ubnt解决方案
楼主: chinajack

[分享] 直接搞定WPA和WPA2 无线密码P解工具

   关闭 [复制链接]

206

回帖

711

积分

284 小时

在线时间

中尉

注册时间
2009-11-5
金币
476 个
威望
0 个
荣誉
0 个
累计签到:31 天
连续签到:0 天
[LV.50]初入江湖
发表于 2009-12-9 14:15 |显示全部楼层
谢谢楼主 分享
回复

使用道具 举报

154

回帖

275

积分

45 小时

在线时间

少尉

注册时间
2009-3-13
金币
116 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-9 15:21 |显示全部楼层
有用吗?用过的说说
回复

使用道具 举报

134

回帖

279

积分

31 小时

在线时间

少尉

注册时间
2009-10-19
金币
142 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-10 00:15 |显示全部楼层
不懂用,太贵了!!!
回复

使用道具 举报

611

回帖

2489

积分

117 小时

在线时间

少校

注册时间
2009-2-14
金币
1827 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-10 10:42 |显示全部楼层
不管好不好,先鄙视下楼主3 F, q3 B7 n$ A8 [# H" d
我不会下的
回复

使用道具 举报

252

回帖

1058

积分

43 小时

在线时间

上尉

注册时间
2008-7-25
金币
766 个
威望
6 个
荣誉
0 个

尚未签到

发表于 2009-12-10 12:23 |显示全部楼层
真的有这么神奇的工具么?这个要学习一下了。
回复

使用道具 举报

75

回帖

143

积分

22 小时

在线时间

上等兵

注册时间
2009-12-6
金币
60 个
威望
1 个
荣誉
0 个

尚未签到

发表于 2009-12-12 12:17 |显示全部楼层
没钱啦。。。
回复

使用道具 举报

25

回帖

49

积分

27 小时

在线时间

新兵上阵

注册时间
2009-12-6
金币
19 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-12 17:11 |显示全部楼层
不是吧  这么贵
回复

使用道具 举报

100

回帖

309

积分

18 小时

在线时间

少尉

注册时间
2009-10-28
金币
203 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-12 23:00 |显示全部楼层
呵呵     ,妈的全是EN
回复

使用道具 举报

100

回帖

309

积分

18 小时

在线时间

少尉

注册时间
2009-10-28
金币
203 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-12 23:00 |显示全部楼层
能不能有用啊。呵呵
回复

使用道具 举报

399

回帖

1492

积分

105 小时

在线时间

上尉

注册时间
2009-7-23
金币
1047 个
威望
0 个
荣誉
0 个
累计签到:3 天
连续签到:0 天
[LV.20]漫游旅程
发表于 2009-12-13 00:23 |显示全部楼层
coWPAtty for Windows MAIN:
! L( {2 ?+ a8 P: u  d" j: d" u* d- G. a$ H. W' r- G3 u) a. H/ d( f; _
"coWPAtty is designed to audit the pre-shared key (PSK) selection for WPA networks based on the TKIP protocol." - Joshua Wright. + Q* M: e: n) ^6 ]4 i
, v& T. o3 E0 [) J8 m. k8 r1 [1 Y/ _
5 w; N; i: b$ ?8 {7 ]) m- V1 l2 O9 Y7 j
Project Homepage: http://www.willhackforsushi.com/Cowpatty.html / y2 i% o0 J5 O4 T7 A( R( M2 O
3 t. i2 k1 r- y6 L6 _- f; t' T

9 T$ C+ g, m; s- y, M4 z4 ^+ c9 b5 v  F, G" N
/ t7 _) H8 o+ A: b0 l# y( z0 X$ U+ C/ S. y1 A
9 u1 N9 u3 `, j! S) qLocal Mirror: Cowpatty-4.0-win32.zip  MD5: aa9ead2aacfcc493da3684351425d4c6( T5 V" }8 O: J; a; Y: S# O
) @/ k+ ]8 ~  J# ~( O, J2 x6 m, \/ S
0 q+ o7 K) \# c0 F5 Y2 e* x6 w
8 E$ l4 M& W  f1 E! B- }' e/ g; r! ]6 V6 [: u2 Q  M! G& L6 F
. D. |& Y, v+ V7 Y" A2 i) n1 ^1 D/ c# |7 K
coWPAtty Dictionary Attack
1 f3 j: ?2 H# k1 [6 F2 `7 V% p9 |
: v) |+ G4 z6 y9 O
. x2 i1 \3 t- @. v- j1 G5 r
3 k" d5 J: B$ h0 R" w( L4 ^Precomputing WPA PMK to crack WPA PSK/ p4 t7 f4 X& N. d

& f% b+ i" F- n  n+ y4 S) }  {8 L  @* c$ r1 y  V. _: U0 _8 C$ _' ^) J, c% ?, U- ^
& b% y' W& @( L; \8 p3 k! t
coWPAtty Precomputed WPA Attack% {. C0 b6 l( U& q: `6 D) @& y

* [. \, G3 j6 W# _% W8 P7 e1 z$ [# i
, r0 |2 h4 X+ S9 A
: C! C" N7 F. @4 h  R' `coWPAtty Recomputed WPA2 Attack
* k8 S! O9 R$ f( V( k
+ V. Y( o% g1 @5 O7 n0 s' n  j0 S+ {6 J! E7 H
( b3 O- G% L( _6 }2 V+ L% V2 M8 I7 v, s* z% x; {7 q1 ^" G, F
coWPAtty Tables  J- ]( g; B5 G* H/ U. e0 P( [

5 D; t% M4 z6 d4 b3 c, _  J  Z6 w0 w* B6 l! i: K( Z, ]2 y$ B1 d
coWPAtty Usage:
8 i+ Y0 `$ [# Y" h! P/ i* _1 j; a3 c* o1 N6 Y$ E) L* n/ _2 h0 t  Y- q! a
3 t) z% k- i/ d& D ( z+ A& s, x0 t( m- d- R
! j" m7 E! e" gcoWPAtty Dictionary Attack:: u, g: R' Q( j- T5 Y  i1 O1 g2 T
" I# A; K$ B$ Q, o
, S* s7 t8 H5 U; k  ZToperform the coWPAtty dictionary attack we need to supply the tool witha capture file that includes the TKIP four-way handshake, a dictionaryfile of passphrases to guess with and the SSID for the network.
2 B  @# i3 x( l) o: B
0 R7 y$ |& c) Z1 I0 g( S2 I3 h0 x/ j. y2 Z' {% b
: C# B: L8 {9 i( N2 I# i: m( n
8 p( N. B; U3 q0 W- I- N9 }In orderto collect the four-way handshake you can either wait until a clientjoins the network or preferably you can force it to rejoin the networkusing tools like void11 or aireplay and capture the handshakes usingsomething like kismet, ethereal or airodump.% X4 B) Y7 m& _$ E9 T6 k

/ n/ ]2 E; @6 ?/ x& L0 O1 M  v6 V* g9 j, e3 Y% k* k0 b! L, @0 v/ ^7 I, q: ]
4 e: s" H" K- [% X
cowpatty -f dict -r wpapsk-linksys.dump  -s linksys
. @3 Q0 T% d! ]: R$ X- x7 I' o4 \/ X7 e3 M

$ {, g( |$ t+ ~5 V# X5 P) a. D5 U6 f) y' N! }3 L2 E0 d
7 ?3 b+ W. y/ g% T9 x  t3 n3 s' e1 r, b% J% I  _
# R6 D0 x7 H$ }+ p) Z, Y$ I8 j" O. D0 F( w3 }$ p/ r" Q" o# n( r# M: {2 E+ _* U/ i) `2 e
" L6 F+ }' F0 v: Q6 y5 ?2 J9 R! z& q* w9 R
9 ]1 @& H/ A4 ]: F6 H; @) |
As youcan see this simple dictionary attack took 51 seconds, we can speed upthis process by precomputing the WPA-PMK to crack the WPA-PSK (seebelow).
) X* K. s, l# I( l4 t
- F- {- b% Q9 \! ?, f% S
/ B# X0 W6 R- J: d: @; x* X/ J; M
! O' R) o* p  X% \2 b! P9 W; {wpapsk-linksys.dump is the capture containing the four-way handshake
$ ^* O' B+ P3 ]; P; \
8 u5 H8 q2 n; w0 N. I5 h9 e" V/ f  T
# K4 R% C, x" G
+ f% Q8 r- Q9 \6 H- m4 Odict is the password file# s/ \6 j# `  z0 H

7 b3 q- M. ]  ~1 }4 {2 D6 o, ~) W: L! d6 I& f' h5 w9 K. g) ?3 Q2 W6 N: i3 J& I9 E; O

6 w7 ^" B" C0 d# Y7 dlinksys is the network SSID9 u2 a9 r2 t( F
8 [9 P- d8 }. t! ^: _! a
) O  a# ?2 m( o1 ]8 K0 V
' V& W2 D; {# f7 H  Z. m% @4 y6 r- `( c* R* e( I
5 Q6 B% b% F+ d6 H( dPrecomputing WPA PMK to crack WPA PSK:
, Q' q, n( [% Q* }1 K6 X8 Z5 ~. ^% z1 ^) f3 h/ M: {" Q
5 {/ M0 h) t8 X" w: f! Z1 g  Y, dgenpmkis used to precompute the hash files in a similar way to Rainbow tablesis used to pre-hash passwords in Windows LANMan attacks.  There is aslight difference however in WPA in that the SSID of the network isused as well as the WPA-PSK to "salt" the hash.  This means that weneed a different set of hashes for each and every unique SSID i.e. aset for "linksys" a set for "tsunami" etc.) v  Y/ I& U9 ^& {  w& j9 V+ R7 v
( @1 W/ @: P& i- g
! W. R5 [: [8 f9 p5 b# \  b3 b
+ X# o5 Y  I0 x* \4 |1 f! b3 g! F) ?& X# n2 M  _
: o+ `. X6 U9 x4 e% L
! L8 z* n: G  \! e7 k4 SSo to generate some hash files for a network using the SSID cuckoo we use:  ^4 Q! M% U/ ]8 a
8 t* }. D( }% Y7 C. ?7 D
. {2 I  j' Q0 Z6 e, W; l' Y+ e! n5 w* s" d# p& i: h; m
# p: c+ ?# l4 j' o
8 t; J: I( l% B6 C0 C, O6 s) I! r# r: ?$ l; s
genpmk  -f  dict  -d linksys.hashfile  -s linksys    v' a! u& a3 ?. I5 p2 f& }
9 w" H0 U. |& Y4 T8 A
8 M4 z7 x0 S( b3 I- F. P# |( F
+ x8 R" P- p0 k/ e! s- y, q# n! K
- ?2 i8 E  ]3 Y. R4 Q0 N3 |6 ?0 Z
; M9 c! Z. G5 {" ^* a/ d* F* H- r, I1 ]. _3 f
, S- Q1 a2 F4 n6 d

6 M: _; p2 R+ P$ M1 S3 d5 m" k/ ?7 H) f& S
$ e. R7 w2 ]* k0 R$ B8 {# C3 B' {! k- d1 F( c$ E, W  ?* s6 Y9 D9 ?8 }$ U0 u- a/ L& U# f
dict is the password file
# b) h9 w: i3 \: g
/ e; I* I& A( W4 [* O& N1 v! Q. v1 \4 H/ j# W% ^1 y) G
) d: u/ c3 G% F! N( r9 K" G' k( R. U; I6 }9 ^4 W* s; T( }
linksys.hashfile is our output file
8 M! ~2 a# u. \  |7 g5 T+ m% J" W; \# }/ X% Z. Q
9 C1 `0 I$ m; E; |
) @3 q1 `4 X% w
( G. }; e9 h  X$ z+ `0 {  `, nlinksys is the network ESSID4 ~' C, ]" H8 o5 B" n- Z4 O0 k. m

, k( J( L$ A. u* M4 I+ T5 j0 s$ l2 `! q  X) q
6 v6 {7 b0 b5 H' {* S; ^4 B
0 J" @  r" `( t( f" P- o: t; x( P8 a% S% `0 r5 r( XcoWPAtty Precomputed WPA Attack:# ?/ x) d2 _& C+ W/ i
! `7 H, y2 v8 u  J
4 k% ]$ }- _3 R+ @1 SNow wehave created our hash file we can use it against any WPA-PSK networkthat is utilising a network SSID of cuckoo.  Remember the capture(wpa-test-01.cap) must contain the four-way handshake to be successful.% B3 y( m4 _0 a% z" X

; c  b" B- z0 [% L3 m" r/ l3 a2 G; @+ I# A1 Q
+ w3 y6 f. H1 R* w8 g; }, e0 K; o" p/ Z+ I5 u+ @! H; P( I: ]) b& [0 r. E. \* N: k

! Z2 r1 U2 A1 z, B8 N# y2 tcowpatty  -d linksys.hashfile -r wpapsk-linksys.dump  -s linksys  % q! L& S* [8 _5 n# L1 `

- y+ L& X1 z4 P! V2 |+ {# d  \& b( s, m, N
; N0 F8 Q6 F4 h) b
# j1 X$ z" e; ?) V
2 B1 F: w: A/ t/ t' A# {* \( E% U* T; @# h
& R1 V1 X  u4 A# O5 W3 n# e# y  E- f5 y2 ]0 S6 e
5 q, R- C, o! ?0 Z0 \
# }( e$ }9 ?( M' |! ]9 l
5 R2 }' w3 n# Y8 V% ]1 A& j% T) s8 dwpa-test-01.cap is the capture containing the four-way handshake& s. b7 H7 p8 |- O! R5 a
, f' u" p* X0 F' }
. {  e2 R  w8 A3 n% x7 S% K
+ D$ G% D  N$ N* v3 Q  Q
& K% B. _& r+ @3 T- j) G; zlinksys.hashfile are our precomputed hashes
  B. t% r# {5 z/ i1 r# O; C3 N' d, n+ N( C
9 r0 ^+ f6 ^  G" n( {) w) ?
; e- M" y* t# g+ i  K/ E& R) l* w  u# T
linksys is the network ESSID5 G) ]! Q! j2 p0 B4 s

3 k+ _6 ]4 h1 g, _: v  Y2 R+ H! o  [1 |3 a8 E8 y0 l& e
1 J7 O, ]2 y# v, S- F) D) d- R$ t3 F1 K3 I5 y: `) h, _9 b  `) J
# w) ?( }2 j( u# n9 x
# W  x7 ^+ G1 |" M  _Notice that cracking the WPA-PSK took 0.04 seconds with the pre-computed attacked as opposed to 200 secondswith standard dictionary attack mode, albeit you do need to pre-computethe hash files prior to the attack.  However, precomputing large hashfiles for common SSIDS (e.g. linksys, tsunami) would be a sensible movefor most penetration testers.  O9 e( B5 i* T7 D0 `1 t
8 B; x7 H3 \8 ~$ w7 F# K
" k& a: p/ u. L4 |* C0 e! C0 F# l$ b, ^/ L/ E+ [- J
1 z4 O: }- l$ l- F$ O* _$ C3 _
0 F" P# l$ Y; V$ Y7 s0 T% b! ~coWPAtty Precomputed WPA2 Attack:
" c/ Z$ `  f1 N/ k0 P$ y5 O0 Z3 d: w# N0 j4 ~/ G2 p8 I$ E
coWPAtty4.0 is also capable of attacking WPA2 captures.  Note: The same hashfile as was used with the WPA capture was also used with the WPA2capture.
3 V7 p, I- s( x1 c5 u) e
+ N2 [0 q2 z* e- W9 m7 }. Z' Q! B1 S+ v! L$ Z5 \) z/ u# {3 d
: q3 o5 g6 g  x- J
cowpatty  -d linksys.hashfile -r wpa2psk-linksys.dump  -s linksys
' ?- N# h4 w% }, M! Y6 T% F& C- t( Z! K' {3 |0 ^$ [

4 r9 s1 h, o2 F: U! Y6 f/ h" M; G* X9 x' b# N3 J$ o* S
. ~( d4 ^  u4 [+ S. z5 G7 E5 \% c3 I) A6 T: w; y3 }+ {- k6 d: B% e" C

8 V% X9 t% O, L( J! n3 T( {0 F# h: S0 |6 {$ p$ h6 _3 }8 ?/ U4 W3 u) F4 e7 l5 J
% g6 _# a! f  X( K1 ?$ U- K5 L/ C  @$ l
6 I  }8 t8 Y8 m
wpa2psk-linksys.dump is the capture containing the four-way handshake: P! w, t5 ^3 a; w

4 x( m9 O7 x; o, Q$ _8 O: U, S6 O8 l6 N, C/ w, B5 E7 f8 R/ J, B# X3 h. E9 Z+ I& U
8 ~0 N! i& F% G) J& G! x5 @0 d
dict is the password file) }; s) c1 S0 U" `4 N1 y9 y2 x

% ?, o9 d4 `6 F6 E% `/ y: Y# I2 b
- }3 b6 j9 {! D. Y* C7 T+ _
' D) [: k$ K5 I: R4 B  C2 R3 ylinksys is the network SSID
3 w6 z* t/ Q1 C+ @1 j, A5 e6 m  {/ F4 N
+ S! m& n4 m! a6 a# |; u8 }
* }' v6 p8 L' O' x8 H1 j  _! m, M' b9 {9 @, A8 {
3 b2 }& F2 s/ E7 m$ d( Z$ [* ocoWPAtty Tables:
! I- E, d5 |5 t2 I; ], f: ~. u& `4 t, P8 gThe Church of Wifi have produced some lookup tables for 1000 SSID's computed against a 170,000 word password file.  The resultant table are approximately 7 Gigabytes in size and can be downloaded via Torrent:2 L8 e& ]- G# E0 Q3 k( I/ r) J9 l
+ u  ~( W) a2 a, \1 J8 N  b9 v  e! c+ W0 y6 }0 e. M7 k* j. u1 l! c" p' M5 e
http://torrents.lostboxen.net/co ... atty-4.0_2006-10-19) J) m' V( F1 s: h. S8 b% t
( _+ F4 M3 K9 d5 d( o9 ~' d, G# j0 O
4 l% Y- E. {3 Z5 w9 B$ PA 33 Gigabyte set of tables are also available: http://umbra.shmoo.com:6969/1 P" V6 G( J9 W* _7 l1 n. ~4 b& f# i# J
6 J3 t- q, E; ^0 A0 Z: U5 e' p! I  |
Or you can buy them via DVD, direct from Renderman (initiator of the project): http://www.renderlab.net/projects/WPA-tables/. J% }2 r' B; I6 C+ ~; `
回复

使用道具 举报

399

回帖

1492

积分

105 小时

在线时间

上尉

注册时间
2009-7-23
金币
1047 个
威望
0 个
荣誉
0 个
累计签到:3 天
连续签到:0 天
[LV.20]漫游旅程
发表于 2009-12-13 00:24 |显示全部楼层
5金币就给你一堆英文的,你看懂了吗
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:19 |显示全部楼层
这么贵  不买
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册 微信登录

本版积分规则

Archiver | 手机版 | 无线门户 ( 粤ICP备11076993号|粤公网安备44010602008359号 ) |网站地图

GMT+8, 2026-8-19 10:53

返回顶部 返回列表