|
|||||||
| Wireless Specific topics related to the attack & defense of wireless systems |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
||||
|
Very interesting thread you got there prez. Very informative. So it took you about 30 minutes to create the hashes...which shaved you off about ...34 minutes...hmmm....interesting.
__________________
--=Xploitz=-- ®
|
|
|||
|
Really interesting dear Prez98....
around 35 min for all....it's really short........ 64563.39 passphrases/second... it' really fast.... Nice...
__________________
|
|
|||
|
This should be in reply to the WPA Brute forcing thread in the specialist>wireless section of the forums, but I'm too noob to post there still.
Prez mentioned a 1mill+ length password file used to create the hash tables in conjuction with the 1k most common ssid's. A couple questions regarding that: Would there ever be a situation where the ssid is not known? If we know the ssid and take a day to compile hash tables, wouldn't that be faster than running the hack with 1,000 times the data in the hash list? Or am I misunderstanding the speed at which cowpatty operates a hash table. To restate the question more clearly - Would it be faster to use the 40GB hash tables with 1,00 ssid's, or to build a hash table for the single ssid in question? Also, is the 1mill+ password file available for download? Thank you -Ethernull |
|
||||
|
Moved to existing thread.
Quote:
This link should work for you.
__________________
theprez98 "I want peace on earth and goodwill toward men." "We are the United States Government. We don't do that sort of thing!" Last edited by theprez98; 07-19-2007 at 02:19 AM. |
|
|||
|
well the 2 in conjunction is the best
i use airolib to maintain an essid / pass sqlite database i precompute this table(so when you add a new essid it's 99, xxxx % computed) first step is verify if Victim essid is in the list.... if it is launch aircrack in conjonction with database........ if not in list ..... then add essid to database and recompute the table.... it's fast(airolib compute at about 100 k/s) because you have only a number of pmk to compute equal to number of passwords in database .... then use aircrack with the database....... hope it's more clear.... im french so it's not easy for me to explain something in english...... for the case you have no ssid , you can do a deaut attack when the client will reconnect you will catch this ssid........ hope helps
__________________
Last edited by shamanvirtuel; 07-19-2007 at 02:21 AM. |
|
||||
|
The name of the file doesn't matter, as long as it's a standard cap format and it has all four parts of the handshake.
__________________
theprez98 "I want peace on earth and goodwill toward men." "We are the United States Government. We don't do that sort of thing!" |
|
|||
|
Will when i did the WPA crack, airodump registered a handshake on the top right corner of the konsole with the MAC of the AP.
|
|
||||
|
Ok..I'm having very similar issues with cowpatty that Funnyman is having, except it says.....
Code:
{-=Xploitz=-} ~ # cowpatty -r /root/xploitzpsk-01.cap -d /root/testhash -s "Xploitz Network"
cowpatty 4.0 - WPA-PSK dictionary attack. <jwright@hasborg.com>
End of pcap capture file, incomplete TKIP four-way exchange. Try using a
different capture.
{-=Xploitz=-} ~ #
Code:
{-=Xploitz=-} ~ # aircrack-ng -w testhash -b 00:18:F8:B5:F2:D6 xploitzpsk-01.cap
Created thread for id 0.
Opening xploitzpsk-01.cap
Read 0 packets.
Aircrack-ng 1.0 r611
[00:00:02] 108 keys tested (49.50 k/s)
Current passphrase: [*viva-voce\Y
Master Key : 0F EE 88 1C 15 6B 0F 15 C5 58 86 3F 05 73 91 D7
96 02 17 6F A1 59 9A AA DA 1C CD 3B 4C D4 CC E0
Transcient Key : 0C D2 41 22 16 37 3F 63 2D 9F FE 6A FE 6F 1A 65
A3 98 EE 09 4F 16 74 6F CD E2 12 92 6F B8 AB CF
13 1A 86 DE 8C 29 F5 ED A6 0B 49 73 8F 0A C1 11
EE 13 9E 35 DC A2 E0 E4 98 8F D7 68 1C 8A 71 22
EAPOL HMAC : D8 B2 15 53 46 CF A7 2C 52 DC 5C 83 CA 79 74 BD
Passphrase not in dictionnary
. Now I've tried deauthing myself.... and I've tried catching the handshake without deauthing by powering up my other laptop and connecting to the internet..I KNOW that not deauthing and powering up my laptop WILL CAPTURE the 4 way handshake in ENTIRETY..i verified this in wireshark as well..but heres the catch...if I substitute my xploitzpsk-01.cap with the test one in /pentest/wireless/aircrack-ng/test/wpa2.eapol.cap the ****er (cowpatty) will work!! WTF??? This would suggest that my capture didn't catch the 4-way handshake..but wireshark says I DID when I opened my xploitzpks-01.cap file!! This is very frustrating because aircrack will let me but cowpatty won't. If there was an cowpatty forum Id post my issues there..but its Church of WIFI and I cant access the regular members forums cause I lack membership. Someone..please throw me a bone here!! Something...anything.
__________________
--=Xploitz=-- ®
Last edited by -=Xploitz=-; 07-27-2007 at 08:11 PM. |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|