ubnt解决方案
楼主: chinajack

[分享] 直接搞定WPA和WPA2 无线密码P解工具

   关闭 [复制链接]

351

回帖

677

积分

118 小时

在线时间

中尉

注册时间
2009-6-13
金币
298 个
威望
1 个
荣誉
0 个

尚未签到

发表于 2009-12-8 22:40 |显示全部楼层
先看看 搞不定再找楼主
回复

使用道具 举报

351

回帖

677

积分

118 小时

在线时间

中尉

注册时间
2009-6-13
金币
298 个
威望
1 个
荣誉
0 个

尚未签到

发表于 2009-12-8 22:41 |显示全部楼层
假的。。。。。。。。。。。。。。。。。
回复

使用道具 举报

206

回帖

711

积分

284 小时

在线时间

中尉

注册时间
2009-11-5
金币
476 个
威望
0 个
荣誉
0 个
累计签到:31 天
连续签到:0 天
[LV.50]初入江湖
发表于 2009-12-9 14:15 |显示全部楼层
谢谢楼主 分享
回复

使用道具 举报

154

回帖

275

积分

45 小时

在线时间

少尉

注册时间
2009-3-13
金币
116 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-9 15:21 |显示全部楼层
有用吗?用过的说说
回复

使用道具 举报

134

回帖

279

积分

31 小时

在线时间

少尉

注册时间
2009-10-19
金币
142 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-10 00:15 |显示全部楼层
不懂用,太贵了!!!
回复

使用道具 举报

611

回帖

2489

积分

117 小时

在线时间

少校

注册时间
2009-2-14
金币
1827 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-10 10:42 |显示全部楼层
不管好不好,先鄙视下楼主
9 W  V, I$ {/ A, w: {我不会下的
回复

使用道具 举报

252

回帖

1058

积分

43 小时

在线时间

上尉

注册时间
2008-7-25
金币
766 个
威望
6 个
荣誉
0 个

尚未签到

发表于 2009-12-10 12:23 |显示全部楼层
真的有这么神奇的工具么?这个要学习一下了。
回复

使用道具 举报

75

回帖

143

积分

22 小时

在线时间

上等兵

注册时间
2009-12-6
金币
60 个
威望
1 个
荣誉
0 个

尚未签到

发表于 2009-12-12 12:17 |显示全部楼层
没钱啦。。。
回复

使用道具 举报

25

回帖

49

积分

27 小时

在线时间

新兵上阵

注册时间
2009-12-6
金币
19 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-12 17:11 |显示全部楼层
不是吧  这么贵
回复

使用道具 举报

100

回帖

309

积分

18 小时

在线时间

少尉

注册时间
2009-10-28
金币
203 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-12 23:00 |显示全部楼层
呵呵     ,妈的全是EN
回复

使用道具 举报

100

回帖

309

积分

18 小时

在线时间

少尉

注册时间
2009-10-28
金币
203 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-12 23:00 |显示全部楼层
能不能有用啊。呵呵
回复

使用道具 举报

399

回帖

1492

积分

105 小时

在线时间

上尉

注册时间
2009-7-23
金币
1047 个
威望
0 个
荣誉
0 个
累计签到:3 天
连续签到:0 天
[LV.20]漫游旅程
发表于 2009-12-13 00:23 |显示全部楼层
coWPAtty for Windows MAIN:
5 x9 z+ T% V* b# L( A* d- G. a$ H. W. R& X$ k% n2 s  `  i7 m
"coWPAtty is designed to audit the pre-shared key (PSK) selection for WPA networks based on the TKIP protocol." - Joshua Wright.
! v9 ]4 |/ y" c! T6 K/ N7 }, v& T. o3 E0 [) J8 m. k8 r1 [1 Y/ _
6 `) }" R' i1 e. F) Q8 ~' C- P4 d3 S! [8 a/ M5 {% \  J
Project Homepage: http://www.willhackforsushi.com/Cowpatty.html # }% i6 ~' e* n, n
4 W7 L, ]4 S* |* w  W8 o  q
8 U6 X4 Q* j: L" g, [. B
4 z4 ^+ c9 b5 v  F, G" N
6 c4 R9 C3 u- H) E% u/ M0 l# y( z0 X$ U+ C/ S. y1 A  i8 T- V% E& K4 D4 ]
Local Mirror: Cowpatty-4.0-win32.zip  MD5: aa9ead2aacfcc493da3684351425d4c6
1 W" _) @$ X4 q. _2 z, R# R  }6 y9 n
" X. P1 x! M) g- S( c2 J
8 E$ l4 M& W  f1 E! B- }' e/ g; r! ]6 V6 [: u2 Q  M! G& L6 F3 _& v, Y! r5 P7 X0 U/ Q! g

7 M  k0 }- ?1 s9 T  ScoWPAtty Dictionary Attack* {2 U5 w3 l, o

/ N# y# P3 e& {5 q! W6 F: `: v) |+ G4 z6 y9 O
( x: Z  h% b# T+ q% ^) ]/ v( b( m
8 [. Q- B; D! |5 g! H9 MPrecomputing WPA PMK to crack WPA PSK# c! ]* Q5 }! _
* c3 @3 n5 g* k5 i2 k
8 L  @* c$ r1 y  V- O: d8 U6 V; r  `2 ^9 {! s
$ o. {) ~6 N* j$ J
coWPAtty Precomputed WPA Attack- x* k6 [* H( L; \6 G3 n

( O1 z; Y  Y" q$ c2 b* U
8 J+ W5 s$ c* V, e# `/ g7 E, r0 |2 h4 X+ S9 A
6 h7 T' `  F1 O: F2 [1 J; `coWPAtty Recomputed WPA2 Attack; p3 R& p  L3 }4 \. v( q
- [* R( y) X4 g% p7 G! c) @- A
# A% K$ U3 S! s4 w
( b3 O- G% L( _6 }2 V+ L% V2 M8 I7 v, s* z
& h& G5 S& _' G, ~) vcoWPAtty Tables
0 P4 e- ]5 D3 Q5 m* t& ^0 ]) k6 W4 P* ~5 x. o3 z
  J  Z6 w0 w* B6 l! i: K
. l+ n5 W# G; i$ K# }coWPAtty Usage:/ t: F6 i- x/ p6 b) R
! P/ i* _1 j; a3 c
, J) M  C4 J) B8 ?5 a1 d. k3 t) z% k- i/ d& D ( z+ A& s, x0 t( m- d- R
* x" _2 c/ a/ h: \coWPAtty Dictionary Attack:: u, g: R' Q( j- T5 Y  i1 O1 g2 T
( O7 J4 B0 m6 M- z; `5 S) M" W: r1 {$ [8 @/ w1 L
Toperform the coWPAtty dictionary attack we need to supply the tool witha capture file that includes the TKIP four-way handshake, a dictionaryfile of passphrases to guess with and the SSID for the network.0 P; H/ y) K7 g, q

1 B, U. J9 q. ]0 P( S2 I3 h0 x/ j. y2 Z' {% b
9 ?! W( A% f6 S9 b* `) }$ a! \- }8 T5 d7 i. W
In orderto collect the four-way handshake you can either wait until a clientjoins the network or preferably you can force it to rejoin the networkusing tools like void11 or aireplay and capture the handshakes usingsomething like kismet, ethereal or airodump.
2 {- v" R  H/ i, z$ |3 z9 ~  _' j0 p# }! X& V: H9 U
/ x& L0 O1 M  v6 V* g9 j, e3 Y% k* k: h  |& Y2 V: K

: I' x8 a9 }9 c7 ]) mcowpatty -f dict -r wpapsk-linksys.dump  -s linksys
6 o# D% x! I5 `5 |! a1 l
8 t: r& V' r1 u8 A1 E
; ]6 D, u, F: p5 U6 f) y' N! }3 L2 E0 d$ Y& o: t  m/ H* Y, T  B
9 x  t3 n3 s' e1 r, b% J% I  _/ n3 p. ~; A3 i, q* w) z
8 j" O. D0 F( w3 }$ p/ r" Q" o# n( r# M: {
- p! P" X. f; e. E6 `2 I3 n* S" L6 F+ }' F0 v: Q6 y
8 m* j; \* n/ E7 ^5 S* o+ F  {+ r( @$ a9 ?
As youcan see this simple dictionary attack took 51 seconds, we can speed upthis process by precomputing the WPA-PMK to crack the WPA-PSK (seebelow).! ^  q) w, k0 H! o( y+ _1 Y  x
6 n. x" Z% U/ W7 R" N, B! L
7 v" n2 Y6 e. \
: @; x* X/ J; M
  o1 W3 x! ]7 i8 n0 Ywpapsk-linksys.dump is the capture containing the four-way handshake
4 F- C+ \& w2 ^# K# i( I3 C
5 @4 M. F" P! M  H3 y* Z0 N. I5 h9 e" V/ f  T$ p- o. z3 |" r% N
9 ~5 F: N: O- R7 k3 P/ k. N
dict is the password file) }' i9 K8 u  I  l0 @& Y* k$ c

! Z/ w1 }! e" n3 \5 t- b* d" h5 J, ~) W: L! d6 I& f' h5 w9 K. g) ?
  L; M$ S0 b( ?* p. q) Q+ Y* T1 k8 [9 n: f: b
linksys is the network SSID# H; ]3 K' R2 L- I5 e9 }7 J

( C& A; o* {: j# i9 O( i! t$ E! \- ~: x0 M
' V& W2 D; {# f7 H  Z. m% @4 y6 r- `( c* R* e( I
2 w5 G5 L  ]. C6 D( hPrecomputing WPA PMK to crack WPA PSK:8 u* I$ Z, S& i7 j2 G0 J
. ^% z1 ^) f3 h/ M: {" Q
2 h) y; C% l! Y: m6 zgenpmkis used to precompute the hash files in a similar way to Rainbow tablesis used to pre-hash passwords in Windows LANMan attacks.  There is aslight difference however in WPA in that the SSID of the network isused as well as the WPA-PSK to "salt" the hash.  This means that weneed a different set of hashes for each and every unique SSID i.e. aset for "linksys" a set for "tsunami" etc.
; n, d5 T/ Y0 B2 u9 Y- N' ]: I
7 A* x2 O; m+ l8 j2 n9 v6 O$ M8 }2 q
( b* E: C6 ]5 T3 }# e+ f9 k! I8 C+ X# o5 Y  I0 x* \4 |1 f! b3 g! F) ?& X# n2 M  _% y6 t& T* R4 b. R
& J0 x% `" Y. v) b% o% j" t+ x
So to generate some hash files for a network using the SSID cuckoo we use:6 i& o  \! H: v% `& [# ~4 J

. B" ?! c/ f$ u5 Z) W9 U; O% Z. {2 I  j' Q0 Z6 e, W; l' Y$ }# l) E$ T4 U9 \7 V" C
6 ]4 A4 a. N% [) x
8 t; J: I( l% B6 C
* X1 N. X# r: z/ r" r5 s! Kgenpmk  -f  dict  -d linksys.hashfile  -s linksys  * o' D# V& y6 J& u: A, ]

5 S! l% \$ F5 ~9 _% _' B+ P5 G* \8 M4 z7 x0 S( b3 I- F. P# |( F
* z. V" k8 l$ R+ @) Q8 i6 H( H# t- p! \" {! f* [+ y: ?) w# g8 j
- ?2 i8 E  ]3 Y. R4 Q0 N3 |6 ?0 Z
# w$ z: B/ e+ `# M! o- P: M8 E) H9 J1 B" D& c% h2 v0 J

6 D# ]% Z- L9 \& O' c* F
# H- d! C/ i& K+ h( _  O: }5 Q5 m" k/ ?7 H) f& S6 f6 e+ f" O3 f, s
1 F( c$ E, W  ?* s6 Y
3 G9 ]9 t( _9 _3 u: x. gdict is the password file# K0 c& @* g' S' R9 l) a' D/ ?

9 X! b1 @* A: U1 v! Q. v1 \4 H/ j# W% ^1 y) G
% ^7 Y* b8 f& c8 R3 y0 y5 J  D
9 k7 _6 @; p7 i$ s5 `linksys.hashfile is our output file3 @4 ]- S* W0 w7 g; v1 I0 x3 Y
1 N, a* \; b( H1 x0 B
9 C1 `0 I$ m; E; |/ y3 e3 O5 W) R0 |4 w

1 z! |5 z% |  o. R6 d* Ulinksys is the network ESSID
( M: ?! Z0 K' J4 G- ~( h! z- }. I0 J1 v, L) v; S

, n: e0 D( E! h; o1 s$ Z. N6 v6 {7 b0 b5 H' {* S; ^4 B0 |' }, {% d+ S' ]
( P8 a% S% `0 r5 r( XcoWPAtty Precomputed WPA Attack:# ?/ x) d2 _& C+ W/ i% [; q4 T$ w* o% w) i8 d1 d
' ?( E; O# y. [+ U) s5 B
Now wehave created our hash file we can use it against any WPA-PSK networkthat is utilising a network SSID of cuckoo.  Remember the capture(wpa-test-01.cap) must contain the four-way handshake to be successful.
& p( a3 y" ~/ s6 x  y$ G2 t- l5 j
: x2 Q+ ]" x$ V9 ?7 [3 m" r/ l3 a2 G; @+ I# A1 Q) ~9 F- [' \- i/ [1 a
0 K; o" p/ Z+ I5 u+ @! H2 d) T4 k" w6 u! _0 z' S

7 l) N/ Z, o3 x( f  c& |. @cowpatty  -d linksys.hashfile -r wpapsk-linksys.dump  -s linksys  0 q' j* V6 K/ c- H, H- E9 g
" ?4 n5 b! R) V" m7 K! f, O7 Z. V9 k3 s8 u
+ {# d  \& b( s, m, N5 I9 P8 F4 `( o8 l: y1 {

6 c: p$ ~# N: F+ w3 a9 i  i6 J. r: B7 A
$ D7 R" ]& U* m$ `: E( n
& R1 V1 X  u4 A# O! Q4 Z# z, z3 _, ^9 [' }
, h7 c3 |5 D' C  |) {
# }( e$ }9 ?( M' |! ]9 l
3 w, Y1 o+ m, t4 _wpa-test-01.cap is the capture containing the four-way handshake
3 o2 {1 a- J( p6 H6 r$ ^/ q8 r
1 d# C" c+ R6 G3 c7 L7 ?5 E1 L. {  e2 R  w8 A3 n% x7 S% K4 T* k, d" t" m6 T6 z

! t  K+ d; N2 l; F" [4 l& z% Plinksys.hashfile are our precomputed hashes
0 n  {2 Z# R0 |5 ^! [. u: k. j
! E$ F8 w/ _  f) g8 J" Y; U% }4 |0 I
; e- M" y* t# g+ i' Y# b8 K1 _, e! d+ ^
linksys is the network ESSID8 X  j. [# P3 u$ Q

' A% v7 Y& u' J* p+ H! o  [1 |3 a8 E8 y0 l& e
+ T' _( O5 z5 n) S, p2 l
: q! o; [- e' |0 U# w) ?( }2 j( u# n9 x& x  ?( W1 U3 r9 K6 \2 O, o- M
Notice that cracking the WPA-PSK took 0.04 seconds with the pre-computed attacked as opposed to 200 secondswith standard dictionary attack mode, albeit you do need to pre-computethe hash files prior to the attack.  However, precomputing large hashfiles for common SSIDS (e.g. linksys, tsunami) would be a sensible movefor most penetration testers.7 b0 n3 {- o+ ~
: B0 x, L$ m% \7 p& G: ?% C
" k& a: p/ u. L4 |* C0 e% W( s( [7 S. ]
1 z4 O: }- l$ l- F$ O* _$ C3 _$ f* ~  n. H) W% A$ G. n# C
coWPAtty Precomputed WPA2 Attack:; B1 P' y. I) z  ?5 a
0 P$ y5 O0 Z3 d1 o% O3 m0 G8 `5 f: `$ n# Z, o6 a
coWPAtty4.0 is also capable of attacking WPA2 captures.  Note: The same hashfile as was used with the WPA capture was also used with the WPA2capture.5 {* ?" }, ?7 {  w% h0 o8 N

$ C! J" Q( _' |5 |6 P% H9 o- W9 m7 }. Z' Q! B1 S
% }6 Q! G3 M' s: u+ K. |6 w" a0 t1 u7 s) o- A9 n# ]' \* `
cowpatty  -d linksys.hashfile -r wpa2psk-linksys.dump  -s linksys
* |# }7 Z6 V$ K! ^9 U3 \1 x$ Q# v* J3 v" I; j' k

9 S) a9 X% A* C0 f; G* X9 x' b# N3 J$ o* S9 q1 v. h6 ?8 P, u) C
% H& \2 y# z. C7 u
' D( o5 o) t5 ~1 ]
# h: S0 |6 {$ p$ h6 _3 }8 ?/ U4 W! a9 j0 [* {# V5 K
% g6 _# a! f  X( K1 ?
" W- P! f8 j: s# L2 r  l  ], G: ]; ?2 K3 Z
wpa2psk-linksys.dump is the capture containing the four-way handshake2 Z7 d4 S$ q1 @' }# i
$ K) [; \9 a& Y7 Z
6 O8 l6 N, C/ w, B5 E7 f8 R8 N2 ?  x) Y) _- ?1 }1 V# `

$ P! }& O6 T/ M- Q1 K/ [/ L9 adict is the password file; z* G) Y' T; Y; ?' O  Y
: ?4 y+ O8 B# p. H
6 E% `/ y: Y# I2 b
  t' Y$ F7 ]) [: m% U8 c7 n/ c, d6 ]
linksys is the network SSID
" t7 k& \  N) `$ K/ |6 h
" X- @* c9 y% o: {+ S! m& n4 m! a6 a# |; u8 }( v$ R1 Q/ `+ ^2 l; Y
  _! m, M' b9 {9 @, A8 {
9 F$ \' `+ C2 H4 JcoWPAtty Tables: ' z4 o; i; w$ a9 T. V, |, `
2 I; ], f: ~. u& `4 t, P8 gThe Church of Wifi have produced some lookup tables for 1000 SSID's computed against a 170,000 word password file.  The resultant table are approximately 7 Gigabytes in size and can be downloaded via Torrent:
: C7 z6 z& Q' p) z* _) A+ u  ~( W) a2 a, \1 J8 N  b9 v  e! c+ W0 y6 }0 e. M7 k* j! h2 o) n. S; V% t
http://torrents.lostboxen.net/co ... atty-4.0_2006-10-19
0 k3 B" G* l3 H5 W! N( _+ F4 M3 K9 d5 d" M$ V. p0 u2 ^' \" b( L) c1 v. ^2 t8 J
4 l% Y- E. {3 Z5 w9 B$ PA 33 Gigabyte set of tables are also available: http://umbra.shmoo.com:6969/1 P" V6 G( J9 W
# T+ W8 R' N& Z# |) i6 L  A6 J3 t- q, E; ^0 A0 Z
, Q# N6 K5 n+ B- \( G& nOr you can buy them via DVD, direct from Renderman (initiator of the project): http://www.renderlab.net/projects/WPA-tables/. J% }2 r' B; I6 C+ ~; `
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册 微信登录

本版积分规则

Archiver | 手机版 | 无线门户 ( 粤ICP备11076993号|粤公网安备44010602008359号 ) |网站地图

GMT+8, 2026-8-17 19:16

返回顶部 返回列表