Breaking News

How To Hack WiFi WEP/WPA/WPA2 Password Using Fluxion Tool [kali Linux]



Are you bored from searching always about How To Hack Wifi? Do you want to know how to hack wifi WEP/WPA/WPA2 Password using Fluxion Tool using Kali Linux OS? So today we will only talk about Hacking a Wifi Networking by the help of Kali Linux. So Keep Reading this Posts....
If don't know about Kali Linux / If you don't know How To Install Kali Linux? Click Here to Learn.



 How Fluxion Works Its Magic:  Fluxion is the future—a blend of technical and social engineering automation that trick a user into handing over the Wifi password in a matter of keystrokes. Specifically, it's a social engineering framework using an evil twin access point (AP), integrated jamming, and handshake capture functions to ignore hardware and focus on the "wetware."

Fluxion is a unique tool in its use of a WPA handshake to not only control the behavior of the login page, but the behavior of the entire script. It jams the original network and creates a clone with the same name, enticing the disconnected user to join. This presents a fake login page indicating the router needs to restart or load firmware and requests the network password to proceed. Simple as that.



"How To Capture WPA Passwords With Fluxion" 
 Step-1  Install Fluxion 

To get Fluxion running on our Kali Linux system, Type the Following Commands in your Terminal: (The First Link has broken, try the 2nd one)
git clone https://github.com/wi-fi-analyzer/fluxion
git clone https://github.com/FluxionNetwork/fluxion
 Note:  The developer of Fluxion shut down the product recently, but you can get an older version of it using the command above instead (not the URL you see in the image below).



Then, let's check for missing dependencies by navigating to the folder and starting it up for the first time. Enter the three Commands one by one:




You will likely see the following, where some dependencies will be needed.


Run the installer to fetch dependencies and set your board to green with; Enter the below Command:



A window will open to handle installing the missing packages. Be patient and let it finish installing dependencies.


After all the dependencies are met, our board is green and we can proceed to the attack interface. Run the Fluxion command again with sudo ./fluxion to get hacking.


 Step-2  Scan WiFi Hotspot

The first option is to select the language. Select your language by typing the number next to it and press enter to proceed to the target identification stage. Then, if the channel of the network you wish to attack is known, you may enter 2 to narrow the scan to the desired channel. Otherwise, select 1 to scan all channels and allow the scan to collect wireless data for at least 20 seconds.


A window will open while this occurs. Press CTRL+C to stop the capture process whenever you spot the wireless network that you want. It is important to let the attack run for at least 30 seconds to reasonably verify if a client is connected to the network.

 Step-3  Choose Your Target AP

Select a target with active clients for the attack to run on by entering the number next to it. Unless you intend to wait for a client to connect (possibly for a long time), this attack will not work on a network without any clients. Without anyone connected to the network, who would we trick into giving us the password?

 Step-4  Select Your Attack

Once you've typed the number of the target network, press enter to load the network profile into the attack selector. For our purpose, we will use option 1 to make a "FakeAP" using Hostapd. This will create a fake hotspot using the captured information to clone the target access point. Type 1 and press enter.

 Step-5  Get a HandShake 

In order to verify that the password we receive is working, we will check it against a captured handshake. If we have a handshake, we can enter it at the next screen. If not, we can press enter to force the network to provide a handshake in the next step.

 Must Read: 
Using the Aircrack-ng method by selecting option 1 ("aircrack-ng"), Fluxion will send deauthentication packets to the target AP as the client and listen in on the resulting WPA handshake. When you see the handshake appear, as it does in the top right of the screenshot below, you have captured the handshake. Type 1 (for "Check handshake") and enter to load the handshake into our attack configuration.

 Step-6  Create The Fake Login Page 

Select option 1, "Web Interface," to use the social engineering tool.


You will be presented with a menu of different fake login pages you can present to the user. These are customizable with some work, but should match the device and language. The defaults should be tested before use, as some are not very convincing.


1 chose an English language Netgear attack. This is the final step to arm the attack; At this point, you are ready to fire, so press enter to launch the attack. The attack spawns multiple windows to create a cloned version of their wireless network while simultaneously jamming the normal access point, enticing the user to join the identically named, but unencrypted, network.


 Must Read: 

 Step-7  Capture the Password

The user is directed to a fake login page, which is either convincing or not, depending on which you chose.

Entering the wrong password will fail the handshake verification, and the user is prompted to try again. Upon entering the correct password, Aircrack-ng verifies and saves the password to a text file while displaying it on the screen. The user is directed to a "thank you" screen as the jamming ceases and the fake access point shuts down.



You can verify your success by checking the readout of the Aircrack-ng screen.


Key captured and verified. The network is ours!


Congratulations, you've succeeded in obtaining and verifying a password, supplied by targeting the "wetware." We've tricked a user into entering the password rather than relying on a preexisting flaw with the security.

Warning: This Technique Could Be Illegal Without Permission

Legally, Fluxion combines scanning, cloning, creating a fake AP, creating a phishing login screen, and using the Aircrack-ng script to obtain and crack WPA handshakes. As such, it leaves signatures in router logs consistent with using these techniques. Most of these practices are illegal and unwelcome on any system you don't have permission to audit.

 Also Read: 
Help this Website to grow faster. Before you leave from here click on this ads. And support us!
Click on it

2 comments: