Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 54 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow Stealing wireless password with fake AP
EH-Net
May 21, 2013, 03:39:59 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Stealing wireless password with fake AP  (Read 7352 times)
0 Members and 1 Guest are viewing this topic.
matanddie
Newbie
*
Offline Offline

Posts: 1


View Profile
« on: July 19, 2012, 09:12:50 AM »

Hi everyone;

I have a question, and hope you can help

ESSID of my real AP is test
BSSID of my real AP: 1F:X:X:X:X:X
Password of my real AP: 12345678 (WPA2)

I have created a fake AP with ESSID test and BSSID 1F:X:X:X:X:X


   1. From my netbook, i first connected to my real AP and i can capture
   4-way handshake.
   2. Then i shut down real AP
   3. Then i open fake AP
   4. My netbook connected to fake AP.

However i can not capture 4-way handshake ? I really wonder why ? My fake
AP is same as real AP. So my netbook should send password to my fake AP ?

Shortly, i'm trying to steal passwords with fake APs and i can not do it.
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #1 on: July 21, 2012, 03:16:10 PM »

Have you configured your fake AP with the WPA2 key? The client doesn't send the password in clear-text, so you're not going to capture any more than you would by capturing the four-way handshake with the legitimate AP.

The purpose of this type of setup would be to get the client to associate with your fake AP and then capture unencrypted network traffic, not obtain the WPA2 key.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #2 on: August 02, 2012, 03:09:15 PM »

u may get the  password's hash with it so its not useful try to do some other practices for example try to crack wpa2 with brute force and so on
« Last Edit: August 02, 2012, 03:11:26 PM by cyber.spirit » Logged

ICS Academy Network Security Certified
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #3 on: August 06, 2012, 10:13:24 AM »

There is also a pretty cool script written by g0tmi1k called fakeap that might be worth looking into...
Logged

OSWP | Hackingdojo Nidan | eCPPT
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.093 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.