Showing posts with label Protection. Show all posts
Showing posts with label Protection. Show all posts

Top 5 Useless Apps for Android

Top 5 Useless Apps for Android

Android is a mobile operating system developed by Google and we Android users are blessed with 2.8 million apps to choose from . Android Apps Development is the hot trend in the tech world right now. The User Interface and function of the various Android Apps really took the entire smart phone world by storm.But there also exist some apps which are just pointless.
So,here is the list of Top 5 Useless Applications for Android that are totally useless and un-productive.Lets see.

 Top 5 Useless Apps for Android

1.Useless Button
Tired of awesome productivity apps ? Try this one and turn pleasure of Android into pain for free! When you open up the app,a button is displayed and you have to keep clicking the button all day long .A completly useless and pointless button.
Check it out on Play Store :


2.ayy lmao
When you open this app, and click on it the bunch of aliens starts dancing.Thats it. It completely changed my life. I got a new job, I feel more awaken and happy. Haha,Just Kidding.This is a Completely pointless app.
Check it out on Play Store :


3.Amethyst
Some of you are familiar with this app but just in case,if you don't know about this then let me tell you that this is the most costly app in the Google Play Store that does absolutely nothing except showing the world how rich you are!
Check it out on Play Store if you haven't already:


4.Fan cooler
An app which only takes up your phone space and when opening it up the fan is being displayed which does nothing but spin , made to trick that you are actually feeling air out of it.
Check this out on Play Store :


5.Clean Master
Didn't expected this people? Lets face it.

I remember in my old Motorola Cliq days from Android 1.5 Cupcake to custom 2.3 Gingerbread Rom's ,It was used to be a minimal app that let you clean out your junk and give your device more space but what happened is, now not only it tooks a health amount of size from your storage but tries to do everything by adding a bunch of pointless, useless features that actually do more harm than good which includes an antivirus, boost RAM functionality & task killer functions(which doesn't really work).It is highly recommended to uninstall these type of apps.

How To Track a Cell Phone

Are you looking to know how to track a cell phone with pin point accuracy? Do you need to exactly know where your child or employees are moving around during your absence? If so you have come to the right place. In this article I will let you know some of the possible methods to GPS track a cell phone in simple steps.

1. Track a Cell Phone That’s Not Yours


If you need to track someone else’s phone such as your children or employees, you can simply use a cell phone tracking app such as mSpy Premium. This is a very small app that can be installed in just a few simple steps and takes only 2-3 minutes to complete. Once installed the app stays hidden on the phone but keeps track of every activity on the phone including its GPS location, Call Logs, Text Messages and more.

 Track a Cell Phone with mSpy
download


Track a Cell Phone with mSpy

How Tracking Works?

  • You will have to download and install the tracking app onto the target phone of whose location and activities you want to track.
  • Installation takes only a few minutes during which you should have the target phone in your hand.
  • Once the installation is complete, the tracking process will begin immediately and the recorded logs are silently uploaded to your online account as shown in the demo below.
  • You can login to your secure online account at any time to view the logs containing GPS location, Calls, Phone Contacts, Text Messages and more.

Watch mSpy Premium Demo

You can take a look at the live demo of mSpy in action from the following link: 


mSpy Premium Features:

  • 100% Stealth Tracking: This app runs in invisible mode and hides itself from the target phone user.
  • GPS Location Tracking: GPS positions are uploaded at a time interval you select with a link to the map.
  • Track Text Messages & Emails: Every text message sent and received including SMS and emails are logged even if the phone logs are deleted.
  • Call Logs: Each incoming and outgoing number on the phone is logged along with duration, date and time stamp.
  • Phone Contacts: Get access to complete contact list on the target phone.
  • Browser History: All websites visited on the phone are logged.
  • Social Networking & Messenger Activity: All social media activity such as Facebook, Twitter, LinkedIn, WhatsApp, Skype, iMessages, Instagram and many more are recorded.

You can download mSpy Premium from the link below:


Supported Phones: Android, iPhone, iPad and Tablets.

2. Tracking a Lost Cell Phone

Now, let us look at some of the possible options to track a phone in case if it is lost or stolen.

For Android Phones:

If you need to track a lost android phone, you can follow the steps mentioned below:
 Android Device Manager


Android Device Manager

  • Download Android Device Manager from Google play store and install it on another android device. This app lets you track your stolen android phone and also lets to remotely lock or erase all the data on it.
  • From “Android Device Manager” log into your Google account using the same ID associated with your lost phone. After successful login this app will attempt to locate your device and show its last known location on the map.
  • In addition, you will also be able to perform several actions on your lost phone such as give a Ring, Lock the device or Erase all the data stored on it.

For Apple iPhones:

If you need to track a lost iPhone, you can follow the steps mentioned below:

 Apple Icloud

  • Login to the iCould Website using an Apple ID associated with your lost phone. Since location tracking is turned on by default on all iPhone devices, iCould lets you track it from your web browser or your iPad and shows its location on the map.
  • When your phone is found nearby to your location you have an option to Play Sound on it so that your iPhone will emit a sound, helping you track it down.
  • If this does not help, you can choose the option Lost Mode which will remotely lock your phone down and display a phone number that can be reached at.
  • When none of the above options work, you can finally decide to go with the option Erase iPhone which will completely wipe out all the data stored on it. This way you can prevent your private information from falling into the wrong hands.

For Windows Phones:

In order to track down a lost Windows phone, you can try the below mentioned steps:

 Track Windows Phone

Track Windows Phone
  • Go to Windows Phone Website and locate the option Find My Phone on the top-right corner of the page.
  • This will ask you to sign-in using your Windows account associated with your lost phone. If your phone gets traced you will see a map showing its exact location. You will also find options to Lock, Ring and Erase its data in case if your phone is found to be completely lost.
Keep Visit, And Keep Sharing☺

How To Hide Your Ip Address Online

How to Hide Your IP Address Online? 

 Hide Ip Address Online

Following are some of the most common ways to hide IP address on the Internet:

1. Using a VPN Proxy – Safe and Secure Way to Hide IP

Using a trusted VPN proxy service is by far the best way to conceal your IP address online. Here is a list of most popular VPN services that will hide your IP address:

1. Hide My Ass VPN – Hide My Ass is one of the most popular and trusted VPN service that allows people to easily conceal IP address and protect their online privacy.

2. VyprVPN – VyprVPN offers the world’s fastest VPN services that allows people to easily conceal their real IP.

Advantages of using a VPN to hide your IP address:
  1. In addition to hiding your IP, a VPN is very fast, offers high performance and encrypts all your web traffic to keep you safe from hackers and intruders.
  2. You have a long list of countries and states to select your desired IP address location.
  3. By selecting an IP address of your choice, a VPN allows you to easily access restricted websites that are not available for your country.

Why Hide IP Address?

Following are some of the reasons why people want to hide their IP address:
  1. By hiding the IP address, one can browse anonymously.
  2. To access or unblock websites that are not available to the IP address of a particular Geo location.
  3. To stay safe from hackers by showing a fake IP to the outside world while keeping real IP concealed.
  4. Hiding IP means hiding Geo location.
  5. Hiding IP prevents leaving a digital footprint.

2. Web Based Proxies

This is another popular way to quickly hide IP address on the Internet. Following are some of the popular web based proxies to conceal your IP address:
The downside of using these free web based proxy servers to mask your IP address is that most of them are overloaded and are too slow to use. In addition, your security and privacy may get compromised during the usage.

What is the Best Way to Hide IP Address?

I have made a sincere attempt to present you with all available options to hide your IP address. If you only want to conceal your IP address for a specific amount of time and are not concerned with the security and performance, go for the free web based proxy services.
On the other hand, if you have the necessity to hide IP address on a regular basis, need high security and performance, go for paid VPN services like Hide My Ass or VyprVPN.

How to Ensure Your IP Change?

To make sure your IP is changed, just type ‘my IP address’ on Google before and after using any of the above services. Just compare both the IP addresses and make sure they are different. If yes, that means you have successfully changed your IP so that your real IP address is hidden from public.
Thanks For Visit, Keep Sharing.

What is spyware ? how it comes to your Pc? Prevent it

What is spyware ? how it comes to your Pc? Prevent it

Often you can heard a word spyware. Is it important to know about spyware ? Yes!
We are in advanced technology world. Day by day the technology is developing. At the same time crime is also increasing. One of the crime is spyware method.

Spyware:

Spywareis software that resides on a computer and sends information to its creator. That information may include surfing habits, system details or, in its most dangerous form, passwords and login information for critical applications such as online banking. Many spyware programs are more annoying than dangerous, serving up pop-up ads or gathering e-mail addresses for use inspamcampaigns. Even those programs, however, can cost you valuable time and computing resources.
According to a number of sources, the first use of the term spyware occurred in a 1994 posting that made light of Microsoft’s business model. Later, the term was used to describe devices used for spying, such as small cameras and microphones. In 2000, a press release from security software provider Zone Labs used the current meaning of spyware for the first time and it’s been used that way ever since.

How it comes to ur pc


Often, spyware comes along with a free software application, such as a game or a supposed productivity booster. Once it’s downloaded to your computer, the functional element of the software works exactly as promised, while the information-gathering system sets up shop behind the scenes and begins feeding your personal data back to headquarters.

Internet security
The Best way to avoid and remove spywares is installing a best internet security software or spyware remover softwares. Get a original internet security and update it properly. Scan daily your pc using internet security while scanning you better to avoid doing other things in your pc. My advice is use KASPERSKY INTERNET SECURITY for better security.
other than internet security, you prevent your system from getting infect. Be careful when you download files from websites and mail.



Thanks For Visit, Keep Sharing.

How To Protect Your USB Drive From Virus

How To Protect Your USB Drive From Virus by Using Dummy File

Major Problem: 

The main source which cause to spread the virus is our Pen Drive other than the Internet.  When we insert our Pen drive in any other system, the malicious softwares(worm,virus,…) will copy them itself to your folder.  No matter whatever you do,you can not stop the infection of malicious softwares when insert your pen drive in infected system.

How to prevent that?

So Here is simple and most effective Hack to protect your Pen drive from infection.
      The main concept of this trick is to fill the Pen drive space with file so that no other files(malicious softwares) can not be to your Pen Drive. 
To fill the Pen drive space what you need to do,  are you need to copy the lot of files to your pen Drive?  or copy a big size file?
The answer is that you don’t need to above things in order to fill the Pen drive Space.  At the same time you can not fill the Pen drive space completely. 

Then What should you do?

 Follow my steps:
Step 1:
Download this file.
Step 2:
Extract the zip file.  There will be a file “usbdummyprotect.exe”.  Copy the file to your USB.
Step 3:
Whenever you bring your pen drive to outside place click the EXE file.  It will create a dummyfile.txt
USB Dummy Protect

 USB Dummy Protect

The dummyfile.txt will occupy the Pen drive memory.  So it will  prevent from virus copied to your Pen drive.   If you like to un infected files to your pen drive then deltete the dummyfile.txt
Thanks For Visit, Keep Sharing.

Things you should know wireless hacking basics

Things You Should Know: Wireless Hacking basics

Pre-requisites

You should know-
  • Nothing really.

Post-reading

You will know - 
  • What are the different flavors of wireless networks you'll encounter and how difficult it is to hack each of them.
  • What are hidden networks, and whether they offer a real challenge to a hacker.
  • You'll have a very rough idea how each of the various 'flavors' of wireless networks is actually hacked.
(The last point would be covered in details in the next post)
 

Wireless Security Levels

Below is a (bad but hopefully helpful) analogue I'm using to explain various possible security implementations that a wireless network may have.
Suppose you are the owner of a club. There can be many possible scenarios as far as entry to the club is concerned :-

 
  • Open Entry

     Open entry and unrestricted usage
    Open networks- They don't require passwords to
    connect to the wireless router (access point).
    1. Open entry and unrestricted usage - Anyone can walk right in. They have unrestricted access to the dance floor, free beer, etc.
      This is open network. This is only used in public places (restaurants, etc.) which offer free Internet access to it's users (WiFi hotspots) . It's fairly uncommon to find such networks.
    2.  Open entry but restricted usage - Anyone can walk right in, but have to pay for drinks. For the router's security purposes, this is also an open network. However, connecting to the wireless router (entering the club) doesn't guarantee you unlimited access to the internet. There is another layer of authentication. These are seen in public places (airports, restaurants, fast food joints, shopping malls) where they let you connect to the wireless network without any password, but after that you have an additional layer between you and the internet. This layer usually restricts your ability to access the internet (either by bandwidth or by time). This layer can be used to charge you for the amount of data you use.
 The point to note in the discussion above is that wireless hacking usually refers to cracking the router's password. The additional layer which might be present between you and the internet after you login is something you'll have to deal with separately, and is not covered under wireless hacking. So, from wifi hacking perspective, both the networks above are the same, "open", and do not require any hacking. 


 
  • Stupidly Guarded Entry (WEP)

     Stupidly Guarded Entry (WEP)
    ISPs may require users to login to
    their accounts to access the internet.
     Colleges often allocate student's IDs and passwords using which students can access Internet facilities offered by the institute.
    Colleges often allocate student's IDs and
    passwords using which students can access
    Internet facilities offered by the institute.
     
    1. Password at door and unrestricted access - The member of the club pay a certain amount every month, and get access to free drinks. They have to say the password at the shady looking entrance to the club. Unfortunately, it's quite easy for anyone to overhear the password and get in. This is WEP protected network. For a person who has Kali Linux installed on his machine, hacking this kind of wireless network is a matter of minutes. These are easy targets. However, nowadays it's fairly uncommon to find WEP protected networks, because of the ease with which they can be hacked into. WPA and WPA-2 are more common. 
    2. Password at door but restricted access - Only members can enter, but they still have to pay for their drinks. This is the case when the network has password and an additional layer to get access to the internet. This is common in two cases - 
      1. ISP requires login - Many ISP's require users to login to their account to access the internet. Often logging in provides an interface which lets the users see their bandwidth usage, details of their network plan, etc.
      2. Colleges/ Schools/ Offices - Many institutes provide users accounts which they use to access the institutes' network.  
Again, from the wireless hacking perspective,both the networks above are "WEP protected", and are rather simple to hack into.
  • Well Guarded Entry

    As far as the bifurcation into whether or not another layer of authentication is present once you have the wireless network password is concerned, WEP and WPA cases are the same. The only difference is that the college wireless routers have WPA instead of WEP (as a matter of fact, the two images in the section above are from my home network tikona and my college network, and both are WPA protected. Of course the login screen would be no different if the router was configured to be WEP protected, as these are two independent authentication steps, and so I included those images in WEP section). Thus, this doesn't merit further discussion. However, there's another subcategory in this that we will discuss.
     
    1. Fingerprint and retinal scan for entry - The entry to this club is secure enough for most purposes. Getting past this level of security takes a lot of time and efforts. Theoretically, if you're willing to do what it takes, you may still get it. But a heist (if I may call it that) of this magnitude will take a lot of planning, and even then, a lot depends on sheer luck. This is WPA secure network. The only way to crack this network with dictionary or bruteforce attacks. Bruteforce attacks may take forever (literally) depending on the length of the password, and dictionary attacks too will take days/weeks depending on size of dictionary, and still may fail (if the password is not in the dictionary). [More on this later]. So if you want to crack the password of a WPA network... get a new hobby.
    2. Fingerprint and retinal scan for entry, and a card which you can quickly swipe to avoid standing in a queue since the aforementioned scans take some time - By introducing this card the club created an alternate path for entry. While this saves time for the legitimate users, the card can be stolen. While it's not as easy as overhearing the password (WEP), or walking right in (open), pickpocketing a member is much easier than murder and mutilation (you really want to enter that club if you're going that far). This is WPA with WPS enabled. WPS has a vulnerability which allows a hacker to get a password in around 3 hours (can be more sometimes, up to 10-12 hours, but that figure is nothing compared to WPA). Just like WEP, WPS is now a well known weak point and new routers have either disabled WEP or added some measures (like rate limiting) which make it really hard to, well, pickpocket the members. 
    • Bonus : Hidden entry

      Any of the above clubs could have a secret entrance. Sounds cool, right? This is somewhat similar to what we call "Security Through Obscurity". How we you get in if you don't know where the club's entrance is? Well, while you don't know where the club entrance is, you know where the club is. You have two options-
      1. Passive method - You go to the roof of a nearby building, take your binoculars out, and try to find out how people enter the building. In wireless terms, you wait till a client connects to the network. This may take a lot of time, but it's relatively safer from a forensic viewpoint (by not doing anything, just watching patiently, you ensure that you don't leave any clues behind which may later be used to catch you).
      2. Active method - You cut off the electric/water supply to the building, or maybe somehow trigger the fire alarm. One way or the other, force the members to get out of the club. Once they find out that everything is fine, they'll swarm back in. You will know where the gate is. In wireless terms, you can de-authenticate the clients (you'll be doing this often, whether you're hacking a WEP network, or getting a WPA handshake [again, more on this later]). Off course, this method results in you leaving behind some traces, but at least you don't have to wait for hours.
      The analogue of hidden entry clubs are hidden networks. As long as the network has clients, it's quite easy to find out the name of the network (SSID to be precise, setting the network to hidden basically stops the access point from revealing it's SSID). However, when a client connects to the network, beacon frames (date packets) with SSID (in clear-text, i.e. unencrypted) are transmitted, which you can capture and get the SSID of the network. So, hidden networks don't really offer much protection to a network, and a WEP protected hidden network just means that instead of 10 mins it will take 15 mins to get the password. For a WPA network, making the SSID hidden doesn't really do a lot since WPA networks are practically uncrackable and a person who has the time and processing power to get past WPA encryption won't be stopped by the hidden SSID.

      Summary

      • There can be additional authentication steps (logins) or other barriers between you and internet even after you get access to the router. However, this is an entirely separate problem and not too relevant to the discussion of wireless hacking. Still it's something you must be aware of.
         
      • Wireless hotspots or open networks don't have any encryption. They can be accessed by anyone. Also, the data transmitted by you is not encrypted and can be read by anyone in the vicinity. Anything which you send to the destination server in plain-text (say, to google), will be transmitted from your machine to the wireless router in plain-text. Anyone in the vicinity can easily read it using Wireshark or any other similar tool. Of course, sensitive data is rarely sent in plain-text, so don't sit around wireless hotspots hoping to get someone's FB login credentials. However, lack of encryption in open networks should be considered seriously. As far as wireless hacking is concerned, not a lot to do here (other than sniffing at unencrypted data in the air).
      • WEP - This is where most of the stuff happens. Countless vulnerabilities, countless attacks, countless research papers listing the issues, countless tools to get the passwords. It doesn't take too much effort to learn how to hack these. If you are familiar with linux, then it takes practically no efforts at all. Just some terminal commands, and you're done (with wifite you don't even have to bother with that).
      • WPA - Don't want to mess with this guy. Theoretically there's a way to get in. Practically it will take forever. Dictionary attacks and bruteforce are the methods to get in. Will cover all this in the advanced version of this guide. PS: When I say WPA, I refer to both WPA and WPA-2. For the sake of this post, they are the same (actually they have a lot of difference, the common thing is neither is an easy target for hackers).
      • WPA with WPS - Tough guy with a weak spot. Hit him where it hurts and the 'it takes forever to get in' becomes a matter of hours. Not as easy as WEP, but still do-able. Unfortunately, you might encounter a guy who has a weak spot but has started learning his lessons and guards that spot properly (WPS but with rate-limiting or some other security measure).


    I hope you now have a general idea about the various flavors of wireless security. I have a few advanced guides in mind too, which will touch the cryptographic specifics about these 'flavors', the vulnerabilities, and their exploits. As far as the practical hacking process is concerned, there are plenty of tutorials here on this website and elsewhere on the internet regarding that, so I am not covering that again. I hope that this time when you read a guide you are aware of what's going on, and don't end up trying an attack that works on WEP targets on a WPA network.
    Thanks For Visit, Keep Sharing.

    Things you should know: Wireless hacking intermedicate

    Things You Should Know: Wireless Hacking Intermedicate

     Wireless Hacking Intermedicate

    Pre-requisites You should know (all this is covered in Wireless Hacking basics)- What are the different flavors of wireless networks you'll encounter and how difficult it is to hack each of them. What are hidden networks, and whether they offer a real challenge to a hacker. Have a very rough idea how each of the various 'flavors' of wireless networks is actually hacked. Post-reading You will know - Know even more about different flavors of wireless networks. How to go about hacking any given wireless network. Common tools and attacks that are used in wireless hacking. The last two points would be covered in detail in the coming posts. A rough idea about the cryptographic aspects of the attacks, the vulnerabilities and the exploits. A rough idea about the cryptographic aspects of each 'flavor' of wireless network security. Pirates of the Caribbean Suppose you are in ship manufacturing business. These are times when pirates were rampaging the seas. You observed how the merchant ships are all floating unguarded in the seas, and the pirate industry is booming because of easy targets. You decide to create fortified ships, which can defend themselves against the pirates. For this, you use an alloy X. Your idea was appreciated by merchants and everyone started using your ships.... The most iconic pirates of modern times Unfortunately, your happiness was short lived. Soon, the pirates found out flaws in your ships and any pirate who knew what he was doing could easily get past your ship's defense mechanisms. For a while you tried to fix the known weaknesses in the ship, but soon realized that there were too many problems, and that the very design of the ship was flawed. You knew what flaws the pirates were exploiting, and could build a new and stronger ship. However, the merchants weren't willing to pay for new ships. You then found out that by remodeling some parts of the ship in a very cost efficient way, you could make the ship's security almost impenetrable. In the coming years, some pirates found a few structural weaknesses in alloy X, and some issues with the core design of the ship (remnant weaknesses of the original ship). However, these weaknesses were rare and your customers were overall happy. After some time you decided to roll out an altogether new model of the ship. This time, you used a stronger allow, Y. Also, you knew all the flaws in the previous versions of the ship, and didn't make any errors in the design this time. Finally, you had a ship which could withstand constant bombardment for months on end, without collapsing. There was still scope for human error, as the sailors can sometimes be careless, but other than that, it was an invincible ship. WEP, WPA and WPA-2 WEP is the flawed ship in the above discussion. The aim of Wireless Alliance was to write an algorithm to make wireless network (WLAN) as secure as wired networks (LAN). This is why the protocol was called Wired Equivalent Privacy (privacy equivalent to the one expected in a traditional wired network). Unfortunately, while in theory the idea behind WEP sounded bullet-proof, the actual implementation was very flawed. The main problems were static keys and weak IVs. For a while attempts were made to fix the problems, but nothing worked well enough(WEP2, WEPplus, etc. were made but all failed). WPA was a new WLAN standard which was compatible with devices using WEP encryption. It fixed pretty much all the flaws in WEP encryption, but the limitation of having to work with old hardware meant that some remnants of the WEPs problems would still continue to haunt WPA. Overall, however, WPA was quite secure. In the above story, this is the remodeled ship. WPA-2 is the latest and most robust security algorithm for wireless networks. It wasn't backwards compatible with many devices, but these days all the new devices support WPA-2. This is the invincible ship, the new model with a stronger alloy. But wait... In last tutorial I assumed WPA and WPA-2 are the same thing. In this one, I'm telling you they are quite different. What's the matter? Well actually, the two standards are indeed quite different. However, while it's true there are some remnant flaws in WPA that are absent in WPA-2, from a hacker's perspective, the technique to hack the two networks is often the same. Why? Very few tools exist which carry out the attacks against WPA networks properly (the absence of proof-of-concept scripts means that you have to do everything from scratch, which most people can't). All these attacks work only under certain conditions (key renewal period must be large, QoS must be enabled, etc.) Because of these reasons, despite WPA being a little less secure than WPA-2, most of the time, a hacker has to use brute-force/dictionary attack and other methods that he would use against WPA-2, practically making WPA and WPA-2 the same thing from his perspective. PS: There's more to the WPA/WPA-2 story than what I've captured here. Actually WPA or WPA-2 are ambiguous descriptions, and the actual intricacy (PSK, CCMP, TKIP, X/EAP, AES w.r.t. cipher used and authentication used) would required further diving into personal and enterprise versions of WPA as well as WPA-2. How to Hack Now that you know the basics of all these network, let's get to how actually these networks are hacked. I will only name the attacks, further details would be provided in coming tutorials- WEP The Initialization vector v passed to the RC4 cipher is the weakness of WEP Most of the attacks rely on inherent weaknesses in IVs (initialization vectors). Basically, if you collect enough of them, you will get the password. Passive method If you don't want to leave behind any footprints, then passive method is the way to go. In this, you simply listen to the channel on which the network is on, and capture the data packets (airodump-ng). These packets will give you IVs, and with enough of these, you can crack the network (aircrack-ng). I already have a tutorial on this method, which you can read here - Hack WEP using aircrack-ng suite. Active methods ARP request replay - The above method can be incredibly slow, since you need a lot of packets (there's no way to say how many, it can literally be anything due the nature of the attack. However, usually the number of packets required ends up in 5 digits). Getting these many packets can be time consuming. However, there are many ways to fasten up the process. The basic idea is to initiate some sort of conversation in the network, and then capture the packets that arise as a result of the conversation. The problem is, not all packets have IVs. So, without having the password to the AP, you have to make it generate packets with IVs. One of the best ways to do this is by requesting ARP packets (which have IVs and can be generated easily once you have captured at least one ARP packet). This attack is called ARP replay attack. We have a tutorial for this attack as well, ARP request replay attack. Chopchop attack Fragmentation attack Caffe Latte attack I'll cover all these attacks in detail separately (I really can't sumarrize the bottom three). Let's move to WPA- WPA-2 (and WPA) There are no vulnerabilities here that you can easily exploit. The only two options we have are to guess the password or to fool a user into giving us the password. Guess the password - For guessing something, you need two things : Guesses (duh) and validation. Basically, you need to be able to make a lot of guess, and also be able to verify if they are correct or not. The naive way would be to enter the guesses into the password field that your OS provides when connecting to the wifi. That would be slow, since you'd have to do it manually. Even if you write a script for that, it would take time since you have to communicate with the AP for every guess(that too multiple times for each guess). Basically, validation by asking the AP every time is slow. So, is there a way to check the correctness of our password without asking the AP? Yes, but only if you have a 4-way handshake. Basically, you need the capture the series of packets transmitted when a valid client connects to the AP. If you have these packets (the 4-way handshake), then you can validate your password against it. More details on this later, but I hope the abstract idea is clear. There are a few different ways of guessing the password :- Bruteforce - Tries all possible passwords. It is guaranteed that this will work, given sufficient time. However, even for alphanumeric passwords of length 8, bruteforce takes incredibly long. This method might be useful if the password is short and you know that it's composed only of numbers. Wordlist/Dictionary - In this attack, there's a list of words which are possible candidates to be the password. These word list files contains english words, combinations of words, misspelling of words, and so on. There are some huge wordlists which are many GBs in size, and many networks can be cracked using them. However, there's no guarantee that the network you are trying to crack would have it's password in the list. These attacks get completed within a reasonable timeframe. Rainbow table - The validation process against the 4-way handshake that I mentioned earlier involves hashing of the plaintext password which is then compared with the hash in handshake. However, hashing (WPA uses PBKDF2) is a CPU intensive task and is the limiting factor in the speed at which you can test keys (this is the reason why there are so many tools which use GPU instead of CPU to speed up cracking). Now, a possible solution to this is that the person who created the wordlist/dictionary that we are using can also convert the plaintext passwords into hashes so that they can be checked directly. Unfortunately, WPA-2 uses a salt while hashing, which means that two networks with the same password can have different hashing if they use different salts. How does WPA-2 choose the salt? It uses the network's name (SSID) as the salt. So two networks with the same SSID and the same password would have the same salt. So, now the guy who made the wordlist has to create separate hashes for all possible SSID's. Practically, what happens is that hashes are generated for the most common SSID's (the default one when a router is purchases like -linksys, netgear, belkin, etc.). If the target network has one of those SSID's then the cracking time is reduced significantly by using the precomputed hashes. This precomputed table of hashes is called rainbow table. Note that these tables would be significantly larger than the wordlists tables. So, while we saved ourselves some time while cracking the password, we had to use a much larger file (some are 100s of GBs) instead of a smaller one. This is referred to as time-memory tradeoff. This page has rainbow tables for 1000 most common SSIDs. Fool a user into giving you the password - Basically this just a combination of Man in the middle attacks and social engineering attacks. More specifically, it is a combination of evil twin and phishing. In this attack, you first force a client to disconnect from the original WPA-2 network, then force him to connect to a fake open network that you create, and then send him a login page in his browser where you ask him to enter the password of the network. You might be wondering, why do we need to keep the network open and then ask for the password in the browser (can't we just create a WPA-2 network and let the user give us the password directly). The answer to this lies in the fact that WPA-2 performs mutual authentication during the 4-way handshake. Basically, the client verifies that the AP is legit, and knows the password, and the AP verifies that the client is legit and knows the password (throughout the process, the password is never sent in plaintext). We just don't have the information necessary enough to complete the 4-way handshake. Bonus : WPS vulnerability and reaver [I have covered it in detail seperately so not explaining it again (I'm only human, and a very lazy one too)] The WPA-2 4 way handshake procedure. Both AP and the client authenticate each other Tools (Kali) In this section I'll name some common tools in the wireless hacking category which come preintalled in Kali, along with the purpose they are used for. Capture packets airodump-ng wireshark (really versatile tool, there are books just covering this tool for packet analysis) Crack handshakes aircrack-ng (can crack handshakes as well as WEP) hashcat (GPU cracking) cowpatty WPS reaver pixiewps (performs the "pixie dust attack") Cool tools aireplay-ng (WEP mostly) mdk3 (cool stuff) Automation wifite fluxion (actually it isn't a common script at all, but since I wrote a tutorial on it, I'm linking it) You can find more details about all the tools installed on Kali Tools page. Okay guys, this is all that I had planned for this tutorial. I hope you learnt a lot of stuff. Will delve into further depths in coming tutorials.
    Thanks For Visit, Keep Sharing.