EvilZone

Hacking and Security => Beginner's Corner => : xsysudo September 18, 2015, 04:49:58 PM

: need some more suggestions on cracking a wpa2 handshake capture...
: xsysudo September 18, 2015, 04:49:58 PM
Hi everyone. I'm new here.
Need some suggestions on cracking a wpa2 handshake capture:
Reaver failed wps pins but I got de handshake cap file using wifite. That's it. Already tried a lot of dictionaries on aircrack lots of time wasted and nothing... any more ideas?
Thanks
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: white-knight September 18, 2015, 08:39:38 PM
Reaver is your best bet , just cause it failed dont mean it wont work , try to learn more about using it .

You can try bruteforce against the handshake but it can take a day or a lifetime to crack it. maybe try to get more info on the manufacture  when scanning , google to find default pins or default passwords might get lucky . the more info you have the better .

If you cant do that try other ways of getting it , this question is asked alot here so look around you might find ur answer ..

When all else fails just go ask for the password and nudes . thats what i do  :o
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: phoenixcoder September 24, 2015, 04:35:24 AM
You can send the cap here and I'll take care of it.

http://timourrashed.com/wpa-cracker-online-service/


Sent from my iPhone using Tapatalk
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: blindfuzzy September 24, 2015, 06:54:40 PM
You can send the cap here and I'll take care of it.

http://timourrashed.com/wpa-cracker-online-service/


Sent from my iPhone using Tapatalk

This is unnecessary. You can just look for the information on how to do it yourself versus paying someone to do it.
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: blackrat September 24, 2015, 07:16:27 PM
Evil-Twin ?? (not for handshake cracking but i find it successful)
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: phoenixcoder September 24, 2015, 07:18:19 PM

This is unnecessary. You can just look for the information on how to do it yourself versus paying someone to do it.

True people can look up the info, however brute forcing and using wordlists require extensive computing power that most people do not have at their disposal.

Thus the question will be "how fast or crucial do I require the password?"

That's completely up to the interested party to answer


Sent from my iPhone using Tapatalk
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: xsysudo September 29, 2015, 01:53:22 PM
I've got Aircrack running on a intel i5 plus GeForce GTX 430 and 8GBDDR for almost 3 weeks and still nothing... The dic file is the generic "acdcdictionary.txt" 27GB.

Maybe i should get other appropriate dic file for local and nacional Portuguese words but can't find it any... Any links to get more custom dic wordlists?

Also tried on some free online has crack sites like wpa-sec.stanev.org and www.OnlineHashCrack.com but no results.

I know i must be patient but the i am beginning to lose hope on this one.
Reaver locks the router after some attempts, even with --ignore-locks -d 61 commands.

BTW the equipment is a TECHNICOLOR TG784n V3 from Vodafone Portugal.

Thks
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: white-knight September 29, 2015, 02:55:00 PM
No matter the power of your machine and time you have you still might not get the password in a dictionary..

The only way you can crack the password with a DICTIONARY is if the password is actually in it .

Since you have the brand info try to look up default passwords and info  and maybe how the security of the WPS is set up.


http://www.techarp.com/showarticle.aspx?artno=763

scroll down some and you can read of the defaults  , then maybe try something similar first.

You could always try a paid version of online cracker .
: need some more suggestions on cracking a wpa2 handshake capture...
: phoenixcoder September 29, 2015, 04:24:43 PM
I've got Aircrack running on a intel i5 plus GeForce GTX 430 and 8GBDDR for almost 3 weeks and still nothing... The dic file is the generic "acdcdictionary.txt" 27GB.

Maybe i should get other appropriate dic file for local and nacional Portuguese words but can't find it any... Any links to get more custom dic wordlists?

Also tried on some free online has crack sites like wpa-sec.stanev.org and www.OnlineHashCrack.com but no results.

I know i must be patient but the i am beginning to lose hope on this one.
Reaver locks the router after some attempts, even with --ignore-locks -d 61 commands.

BTW the equipment is a TECHNICOLOR TG784n V3 from Vodafone Portugal.

Thks

Technicolor's password falls in the keyspace of 10 char that can vary among the following chars "0123456789ABCDEF"

In other words, you will have to try a maximum of 16^10=1,099,511,627,776 combinations so even if your hardware can crack 100k passwords per second it will take you roughly 4 months. At a speed of 6k (average of most hardware), it will take you 70 months or 6 years.

Hope that clears things up
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: 0E 800 September 29, 2015, 06:05:44 PM
I wouldnt trust wifite. I havent used it in a while, does it even us wlan0mon interface?

To verify the handshake, try:
:
pyrit -r your.cap analyze
You might want to try out:

https://github.com/SilentGhostX/HT-WPS-Breaker

https://github.com/nxxxu/AutoPixieWps

Both are automated Pixie attacks.
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: rogue.hackz September 30, 2015, 06:22:56 PM
https://github.com/SilentGhostX/HT-WPS-Breaker

Hmm...looks like that tool has been released like a few hours ago lol.

Anyway haven't tried that tool but what I can say is that I tend to stay away from tools that try to be too many things at the same time cos they tend to fail massively for the most part. Jack of all trades but master of none, better to mess around and learn individual toolset yourself and know what works and what not other than relying on something automated.

@OP: Incase you wanted some free external service like WPA Cloud Cracking online you might wanna check this out:

wpa-sec.stanev.org

If you don't have the hardware it's better to get it done else where than wasting your cpu cycles and waiting forever.
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: phoenixcoder September 30, 2015, 06:59:53 PM
@OP you can also send the handshake to me via direct message and I'll be more than happy to give it a shot
: Re: need some more suggestions on cracking a wpa2 handshake capture...
: xsysudo October 02, 2015, 05:47:04 PM
@OP you can also send the handshake to me via direct message and I'll be more than happy to give it a shot

PM failed. Not sure if I can post the link of the cap file here... Valid for 48h
http://expirebox.com/download/b4c40b16419a7ae2dd010c3dbef1b0a7.html