ubnt解决方案
楼主: chinajack

[分享] 直接搞定WPA和WPA2 无线密码P解工具

   关闭 [复制链接]

351

回帖

677

积分

118 小时

在线时间

中尉

注册时间
2009-6-13
金币
298 个
威望
1 个
荣誉
0 个

尚未签到

发表于 2009-12-8 22:40 |显示全部楼层
先看看 搞不定再找楼主
回复

使用道具 举报

351

回帖

677

积分

118 小时

在线时间

中尉

注册时间
2009-6-13
金币
298 个
威望
1 个
荣誉
0 个

尚未签到

发表于 2009-12-8 22:41 |显示全部楼层
假的。。。。。。。。。。。。。。。。。
回复

使用道具 举报

206

回帖

711

积分

284 小时

在线时间

中尉

注册时间
2009-11-5
金币
476 个
威望
0 个
荣誉
0 个
累计签到:31 天
连续签到:0 天
[LV.50]初入江湖
发表于 2009-12-9 14:15 |显示全部楼层
谢谢楼主 分享
回复

使用道具 举报

154

回帖

275

积分

45 小时

在线时间

少尉

注册时间
2009-3-13
金币
116 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-9 15:21 |显示全部楼层
有用吗?用过的说说
回复

使用道具 举报

134

回帖

279

积分

31 小时

在线时间

少尉

注册时间
2009-10-19
金币
142 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-10 00:15 |显示全部楼层
不懂用,太贵了!!!
回复

使用道具 举报

611

回帖

2489

积分

117 小时

在线时间

少校

注册时间
2009-2-14
金币
1827 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-10 10:42 |显示全部楼层
不管好不好,先鄙视下楼主- v/ x9 t5 ^5 C8 a. s4 G4 A
我不会下的
回复

使用道具 举报

252

回帖

1058

积分

43 小时

在线时间

上尉

注册时间
2008-7-25
金币
766 个
威望
6 个
荣誉
0 个

尚未签到

发表于 2009-12-10 12:23 |显示全部楼层
真的有这么神奇的工具么?这个要学习一下了。
回复

使用道具 举报

75

回帖

143

积分

22 小时

在线时间

上等兵

注册时间
2009-12-6
金币
60 个
威望
1 个
荣誉
0 个

尚未签到

发表于 2009-12-12 12:17 |显示全部楼层
没钱啦。。。
回复

使用道具 举报

25

回帖

49

积分

27 小时

在线时间

新兵上阵

注册时间
2009-12-6
金币
19 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-12 17:11 |显示全部楼层
不是吧  这么贵
回复

使用道具 举报

100

回帖

309

积分

18 小时

在线时间

少尉

注册时间
2009-10-28
金币
203 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-12 23:00 |显示全部楼层
呵呵     ,妈的全是EN
回复

使用道具 举报

100

回帖

309

积分

18 小时

在线时间

少尉

注册时间
2009-10-28
金币
203 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-12 23:00 |显示全部楼层
能不能有用啊。呵呵
回复

使用道具 举报

399

回帖

1492

积分

105 小时

在线时间

上尉

注册时间
2009-7-23
金币
1047 个
威望
0 个
荣誉
0 个
累计签到:3 天
连续签到:0 天
[LV.20]漫游旅程
发表于 2009-12-13 00:23 |显示全部楼层
coWPAtty for Windows MAIN:
6 o! G' M) M+ n; ]3 o6 r* d- G. a$ H. W6 t  g2 x0 z8 `$ A2 C. h
"coWPAtty is designed to audit the pre-shared key (PSK) selection for WPA networks based on the TKIP protocol." - Joshua Wright.
+ z3 H0 G$ q( B  B% T% W. l( C, v& T. o3 E0 [) J8 m. k8 r1 [1 Y/ _ : [) w$ G  {9 E# q& ?( I

$ `2 q3 n& z0 i! A" _8 R8 ]3 tProject Homepage: http://www.willhackforsushi.com/Cowpatty.html
% G+ E% D+ l$ Y& R
, X- e. n/ R9 o) Y/ F; p6 ~7 i* g( i
4 z4 ^+ c9 b5 v  F, G" N$ g; i0 q1 v. n4 E4 _
0 l# y( z0 X$ U+ C/ S. y1 A" d  b) b- m3 ?  q' ?" @
Local Mirror: Cowpatty-4.0-win32.zip  MD5: aa9ead2aacfcc493da3684351425d4c6
4 I9 d5 ]- ~$ H$ ?
8 a7 }9 ^6 N% q1 B: T+ f6 w* U/ C; L2 [# P+ X% k* Y) r
8 E$ l4 M& W  f1 E! B- }' e/ g; r! ]6 V6 [: u2 Q  M! G& L6 F/ o9 K. K& S- S; j* h' S
3 d; [3 K: s% X. ]) L
coWPAtty Dictionary Attack, _  O- U0 _4 e: S) s

. R* A6 M" x9 D. n1 }: v) |+ G4 z6 y9 O
' F8 `4 @: ^& _5 g, q) Z; t8 G* C6 k( |3 r; s
Precomputing WPA PMK to crack WPA PSK
+ q7 v- \$ a' o* z* F2 v0 c4 h$ Z4 F8 X2 N9 u$ O4 T  o
8 L  @* c$ r1 y  V5 ^* M* S7 g% j9 c  E+ _/ o
* A) L$ b7 J2 W' {" a6 O8 w
coWPAtty Precomputed WPA Attack) D0 r4 S% q4 Q6 k( Q5 g# `
: q6 q/ ~+ N" x1 e

% J) X! y  l& D! P+ o' q9 ~% P* C, r0 |2 h4 X+ S9 A" J# }2 l. j4 _" A; m& k$ o
coWPAtty Recomputed WPA2 Attack) k) D' D  n5 _! u
# O- ?8 F" C" }- N! Y4 M* `

6 f  f4 o/ w( x4 P/ q% q2 P; M. S0 k( b3 O- G% L( _6 }2 V+ L% V2 M8 I7 v, s* z! c- t4 L) W( U
coWPAtty Tables- c( Y8 q+ f1 j; y' w

# l& g# q9 t4 ^. Q9 g3 t- f3 n  J  Z6 w0 w* B6 l! i: K
# p6 L3 @) m2 ]+ N/ a  D* @6 vcoWPAtty Usage:
' m0 x' b% K1 ~$ f5 i% u! P/ i* _1 j; a3 c
+ f- }  L1 v! v3 t) z% k- i/ d& D ( z+ A& s, x0 t( m- d- R
/ J& `) x" t1 z% jcoWPAtty Dictionary Attack:: u, g: R' Q( j- T5 Y  i1 O1 g2 T
9 F! T- i5 P5 ^- `
, n2 f, Z1 |; R' u; ]6 H9 G, Y' EToperform the coWPAtty dictionary attack we need to supply the tool witha capture file that includes the TKIP four-way handshake, a dictionaryfile of passphrases to guess with and the SSID for the network.5 P& @% ]; I: }! D

. {  |5 M: k/ ]( S2 I3 h0 x/ j. y2 Z' {% b. o5 _* N1 J) [2 _8 F4 L

- R) h% Q! ]. v0 V/ D; zIn orderto collect the four-way handshake you can either wait until a clientjoins the network or preferably you can force it to rejoin the networkusing tools like void11 or aireplay and capture the handshakes usingsomething like kismet, ethereal or airodump.; I$ E8 U3 [* F1 ~& K, q  I2 {

7 \  |' e: ~7 \( Z% p$ u/ x& L0 O1 M  v6 V* g9 j, e3 Y% k* k
( A! Z! `: h) C& C" v1 t5 F. b: w& x8 g1 `! f0 w4 a
cowpatty -f dict -r wpapsk-linksys.dump  -s linksys
# f! Q4 E4 w7 H* X$ K$ Y
" v3 i/ {7 P0 q* T0 B: Z( ^  N3 q7 M0 _( d5 P8 F
5 U6 f) y' N! }3 L2 E0 d
& ^! c; \8 K4 r, x. R+ H  R9 x  t3 n3 s' e1 r, b% J% I  _2 f' h# Y( Q; G2 [
8 j" O. D0 F( w3 }$ p/ r" Q" o# n( r# M: {& R0 P5 p5 S6 Q$ M0 Y( J+ m, k' M* V
" L6 F+ }' F0 v: Q6 y/ I  P1 X8 x' s, Q9 l! [+ N

; G  B. e: W& O  ZAs youcan see this simple dictionary attack took 51 seconds, we can speed upthis process by precomputing the WPA-PMK to crack the WPA-PSK (seebelow)." K9 C9 U5 s7 ^3 O4 X9 ^
( u( \1 \; P7 X' z( \% K

( O8 L- W: l' ]$ W' U& Y: @; x* X/ J; M+ m* K! B* s5 Q
wpapsk-linksys.dump is the capture containing the four-way handshake
. ^! P. J" X6 L* ~, p, R7 f4 {4 M, _! H7 i. A, z8 L
0 N. I5 h9 e" V/ f  T
/ P$ ?% V5 f% m) R7 ?- r7 L
5 }, W# E% y9 h& G8 D8 Edict is the password file! E) i6 w0 ?% |+ U/ N8 Z' p

# v0 b! R6 O9 e  f0 @, ~) W: L! d6 I& f' h5 w9 K. g) ?9 z7 P2 r& H2 J7 d

' d- o; |& h- ^1 ?- ]  f* Llinksys is the network SSID& k, v6 U" ^( O/ P! m: G  k
! I, u% X3 Y+ L' [: P  L, _: ]+ f

$ u/ y, T) _% _: H0 M  z; l9 Z# h' V& W2 D; {# f7 H  Z. m% @4 y6 r- `( c* R* e( I! X# w5 o, M: q! E( i
Precomputing WPA PMK to crack WPA PSK:
. h3 k  o2 R; r9 U5 q. ^% z1 ^) f3 h/ M: {" Q* X1 P# Q! p# M2 C
genpmkis used to precompute the hash files in a similar way to Rainbow tablesis used to pre-hash passwords in Windows LANMan attacks.  There is aslight difference however in WPA in that the SSID of the network isused as well as the WPA-PSK to "salt" the hash.  This means that weneed a different set of hashes for each and every unique SSID i.e. aset for "linksys" a set for "tsunami" etc.( x- T; m6 \: @3 H( c; i
4 P& y8 X, S9 m. p% h

1 `; D4 W* C6 ~+ X# o5 Y  I0 x* \4 |1 f! b3 g! F) ?& X# n2 M  _
6 x" E' h% h0 L7 X3 s6 y, l1 O/ c" G2 Z. Z
So to generate some hash files for a network using the SSID cuckoo we use:
4 [9 S- v7 c1 N+ v7 k' `; }" v9 V7 P2 }" p
. {2 I  j' Q0 Z6 e, W; l' Y' [0 a/ \6 N* p: ?; U: N% b" O7 v5 Y

' N; G/ E' n" p: I8 t; J: I( l% B6 C8 y$ _8 z* z7 j: W5 ~: g7 Y: E' U
genpmk  -f  dict  -d linksys.hashfile  -s linksys  8 E+ m# ?8 _5 _$ `/ ~0 ^
9 o/ E' E+ R% K9 c* @3 y/ n
8 M4 z7 x0 S( b3 I- F. P# |( F: e' Z1 F8 {5 f+ c5 z
0 N) S) {/ ?5 z1 u. V9 o
- ?2 i8 E  ]3 Y. R4 Q0 N3 |6 ?0 Z
/ r: s& ?6 A: v; A: H* `$ h( g
7 @# }+ ^$ F* z4 X4 `$ L5 K# p
! D& S( `6 ?4 i1 M1 w3 s7 w7 {' e' A6 M' B( R6 V5 O! e
5 m" k/ ?7 H) f& S$ G. Y5 L; ^7 i/ G- W" q; a
1 F( c$ E, W  ?* s6 Y
3 r$ ^( a3 }2 f. \, I6 Cdict is the password file
- o8 O! Q! |; x; X5 _) B% t* R
- z. z9 N# H! D( i  W; f1 v! Q. v1 \4 H/ j# W% ^1 y) G
% h0 e7 e. e2 A
: u' n$ R, }/ U8 _; e+ ~  Jlinksys.hashfile is our output file
6 G/ g8 e' @) e3 b: D3 c6 ^- n4 S5 J# [$ P% W- N8 Z3 s
9 C1 `0 I$ m; E; |1 R  i) v9 N: l, Q3 L( V
  Y0 f& u4 W/ }$ N% P: ^8 L
linksys is the network ESSID9 i. N6 P' `  ^# M- Q- d; }

8 g, L5 b% l& |( D! o, r4 D" s0 B
' W( H" l) T/ j: f  \  w6 Z1 s6 v6 {7 b0 b5 H' {* S; ^4 B
, s3 Z% U3 k0 P& }# u3 S( P8 a% S% `0 r5 r( XcoWPAtty Precomputed WPA Attack:# ?/ x) d2 _& C+ W/ i) a: D* N; m  G$ M

5 ?) F; e! H: BNow wehave created our hash file we can use it against any WPA-PSK networkthat is utilising a network SSID of cuckoo.  Remember the capture(wpa-test-01.cap) must contain the four-way handshake to be successful.
2 G! X8 Z, R; c) O  A/ Z/ u; m7 ^; O- M! T7 ~
3 m" r/ l3 a2 G; @+ I# A1 Q) ]6 j+ E& N1 I6 U& X# {: U
0 K; o" p/ Z+ I5 u+ @! H
( u# k" X5 d+ z! n# s
% f% w9 a" ~) F' @2 \* K) c9 _cowpatty  -d linksys.hashfile -r wpapsk-linksys.dump  -s linksys  
- ^0 G" h% f, W- e% u* ]3 Y
) @8 g- H6 v% T$ I' E, p4 h1 Q5 p) ^+ {# d  \& b( s, m, N
" o! o) ?, V& s9 F) f+ T* j0 }* S' n  w, p( U$ P- B

' o) {& F( }; I0 l( s
; X+ h" Z7 r6 e5 P# Y& R1 V1 X  u4 A# O4 |3 X: V6 E6 s- v* ^$ |

$ d$ L5 y; O9 M' h# }( e$ }9 ?( M' |! ]9 l3 i& p5 ~: l/ F4 u" G5 M8 N
wpa-test-01.cap is the capture containing the four-way handshake
3 @% N$ u' R# B0 I$ l  @5 h4 z6 n  }6 }+ v6 g7 O
. {  e2 R  w8 A3 n% x7 S% K. U% y5 W7 R! E$ T; `+ V2 K2 _
, _. q7 W# G6 ]) H- N' c  i+ c
linksys.hashfile are our precomputed hashes# z# c/ g+ k7 n( c' o3 v

$ ]* t7 u1 k# u* n+ w
; z' q: ^5 d4 Y7 I$ X4 w3 Q' [, V; e- M" y* t# g+ i5 m: Q' d% @7 Y1 s, u
linksys is the network ESSID# F3 f$ y, {. O
& m4 P; |. H% F5 W0 V
+ H! o  [1 |3 a8 E8 y0 l& e' |2 t; T4 {3 J* B# M

! g4 ~8 f  m% V! D# c# w) ?( }2 j( u# n9 x) c  D% M; g. i+ s0 I
Notice that cracking the WPA-PSK took 0.04 seconds with the pre-computed attacked as opposed to 200 secondswith standard dictionary attack mode, albeit you do need to pre-computethe hash files prior to the attack.  However, precomputing large hashfiles for common SSIDS (e.g. linksys, tsunami) would be a sensible movefor most penetration testers.9 ?+ a" |, d8 M; T% Q
( ]5 T! g" J& z5 E# w- e" W3 T0 w
" k& a: p/ u. L4 |* C0 e
, w* F( M5 e: L: X. D1 z4 O: }- l$ l- F$ O* _$ C3 _
( d; t$ i: c& I, l7 c8 bcoWPAtty Precomputed WPA2 Attack:5 ~5 W& Q  c; c0 B/ z6 c# X
0 P$ y5 O0 Z3 d
$ j3 y, b" Z; L8 i% VcoWPAtty4.0 is also capable of attacking WPA2 captures.  Note: The same hashfile as was used with the WPA capture was also used with the WPA2capture.0 n  K' T2 v' H5 g0 g5 E) u- Q

5 [- \7 t, }1 ]- W9 m7 }. Z' Q! B1 S; t: R) s/ k# B+ b5 ]2 q& E
6 `- t; X0 g9 g6 E
cowpatty  -d linksys.hashfile -r wpa2psk-linksys.dump  -s linksys3 l) Q# `, E% W6 [- c
3 m* y6 Z% w- b% ]" l8 z& k; `7 i

8 p0 D  i; x) B% t2 |6 c; G* X9 x' b# N3 J$ o* S: A9 ^+ u3 v6 b' U, I* W( b3 L; }

% [% c' j! `* u9 i( u
, j% e: w8 H! c& ?- F, Y# h: S0 |6 {$ p$ h6 _3 }8 ?/ U4 W3 X# K1 i/ P( C5 z
% g6 _# a! f  X( K1 ?
% J6 U# K% X0 u, b2 C
& y# D5 O# z+ X% ^3 B! t; t) F5 owpa2psk-linksys.dump is the capture containing the four-way handshake3 D3 z8 }; b' ~" q/ X9 u# f/ T& S0 Y1 Z
0 i: q4 B9 l4 N7 H, X3 A
6 O8 l6 N, C/ w, B5 E7 f8 R
$ B& u! O: J/ @3 a: _
; r+ [& z2 m  l! w5 j3 D& _0 Sdict is the password file: ]6 D7 x. e* ]3 B5 \# G
0 D+ d' G* z, }. ^8 y+ b4 K3 D
6 E% `/ y: Y# I2 b
! E% D# d  J3 ]/ Y# O. Q9 T0 R0 a7 c0 r/ h
linksys is the network SSID9 d  ~5 C3 T% ]5 t6 R3 c/ k  S

! Z" q+ |1 |  W0 _+ S! m& n4 m! a6 a# |; u8 }
9 x, X8 Y0 l' W7 H  _! m, M' b9 {9 @, A8 {
7 ]+ @' c! `/ @4 IcoWPAtty Tables: + u6 c" {2 \4 G( b$ s0 }2 \, t, A
2 I; ], f: ~. u& `4 t, P8 gThe Church of Wifi have produced some lookup tables for 1000 SSID's computed against a 170,000 word password file.  The resultant table are approximately 7 Gigabytes in size and can be downloaded via Torrent:
% P9 m% {0 @- p9 M# V% b+ u  ~( W) a2 a, \1 J8 N  b9 v  e! c+ W0 y6 }0 e. M7 k* j
& b$ N) ~/ X1 o- Ghttp://torrents.lostboxen.net/co ... atty-4.0_2006-10-19
6 e9 e& J+ g' m7 |9 I( _+ F4 M3 K9 d5 d
6 K$ G( h- F& z3 ~  w, u4 l% Y- E. {3 Z5 w9 B$ PA 33 Gigabyte set of tables are also available: http://umbra.shmoo.com:6969/1 P" V6 G( J9 W( d5 J# _3 q1 l) o/ ^
6 J3 t- q, E; ^0 A0 Z) E8 I( r" v. y/ Z% [
Or you can buy them via DVD, direct from Renderman (initiator of the project): http://www.renderlab.net/projects/WPA-tables/. J% }2 r' B; I6 C+ ~; `
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册 微信登录

本版积分规则

Archiver | 手机版 | 无线门户 ( 粤ICP备11076993号|粤公网安备44010602008359号 ) |网站地图

GMT+8, 2026-8-17 12:52

返回顶部 返回列表