I Inadvertently Left Kali Running a Scan on Local APs Using the Airodump Function in Aircrack Whilst I Was Away for a Couple of Days. Upon My Return I Find That It Has Seemingly Grabbed Shedloads of WPA Handshakes for Various BSSIDs Whilst I've Been Away. As I'm Used to Using the Tutorials on Here (Whereby You Use the -W Command to Create a File for the Captured 'Shakes) I've No Idea Where to Find the Handshakes. I Know I Need to Make a Start on the Linux Basics Tutorials but Any Assistance in the Interim on Locating and Getting to Grips on the 'Shakes I've Grabbed Would Be Appreciated.
Forum Thread: Confused Noob
- Hot
- Active
-
Forum Thread: My PC Not Working 0 Replies
1 hr ago -
Forum Thread: www.prohealthpedia.com/Keto-Gedeon/ 0 Replies
5 hrs ago -
How to: Sign the APK File with Embedded Payload (The Ultimate Guide) 4 Replies
7 hrs ago -
Forum Thread: health2wealthclub.Com/Male-Ultracore/ 0 Replies
8 hrs ago -
Forum Thread: Problem with .Apk Payloads 19 Replies
1 day ago -
Forum Thread: www.prohealthpedia.com/Retro-X-Power/ 0 Replies
1 day ago -
Forum Thread: health2wealthclub.Com/Biogenix-Rx/ 0 Replies
1 day ago -
Forum Thread: Http://thesupplementcop.com/Alpha-Testo-Boost-X/ 0 Replies
1 day ago -
Forum Thread: http://thesupplementcop.com/alpha-testo-boost-x/ 0 Replies
1 day ago -
Forum Thread: Parrot Security Os Problem...... 12 Replies
2 days ago -
Forum Thread: Airdump-Ng Can't Find Any Network in Monitor Mode 6 Replies
2 days ago -
Forum Thread: Wlan Rename After Update / Upgrade in Kali Linux 1 Replies
3 days ago -
How to: HACK Android Device with TermuX on Android | Part #1 - Over the Internet [Ultimate Guide] 134 Replies
3 days ago -
How to: Embed MSF Payload in Original APK Files | Part #1 - Using TheFatRAT 19 Replies
4 days ago -
Forum Thread: Https Site in My Browser Automatically Downgrade into Http or Site Not Open..Am I Hacked . 1 Replies
4 days ago -
Forum Thread: Kali Linux Initramfs Boot Error 0 Replies
4 days ago -
Forum Thread: I Want to Hack a Facebook Account. 9 Replies
5 days ago -
Forum Thread: How to Hack Router Password to Access Router Control Panel? 6 Replies
6 days ago -
Forum Thread: How to Hack an Android Device with Only a Ip Adress 36 Replies
6 days ago -
Forum Thread: My Instagram Account Has Been Hacked 0 Replies
6 days ago
-
How To: Spy on Traffic from a Smartphone with Wireshark
-
How To: Use Hash-Identifier to Determine Hash Types for Password Cracking
-
How To: Identify Missing Windows Patches for Easier Exploitation
-
How to Hack Wi-Fi: Stealing Wi-Fi Passwords with an Evil Twin Attack
-
How To: Crack Wi-Fi Passwords with Your Android Phone and Get Free Internet!
-
How To: 4 Ways to Crack a Facebook Password & How to Protect Yourself from Them
-
Android for Hackers: How to Turn an Android Phone into a Hacking Device Without Root
-
How To: Buy the Best Wireless Network Adapter for Wi-Fi Hacking in 2019
-
How To: Get Root Filesystem Access via Samba Symlink Traversal
-
How To: Hack Android Using Kali (Remotely)
-
How To: Get Unlimited Free Trials Using a "Real" Fake Credit Card Number
-
How to Hack Wi-Fi: Cracking WPA2 Passwords Using the New PMKID Hashcat Attack
-
How To: Find Vulnerable Webcams Across the Globe Using Shodan
-
How To: Top 10 Things to Do After Installing Kali Linux
-
How To: Find Anyone's Private Phone Number Using Facebook
-
How To: Securely Sniff Wi-Fi Packets with Sniffglue
-
How To: Crack Any Master Combination Lock in 8 Tries or Less Using This Calculator
-
How to Hack Wi-Fi: Cracking WPA2-PSK Passwords Using Aircrack-Ng
-
How To: Automate Wi-Fi Hacking with Wifite2
-
How To: Check if Your Wireless Network Adapter Supports Monitor Mode & Packet Injection
2 Responses
Ciuffy is correct about the headline - I don't post much and was rushing off to a beer festival. Many thanks for your help.
A few things you can do (assuming you're using Kali):
Open up a terminal and run from the command line:
wpaclean new.cap old.cap
Note that the order in this is the opposite of what you'll usually see -- enter the file name you want to give your clean cap file FIRST, and then the file of the one you have now. e.g.
wpaclean SmallCap.cap HugeCapBecauseILeftAirCrackRunning.cap
This will strip the file down to only the relevant handshakes (you only need two from each set, but they have to be the right two).
pyrit -r Old.cap -o New.cap strip
This will strip it down to just handshakes, but won't pre-select them for you.
After that you can run:
pyrit -r New.cap analyze
This will return a list of all handshakes, and tell you if they're usable ("good spread") or not.
And, finally, you can do it manually by opening the cap file in wireshark and selecting individual packets. See this for an explanation:
http://aircrack-ng.org/doku.php?id=wpa_capture&DokuWiki=074d5917c87bb3032d8c42de85f2e8da
Caveat:
I've only ever used these on cap files that captured handshakes from a single ESSID. Not certain how they'll work if you have dozens of different ESSIDs in there.
What I've done is run pyrit strip on the cap file first, run pyrit analyze on it, and then run it through wpaclean. Then I'll open up the final cap file in wireshark and make sure they all look good. But I think you can get away with just wpaclean.
Share Your Thoughts