ubnt解决方案
楼主: chinajack

[分享] 直接搞定WPA和WPA2 无线密码P解工具

   关闭 [复制链接]

399

回帖

1492

积分

105 小时

在线时间

上尉

注册时间
2009-7-23
金币
1047 个
威望
0 个
荣誉
0 个
累计签到:3 天
连续签到:0 天
[LV.20]漫游旅程
发表于 2009-12-13 00:24 |显示全部楼层
5金币就给你一堆英文的,你看懂了吗
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:19 |显示全部楼层
这么贵  不买
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:20 |显示全部楼层
这么贵  还是买了
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:20 |显示全部楼层
这么贵  还是英文的
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:21 |显示全部楼层
这么贵  怎么不翻译下
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:22 |显示全部楼层
这么贵  不懂 上当了
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:24 |显示全部楼层
coWPAtty for Windows MAIN:; S; m, t( [/ `. e, Z# r! I3 T) S
+ d6 s4 q4 z6 [  |) T
3 ?8 Q7 _  W0 X: \"coWPAtty is designed to audit the pre-shared key (PSK) selection for WPA networks based on the TKIP protocol." - Joshua Wright. ' F  @6 o- p1 O, g  _: {
# C7 }/ h9 R: N0 H ; N; P1 Z. v: ~
. N6 N9 i# k$ _2 g. R
Project Homepage: http://www.willhackforsushi.com/Cowpatty.html   Y: Z7 |3 e: Y. n
6 D7 F% G; C/ O7 d
7 d7 b& }6 g1 R. m0 r  P
4 d$ r3 x, K2 c& }9 C4 @4 W3 k# V
1 k4 f( x0 T; @; A1 a& H, i# @- u* B% {2 _1 v2 r- t, f7 a# S1 ^# e4 O
Local Mirror: Cowpatty-4.0-win32.zip  MD5: aa9ead2aacfcc493da3684351425d4c6
. c2 p2 N$ M5 |1 w$ x9 x1 O. E0 a, @" k* k0 V! p/ ^& b! W
: |; K- _5 }9 o" V5 z1 R4 Q4 _+ V+ i
( A' I! E( W. S# W/ N; E/ R& D7 u5 N, q- ~
$ U! w( d) a, G4 S7 _* s
- E1 l1 T- N+ s8 _coWPAtty Dictionary Attack' H7 ^3 r' q  r8 \. L( F

. T* l1 t7 B8 s, N, M' d2 J
! ^+ w; ]2 p  \  E/ Z: e; N/ \: S$ ~$ T4 `: h& H
+ w9 m  ~! Q) ~) I. D' y5 OPrecomputing WPA PMK to crack WPA PSK5 o$ {8 h; m4 v# l3 N9 S$ I
$ S" S& v2 f6 K/ X- B7 C
  C8 R: t+ f7 `' ^& R
5 f5 K0 o5 W. [  [! M! d9 T7 p6 t; X3 h! y
coWPAtty Precomputed WPA Attack
6 D& ?( d( @3 M- z1 K
" E5 x" S/ ~0 y' ^4 s" J
. ?4 M0 x1 G0 U* D% Z3 j8 e: N( q+ }& i, [0 H5 g: ~
4 R( |% m9 t+ [6 \: ]6 n& pcoWPAtty Recomputed WPA2 Attack
2 v, v2 ^6 \& a$ f3 _  r0 k( N) v9 Z
2 a' X/ Y! V! X/ Z5 g( ~7 K/ u5 U# ]7 x3 u+ q" i  D$ {0 ], e. I' ~1 j
4 A0 h, q# Q! ]: [7 ^
coWPAtty Tables
, y1 |3 s& g# ~0 ~' K% a
4 Z5 `3 W: ?( a) E' p: X/ ]3 g! I7 U
" P  v# i* p* G8 ScoWPAtty Usage:7 b, W( \( k$ \! _
7 N+ B( ~4 d  i, A( r' }1 m+ V: T7 v5 p$ Z6 ?
8 y, g* h# y- }$ f6 T; q, M- o. D, z) [
% D% I8 m5 g( P6 W- [( _( acoWPAtty Dictionary Attack:
& B6 ]8 [/ x1 X; g1 \) u) I5 n& `4 y* l" A
0 E# _. b7 Y& W& XToperform the coWPAtty dictionary attack we need to supply the tool witha capture file that includes the TKIP four-way handshake, a dictionaryfile of passphrases to guess with and the SSID for the network.
/ r7 v& W5 S. ~: x& @- \- b: ^9 T5 i% c' ?& }
7 }" F6 I% c9 w) l- C, V2 H* y9 e# }" t8 I; K
; y9 }( }' q, O5 Z
In orderto collect the four-way handshake you can either wait until a clientjoins the network or preferably you can force it to rejoin the networkusing tools like void11 or aireplay and capture the handshakes usingsomething like kismet, ethereal or airodump.
7 s8 v5 U7 n) Z# T, e7 C# H- t) S  ?# F+ J9 I
! G$ z6 @8 V  S7 w8 C$ q9 K
, Y0 ~" g5 o  p. I+ T6 ]& l& }+ Y
) _' B, E4 l9 vcowpatty -f dict -r wpapsk-linksys.dump  -s linksys/ L9 V5 @0 T8 A# n2 q$ F1 F
1 p8 ~0 J+ y' q4 K3 z

6 M- E! |3 G! i1 W3 f; s! t7 r7 z2 ]! a: T4 q
. B$ s' Q! g0 J% |/ ?) n5 a! M! m, ^0 l1 @$ i/ [- g5 c7 X; R: ], M  W' K
/ ]6 c; a8 e! U5 F4 P- \! q  v- O" s, I8 u8 Q# \6 K$ L. f9 r- a* u7 u
, \8 r8 x; G9 ^" ^2 u/ D" p( \3 `; B4 [$ Q6 N. C1 N
+ ~, W; M! {& G$ Z/ x) f
As youcan see this simple dictionary attack took 51 seconds, we can speed upthis process by precomputing the WPA-PMK to crack the WPA-PSK (seebelow).
$ u1 C, {# F7 O7 i( L/ N8 j
/ J( x) W3 d+ e" l' B+ G0 G) `9 B" h# E4 M7 A6 D# E) l. O
; P( J: j. a% W, @
& H; z' G7 u# j* ?3 [wpapsk-linksys.dump is the capture containing the four-way handshake1 k+ U( o; Z0 ?% n4 e) n  G
; W0 `' [) Q6 _6 \& k
5 k7 P% [7 V0 ^4 o+ P1 }6 ^  j# p* y) N# j/ T% ?* }8 C
, d& \) D) s3 a+ Q0 m2 Y$ g
dict is the password file. G0 B& D+ J) H0 M, \2 Z* U9 Y2 u

! O0 O6 K6 G. C: {' H/ G" Q* j  U8 R
( ?3 m3 `# m* \* z0 V$ t# J0 F0 _' M: d
linksys is the network SSID4 |6 t: G3 y2 {7 M$ T
$ M! r1 ]% Y* s8 B/ K4 `

9 F) t% K" b, ~: p4 d4 G) s5 t& G* H7 r! N, T$ Y+ ?9 i& l! p% H9 p" ~3 _' m
Precomputing WPA PMK to crack WPA PSK:! |; L+ S0 b8 l, ]& |
9 q7 u" }+ G; X0 N7 E8 v6 M" O' }" Y
# ~  V% E" H3 K; Z! A3 D' hgenpmkis used to precompute the hash files in a similar way to Rainbow tablesis used to pre-hash passwords in Windows LANMan attacks.  There is aslight difference however in WPA in that the SSID of the network isused as well as the WPA-PSK to "salt" the hash.  This means that weneed a different set of hashes for each and every unique SSID i.e. aset for "linksys" a set for "tsunami" etc.
' z6 w' _5 O. G' p3 [6 R5 s$ W! c' u" ]$ t+ }3 A" U* b5 y
3 l% ^! n! D4 ^; p1 B1 {# Y
0 Q3 a% ?% z  F0 A( K; g+ `+ P& e! U5 F. a! {* B2 U: |
/ X# O+ e5 L: Z/ r( c. H4 f6 Q6 F- A. t0 o$ \+ d9 t" Y% l+ v
So to generate some hash files for a network using the SSID cuckoo we use:
  q" I* }+ [4 u: m9 o3 B
* y/ S- A. m2 O2 o
6 v( T, h9 h& e3 K" a& t$ @3 T3 @. i7 t/ r# i4 K3 L, |+ p& s/ D% g% r0 p5 d2 _3 A4 c7 T0 h) g7 Q5 G5 D

* W. E: b! o" B0 ~& Hgenpmk  -f  dict  -d linksys.hashfile  -s linksys  0 V2 M. N( s9 M' m, d* Y1 R- _# A- v
/ A1 J5 W& T+ \
3 r( c% ?) b6 C# R0 X
' Y$ g4 }) k+ u( L( ^0 _' _* `; ^% _4 z) N, S/ N* t
3 C1 |! t6 i( h( v+ D, [
9 }! c; M, A* T' F/ g; L7 o
7 W2 h  {" V; v0 R: ]# Y7 t; ]( v: r5 n+ D- ^

: P  L/ C5 q: z: O4 O& J  S3 V. I$ U3 {9 m% r6 Q9 R/ n. X4 \  N+ l, ?8 P
: p9 `8 q9 ?/ E- |5 y/ k- p
0 x; e6 o& ~0 @) m4 Gdict is the password file) i. {3 i5 m" o- I: L" I. w

: Y& v0 C2 R0 V: Q3 z" ~  p3 u( U# ^* Y" o9 N
9 s9 T& F" C9 X! z. V% l
( v' \+ y  n3 H1 E7 J2 Plinksys.hashfile is our output file# r% X+ `4 W# ^

) ?7 G; n" B4 D' z; R% _1 ?
8 O+ G: k- w; U1 K2 U6 w8 H, h$ t) S0 p: o% i" q! T. d5 }3 }; a5 O/ o. `
linksys is the network ESSID  m2 W9 Q- X  a3 Z0 t' t
% m% {; k! ~4 G# N
# E# k+ t' ^9 C- ^, F: Q8 X9 l  J# z0 A* }) K) U
  T; s, O5 U2 \2 K9 O
- b- m+ Y& Z9 J' a7 HcoWPAtty Precomputed WPA Attack:; I) U0 s+ V# v6 g
" Q8 [/ o# h- o% ^4 R
4 A6 I+ m7 T7 ?$ z4 s8 W& F/ }' nNow wehave created our hash file we can use it against any WPA-PSK networkthat is utilising a network SSID of cuckoo.  Remember the capture(wpa-test-01.cap) must contain the four-way handshake to be successful.
2 x' U* T( m* a' S
; |' m5 f- U8 y" @5 J
# @/ U( w; U" J) B5 }( c8 W, U8 h' j; e) R# Q8 ?- t% R/ ]; k% M: v
- o: q- X2 Y- ?9 u3 c. o& }0 P8 g1 V- B# t0 l! m
cowpatty  -d linksys.hashfile -r wpapsk-linksys.dump  -s linksys  7 T) Y. n$ F+ }
) C9 u6 k+ H1 C4 j  J2 f5 e

: Z. j1 J, i6 W8 f2 {* W+ Y$ [6 d0 G" c, ^6 P" c9 `  ^8 S" ~# Q& |/ u( s

5 K: F" B/ B+ z! S5 }* `* f' Q7 D; e
2 U! R7 ?4 k$ k
0 U! Q! M7 ^& @8 l% j8 C9 \2 D! P3 Q. m2 n0 X1 P5 e  u/ k1 _4 h( F3 A
) k- }2 w" S* o1 b" F; [8 @
wpa-test-01.cap is the capture containing the four-way handshake
$ B3 U' d6 Q* K3 }1 x4 e' t
6 b& t7 U, h" V" T6 Z
# N& B/ g2 Y. u, z, ?6 D0 }/ I+ k9 q$ _; a
; y, x9 D, s( Z6 W9 f( `linksys.hashfile are our precomputed hashes2 I; y$ u. w0 n9 U! e
0 T8 z6 a7 U9 Y

! o) G2 P" d: R$ \! O5 s% W9 K" L) O  W, e- W) L! A6 {" C! c6 N, {8 f# P* f7 T% F, V
linksys is the network ESSID5 c* D, u! L1 R5 E* p* f

5 x; O3 ]7 E1 x# n2 z3 D' ~% Q9 e& m; I6 d
, ~/ J% X/ q8 b' `( a0 X( u) O* ?% ~( Y( `) I0 n' c& b7 z% t% ]9 G& B
) _% F0 n/ M$ o) s" @3 z
Notice that cracking the WPA-PSK took 0.04 seconds with the pre-computed attacked as opposed to 200 secondswith standard dictionary attack mode, albeit you do need to pre-computethe hash files prior to the attack.  However, precomputing large hashfiles for common SSIDS (e.g. linksys, tsunami) would be a sensible movefor most penetration testers.- x0 R. c6 n% |4 x2 b7 ^' X, L

. |, J, V  l& F: ]
1 L6 I$ `. G: p" r( F! H4 x2 Z. h/ v9 I' b! |- p& A/ I; X3 C) \& ~) [
: _/ o8 G0 Y$ bcoWPAtty Precomputed WPA2 Attack:
3 a* ~9 a2 g$ r+ Z( v$ [# x! P- V$ E' z* M# \" I7 l+ |7 }, {+ ]5 h2 \
coWPAtty4.0 is also capable of attacking WPA2 captures.  Note: The same hashfile as was used with the WPA capture was also used with the WPA2capture.1 H3 W3 M' M8 s3 Y, L* A
- y3 R1 Z4 f+ T4 `
7 K" B9 L* y# r1 j
9 [. Y: b  U* F  q2 a! I% d1 q$ S6 `3 L+ S9 m! v
cowpatty  -d linksys.hashfile -r wpa2psk-linksys.dump  -s linksys
% D4 {2 @1 {& U$ m( s2 D7 P6 m1 T2 ~
6 R; s2 K% `. U2 Q3 j" ^+ _- b6 t5 x( @# x7 }
7 J5 z1 m" a% c- b3 r2 y* S, k/ ?
, Z! }3 T3 ?0 _
7 g5 U* t$ K! f! j: T$ y! R  V1 `: W
" ]9 [' ]9 o, |" T
) |. N# [0 C% {6 v/ j! o# B* A4 N5 X; D
8 Q4 |" m0 Q: y6 t- t( e) x6 a  c" K) o0 `) i3 Z
" [" K7 G$ P- Q! F; j& hwpa2psk-linksys.dump is the capture containing the four-way handshake' ]! ~; [" c  e* F

2 l9 }$ f' k" ]+ h7 V& i/ g9 H$ O/ Z# G) A8 x+ x# o* Y  G% J
. X( _8 v3 U, B+ i" p
" L1 j/ @. P# H: M; s% Edict is the password file, B8 D0 i5 v" r
' u' h9 h+ y( s/ R( z
. v( p0 P- s& ?. R3 V1 k! [# B0 b
( B2 I$ s/ c# ]+ a& t1 G6 ?* a" C3 e
linksys is the network SSID
( @8 K0 e! A- Q: R. ]/ w& C9 L4 i" l+ c5 k/ `
! w5 k3 Z$ K- V1 ~! g& _- h, R, e9 A( `  ]4 Z$ u, `
5 q+ l. h9 m& w& b
' H: ]5 L/ v- h( F. x5 [coWPAtty Tables: ) ^4 o  }: \& d" u& k
1 v) S7 z& Y9 iThe Church of Wifi have produced some lookup tables for 1000 SSID's computed against a 170,000 word password file.  The resultant table are approximately 7 Gigabytes in size and can be downloaded via Torrent:2 D8 N. r1 ~) w: Z6 R
" C' `- u6 g# T& I* k6 q  v% Q9 o0 G* m
. l" D; I* \& ihttp://torrents.lostboxen.net/co ... atty-4.0_2006-10-19$ x- v6 z* \, R2 Z
- U1 A$ G. s" D# X4 W, H' k( x, |2 ^: i, C5 c) M. p" W. ~6 a
# }$ g/ V1 g( @2 _  H% I, BA 33 Gigabyte set of tables are also available: http://umbra.shmoo.com:6969/5 J  G# p0 f8 p4 `$ g8 L1 H( f! k" h/ g6 V4 y# }
- U  [) P, s+ X
6 z% R! @; `) {5 [Or you can buy them via DVD, direct from Renderman (initiator of the project): http://www.renderlab.net/projects/WPA-tables/" c! Q! y) H  G* i
6 S/ x, G5 d- Y/ N' Y# b1 P# k$ B
回复

使用道具 举报

97

回帖

416

积分

23 小时

在线时间

少尉

注册时间
2009-12-6
金币
316 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 17:19 |显示全部楼层
楼主这是在抢钱啊
回复

使用道具 举报

60

回帖

428

积分

37 小时

在线时间

少尉

注册时间
2007-2-8
金币
353 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 20:10 |显示全部楼层
hahoahaoahoahao
回复

使用道具 举报

478

回帖

3643

积分

61 小时

在线时间

少校

注册时间
2007-8-22
金币
2983 个
威望
3 个
荣誉
0 个
累计签到:4 天
连续签到:0 天
[LV.20]漫游旅程
发表于 2009-12-21 13:57 |显示全部楼层
机器要跑好几个光年
回复

使用道具 举报

161

回帖

683

积分

48 小时

在线时间

中尉

注册时间
2008-11-21
金币
475 个
威望
3 个
荣誉
0 个
累计签到:6 天
连续签到:0 天
[LV.20]漫游旅程
发表于 2009-12-21 14:10 |显示全部楼层
有这东西???????????????????????????????????????
回复

使用道具 举报

1036

回帖

4235

积分

369 小时

在线时间

少校

注册时间
2009-2-4
金币
3100 个
威望
3 个
荣誉
1 个
累计签到:138 天
连续签到:0 天
[LV.200]无线新星
发表于 2009-12-23 19:47 |显示全部楼层
骗人的,好像,还是不买了。楼主不厚道
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册 微信登录

本版积分规则

Archiver | 手机版 | 无线门户 ( 粤ICP备11076993号|粤公网安备44010602008359号 ) |网站地图

GMT+8, 2026-8-20 16:29

返回顶部 返回列表