Showing posts with label Wireless. Show all posts
Showing posts with label Wireless. Show all posts

Tìm Kiếm Mã PIN Router Trực Tuyến - Search PIN Wifi Router Online

Tìm Kiếm Mã PIN Router Trực Tuyến
Search PIN Wifi Router Online


Công cụ dò tìm mã PIN router trực tuyến tại


Sử dụng công cụ Hydra để Hack Router Password

Mở Terminal lên và gõ xhydra và Enter


Sau đó sẽ xuất hiện một cửa sổ giao diện. Tại đây, ở tab Target, bạn chọn

  • Single Target:  Nhập vào địa chỉ IP của Router (thông thường thì có IP là 192.168.1.1 hoặc 192.168.0.1)
  • Protocol: Chọn tùy chọn http-get
  • Port: 80





Chuyển sang tab Passwords

  • Username: Admin hoặc bạn có thể chọn Username list để chọn file chứa các tên User có sẵn
  • Password: Tất nhiên bạn sẽ chọn Password List để cung cấp cho chương trình file từ điển có chứa sẵn Password (giống như phương pháp Hack Password Wifi bằng cách dò mật khẩu thông qua từ điển)



Bây giờ nhấn vào tab Start để bắt đầu. Sau khi dò được UsernamePassword sẽ được hiển thị như trong hình





10 Most Popular Password Cracking Tools

A password is the secret word or phrase that is used for the authentication process in various applications. It is used to gain access to accounts and resources. A password protects our accounts or resources from unauthorized access.
What is Password Cracking?
Password cracking is the process of guessing or recovering a password from stored locations or from data transmission system. It is used to get a password for unauthorized access or to recover a forgotten password. In penetration testing, it is used to check the security of an application.
In recent years, computer programmers have been trying to create algorithms for password cracking in less time. Most of the password cracking tools try to login with every possible combination of words. If login is successful, it means the password was found. If the password is strong enough with a combination of numbers, characters and special characters, this cracking method may take hours to weeks or months. A few password cracking tools use a dictionary that contains passwords. These tools are totally dependent on the dictionary, so success rate is lower.
In the past few years, programmers have developed many password cracking tools. Every tool has its own advantages and disadvantages. In this post, we are covering a few of the most popular password cracking tools.
1. Brutus
Brutus is one of the most popular remote online password cracking tools. It claims to be the fastest and most flexible password cracking tool. This tool is free and is only available for Windows systems. It was released back in October 2000.
It supports HTTP (Basic Authentication), HTTP (HTML Form/CGI), POP3, FTP, SMB, Telnet and other types such as IMAP, NNTP, NetBus, etc. You can also create your own authentication types. This tool also supports multi-stage authentication engines and is able to connect 60 simultaneous targets. It also has resume and load options. So, you can pause the attack process any time and then resume whenever you want to resume.
This tool has not been updated for many years. Still, it can be useful for you.
2. RainbowCrack
RainbowCrack is a hash cracker tool that uses a large-scale time-memory trade off process for faster password cracking than traditional brute force tools. Time-memory trade off is a computational process in which all plain text and hash pairs are calculated by using a selected hash algorithm. After computation, results are stored in the rainbow table. This process is very time consuming. But, once the table is ready, it can crack a password must faster than brute force tools.
You also do not need to generate rainbow tablets by yourselves. Developers of RainbowCrack have also generated LM rainbow tables, NTLM rainbow tables, MD5 rainbow tables and Sha1 rainbow tables. Like RainbowCrack, these tables are also available for free. You can download these tables and use for your password cracking processes.
Download Rainbow tables here: http://project-rainbowcrack.com/table.htm
A few paid rainbow tables are also available, which you can buy from here: http://project-rainbowcrack.com/buy.php
This tool is available for both Windows and Linux systems.
Download Rainbow crack here: http://project-rainbowcrack.com/
3. Wfuzz
Wfuzz is another web application password cracking tool that tries to crack passwords with brute forcing. It can also be used to find hidden resources like directories, servlets and scripts. This tool can also identify different kind of injections including SQL Injection, XSS Injection, LDAP Injection, etc in Web applications.
Key features of Wfuzz password cracking tool:
  • Capability of injection via multiple points with multiple dictionary
  • Output in colored HTML
  • Post, headers and authentication data brute forcing
  • Proxy and SOCK Support, Multiple Proxy Support
  • Multi Threading
  • Brute force HTTP Password
  • POST and GET Brute forcing
  • Time delay between requests
  • Cookies fuzzing
4. Cain and Abel
Cain and Abel is a well-known password cracking tool that is capable of handling a variety of tasks. The most notable thing is that the tool is only available for Windows platforms. It can work as sniffer in the network, cracking encrypted passwords using the dictionary attack, recording VoIP conversations, brute force attacks, cryptanalysis attacks, revealing password boxes, uncovering cached passwords, decoding scrambled passwords, and analyzing routing protocols.
Cain and Abel does not exploit any vulnerability or bugs. It only covers security weakness of protocols to grab the password. This tool was developed for network administrators, security professionals, forensics staff, and penetration testers.
Download here: http://www.oxid.it/ca_um/
5. John the Ripper
John the Ripper is another well-known free open source password cracking tool for Linux, Unix and Mac OS X. A Windows version is also available. This tool can detect weak passwords. A pro version of the tool is also available, which offers better features and native packages for target operating systems. You can also download Openwall GNU/*/Linux that comes with John the Ripper.
Download John the Ripper here: http://www.openwall.com/john/
6. THC Hydra
THC Hydra is a fast network logon password cracking tool. When it is compared with other similar tools, it shows why it is faster. New modules are easy to install in the tool. You can easily add modules and enhance the features. It is available for Windows, Linux, Free BSD, Solaris and OS X. This tool supports various network protocols. Currently it supports Asterisk, AFP, Cisco AAA, Cisco auth, Cisco enable, CVS, Firebird, FTP, HTTP-FORM-GET, HTTP-FORM-POST, HTTP-GET, HTTP-HEAD, HTTP-PROXY, HTTPS-FORM-GET, HTTPS-FORM-POST, HTTPS-GET, HTTPS-HEAD, HTTP-Proxy, ICQ, IMAP, IRC, LDAP, MS-SQL, MYSQL, NCP, NNTP, Oracle Listener, Oracle SID, Oracle, PC-Anywhere, PCNFS, POP3, POSTGRES, RDP, Rexec, Rlogin, Rsh, SAP/R3, SIP, SMB, SMTP, SMTP Enum, SNMP, SOCKS5, SSH (v1 and v2), Subversion, Teamspeak (TS2), Telnet, VMware-Auth, VNC and XMPP.
Download THC Hydra here: https://www.thc.org/thc-hydra/
If you are a developer, you can also contribute to the tool’s development.
7. Medusa
Medusa is also a password cracking tool similar to THC Hydra. It claims to be a speedy parallel, modular and login brute forcing tool. It supports HTTP, FTP, CVS, AFP, IMAP, MS SQL, MYSQL, NCP, NNTP, POP3, PostgreSQL, pcAnywhere, rlogin, SMB, rsh, SMTP, SNMP, SSH, SVN, VNC, VmAuthd and Telnet. While cracking the password, host, username and password can be flexible input while performing the attack.
Medusa is a command line tool, so you need to learn commands before using the tool. Efficiency of the tool depends on network connectivity. On a local system, it can test 2000 passwords per minute.
With this tool, you can also perform a parallel attack. Suppose you want to crack passwords of a few email accounts simultaneously. You can specify the username list along with the password list.
Download Medusa here: http://www.foofus.net/jmk/tools/medusa-2.1.1.tar.gz
8. OphCrack
OphCrack is a free rainbow-table based password cracking tool for Windows. It is the most popular Windows password cracking tool, but can also be used on Linux and Mac systems. It cracks LM and NTLM hashes. For cracking Windows XP, Vista and Windows 7, free rainbow-tables are also available.
A live CD of OphCrack is also available to simplify the cracking. One can use the Live CD of OphCrack to crack Windows-based passwords. This tool is available for free.
Download OphCrack here: http://ophcrack.sourceforge.net/
Download free and premium rainbow tables for OphCrack here: http://ophcrack.sourceforge.net/tables.php
9. L0phtCrack
L0phtCrack is an alternative to OphCrack. It attempts to crack Windows password from hashes. For cracking passwords, it uses Windows workstations, network servers, primary domain controllers, and Active Directory. It also uses dictionary and brute force attacking for generating and guessing passwords. It was acquired by Symantec and discontinued in 2006. Later L0pht developers again re-acquired it and launched L0phtCrack in 2009.
It also comes with a schedule routine audit feature. One can set daily, weekly or monthly audits, and it will start scanning on the scheduled time.
10. Aircrack-NG
Aircrack-NG is a WiFi password cracking tool that can crack WEP or WPA passwords. It analyzes wireless encrypted packets and then tries to crack passwords via its cracking algorithm. It uses the FMS attack along with other useful attack techniques for cracking password. It is available for Linux and Windows systems. A live CD of Aircrack is also available.
If you want to use AirCrack NG for password cracking, read tutorials here: http://www.aircrack-ng.org/doku.php?id=getting_started
Download AirCrack-NG here: http://www.aircrack-ng.org/
How to create a password that is hard to crack
In this post, we have listed 10 password cracking tools. These tools try to crack passwords with different password cracking algorithms. Most of the password cracking tools are available for free. So, you should always try to have a strong password that is hard to crack by these password cracking tools. These are few tips you can try while creating a password.
The longer the password, the harder it is to crack: Password length is the most important factor. If you select a small password, password cracking tools can easily crack it by using few words combinations. A longer password will take a longer time in guessing. You’re your password at least 8 characters long.
Always use a combination of characters, numbers and special characters: This is another thing which makes passwords hard to crack. Password cracking tools try the combination of one by one. Have a combination of small characters, capital letters, and special characters. Suppose if you have only numbers in your password. Password cracking tools only need to guess numbers from 0-9. Here only length matters. But having a password combination of a-z, A-Z, 0-9 and other special characters with a good length will make it harder to crack. This kind of password sometimes takes weeks to crack.
Variety in passwords: One important thing you must always take care. Never use same password everywhere. Cyber criminals can steal passwords from one website and then try it on other websites too.
In case you are not sure about the strength of your password, you can check it from variety of online tools available for free. Try this official Microsoft Tool for checking the password strength.
What to avoid while selecting your password
There are a few things which were very common a few years back and still exist. Most of the password cracking tools start from there. Passwords that fall into this category are most easy to crack. These are the few password mistakes which you should avoid:
  • Never use a dictionary word
  • Avoid using your pet’s name, parent name, your phone number, driver’s license number or anything which is easy to guess.
  • Avoid using passwords with sequence or repeated characters: For Ex: 1111111, 12345678 or qwerty, asdfgh.
  • Avoid using passwords that fall in worst password list. Every year, data analysis companies publish the list of worst passwords of the year from analyzing the leaked password data.
    The top 11 worst passwords of 2012:
    • password
    • 123456
    • 12345678
    • abc123
    • qwerty
    • monkey
    • letmein
    • dragon
    • 111111
    • baseball
    • iloveyou
The list for 2013 is yet to be published.
Conclusion:
The password is what makes your network, web accounts and email accounts safe from unauthorized access. These password cracking tools are proof that your passwords can be cracked easily if you are not selecting good passwords. In the article, we have listed every kind of password cracking tools, including web application password cracking tools, network password cracking tools, email password cracking tools, Windows password cracking tools and Wi-Fi password cracking tools. Security researchers use these tools to audit the security of their apps and check how to make their application secure against these tools. Cyber criminals also use these tools, but for wrong purposes. They use these password cracking tools to crack passwords of users and then access their data.
Now it is up to you. You can either use these tools for good work or bad. Although we never encourage using any educational information for any cyber crime. This post is only for educational purposes. If you are using any of these tools for cyber crimes, the author or website publishing the article will never be responsible. Learn things to know how you can be hacked and how to protect yourself.

Hack mật khẩu wifi không cần từ điển.

Với phương pháp này bạn không cần tải bất cứ file từ điển nào từ trên mạng nữa. Bởi vì máy tính sẽ tự tạo ra các password để tìm kiếm trong file *.cap của bạn. Tuy nhiên, đối với phương pháp này, bạn cần có 1 CPU thật mạnh thì thời gian hack mới diễn ra nhanh chóng được.



crunch 8 12 abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 | aircrack-ng --bssid XX:XX:XX:XX:XX:XX-w- 'đường dẫn file *.cap'


  • 8 là số ký tự tối thiểu của mật khẩu.
  • 12 là số ký tự tối đa của mật khẩu.
  • XX:XX:XX:XX:XX:XX là địa chỉ MAC của wifi cần hack nằm trong gói handshake (file *.cap).

Hack wifi bằng phần mềm chuyên dụng trong Kali Linux

Bước 1: Mở Terminal lên và gõ vào wifite để chạy chương trình hack wifi

Bước 2: Đợi cho chương trình quét các mạng wifi nằm trong phạm vi (khoảng 1-2 phút)
Bạn lưu ý tới những mạng wifi có chữ WPS và có nhiều Client truy cập.


B3: Nhấn tổ hợp phím Ctrl+C để dừng quét mạng và sau đó nhấn số thứ tự của mạng wifi bạn muốn hack
Nếu bạn muốn hack nhiều mạng cùng lúc thì số_thứ_tự_1, số_thứ_tự_2, số_thứ_tự_3,....
Nếu bạn muốn hack tất cả các mạng wifi thi gõ vào All.



Bước 4: Ngồi đợi chương trình hack.


Các cách hack wifi của Hacker

Ngày nay hầu hết các thiết bị phát wifi đều đã hỗ trợ chuẩn bảo mật mới hơn, cao cấp hơn là WPA và WPA 2 có tính bảo mật cao hơn rất nhiều. Gần như không ai có thể khai thác được bất kỳ lỗ hổng nào trong cơ chế mã hoá này để tìm ra mật khẩu chính xác từ những gói tin thu thập được trên mạng nội bộ không dây. Tuy nhiên giới hacker không bao giờ chịu bó tay, khi không tìm được lỗ hổng ở cơ chế mã hoá, họ lại tìm ra cách khai thác kẽ hở từ phía người sử dụng. Hiện nay đã có khá nhiều phương thức giúp người khác có thể dò ra mật khẩu wifi nhà bạn, từ đó họ có thể xâm nhập hệ thống mạng nội bộ, lây nhiễm virus ra các máy tính, đánh cắp password của các tài khoản trực tuyến hay phá hoại dữ liệu có trong thiết bị.


Nếu như hack mật khẩu của wifi sử dụng bảo mật chuẩn WEP chỉ dùng một phương pháp đơn giản là chuyển card wifi thành chế độ mornitor, đánh cắp các gói tin được truyền tải giữa Access Point và Client rồi dùng một phần mềm chuyên dụng để tìm ra key mã hoá (chính là password) thì để tìm ra chìa khoá tiến vào mạng không dây sử dụng bảo mật chuẩn WPA và WPA 2 khó hơn nhiều. Hiện nay giới hacker thường dùng 4 phương pháp sau:

Dictionary attack: Sử dụng một cuốn từ điển chứa các loại password thông dụng như tên người, ngày tháng năm sinh… có dung lượng cực lớn để “ướm” thử vào wifi cần thâm nhập. Cách này thường được gọi là “xổ số kiến thiết” do khả năng thành công không cao, nếu như mật khẩu của người dùng không nằm trong dictionary thì vô phương tìm ra.

Bruteforce attack: Có nét tương đồng với cách hack wifi bảo mật chuẩn WEP ở trên khi biến card wifi thành một dạng mornitor để theo dõi các tệp tin trao đổi trong mạng, thu thập chúng rồi tiến hành phân tích từ đó dò ra password. Phương thức này đảm bảo là sẽ tìm ra mật khẩu, tuy nhiên thời gian chạy có thể kéo dài từ vài tiếng tới vài ngày, vài tháng, thậm chí vài năm tuỳ thuộc vào cấu hình máy và độ phức tạp của mật khẩu.


RAT + Wirelesskeyview combo attack: Sử dụng phẩm mềm gián điệp tương tự như Keylog để trộm mật khẩu do người dùng gõ vào sau đó gửi lại cho hacker. Bên cạnh việc lấy password, RAT còn cho phép kẻ sử dụng điều khiển máy của nạn nhân để làm nhiều tác vụ khác, ví dụ như làm bot, nơi trung gian chuyển tiếp phát tán virus…

Rogue Access Point attack: Cách thức hoạt động của phương pháp này rất đơn giản, không tốn nhiều công sức nhưng đòi hỏi hacker phải là người am hiểu về mạng. Cụ thể hơn, kẻ lạ sẽ dùng máy tính hoặc một router phát ra tín hiệu wifi giả mạo có tên giống như bản chính. Khi người dùng không cẩn thận chọn nhầm, Access Point giả sẽ yêu cầu nhập lại mật khẩu, sau đó tất nhiên là hacker sẽ nhận được password của bạn.

Hướng dẫn hack wifi chuẩn mã hóa WPA/WPA2 bằng phương pháp "Dò từ điển password"


B1: Mở Terminal lên (nằm ở góc trải trên của màn hình, có biểu tượng màn hình đen bên trong có 2 ký tự ">_")


B2: Gõ vào wifite

Tạo USB live Kali Linux hoặc Backtrack

B1: Gắn USB vào máy, sao lưu tất cả dữ liệu trong USB vì quá trình tạo USB live sẽ format lại USB.

B2: Tải chương trình tạo USB live tại đây.
Download
Click to begin
4.5MB .exe


B3: Mở chương trình tạo USB live được giống như hình bên dưới.


B4: Thiết lập các thông số cho chương trình để tạo USB live.
  • STEP 1: CHOOSE YOUR KEY
        - Chọn USB cần đặt Kali Linux hay Backtrack.

  • STEP 2: CHOOSE A SOURCE
        - Click vào hình thứ nhất (ISO / IMG / ZIP) và chọn đường dẫn đến nơi chưa tập tin ISO của Kali Linux hoặc Backtrack.
        - Đợi vài phút chờ chương trình kiểm tra file ISO xem có lỗi hay không và lựa chọn kiểu boot phù hợp với hệ điều hành bạn muốn cài đặt (Phần này chương trình sẽ làm bạn chỉ cần đợi).

  • STEP 3: PERSISTENCE
        - Bước này bỏ qua vì chương trình chỉ có 1 chức năng là tạo chế độ Live Mode cho USB của bạn.

  • STEP 4: OPTIONS
     Chỉ cần tick chọn ô thứ hai hoặc cũng có thể tick chọn cả 3 ô.
        - Ô thứ nhất: Hide created files on key - Ẩn tất cả các file cần thiết để cài hệ điều hành trên USB của bạn.
        - Ô thứ hai: Format the key in FAT32 (this will erase your data !!)  - Định dạng USB của bạn theo chuẩn FAT32 (tuỳ chọn này sẽ xóa dữ liệu của bạn !!).
        - Ô thứ ba: Enable launching LinuxLive in Windows (requires internet to install)  - Cho phép chạy LinuxLive trong Windows (cần có internet để cài đặt).

  • STEP 5: CREATE
        - Click vào hình tia sét để bắt đầu cài đặt Kali Linux (hoặc Backtrack) lên USB. Sau đó ngồi đợi cho chương trình hoàn tất.


Như thế là bạn đã có USB live rồi đấy!

Điều kiện cần phải có để hack wifi

- Về phần cứng:
+ 1 USB (tối thiểu 4GB)


+ 1 Máy tính có card mạng tương thích với chương trình hack (cái này ad nghĩ chắc ai muốn hack cũng đủ điều kiện, vì phần mềm tương thích tương đối nhiều :v)



- Về phần mềm:
+ Hệ điều hành Kali linux 1.0.5
Download

Click to begin

2.4GB .iso

hoặc tải bằng torrent
Download

Click to begin

195KB .torrent



+ Nếu bạn không thích hệ điều hành Kali linux bạn có thể sử dụng hệ điều hành Backtrack 5 r3
Download

Click to begin

195KB .torrent




P/S: Nên sử dụng hệ điều hành Kali linux 1.0.5 vì hệ điều hành này được xem là phiên bản Backtrack 6, được tích hợp rất nhiều công cụ bảo mật nổi tiếng và thêm 1 số công cụ mà Backtrack không có.