Post Reply 
Cracking WPA is a bitch!
Author Message
Barcelona
Too Young To Care

Posts: 1,247.2872
Threads: 88
Joined: 10th Jul 2010
Reputation: -0.02892
E-Pigs: 60.4042
Offline
Post: #11
RE: Cracking WPA is a bitch!
(09/01/2011 05:38 PM)ZiNgA BuRgA Wrote:  WPA was made to fix problems in WEP.
I doubt a rainbow table would work - you're not cracking a hash.

If it's not a dictionary, you could try a hybrid attack if your app supports it.  Beyond that, try passwords they're likely to use.

Does WPA use passwords though?  I thought they just used hex formatted keys, not passwords...

(09/01/2011 05:29 PM)Barcelona Wrote:  Peace lol ive only bruteforced a rar file
Must've been the easiest RAR (ie crappiest password).  RAR encryption is relatively secure.

well it took a day lol and the password was "thepiratebay" i was pissed when i saw that the password was in the description of the torrent

[Image: A73TX.png]
Quotes That Made Me Lol
Joomla12 Wrote:Who are you?
(02/08/2011 08:26 AM)eKusoshisut0 Wrote:  ┻┻ ︵ヽ(`Д´)ノ︵ ┻┻
Previous Signatures
First Signature Wrote:Rep me up or I'll GENTLY CARESS you in the booty!
Second Signature Wrote:Studies have shown that for everyone person that doesn't rep me up, an angel gets a hernea.
Third Signature Wrote:Dead Trademark91 killed me.
Fourth Signature Wrote:Windows Proud
Fifth Signature Wrote:I'm waiting for someone to chime in with an arrow. Any tamed wolves you can be traced back to my forum signature.
Sixth Signature Wrote:[Image: 7hjyW.png]
09/01/2011 06:16 PM
Find all posts by this user Quote this message in a reply
Mickey
Down with MJ yo

Posts: 3,663.2843
Threads: 251
Joined: 26th Apr 2008
E-Pigs: 28.7300
Offline
Post: #12
RE: Cracking WPA is a bitch!
(09/01/2011 05:38 PM)ZiNgA BuRgA Wrote:  WPA was made to fix problems in WEP.
I doubt a rainbow table would work - you're not cracking a hash.

If it's not a dictionary, you could try a hybrid attack if your app supports it.  Beyond that, try passwords they're likely to use.

Does WPA use passwords though?  I thought they just used hex formatted keys, not passwords...

(09/01/2011 05:29 PM)Barcelona Wrote:  Peace lol ive only bruteforced a rar file
Must've been the easiest RAR (ie crappiest password).  RAR encryption is relatively secure.

It actually is a hash, but it's salted by the ssid, which is why rainbow tables only work with common ssid's such as Netgear or Linksys. This one was Mark423 :/ What's a hybrid attack? Aircrack encodes the password with the salt and compares it to the hash captured in the 4-way handshake. I've got it to work other times :/
Quote:Problem is, it's a very slow process. Each passphrase is hashed 4096 times with SHA-1 and 256 bits of the output is the resulting hash. This is then compared to the hash generated in the initial key exchange. Alot of computing power is required for this. My dopey little P3/700 laptop only tests about 12 passphrases/second.

To complicate matters, the key hash can be different depending on the network it's implimented on. The SSID and the SSID length is seeded into the passphrase hash. This means that the passphrase of 'password' will be hashed differently on a network with the SSID of 'linksys' than it will on a network with the SSID of 'default'.
Source
EDIT: John the Ripper(JtR) takes a wordlist provided, and adds numbers and substitutes symbols for letters etc, which is what I'm running now. Is that a hybrid attack?

[Image: MiCk3Y.jpg]

[Image: battle.png]

Spoiler for link:
(This post was last modified: 09/01/2011 06:57 PM by Mickey.)
09/01/2011 06:51 PM
Find all posts by this user Quote this message in a reply
trademark91
Unique?
Fractal Insanity

Posts: 4,719.9300
Threads: 269
Joined: 4th Jan 2008
Reputation: -6.15982
E-Pigs: 105.8691
Offline
Post: #13
RE: Cracking WPA is a bitch!
If it's a 2wire router, the passwords are all 10 digit numerical phrases by default, etc 1234567890 could be a default password. I would suggest a brute force of numbers between 0000000000-9999999999 as a starting point for 2wire routers. Though that might take a while, unless the password started with a 0 or a 1...

[Image: 531115][Image: 76561198014212040.png]
windows Proud
09/01/2011 08:12 PM
Find all posts by this user Quote this message in a reply
ProperBritish
Daddy Proper
Team DreamArts

Posts: 5,666.3250
Threads: 192
Joined: 19th Nov 2008
Reputation: -2.36574
E-Pigs: 147.7035
Offline
Post: #14
RE: Cracking WPA is a bitch!
(09/01/2011 08:12 PM)trademark91 Wrote:  If it's a 2wire router, the passwords are all 10 digit numerical phrases by default, etc 1234567890 could be a default password. I would suggest a brute force of numbers between 0000000000-9999999999 as a starting point for 2wire routers. Though that might take a while, unless the password started with a 0 or a 1...

or a bruteforce Hexadecimal from 0000000000 to FFFFFFFFFF sounds logical if this fails

[Image: rsz_contrast.png]

Spoiler for More sigs:
[Image: 6xu74t8]
[Image: sig.php]

[Image: 656embk]
[Image: sig.png]
(This post was last modified: 09/01/2011 08:54 PM by ProperBritish.)
09/01/2011 08:54 PM
Find all posts by this user Quote this message in a reply
Barcelona
Too Young To Care

Posts: 1,247.2872
Threads: 88
Joined: 10th Jul 2010
Reputation: -0.02892
E-Pigs: 60.4042
Offline
Post: #15
RE: Cracking WPA is a bitch!
but if its encrypted with wpa-tkip, then it will take a while, cause those can have personal passwords

[Image: A73TX.png]
Quotes That Made Me Lol
Joomla12 Wrote:Who are you?
(02/08/2011 08:26 AM)eKusoshisut0 Wrote:  ┻┻ ︵ヽ(`Д´)ノ︵ ┻┻
Previous Signatures
First Signature Wrote:Rep me up or I'll GENTLY CARESS you in the booty!
Second Signature Wrote:Studies have shown that for everyone person that doesn't rep me up, an angel gets a hernea.
Third Signature Wrote:Dead Trademark91 killed me.
Fourth Signature Wrote:Windows Proud
Fifth Signature Wrote:I'm waiting for someone to chime in with an arrow. Any tamed wolves you can be traced back to my forum signature.
Sixth Signature Wrote:[Image: 7hjyW.png]
09/01/2011 09:00 PM
Find all posts by this user Quote this message in a reply
Mickey
Down with MJ yo

Posts: 3,663.2843
Threads: 251
Joined: 26th Apr 2008
E-Pigs: 28.7300
Offline
Post: #16
RE: Cracking WPA is a bitch!
I have noooo idea what router it is :/

[Image: MiCk3Y.jpg]

[Image: battle.png]

Spoiler for link:
09/01/2011 09:42 PM
Find all posts by this user Quote this message in a reply
ZiNgA BuRgA
Smart Alternative

Posts: 17,022.2988
Threads: 1,174
Joined: 19th Jan 2007
Reputation: -1.71391
E-Pigs: 446.1294
Offline
Post: #17
RE: Cracking WPA is a bitch!
(09/01/2011 06:51 PM)Mickey Wrote:  It actually is a hash, but it's salted by the ssid, which is why rainbow tables only work with common ssid's such as Netgear or Linksys. This one was Mark423 :/ What's a hybrid attack? Aircrack encodes the password with the salt and compares it to the hash captured in the 4-way handshake. I've got it to work other times :/
Oh I see, you've captured the key exchange...

And yes, you got the idea of a hybrid attack.  Typically also appending some numbers/letters to words also works.
10/01/2011 04:00 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Mickey
Down with MJ yo

Posts: 3,663.2843
Threads: 251
Joined: 26th Apr 2008
E-Pigs: 28.7300
Offline
Post: #18
RE: Cracking WPA is a bitch!
It's been 16 hours and the hybrid attack with a small 10mb list is only at 24%, this is one of my smaller lists lol

[Image: MiCk3Y.jpg]

[Image: battle.png]

Spoiler for link:
10/01/2011 07:03 AM
Find all posts by this user Quote this message in a reply
Post Reply 


Forum Jump:


User(s) browsing this thread:

 Quick Theme: