for others to connect to.

Using Airbase, you can pretend to be a legitimate access point and perform man-in-the-middle attacks on devices that connect to your system.

This attack is also called the “Evil Twin Attack”. Assuming you are in Starbucks trying to connect to their Wifi, an attacker can create another access point with the same name (usually with better signal strength) making you think that the access point belongs to Starbucks.

It is hard for regular users to differentiate between a legitimate access point and a rogue access point. So the evil twin attack remains one of the most dangerous wireless attacks we encounter today.

Aircrack-ng Man Page

In addition to these, there are a few more tools for you to use in the Aircrack arsenal.

  • Packetforge-ng — Used to create encrypted packets for injection.
  • Airdecap-ng —  Decrypts WEP/WPA encrypted capture files after you crack the key with aircrack-ng. This will give you access to usernames, passwords, and other sensitive data.
  • Airolib-ng —  Stores pre-computed WPA/WPA2 passphrases in a database. Used with aircrack-ng while cracking passwords.
  • Airtun-ng —  Creates virtual tunnel interfaces.

Summary

The world is a more connected place, thanks to WiFi. We enjoy the benefits of WiFi almost every single day. With all its benefits, it is also a vulnerable network capable of exposing our private information, if we are not careful.

Hope this article helped you understand WiFi security and Aircrack in detail. To learn more about Aircrack, check out their official wiki.

Loved this article? Join my Newsletterand get a summary of my articles and videos sent to your email every Monday. You can also find my blog here.

Thomas d'Otreppe – Open Source – AndroidiOSWindowsMac
aircrack-ng is a set of tools for auditing
wireless networks. It's an enhanced/reborn version
of aircrack. It consists of airodump (an 802.11
packet capture program), aireplay (an 802.11
packet injection program), aircrack (static WEP
and WPA-PSK cracking), airdecap (decrypts WEP/WPA
capture files), and some tools to handle capture
files (merge, convert, etc.).

Aircrack-ng -w

Overview

Aircrack-ng is a Open Source software in the category Servers developed by Thomas d'Otreppe.

The latest version of Aircrack-ng is currently unknown. It was initially added to our database on 10/16/2009.

Aircrack-ng

Aircrack-ng runs on the following operating systems: Android/iOS/Windows/Mac.

Aircrack-ng has not been rated by our users yet.

Write a review for Aircrack-ng!

02/02/2021 MEGAsync 4.4.0
05/19/2021 RedCrab 8.1.0
05/19/2021 ACDSee Photo Studio Home 2021 24.0.1
02/18/2021 Freemake Video Downloader 4.1.12.52
05/19/2021 Quantum GIS 3.18.3
Secure and free downloads checked by UpdateStar
05/18/2021 How to setup a VPN on a Windows computer using PureVPN for example
05/16/2021 Why you should think about using a VPN to protect your privacy
05/11/2021 Adobe fixes 43 vulnerabilities with May updates
05/05/2021 Firefox 88.0.1 available for download
04/30/2021 CCleaner 5.79 update available for download