Kali Linux Password Wordlist

Rockyou wordlist is a password dictionary used to help to perform different types of password cracking attacks. It is the collection of the most used and potential passwords. Many Password cracking tools are used dictionary attack method, in this case, you will have a requirement of password wordlist. So Offensive Security has added already many dictionaries in Kali Linux by default, RockYou wordlist is one of the biggest dictionaries. Wordlists included with Kali are in /usr/share/wordlists. For example, here's how to use the rockyou password list: $ cd /usr/share/wordlists $ gunzip rockyou.txt.gz $ ls -lh rockyou.txt. Now you can use this with John the Ripper, Metasploit, Aircrack, etc.

Kali Linux Password Dictionary Location

a

Before starting the attack lets have a small introduction about WPA/WPA2 .

Cracking password hashes with a wordlist In this recipe, we will crack hashes using John the Ripper and the password lists. We will also work with a local shadow file from a Linux machine and we will try to recover passwords based off wordlists. If you don't want to use the default password.lst file of JohnTheRipper, just specify the path to the new file using the -wordlist argument: john -wordlist=password.lst protectedpdf.hash. As final recommendation, the tool offers to crack a lot of files, so you may want to read the documentation of the library.

What is WPA/WPA2

Wi-Fi Protected Access (WPA) and Wi-Fi Protected Access II (WPA2) are two security protocols and security certification programs developed by the Wi-Fi Alliance to secure wireless computer networks. The Alliance defined these in response to serious weaknesses researchers had found in the previous system, WEP (Wired Equivalent Privacy).
WPA became available in 2003. The Wi-Fi Alliance intended it as an intermediate measure in anticipation of the availability of the more secure and complex WPA2. WPA2 became available in 2004 and is a common shorthand for the full IEEE 802.11i (or IEEE 802.11i-2004) standard.
A flaw in a feature added to Wi-Fi, called Wi-Fi Protected Setup, allows WPA and WPA2 security to be bypassed and effectively broken in many situations. WPA and WPA2 security implemented without using the Wi-Fi Protected Setup feature are unaffected by the security vulnerability.

WPA2 has replaced WPA. WPA2, which requires testing and certification by the Wi-Fi Alliance, implements the mandatory elements of IEEE 802.11i. In particular, it includes mandatory support for CCMP, an AES-based encryption mode with strong security. Certification began in September, 2004; from March 13, 2006, WPA2 certification is mandatory for all new devices to bear the Wi-Fi trademark.

Requirements to start attack

  1. Kali Linux (Installed in virtual machine (or) as host).
  2. External WIFI card.
  3. A word-list containing passwords. (In kali you are having wordlist rockyou.txt which is located in /usr/share/wordlists)

Step 1

First we have to check our wifi card is connected with our device or not. To see that we have a command

ifconfig

Now you can see we are having wireless interface as wlan0 connected to our machine.

Step 2

To capture the packets of the wireless network we need to turn on our wifi card to monitering mode. To do that we have command

  • airmon-ng start [interface name]

airmon-ng start wlan0

Kill all the process/PID which can create problems while cracking.

  • kill [PID no.]

Step 3

Now we are in monitoring mode having interface wlan0mon. After entering into monitoring mode please check the interface name again to go further.

we can sniff the packets of the entire network and we can see how many accesspoints are around you. To do that

  • airodump-ng [present interface name]
Kali Linux Password Wordlist

airodump-ng wlan0mon

Step 4

Now you are having list of Wifi accesspoints around you , select the desired once you want to crack. To do that

  • airodump-ng -c [channel] –bssid [Target Mac] -w [file_name you want to save] [interface]

airodump-ng -c 1 –bssid FC:4A:E9:4B:01:8A -w 000 wlan0mon

Do not close this window because you will get handshake here.

Step 5

To crack the wifi password we need to have handshake i.e to connect any wifi router we need to exchange our key with the router to verify the Guinean user and if our key is correct we will get connected. Every time the user try to connect the exchange of keys take place and the process is called handshake.

Now we are going to take the advantage of this process . Only handshake happens when a user tries to connect to the route, as we can’t wait for the new user to connect .

we can disconnect the user already connected and those users who are disconnected tries to connect back to the route. In the mean time we can sniff handshake. To do this

  • aireplay-ng -0 [no.of packets] -a [accesspoint mac] [interface]

airreply-ng -0 1000 -a FC:4A:E9:4B:01:8A wlan0mon

It will send Deauth packets to the users and disconnect them don’t stop this process until you get the handshake.

Download Wordlists For Kali Linux

See we got the handshake. This handshake that we captured is saved in a file 000 that we have given in Step 4.

Step 6

The last and final step to get password . We are having a tool named Aircrack which will brute force the list of word-list password and tries to crack the wifi pin.

To crack the password using Aircrack

  • aircrack-ng [file containing handshake packets] -w [word-list containing passwords]

aircrack-ng 000.cap -w rockyou.txt

Sucessfully Cracked the wifi password.

Kali Linux Username And Password Wordlist

Note: This method only works when you are having correct password in your word-list. If you are not having correct password in your word-list file then this attack is of no use.

This article is only for Educational purpose , I am not responsible for any illegal activities. Do not break into devices that you don’t have permission.
If you think this article is helpful please let me know on the comments below. And Share as much as possible. Thank you 🙂