0:00 Music 0:07 Wi-Fi, it's easy to hack. 0:09 It has... 0:11 So, basically, I know the cases how Wi-Fi was hacked within like two or three seconds. 0:20 So, there are like protocols which called VPS. 0:24 So, that VPS protocol is... 0:29 Used in routers. 0:31 So when you basically attack the router with VPS, it means that 0:40 like 90% that you will hack it because you are using the known pattern of passwords from the list. 0:50 So, for example, when you buy the router number one, like TP-Link, when you buy it, your friend has the same VPS code. 1:01 VPS code is like 12345678 or 1234567777. 1:08 And the difference between me and him can be like one symbol. 1:12 And based on me, who is scanning Wi-Fi, I can see the MAC address of the device. 1:21 And based on MAC address, I can know the vendor. 1:24 Based on the vendor, I can try to use the VPS attack because there are lists. 1:30 And I will show you the tool. 1:35 Which is doing that stuff. 1:36 So there is a tool which is doing this by default, very easy tool. 1:40 It's called Air. 1:43 But Ergedon was made by one very cool Spanish guy. 1:50 Air get on. 1:51 And so. 1:58 Let me maybe show you better some pictures of that stuff. 2:07 So what is Ergydon? 2:11 You just install it and it gives you the wizard. 2:16 And what you do, you just choose the network interface after you put it in the monitor mode. 2:23 And after you just do whatever you want. 2:26 For example, let me show you VPA2. 2:32 Cracking. 2:34 So this is menu for repeat to cracking. 2:38 So bad. 2:45 This one, I think, a little bit better. 2:49 Okay, so in that menu, you just choose the handshake attack or offline VPA decrypt menu if you found the key, or you can use VPS attack. 3:04 So when you choose VPS attack, 3:06 against router. 3:08 If it has the VPS, 90% you will get the password within like 5-10 seconds. 3:14 Or within 5 minutes, because it has the tries, retries. 3:19 But evidently you will get the password. 3:21 For VPA2, you just need to capture the handshake. 3:27 And after you just need to brute force it, use it air crack and G. 3:31 So air crack and G can decrypt the handshake and you will get the password, the key. 3:40 For example, this is the key. 3:41 So again, 3:43 you turn on the network Wi-Fi video card. 3:48 After you put it in the network mode, after you choose the Wi-Fi which you're going to attack, and after you get the handshake, 4:00 of people who are connecting to that device and after you decrypt it. 4:05 I can also show you it here visually. 4:08 So do a little bit more Wi-Fi audit. 4:12 We are not going to hack anything, but I will show you. 4:16 So this is the device. 4:22 Why I'm using external? 4:23 Because the internal one does not have the appropriate drivers on Windows specifically. 4:33 So let me detect. 4:35 So this is my interface. 4:37 It's called interface. 4:38 Now let me hide that menu again. 4:43 Now I click next and I scan for Wi-Fi. 4:47 And you can see the strength of the signal, the type of the signal, you know, and here what I wanted to show you. 4:56 This is MAC address. 4:59 Based on this MAC address, I can know who is the vendor. 5:02 This is what I wanted to show you. 5:04 Because in your default here, right, you don't see that stuff. 5:12 Even if you go to properties, Microsoft doesn't want to show you that stuff. 5:18 Right? 5:19 And there is a reason why they don't want to show it. 5:23 Because if you know the vendor and it has VPS enabled, most likely you know the password. 5:33 So we can just choose what we want. 5:36 And, you know, after we can scan for clients, run the AOS. 5:41 So we will scan. 5:42 for all the people who are here. 5:44 After, we will kick somebody. 5:47 For example, him. 5:48 We will kick him. 5:49 And after, when he will again connect, we will capture the handshake. 5:54 So we are not going to do it. 5:56 But there is also option to scan for BPS. 6:00 The same what I just told you. 6:01 If you have very good password, 6:03 You are not vulnerable. 6:05 This is for sure. 6:06 Because it is not possible to brute force extremely strong password for VPA2. 6:13 So if you are putting the extremely strong password for Wi-Fi, VPA2, I don't know if it is easy to hack it. 6:25 Other methods to do it, like evil twin, karma attack, some other stuff. 6:32 So there is like a separate, you know, education about hacking of Wi-Fi, but I will just tell you that karma attack, evil twin attack, 6:44 and some other attacks are there which can, which does not really care, and Pixie Dust. 6:52 So Pixie Dust is also attack related to WPS, and Karma and Tablet Twin are the attacks which can target even BPA3. 7:06 But in reality, VPA 3 Enterprise and VPA 2 with a hard password, you are good enough.
0:00 Music 0:07 Wi-Fi, it's easy to hack. 0:09 It has... 0:11 So, basically, I know the cases how Wi-Fi was hacked within like two or three seconds. 0:20 So, there are like protocols which called VPS. 0:24 So, that VPS protocol is... 0:29 Used in routers. 0:31 So when you basically attack the router with VPS, it means that 0:40 like 90% that you will hack it because you are using the known pattern of passwords from the list. 0:50 So, for example, when you buy the router number one, like TP-Link, when you buy it, your friend has the same VPS code. 1:01 VPS code is like 12345678 or 1234567777. 1:08 And the difference between me and him can be like one symbol. 1:12 And based on me, who is scanning Wi-Fi, I can see the MAC address of the device. 1:21 And based on MAC address, I can know the vendor. 1:24 Based on the vendor, I can try to use the VPS attack because there are lists. 1:30 And I will show you the tool. 1:35 Which is doing that stuff. 1:36 So there is a tool which is doing this by default, very easy tool. 1:40 It's called Air. 1:43 But Ergedon was made by one very cool Spanish guy. 1:50 Air get on. 1:51 And so. 1:58 Let me maybe show you better some pictures of that stuff. 2:07 So what is Ergydon? 2:11 You just install it and it gives you the wizard. 2:16 And what you do, you just choose the network interface after you put it in the monitor mode. 2:23 And after you just do whatever you want. 2:26 For example, let me show you VPA2. 2:32 Cracking. 2:34 So this is menu for repeat to cracking. 2:38 So bad. 2:45 This one, I think, a little bit better. 2:49 Okay, so in that menu, you just choose the handshake attack or offline VPA decrypt menu if you found the key, or you can use VPS attack. 3:04 So when you choose VPS attack, 3:06 against router. 3:08 If it has the VPS, 90% you will get the password within like 5-10 seconds. 3:14 Or within 5 minutes, because it has the tries, retries. 3:19 But evidently you will get the password. 3:21 For VPA2, you just need to capture the handshake. 3:27 And after you just need to brute force it, use it air crack and G. 3:31 So air crack and G can decrypt the handshake and you will get the password, the key. 3:40 For example, this is the key. 3:41 So again, 3:43 you turn on the network Wi-Fi video card. 3:48 After you put it in the network mode, after you choose the Wi-Fi which you're going to attack, and after you get the handshake, 4:00 of people who are connecting to that device and after you decrypt it. 4:05 I can also show you it here visually. 4:08 So do a little bit more Wi-Fi audit. 4:12 We are not going to hack anything, but I will show you. 4:16 So this is the device. 4:22 Why I'm using external? 4:23 Because the internal one does not have the appropriate drivers on Windows specifically. 4:33 So let me detect. 4:35 So this is my interface. 4:37 It's called interface. 4:38 Now let me hide that menu again. 4:43 Now I click next and I scan for Wi-Fi. 4:47 And you can see the strength of the signal, the type of the signal, you know, and here what I wanted to show you. 4:56 This is MAC address. 4:59 Based on this MAC address, I can know who is the vendor. 5:02 This is what I wanted to show you. 5:04 Because in your default here, right, you don't see that stuff. 5:12 Even if you go to properties, Microsoft doesn't want to show you that stuff. 5:18 Right? 5:19 And there is a reason why they don't want to show it. 5:23 Because if you know the vendor and it has VPS enabled, most likely you know the password. 5:33 So we can just choose what we want. 5:36 And, you know, after we can scan for clients, run the AOS. 5:41 So we will scan. 5:42 for all the people who are here. 5:44 After, we will kick somebody. 5:47 For example, him. 5:48 We will kick him. 5:49 And after, when he will again connect, we will capture the handshake. 5:54 So we are not going to do it. 5:56 But there is also option to scan for BPS. 6:00 The same what I just told you. 6:01 If you have very good password, 6:03 You are not vulnerable. 6:05 This is for sure. 6:06 Because it is not possible to brute force extremely strong password for VPA2. 6:13 So if you are putting the extremely strong password for Wi-Fi, VPA2, I don't know if it is easy to hack it. 6:25 Other methods to do it, like evil twin, karma attack, some other stuff. 6:32 So there is like a separate, you know, education about hacking of Wi-Fi, but I will just tell you that karma attack, evil twin attack, 6:44 and some other attacks are there which can, which does not really care, and Pixie Dust. 6:52 So Pixie Dust is also attack related to WPS, and Karma and Tablet Twin are the attacks which can target even BPA3. 7:06 But in reality, VPA 3 Enterprise and VPA 2 with a hard password, you are good enough.