Skip to main content

How to Capture WPA Passwords with Fluxion

How to Capture WPA Passwords with Fluxion


Install Fluxion

To get Fluxion running on our Kali Linux system, clone the git repository with:
git clone =>https://github.com/wi-fi-analyzer/fluxion

Note: The developer of Fluxion shut down the product recently, but you can get an older version of it using the command above instead (not the URL you see in the image below).


Then, let's check for missing dependencies by navigating to the folder and starting it up for the first time.
cd fluxion
sudo ./fluxion



You'll likely see the following, where some dependencies will be needed.

Run the installer to fetch dependencies and set your board to green with:
sudo ./Installer.sh
A window will open to handle installing the missing packages. Be patient and let it finish installing dependencies.



After all the dependencies are met, our board is green and we can proceed to the attack interface. Run the Fluxion command again with sudo ./fluxion to get hacking.



Scan Wi-Fi Hotspots
The first option is to select the language. Select your language by typing the number next to it and press enter to proceed to the target identification stage. Then, if the channel of the network you wish to attack is known, you may enter 2 to narrow the scan to the desired channel. Otherwise, select 1 to scan all channels and allow the scan to collect wireless data for at least 20 seconds.


A window will open while this occurs. Press CTRL+C to stop the capture process whenever you spot the wireless network that you want. It is important to let the attack run for at least 30 seconds to reasonably verify if a client is connected to the network.

Choose Your Target AP


Select a target with active clients for the attack to run on by entering the number next to it. Unless you intend to wait for a client to connect (possibly for a long time), this attack will not work on a network without any clients. Without anyone connected to the network, who would we trick into giving us the password?



Select Your Attack

Once you've typed the number of the target network, press enter to load the network profile into the attack selector. For our purpose, we will use option 1 to make a "FakeAP" using Hostapd. This will create a fake hotspot using the captured information to clone the target access point. Type 1 and press enter.


Get a Handshake
In order to verify that the password we receive is working, we will check it against a captured handshake. If we have a handshake, we can enter it at the next screen. If not, we can press enter to force the network to provide a handshake in the next step.
Using the Aircrack-ng method by selecting option 1 ("aircrack-ng"), Fluxion will send deauthentication packets to the target AP as the client and listen in on the resulting WPA handshake. When you see the handshake appear, as it does in the top right of the screenshot below, you have captured the handshake. Type 1 (for "Check handshake") and enter to load the handshake into our attack configuration.



Create the Fake Login Page

Select option 1, "Web Interface," to use the social engineering tool.

You will be presented with a menu of different fake login pages you can present to the user. These are customizable with some work, but should match the device and language. The defaults should be tested before use, as some are not very convincing.



I chose an English language Netgear attack. This is the final step to arm the attack; At this point, you are ready to fire, so press enter to launch the attack. The attack spawns multiple windows to create a cloned version of their wireless network while simultaneously jamming the normal access point, enticing the user to join the identically named, but unencrypted, network.br/>

Capture the Password
The user is directed to a fake login page, which is either convincing or not, depending on which you chose.



Entering the wrong password will fail the handshake verification, and the user is prompted to try again. Upon entering the correct password, Aircrack-ng verifies and saves the password to a text file while displaying it on the screen. The user is directed to a "thank you" screen as the jamming ceases and the fake access point shuts down.

You can verify your success by checking the readout of the Aircrack-ng screen.

Congratulations, you've succeeded in obtaining and verifying a password, supplied by targeting the "wetware." We've tricked a user into entering the password rather than relying on a preexisting flaw with the security.
GOODLUCK

Comments

Popular posts from this blog

Samsung Galaxy S6 Edge Power On Off Key Button Switch Jumper Ways Smartphone Repairing

Samsung Galaxy S6 Edge Power On Off Key Button Switch Jumper Ways Smartphone Repairing Samsung Galaxy S6 Edge charging ok, flash ok, but not powering phone, this mean power button cut/line problem.So now follow simple power button jumper ways. Smartphone Repairing If you are facing an energy problem in Samsung Galaxy S6 Edge diagrams in this article can help. Continue with the following troubleshooting solutions and establish bridges necessary for the points that have been damaged. Samsung Galaxy S6 Edge Dead does not start Solution Samsung Galaxy S6 Edge keys Power Jumper Samsung Galaxy S6 Edge On Off Button Ways Samsung Galaxy S6 Edge power button point Trick damaged bridge. Trace point of damage to the meter or check off switch with a new one. We can check problem button to connect the phone to the charger with mobile entertainment indicator appears on the screen and pressing the power button, then this is a power button problem. See diagram and apply jumpers as diagram. Smar...

Samsung Galaxy Grand Neo I9060 Cell Phone Screen Repair Light Problem Solution Jumper Ways Smartphone Repairing

Samsung Galaxy Grand Neo I9060 Cell Phone Screen Repair Light Problem Solution Jumper Ways Smartphone Repairing This post is all about Samsung Galaxy Grand Neo I9060 fix phone screen problem solution. If mobile phone scree display is not working good or the screen light is not working. Samsung Galaxy Grand Neo I9060 cracked screen repair is only possible with phone screen replacement. But if the screen is not broken then replace phone screen is not required. Smartphone Repairing If Samsung Galaxy Grand Neo I9060 screen is blinking or dim light having blank scree. In all these case we have to disassemble the smart phone and check screen jack if there is any rust carbon or damages of screen jack pins.Samsung Galaxy Grand Neo I9060 phone repair tutorials are given in a few more posts so you can search other repairing problem solutions here. If screen jack have no any fault then the above mobile screen repair diagram will help you to find out tracks that are used in screen functi...

Samsung Galaxy J7 Prime Usb Charging Problem Solution Jumper Ways

Samsung Galaxy J7 Prime Usb Charging Problem Solution Jumper Ways Problem:- Samsung Galaxy J7 Prime usb charge solution, Samsung Galaxy J7 Prime usb not recognized not detected Diagnostic: – Plug the USB cable into the PC and phone jack, read the notifications on the screen phone recognized or not. Make sure you can save data to the memory card or not. Replace the USB data cable and try again. Replace the usb charger and try it again can charge it or not. Solution:- If you are facing a load problem in Samsung Galaxy J7 Prime and have tested all the above steps to solve this problem in it. Dismantle the phone and look at the phone for water and carbon damage. Clean it with an electronic cleaner and apply heat with a heat gun to dry it. Keep in mind the heat should not be over and much because it can harm your skin and damage the motherboard. So keep it in the normal stream and look at the parts carefully. Follow all these paths and components as shown in the diagram abov...