NETGEARXX wordlist 1.08

Extremely effective WPA default wordlist

  1. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    I removed it because I cannot find any hard evidence that it is the default for any Netgear wireless routers. Please let me know if you can find any images proving its a default.
     
    • Like Like x 1
  2. mezcalsonique

    mezcalsonique Active Member

    Joined:
    11 Jul 2014
    Messages:
    25
    Likes Received:
    25
    I concur with gearjunkie on this after testing close to 100 NETGEARXX access points for work these past few months. I have recently found two NETGEARXX boxes that have used 'adjective_noun_1d' though... BTW, can anyone tell me what the default format for plain NETGEAR (no suffixed numbers after "NETGEAR" on the eSSID) are? I had thought they used 'adjective_noun_1d' & have tried all other combinations without any luck thus far... Thanks, ms
     
    #162 mezcalsonique, 2 Jul 2015
    Last edited: 2 Jul 2015
    • Like Like x 1
  3. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    Some Netgear boxes does use the default of adjective+noun+1 digit. I find them in about one out of every 20 NETGEARXX boxes I test.

    There is no default format for the plain NETGEAR boxes as far as I know.
     
    • Like Like x 1
  4. mezcalsonique

    mezcalsonique Active Member

    Joined:
    11 Jul 2014
    Messages:
    25
    Likes Received:
    25
    Thank you gearjunkie. I've finally finished running my three NETGEARXX uploads with version 1.04 of your word lists with no joy :( - although I've been told these all use defualt NETGEAR adjective-noun-3digits PSKs, I'm not so sure: in over a hundred boxes tested I've only come accross a couple that haven't been resolved; certainly not three in a row...
     
    • Like Like x 1
  5. olsib

    olsib Active Member

    Joined:
    24 Apr 2015
    Messages:
    5
    Likes Received:
    5
    Thanks from 2 netgearxx one i got one,on netgear03 key was not found,but good work anyway.
     
    • Like Like x 1
  6. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    Go ahead and upload those three NETGEARXX captures. I will test them against my larger adjective-noun wordlist when I get the chance.

    Edit: Nevermind, I saw that they were already uploaded a few posts back. I will run through them tomorrow.
     
    • Like Like x 1
  7. mezcalsonique

    mezcalsonique Active Member

    Joined:
    11 Jul 2014
    Messages:
    25
    Likes Received:
    25

    Thank you gearjunkie - I'd really appreciate that. Since my last post I've come across another three NETGEARXX boxes that v1.04 of the word list can't resolve. I've just uploaded them with this post so feel free to have a crack at them if/when time permits. Have a swell week, mez
     

    Attached Files:

    • Like Like x 1
  8. sigmond

    sigmond Well-Known Member

    Joined:
    24 Feb 2014
    Messages:
    3
    Likes Received:
    2
    dear gear, NETGEAR72 NOT IN VERSION 1.0.4, HERES MY CAP
     

    Attached Files:

    • Like Like x 1
  9. alltsbb

    alltsbb Well-Known Member
    VIP

    Joined:
    5 Feb 2015
    Messages:
    87
    Likes Received:
    76
    Hey gearjunkie, if you wanna toss the the larger dictionary, I'm willing to test some for ya. I finally got my hands on a low end GPU, i can do about 30kh/s with it. AMD R9 M370X (yes, MacBook Pro haha.)
     
    • Like Like x 1
  10. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    I found one with a new adjective:
    NETGEAR27:1040f38a7cce:e4f4c64ae78c:cooltuba772

    Another that is already in the dictionary. I am not sure why you did not find this but can you please try again and let me know the result?
    NETGEAR47:9cd36d00c8d7:ac18263e55a1:curlyonion892

    And the third one that looks like it has been changed from the default format:
    NETGEAR99:4c7c5fd8f84b:c40415713698:topgear99
    --- Double Post Merged, 30 Jul 2015, Original Post Date: 30 Jul 2015 ---
    Thanks for offering to help. This is the larger dictionary without the digits. You have to add either 1 or 3 digits to the end when you are cracking the captures. In oclhashcat, you can use the -a 6 attack mode with the ?d or ?d?d?d masks.

    http://rghost.net/private/847QJCfBS/4c581ebbe5d156bfd36d73927ea8ce83
     
    • Like Like x 1
  11. alltsbb

    alltsbb Well-Known Member
    VIP

    Joined:
    5 Feb 2015
    Messages:
    87
    Likes Received:
    76
    Awesome, If I catch a request before you do, I go ahead and try it :)
     
    • Like Like x 1
  12. olsib

    olsib Active Member

    Joined:
    24 Apr 2015
    Messages:
    5
    Likes Received:
    5
    A have a netgear03 cap and culdnt find the wpa from the file
    --- Double Post Merged, 3 Aug 2015, Original Post Date: 3 Aug 2015 ---
    here is another cap
     

    Attached Files:

    • Like Like x 1
  13. alltsbb

    alltsbb Well-Known Member
    VIP

    Joined:
    5 Feb 2015
    Messages:
    87
    Likes Received:
    76
    There is no valid handshake in that cap...
     
    • Like Like x 1
  14. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    Another new adjective found!

    NETGEAR72:08fc88e143be:6cb0ce362149:manicocean382
     
    • Like Like x 1
    • Winner Winner x 1
  15. olsib

    olsib Active Member

    Joined:
    24 Apr 2015
    Messages:
    5
    Likes Received:
    5
    that dipends i open it with wireshark and in eapol it says key1 key2 key4 maybe is not a 4way handshake but if you open with aircrack is good
    --- Double Post Merged, 5 Aug 2015, Original Post Date: 5 Aug 2015 ---
    i have trying for 3 days non and i cant get another handshake from this ap trust me i have trying almost everything kali slax bt5 but nothing so this is the only handshake that i have
    --- Double Post Merged, 5 Aug 2015 ---
    Immagine.png
     
    • Like Like x 1
  16. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    @olsib I don't have any issues using your capture in hashcat but still nothing was found after testing it against my larger NETGEARXX wordlist. Hashcat only needs a beacon and the first two EAPOL packets to work.
     
    • Like Like x 1
  17. olsib

    olsib Active Member

    Joined:
    24 Apr 2015
    Messages:
    5
    Likes Received:
    5
    Thank you gearjunkie for your patience and time you dedicated for my post,maybe this ap changed the default wpa, from another ap netgear82 wpa is correct breezycheese207
     
    #177 olsib, 6 Aug 2015
    Last edited: 6 Aug 2015
    • Like Like x 1
  18. happyman

    happyman New Member

    Joined:
    22 Aug 2015
    Messages:
    1
    Likes Received:
    1
    I'm looking for someone that has or have fast computers. I came up with a way generate the wordlist. I tried, but I calculated it will take me about a month to generate. I gave up after a day. :(
     
    • Like Like x 1
  19. alltsbb

    alltsbb Well-Known Member
    VIP

    Joined:
    5 Feb 2015
    Messages:
    87
    Likes Received:
    76
    I get around 30kH/s with my card, and with the bigger dictionary and ?d?d?d my time estimated is 2 days, does that seem like too long to you?

    Code:
    Select All
    oclHashcat64.exe -m 2500 --force -a 6 15314_1440252674.hccap netgear_all.txt ?d?d?d
     
    • Like Like x 1
  20. gearjunkie

    gearjunkie Well-Known Member
    VIP

    Joined:
    28 Aug 2014
    Messages:
    454
    Likes Received:
    481
    That time looks about right. Why are you using the --force option though?
     
    • Like Like x 1

Share This Page

Loading...