WPA / WPA2 Auditing Service

Discussion in 'Community Services' started by Mr. Penguin, 11 Apr 2013.

  1. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    Its definitely not 3xxxxxxxxx either. Currently working on the rest of Brazilian phone numbers.
     
    • Like Like x 1
  2. chotani

    chotani Well-Known Member

    Joined:
    3 Nov 2014
    Messages:
    50
    Likes Received:
    44


    Hi Friends
    One more challenge for you..
    ESSID : PTCL-C4B7
    BSSID : F0-82-61-5B-C4-B8
    http://rghost.net/60390380
    Thanks in Advance :mrgreen:
     

    Attached Files:

    • Like Like x 1
  3. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    I have completed my audit with all Brazilian phone numbers (including those starting with 39) without any success. I thought to myself that this is the other 60%. However with some luck, I still found the password :)

    bones:001a3f6a9050:00aa70b59cbd:bones342
    --- Double Post Merged, 18 Jan 2015 ---
    I tried with 8 digits, 9 digits, French phone numbers, and my word lists without any result. I suspect the password format is 10 uppercase hex but I do not have the resources to brute force this combination.
    --- Double Post Merged, 18 Jan 2015 ---
    I went through all four of your handshakes and recovered two keys:

    govindmsc82@unifi:9094e42c9ca4:b86ce87c2aa7:12011988
    yapmun9@unifi:742f688012e2:bc96813a1d93:0149356109
     
    • Like Like x 1
  4. chotani

    chotani Well-Known Member

    Joined:
    3 Nov 2014
    Messages:
    50
    Likes Received:
    44

    Attached Files:

    • Like Like x 1
  5. rdcdt

    rdcdt Active Member

    Joined:
    30 Jun 2014
    Messages:
    29
    Likes Received:
    12
    thank you a lot , for what you do:)
     
    • Agree Agree x 1
  6. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    Sorry, I went through all of them with 8 digits, 9 digits, Malaysian phone numbers, and my word lists without any luck.
     
    • Like Like x 1
  7. birdybike

    birdybike Active Member

    Joined:
    22 Dec 2014
    Messages:
    37
    Likes Received:
    35
    Alright Thanks Gearjunkie.
    --- Double Post Merged, 20 Jan 2015 ---
    Hi Gearjunkie,

    Hope i'm lucky...

    Vendor: unifi (Malaysia)
    Password format: unknown
    SSID: gardener0813@unifi
    BSSID: 94-FB-B3-B6-92-91

    Vendor: unifi (Malaysia)
    Password format: unknown
    SSID: jansoncha@unifi
    BSSID: 70-62-B9-DF-DD-2A

    Vendor: unifi (Malaysia)
    Password format: unknown
    SSID: fathimal1771@unifi
    BSSID: 00-07-27-88-A8-E9

    thanks Gear....
     

    Attached Files:

    • Like Like x 1
  8. a4apple

    a4apple Active Member

    Joined:
    23 Mar 2014
    Messages:
    59
    Likes Received:
    36
    Vendor: Streamyx (Malaysia)
    Password format: unknown
    SSID: Cha Gu Gu
     

    Attached Files:

    • Like Like x 1
  9. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    I see that you did another capture of EvoWingle and this this you even got all the EAPOL packets. Initially, I thought that this was a custom SSID but a little more research revealed that it is a default SSID and the default WPA password is 8 upper hex characters. It took a while to run through all the combinations but I finally got the password for it.

    EvoWingle-C3A3:485ab6c23577:904e2bc8c3a3:8036B51C

    It took me a little bit longer to discover the default password for the PTCL routers as I had to find out who made them first. Once I discovered that PTCL re badges Sagemcom F@st 1704 and 2704 (Jadoo box) routers, it was easy to find out that they also use 8 upper hex characters as the default WPA password.

    PTCL-C4B7:8096b17d1940:f082615bc4b8:615BC4B7

    I did not get anything from your SKYLINK handshake though after going through 8 and 9 digits, Pakistani phone numbers, and my word lists. All I have found so far is that it is a Chinese brand. Let me know if you have some idea of its default password.
     
    #469 gearjunkie, 22 Jan 2015
    Last edited: 27 Jan 2015
    • Like Like x 2
  10. chotani

    chotani Well-Known Member

    Joined:
    3 Nov 2014
    Messages:
    50
    Likes Received:
    44
    Thanks Buddy for both "EvoWingle-C3A3 and PTCL-C4B7".
    I know that was hard but you did that.
    Thank you Very Much.
    For Skylink hand shake old password was below two.when they was using Encryption type WEP.
    I think they have password with 10 to 11 Numeric values.

    3332221110
    11111116320
     
    • Informative Informative x 1
    • Funny Funny x 1
  11. Woei Jing

    Woei Jing Active Member

    Joined:
    22 Jun 2014
    Messages:
    14
    Likes Received:
    9
    Vendor: Unknown
    Model: unknown
    ISP: unknown
    Password format: unknown
    SSID: mofoodmart
    BSSID: FC-B0-C4-BD-65-40
    Default SSID: No

    Vendor: unknown
    Model: unknown
    ISP: unknown
    Password format: unknown
    SSID: NUR_IMAN
    BSSID: FC-8B-97-23-29-60
    Default SSID: No[/QUOTE]

    gearjunkie, thanks for your previous help. This is from Malaysia. I've tested 8 digits both of these but no luck on it. Can you kindly tried this 2 cap with your super PC. my slow pc I only can get 700 pass per sec unlike your super PC 50k per sec. thank you
     

    Attached Files:

    #471 Woei Jing, 22 Jan 2015
    Last edited: 22 Jan 2015
    • Like Like x 1
  12. Iman Alizadeh

    Iman Alizadeh Member

    Joined:
    7 Nov 2014
    Messages:
    24
    Likes Received:
    22
    Hi gearjunkie
    Plz check this cap files.(Country :Iran)
    tnx again
     

    Attached Files:

    • Like Like x 1
  13. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    I have already audited both of them. Please refer to my previous post.
     
    • Like Like x 1
  14. Woei Jing

    Woei Jing Active Member

    Joined:
    22 Jun 2014
    Messages:
    14
    Likes Received:
    9
    owh...thank you for helping to auditing the two caps..sorry i thought you missed my post therefore i repost. Thank you so much for your assistance again. cheers
     
    • Like Like x 1
  15. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    Sorry, I have tested your capture against 8 and 9 digits, Serbian phone numbers, my word lists, and Serbian word lists in without any luck.
    --- Double Post Merged, 23 Jan 2015 ---
    Your luck is improving. Two out of three passwords found!

    jansoncha@unifi:4c21d07d7b24:7062b9dfdd2a:0107604479
    fathima1771@unifi:00072788a8e9:382dd12d970c:fabi1771
    --- Double Post Merged, 24 Jan 2015 ---
    Found it!
    Cha Gu Gu:00300af05106:442a60aede1b:27577898
     
    • Like Like x 3
  16. suheep

    suheep Active Member

    Joined:
    3 Nov 2014
    Messages:
    23
    Likes Received:
    24
    Hi Guys,

    Could you please find out this password?
     

    Attached Files:

    • Like Like x 1
  17. birdybike

    birdybike Active Member

    Joined:
    22 Dec 2014
    Messages:
    37
    Likes Received:
    35
    Hooray! Thanks Gearjunkie!! You are the best!!!
     
    • Like Like x 1
  18. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    BimeDay does not contain a valid handshake so please do another capture if you want me to audit it.

    Out of the other four valid captures, I managed to discover the passwords for two of them:

    maryam:001ffb4cf240:3423ba7fa6e1:15565361
    Hamid:608f5c079d0b:c0a0bb0728f1:09198381095
     
    #478 gearjunkie, 26 Jan 2015
    Last edited: 26 Jan 2015
    • Like Like x 2
  19. birdybike

    birdybike Active Member

    Joined:
    22 Dec 2014
    Messages:
    37
    Likes Received:
    35
    Hi Gearjunkie,

    Hope my luck keep improving...

    Vendor: unifi (Malaysia)
    Password format: unknown
    SSID: wifiunifi
    BSSID: C8-D3-A3-DC-5B-B0

    Vendor: unknown (Malaysia)
    Password format: unknown
    SSID: kibbles
    BSSID: 30-91-8F-4D-8E-68

    Vendor: unifi (Malaysia)
    Password format: unknown
    SSID: limchiachee@unifi
    BSSID: BC-96-81-3A-96-F1

    Thank You Very Much!!!
     

    Attached Files:

    #479 birdybike, 26 Jan 2015
    Last edited: 26 Jan 2015
    • Agree Agree x 1
  20. Devantelim

    Devantelim New Member

    Joined:
    26 Jan 2015
    Messages:
    5
    Likes Received:
    4
    Hi,

    I also want to try my luck here,

    Vendor: unifi (Malaysia)
    Password format: unknown
    SSID: Celcom WiFi-63f1
    BSSID: CC-A2-23-FA-63-F1

    Vendor: unifi (Malaysia)
    Password format: unknown
    SSID: msafi@unifi
    BSSID: CC-B2-55-D7-2A-C5

    Vendor: unifi (Malaysia)
    Password format: unknown
    SSID: juanliew911@unifi
    BSSID: 94-FB-B3-84-7B-25
     

    Attached Files:

    • Like Like x 1

Share This Page

Loading...