WPA / WPA2 Auditing Service

Discussion in 'Community Services' started by Mr. Penguin, 11 Apr 2013.

  1. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    I tested both your handshakes (AP and negar) and found the key for one of them:

    negar:84dbac778dde:bc34004383b8:13531353
    --- Double Post Merged, 15 Apr 2015, Original Post Date: 14 Apr 2015 ---
    Please specify the country of origin.
    --- Double Post Merged, 16 Apr 2015 ---
    I have tested both and found the password for one of them:

    hudzaifahzh@unifi:b09fbad49d14:ccb255d743db:17981699
     
    • Like Like x 1
  2. a4apple

    a4apple Active Member

    Joined:
    23 Mar 2014
    Messages:
    59
    Likes Received:
    36
    Anyone can help me with this would be much appreciated. ;) Thanks in advance
     

    Attached Files:

    • Like Like x 1
  3. Sagaaboyz

    Sagaaboyz Active Member

    Joined:
    16 Aug 2014
    Messages:
    36
    Likes Received:
    31

    Attached Files:

    • Like Like x 1
  4. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    I remember testing these two previously without any results. I will let somebody else try out their word lists.
     
    • Like Like x 1
  5. clarkswalabis

    clarkswalabis Member

    Joined:
    27 Feb 2015
    Messages:
    48
    Likes Received:
    17
    hai dude.attach here my handshake.please try find for me and i want say thank you so much.
     

    Attached Files:

    • Like Like x 1
  6. a4apple

    a4apple Active Member

    Joined:
    23 Mar 2014
    Messages:
    59
    Likes Received:
    36
    It's new one. I guess they changes the password. This is urgent, I cant use internet service and I have assignments to do :( Thanks to those who help
     
    • Funny Funny x 1
  7. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    Both were found after testing!

    kyh55@unifibiz:88329b11ebfd:94fbb3b7aef1:66191689
    whyeautogarage@unifibiz:90187c164b0d:94fbb3bfd37d:whyeautogarage
     
    • Like Like x 1
  8. Mr. Penguin

    Mr. Penguin Administrator
    Staff Member VIP Admin

    Joined:
    18 May 2012
    Messages:
    3,093
    Likes Received:
    1,268
    Fantastically secure password here. I have updated the rules of this thread:

    Rules
    1) Do Not Be Lazy - Spend 1 hour trying to crack yourself
    - Do some research to see if there are any vulerabilities and methods of hacking

    - Have your own small wordlist of commonly used passwords. Also try the network name as the password. Yes people are lazy and stupid. Take advantage.

    - Try commonly used password crackers Like Dumpper / RouterPWN that uses default algorthms to reveal the WPS or WPA keys

    - If you have a really good GPU / Graphics card why not download EWSA and try yourself? A 8 digit numerical password can be cracked in under 10 minutes

    - Use the latest Pixie Dust attack. Works great and you can crack Ralink, Broadcom, Belkin, D-Link and Realtek WPS enabled APs within seconds and offline too.

    2) If you crack something share it
    - It is always good to discover new exploits and patterns in networking. If your password seems somewhat of a default algo share the:
    Code:
    Select All
    a) Format: e.g: hex 8 digit or lowercase nine letters etc b) Network Name: c) MAC Address: d) Country: e) Router Model: f) Brand:
    Tip: See a router? take a photo of the back of it if it has the default password listed. This is how the Netgear vulnerability was found: https://xiaopan.co/forums/downloads/netgearxx-wordlist-by-gearjunkie.415/

    3) Try an online cracker, free or paid
    Heaps online, just need google WPA cracker online and so forth: http://goo.gl/29yojD

    4) Make it Easy
    a) Clean the cap
    b) Do not upload cap files to dodgy file sharing sites
    c) Ensure that a handshake was captured
    d) Do not send personal messages to users on here, keep it in this thread
    e) Do not continually ask for your cap/s to be cracked. Once is enough
    f) Do not double post
    g) If someone helped you, consider sending a donation to them to say thank you for their time and help.

    5) Provide the following information, more detail the more we can help you
    (Use this as a template and fill as much as you can for each network):
    Code:
    Select All
    a) I have attempted to crack the network/s using the following methods: b) I have tried the following password/s formats: c) Mac Address: d) Network Name: e) ISP: f) Model: g) Country: h) Phone number format/s: i) I believe the network could be in this format/s: j) I believe it to be a default password? Yes/No:
    [BCOLOR=#ffff99]Failure to break any of the rules above may result in a forum ban.[/BCOLOR]

    Common Formats
    Code:
    Select All
    Phone numbers Lower case a-z Numbers 0-9 Mix of a-z 0-9 Hex A-F 0-9 MAC Address of the AP
    Length
    Typically 8,9 or 10. Anything outside these isn't feasible to crack affordably with current hardware and technology. When a password contains random symbols, numbers and letters this becomes not feasible as well


    6) Tools:
    a) Dumpper: http://sourceforge.net/projects/dumpper/
    b) Pixie Dust: https://xiaopan.co/forums/downloads/pixiewps.426/updates
    c) AutoPixieWPS: https://xiaopan.co/forums/downloads/autopixiewps.429/
    d) EWSA: https://xiaopan.co/forums/downloads/elcomsoft-wireless-security-auditor.399/
    e) Router Pwn: http://www.routerpwn.com/
    f) Mac Address Finder: http://hwaddress.com/
    g) Acrylic WiFI: https://www.acrylicwifi.com/en/wlan-software/wlan-scanner-acrylic-wifi-free/

    7) Helpful Threads / Resources / Forums
    a) Mr. Penguin's Guide to Hacking WPA / WPA2 with Xiaopan 0.4.5 + Minidwep + Password List
    b) Dummies Guide to Create a Phone Number List for WPA Attack
    c) WPA Handshake and Dictionary Attack
    d) Resources Manager
    e) Online Tools
    f) Dictionary, Passwords & Wordlists
    g) oclHashCat Plus

    Also note that you are leaving yourself open to publishing MAC addresses which can identify you as the owner or identify you nearby. Use at your own risk. We will not delete any caps you upload.
     
    #748 Mr. Penguin, 19 Apr 2015
    Last edited: 20 Apr 2015
    • Agree Agree x 2
    • Like Like x 1
  9. TrueNorth

    TrueNorth Active Member

    Joined:
    4 Apr 2015
    Messages:
    7
    Likes Received:
    7
    Thanks, my mistake. Previously I believe that service provider only used 2wire so I just assumed that's what it was brand. Glad you caught that.

    Wow thanks! That was super fast for an 8 digit upper hex. I didn't even check back here for a few a few weeks 'cause I figured if anyone was even able to crack it, it would take a really long time.
     
    • Like Like x 1
  10. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    I found two of them :)

    phlee5502@unifi:28107b5d7448:485a3f20a65d:09118515
    noorshamsina@unifi:707630d1ac80:ccb255d7c5cb:maryam123
     
    • Like Like x 1
  11. clarkswalabis

    clarkswalabis Member

    Joined:
    27 Feb 2015
    Messages:
    48
    Likes Received:
    17
    Dear dude..thanks with many harm.i also trying but my worldlist not found..thank you for teaching me..


    Sent from my iPhone using Tapatalk
     
    • Funny Funny x 1
  12. DetmL

    DetmL Well-Known Member

    Joined:
    26 Jan 2015
    Messages:
    5
    Likes Received:
    4
    Please try this two handshakes. Thank you.
     

    Attached Files:

    • Like Like x 1
  13. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    I remember testing Alice just last month without any results. Let me know the country where these captures originated so I can try out phones numbers too.
     
    • Like Like x 1
  14. DetmL

    DetmL Well-Known Member

    Joined:
    26 Jan 2015
    Messages:
    5
    Likes Received:
    4
    Thank you gearjunkie for giving your time. I'm from India. You can try out the following numbers from my area: 9436, 9863, 9774, 8974, 9436, 8794, 8014, 8118, 7308, 9089.
     
    #754 DetmL, 22 Apr 2015
    Last edited: 22 Apr 2015
    • Like Like x 1
  15. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    Thanks for the information. I am testing your handshakes now. I have a question on how you the public refers to phone numbers in India. Do they typically just say my phone is 9436123456 (10 digits) or would you also add in a 0 to the front and say its 09436123456 (11 digits)?
     
    • Like Like x 1
  16. DetmL

    DetmL Well-Known Member

    Joined:
    26 Jan 2015
    Messages:
    5
    Likes Received:
    4
    We just start from the number itself without the 0.
     
    • Like Like x 1
  17. Master.BoOsS

    Master.BoOsS Well-Known Member

    Joined:
    25 Jul 2014
    Messages:
    46
    Likes Received:
    44
    I don't have any request, just wanted to say thanks @gearjunkie
     
    • Like Like x 2
    • Friendly Friendly x 1
  18. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    I appreciate your kind words.
    --- Double Post Merged, 26 Apr 2015, Original Post Date: 26 Apr 2015 ---
    Sorry but I went through the phone numbers you mentioned, 8 digits, 9 digits, and my word lists without any luck.
     
    • Like Like x 1
  19. DetmL

    DetmL Well-Known Member

    Joined:
    26 Jan 2015
    Messages:
    5
    Likes Received:
    4
    Thank you gearjunkie for you time and effort.
     
    • Like Like x 1
  20. a4apple

    a4apple Active Member

    Joined:
    23 Mar 2014
    Messages:
    59
    Likes Received:
    36
    I couldnt try anything on myself because i have a very old laptop which i used it for my college work. Now i dont have any access on my place but library. So i have to stay in the library until late night and go back to my place. So please help me :( I think that the unifi is numbers, the another one has wps on it. I tried wps with reaver and bully but my laptop hang on halfway.. so i couldnt continue it. :( Thanks in advance.
     

    Attached Files:

    • Like Like x 1

Share This Page

Loading...