Want to know if your Wi-Fi network is vulnerable to hackers? As a Kali Linux user, there are hundreds of pre-installed security controls and penetration testing tools. These tools are designed for ethical hacking – finding and repairing vulnerabilities in networks – and not for illegal purposes. To find out if a WPA/SPA PSK network is vulnerable to a decryption attack, you can steal the key using a set of tools called air-ng. We’ll show you how!

Root your Kali Linux computer and connect your Wi-Fi card to your computer. After that, turn on your computer. From there you can start channel monitoring and listening to nearby channels. When you find the router you want to hack, look for the hand holding the chain, which will give you the code to access the network. Read on to learn how to use Aircrack-Ng on non-GPU computers! As one of my articles on hacking WiFi, I would like to present another good hacking software to crack WPA2-PSK password. In my previous post, we covered WPA2 using Fly-ng. In this tutorial, we’ll use a piece of software developed by wireless security researcher Joshua Wright (commonly called coWPAtty). This is a simple and fast dictionary/hybrid WPA2 password cracker, so let’s get to it!

To do this we need to use a special network connection. Check out our list of 2017 Kali Linux and Backtrack wireless network adapters above, or find some popular adapters for beginners here.

Cowpatty is one of the hundreds of software included in BackTrack Software. For some reason it is not installed in the /pentest/wireless directory, but in the /usr/local/bin directory, so let’s go there.

Since bin is in the /usr/local/bin directory, this directory should be in your path, and we can use it in any directory in BackTrack.

BackTrack will give you a short help screen. Make sure the calf needs the following.

Next, we need to initialize the capture file where the password prompt will be stored when we hit the 4th path.

This will start hacking on the selected channel (-c 9) on the selected AP (00:25:9C:97:4F:48) and save the hash to a file called call.

Now when someone connects to the AP, we capture the hash and airdump-ng shows us that it was captured in the top right corner.

Now that we have a password hash generator, we can use it to determine the hash with a list of hashes and keywords.

As you can see in the screenshot above, COW creates a hash for each word in our word list with the SSID as the seed and compares it to the captured hash. When pairing is engaged, it displays the password of the AP.

Although making a cow is easy, it is very slow. Password hash with SHA1 and SSID seed. This means that the same password for different SSIDs will generate different hashes. This prevents us from using only Rainbow against all APs. Cowpatty should take the passwords you provide and calculate the hash and SSID for each password. This is very CPU fast and slow.

Cowpatty now supports using precomputed hash files instead of plain text files, cracking WPA2-PSK passwords 1000x faster! The pre-calculated files can be found at Wi-Fi Church, this hash file is pre-calculated using 172,000,000 dictionary files and 1000 known SSIDs. As useful, if the SSID is not at 1 000 000, the hash list is indeed empty.

In this case, we need to create our own request for the desired SSID. We can do this with a program called genpmk. We can create a hash file for the word “dark code” for the SSID “Mandela2”:

Now that we’ve created a hash of the custom SSIDs, we can now reverse the password with the cow script:

If you’re looking for a cheap, simple platform to start using Cowpatty, check out our Kali Linux Raspberry Pi for $35.

Keep coming back for more WiFi hacking and other hacking tips! Didn’t find other WiFi hacking guides? See here. If you have any questions about any of these, ask in the comments below. If it’s irrelevant, ask in the Nullbytes forum.

Want to make money as a white hat? Kickstart your hacking career with the 2020 Premium Ethical Hacking Certification Training Package from the new Zero Byte Store and get over 60 hours of training from cybersecurity professionals. The streaming version is available for a limited time and is ideal for security researchers and hackers to test the security of WPA/WPA2 secured networks without powering up. Fluxion is based on another script called linset. Fluxion is not very different from Linset, but it uses some improvements, bug fixes and other features. Fluxion uses man-in-the-middle/malicious attacks to obtain WPA passwords instead of going the bruteforce/dictionary route.

Flexion is associated with the release of bile (rolling). The latest (fixed) and (beta) lines are here. Read the Fluxion Wiki for the full tutorial.

Warning: Use this tool only on your network. Hijacking networks that you don’t own may be illegal in your country

Step 2: Get signature (unable to use without valid signature, password must be verified)

Step 5: MDK3 creates a process that verifies that all users are connected to the target network, so they can be tricked into connecting to FakeAP and entering their WPA password.

Step 6: A fake DNS server is created to capture all DNS requests and forward them to the server via script.

Step 7: The victim network is activated to serve the page, asking the user to enter the WPA password.

It depends on the victim, and this method does not eat the password. This is a scam, when you catch wpa, you block the victim’s wifi and create a new wifi location without the same name. Then the victim has to connect to this Wi-Fi. When the victim connects to the new Wi-Fi, they will be shown a login page. The victim then enters the password. Almost everyone now uses Wi-Fi, but this wireless system first appeared in the 90s, and today this system is very popular, in every person and office. This wireless AP uses Wi-Fi Protected Security II and a pre-shared key, commonly known as WPA2-PSK, for wireless security. WPA2 uses a strong encryption algorithm, AES, which is difficult to crack but not impossible to crack. Let’s see how to crack Wi-Fi password using Aircrack-ng.

The problem with WPA2 is handling 4-way passwords. If we hold hands we can break it.


Putting your Wi-Fi adapter into monitoring mode is easy. This helps us find all the Wi-Fi and traffic around us. Open your terminal and type:

Now when the Wi-Fi adapter goes into monitoring mode, we can capture Wi-Fi traffic and see important data. We can capture the traffic using Airodump-ng. Just type:

This command will scan the nearby products and all the information received by the Wi-Fi adapter will be displayed on the screen including BSSID (MAC address), number of beacon devices (network information), power (connection distance), speed etc. . Network, frame rate and data encryption (how to use WPA/WPA2 encryption).

After the scan is complete, the next step is to connect the target to our Wi-Fi network so that we can track it properly. So we need all the information we get from the survey. Now open a terminal and type:

When we send an authentication packet to the Wi-Fi system, it disables all other devices on the network.

After sending the authentication packet we receive the WPA handshake. The handshake is the WIFI password, which means it is completely secret. Now we use dictionary with aircrack-ng for encryption

