ubnt解决方案
楼主: chinajack

[分享] 直接搞定WPA和WPA2 无线密码P解工具

   关闭 [复制链接]

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:20 |显示全部楼层
这么贵  还是买了
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:20 |显示全部楼层
这么贵  还是英文的
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:21 |显示全部楼层
这么贵  怎么不翻译下
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:22 |显示全部楼层
这么贵  不懂 上当了
回复

使用道具 举报

133

回帖

624

积分

22 小时

在线时间

中尉

注册时间
2009-11-1
金币
486 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 06:24 |显示全部楼层
coWPAtty for Windows MAIN:; S; m, t( [/ `. e, Z# r! I3 T) S* f: _  N/ a- M/ S) e

; V  {$ {. ]0 H. ~"coWPAtty is designed to audit the pre-shared key (PSK) selection for WPA networks based on the TKIP protocol." - Joshua Wright. 8 n) T0 \1 B# d) Q+ S
# C7 }/ h9 R: N0 H
& K3 x" _' X" N1 t5 P6 c8 R5 C
5 ~% }, |' J3 y7 V4 Y( z' yProject Homepage: http://www.willhackforsushi.com/Cowpatty.html
- R* K* V1 C" x0 R- e) B2 D
9 c+ q% q- L* P' a/ X4 Y7 d7 b& }6 g1 R. m0 r  P
! h' K* i* b* {; O" K9 G( N( V: g- i  C; r1 a
, i# @- u* B% {2 _1 v2 r- t1 g; Z" O: F. n, {: Z; A" T
Local Mirror: Cowpatty-4.0-win32.zip  MD5: aa9ead2aacfcc493da3684351425d4c6
+ K$ h1 m5 v: V) P( L
) _. l- A& G) a+ q6 a
  N) t# |" Q( i% Q/ Z  @( A' I! E( W. S# W0 ]: E2 V5 M; I- O& k* h
$ U! w( d) a, G4 S7 _* s
# w+ f( L% I: f0 q# v9 {+ i0 i7 WcoWPAtty Dictionary Attack
+ E& o& B& i. o/ a  _) V- s- k! i9 R! D

: F0 U, w' S6 F/ V& H$ u. }7 ~: S$ ~$ T4 `: h& H& C+ z- O) m$ ^9 |
Precomputing WPA PMK to crack WPA PSK/ N% p  `# R& A" O8 E% E
1 E4 L7 O9 a6 A8 x6 ?
  C8 R: t+ f7 `' ^& R
* d2 h. M  v! e* K% F& U+ F' [
$ A' G: I. @: B2 J: u; ?coWPAtty Precomputed WPA Attack; h" f/ C0 ]) x" f$ H5 a, e% x

9 S6 \5 D' S6 ~: ?' d5 k+ B
: p+ S: r* ]& D. Z8 ?( q+ }& i, [0 H5 g: ~
6 a0 f: J0 I, X8 e3 ycoWPAtty Recomputed WPA2 Attack% `( X- \" T* r$ i! l1 p7 b3 Q
1 J7 v' g% L% g0 X9 L5 B; G9 M
( ~7 K/ u5 U# ]7 x3 u+ q" i
! x( i: O- i0 J5 _5 y  E3 G) m# f, Q- v
coWPAtty Tables
9 B/ T4 x: ~; N. A$ @4 R- P$ p( p- z  K6 M5 b! t
: X/ ]3 g! I7 U3 Q, ^9 F% B, ^0 x* ]
coWPAtty Usage:7 b, W( \( k$ \! _
8 P* i8 {( S8 ?9 K7 |3 g6 S1 m+ V: T7 v5 p$ Z6 ?& u- ^' u" P4 u; ^# E5 ^4 `  W

  p+ X% z3 q7 T% D% I8 m5 g( P6 W- [( _( acoWPAtty Dictionary Attack:
' O/ s. d# o" J$ `$ i1 Y; v) V) u) I5 n& `4 y* l" A7 y+ u" a0 V1 q3 G
Toperform the coWPAtty dictionary attack we need to supply the tool witha capture file that includes the TKIP four-way handshake, a dictionaryfile of passphrases to guess with and the SSID for the network.3 }3 ?  |! o8 O  }4 P3 J# Z# e( u
: B" f& \3 w( g6 X6 t4 t4 c
7 }" F6 I% c9 w) l- H8 T0 H9 e: Y4 K+ W

6 q$ Y3 I' q6 |* i, Z# MIn orderto collect the four-way handshake you can either wait until a clientjoins the network or preferably you can force it to rejoin the networkusing tools like void11 or aireplay and capture the handshakes usingsomething like kismet, ethereal or airodump.. B- j$ J3 M* p+ S

; A$ P- A/ j' X2 y6 \
( P( h& Z/ S$ s5 n" g3 F* O, Y0 ~" g5 o  p. I+ T6 ]& l& }+ Y6 h9 I6 W# v) w6 H
cowpatty -f dict -r wpapsk-linksys.dump  -s linksys
: M' K! o5 a- \: D$ M* Z
' E" c+ R) B8 M9 k4 z- y7 T# r# j" o) [; Z# @3 ]- y
; s! t7 r7 z2 ]! a: T4 q
+ w" j( S0 ^* k: {+ x! H- D! m, ^0 l1 @$ i/ [- g5 c7 X; R: ], M  W' K1 y1 }" u" l, ^6 m; x% A" v
4 P- \! q  v- O" s, I/ D+ N* i& M% A" @; d
, \8 r8 x; G9 ^" ^# `2 h9 n# q% Z2 Q) S' b1 Y# H
9 @4 y3 D6 E- H# \
As youcan see this simple dictionary attack took 51 seconds, we can speed upthis process by precomputing the WPA-PMK to crack the WPA-PSK (seebelow).
$ K) J. j' w. w# l1 H! J/ x+ c7 k- J- n. s

7 k) p7 b. J; c2 k* u, N, k( h; P( J: j. a% W, @
7 Z. `' S. z1 B1 U, b( P& Rwpapsk-linksys.dump is the capture containing the four-way handshake
6 ]# g- L6 g3 }- \, U9 e/ ?  ]# t5 v* g: ?  U
5 k7 P% [7 V0 ^4 o+ P1 }6 ^- X* T7 s. S4 ^2 r$ _
3 ?) F3 u: K! F
dict is the password file
$ Y3 o  H+ Z2 \1 X7 H8 T0 E' e0 T) Q; A9 o$ }
3 _3 x. H: u& x8 T) @/ p. x1 _
( ?3 m3 `# m* \* z0 V6 u% [7 ~3 h- l6 [1 N' @1 A; P+ H
linksys is the network SSID
$ ], |. E. X. m! P' M6 b7 X' [) s+ z. f4 ^6 C2 Y

/ J5 W1 N! J4 ~4 h- p, C+ p' ]7 @4 d4 G) s5 t& G* H7 r! N, T$ Y+ ?9 i& l
% a4 t6 [+ {1 @& [) _Precomputing WPA PMK to crack WPA PSK:& d2 R6 l+ }3 X1 ^: a
9 q7 u" }+ G; X0 N7 E8 v6 M" O' }" Y
2 v0 m* u  c, f! E, ?genpmkis used to precompute the hash files in a similar way to Rainbow tablesis used to pre-hash passwords in Windows LANMan attacks.  There is aslight difference however in WPA in that the SSID of the network isused as well as the WPA-PSK to "salt" the hash.  This means that weneed a different set of hashes for each and every unique SSID i.e. aset for "linksys" a set for "tsunami" etc.1 d' `% a8 R2 M) B, A; p9 Z0 T

* F" _+ |* h' Y! w6 B4 g" v& A) Q& x; a+ v- Q
0 Q3 a% ?% z  F0 A( K; g+ `+ P& e! U5 F. a! {* B2 U: |" x* \6 z! x5 x+ f6 t5 m

& c# D9 e9 D$ [; G9 \' g% oSo to generate some hash files for a network using the SSID cuckoo we use:
. j3 b/ m4 n! Z* v  a' d! H/ o# y$ s1 p- b1 V

) E1 M' N# k+ v3 s& t$ @3 T3 @. i7 t/ r# i4 K3 L, |+ p& s/ D% g, V) H' ~$ Q7 t( j  E+ L, h

. I0 A, W: `% jgenpmk  -f  dict  -d linksys.hashfile  -s linksys  
4 V4 j5 J& n( l
, N* z" A+ v7 u3 H7 a4 j3 r( c% ?) b6 C# R0 X
: l+ @$ a& H7 Z$ O. J0 _' _* `; ^% _4 z) N, S/ N* t+ V( E; o7 [0 I1 A- `, d! Q

: r+ E7 |' U7 z/ Y! M1 J4 j  w: a4 b8 L. d

9 x5 C: Z- _$ t8 i
* ^3 {" [# O+ l9 ]" [  O" I& J  S3 V. I$ U3 {9 m% r6 Q9 R/ n. X4 \  N+ l, ?8 P: N# g: Y6 [% j; Q2 K" V7 q

/ d# I# i' O" D% V& F2 v+ \9 S# f" Ddict is the password file+ u' B, ]$ ~9 F% j5 i4 g

5 W0 ~! z0 g# w# z; H( ^; o7 B' i) h3 g& j, {2 e
9 s9 T& F" C9 X! z. V% l8 \; A5 R- A! h* b) j! }
linksys.hashfile is our output file4 x! }# r/ h1 S5 o
! G0 i. |) Z7 g' u5 a6 P* b; {2 W+ F
4 N  J, \: `% \! w
2 U6 w8 H, h$ t) S0 p: o
5 g( H5 V0 {( O$ l/ N& Llinksys is the network ESSID
* y$ u. b# R& L. U8 j# k7 b4 R
3 R  z* |! a, ?4 s% A# E# k+ t' ^9 C3 p0 v# T: V; o' Q, Q; i. c, W

3 v: Z/ _: H% i* p6 r7 d- b- m+ Y& Z9 J' a7 HcoWPAtty Precomputed WPA Attack:
$ H/ A0 f) d( Q- P; B& r5 ], M3 a" Q8 [/ o# h- o% ^4 R  d) ]1 P. |3 B4 O7 H1 Z8 J  P
Now wehave created our hash file we can use it against any WPA-PSK networkthat is utilising a network SSID of cuckoo.  Remember the capture(wpa-test-01.cap) must contain the four-way handshake to be successful.
5 w( K; i, S6 H9 ^
& O9 T$ V1 {' z
2 B  v6 w. }: @; u( c8 W, U8 h' j; e) R# Q8 ?- t
# J" ~5 A: z6 H- o: b. ~9 A- o: q- X2 Y- ?9 u3 c. o
, {% C4 y. o. B# Q" d$ tcowpatty  -d linksys.hashfile -r wpapsk-linksys.dump  -s linksys  
  u# g- i4 q6 B: o0 n! A
9 H+ Y8 H$ M8 y6 b# q! b0 z( _' m& S+ c8 Z6 Y0 R
+ Y$ [6 d0 G" c, ^6 P" c
2 o) q6 _3 ^* T0 }/ Y9 P2 U8 y0 i3 ~; q  q' j6 @4 P; Y. }

$ B$ V1 |* I: k' O5 T$ U- ?; E; q6 Z3 @, _/ I6 V
0 U! Q! M7 ^& @8 l% j8 C9 \2 D! P3 Q. m2 n0 X1 P
" a! u* d) L3 G7 q" D" y* l! o/ _. T. a0 _8 R- a6 V
wpa-test-01.cap is the capture containing the four-way handshake
4 R- x/ E+ B& V9 M; z! @+ G5 |) A7 I

' V' b  Y& H& Y+ z0 _, ?6 D0 }/ I+ k9 q$ _; a
, B" ~. r+ ]  y+ C% ilinksys.hashfile are our precomputed hashes1 ~: S! w% z; m
0 I( R& r- a( e: d

0 {4 j! H. }) }- r$ ?+ p) O  W, e- W) L! A6 {" C! c  x' J+ |/ B' M* S/ W( }) n6 j% I
linksys is the network ESSID+ n/ H: ~4 y# H8 A3 h5 F

- r0 F/ [, b7 x* G2 z3 D' ~% Q9 e& m; I6 d$ D* U0 u% X' r( I6 T* X7 K
( a0 X( u) O* ?% ~( Y( `) I) J. W6 {$ D: b$ Y0 A) N3 r( V7 Q

0 T2 y& u8 K  j( }: D* o7 m/ ^Notice that cracking the WPA-PSK took 0.04 seconds with the pre-computed attacked as opposed to 200 secondswith standard dictionary attack mode, albeit you do need to pre-computethe hash files prior to the attack.  However, precomputing large hashfiles for common SSIDS (e.g. linksys, tsunami) would be a sensible movefor most penetration testers.
$ A6 c; m2 G" D% Q/ o2 n3 V7 m4 g$ M+ ^' N) K  ?* w) R$ d" Y
# s# n. u6 S& B0 n% {
( F! H4 x2 Z. h/ v9 I' b! |- p& A/ I; X3 C) \& ~) [
! y( y% O5 h4 {% acoWPAtty Precomputed WPA2 Attack:5 s8 E& Y2 h( y6 R
$ [# x! P- V$ E' z* M# \" I
( q( f/ m/ U. x0 D: L" X, BcoWPAtty4.0 is also capable of attacking WPA2 captures.  Note: The same hashfile as was used with the WPA capture was also used with the WPA2capture.
$ n0 u  G% _6 w5 N  L6 i1 G* X
+ a! ^/ R7 k, \  S( y
  C8 c: C& J1 ?7 u2 [2 O3 I9 [. Y: b  U* F  q2 a! I% d
! r. C% Y0 l7 ocowpatty  -d linksys.hashfile -r wpa2psk-linksys.dump  -s linksys: Q: S! F. c2 S0 U$ j8 n8 }$ ]3 w* c

0 ~: s' y6 M9 M( o! t" ^+ _- b6 t5 x( @# x7 }$ D; U' t* _/ _$ J# v* K. G
. z& T( m% k1 w
! x5 H" Y6 l+ t5 W' ]
- u* I% |7 S: d# y( V4 l

8 G& B% s$ K  k/ a) o9 J/ j! o# B* A4 N5 X; D
# a) `6 {' A9 h( V- f) J$ X7 N( e) x6 a  c" K) o0 `) i3 Z
7 U9 M* b& V* b2 ?" _* ]& C5 S; Dwpa2psk-linksys.dump is the capture containing the four-way handshake
- {% M1 x$ ^8 }7 E7 Q; y4 V& Q# f/ s8 q

: Z" E6 M* Z. ?* U" R4 Z2 Z. X( _8 v3 U, B+ i" p- B: k4 T5 m8 e
dict is the password file
" V7 j! z( G7 O0 f9 S. m; D4 L  \2 _. ]% [! H
. v( p0 P- s& ?. R3 V1 k! [# B0 b
: U6 f7 T- `7 Q5 x: p/ b) _0 s# v& O' h' ?! j# l1 }1 g/ ?
linksys is the network SSID- w+ f0 ?" A  B! p8 T

- `. q" F, V3 t7 N! w5 k3 Z$ K- V1 ~! g& _
" M, M7 q3 Z& }! n% d8 M. w- l8 k6 b9 E" n
' H: ]5 L/ v- h( F. x5 [coWPAtty Tables: ) ^4 o  }: \& d" u& k8 I1 T4 m. t$ E+ x! @  K
The Church of Wifi have produced some lookup tables for 1000 SSID's computed against a 170,000 word password file.  The resultant table are approximately 7 Gigabytes in size and can be downloaded via Torrent:
, S$ o6 r4 P/ ^$ j) ]  c" C' `- u6 g# T& I* k6 q  v% Q9 o0 G* m9 y+ A5 _2 `6 P
http://torrents.lostboxen.net/co ... atty-4.0_2006-10-19$ x- v6 z* \, R2 Z) O6 v5 s% @- e+ D7 P( k

7 N' i# k' H- n7 b# }$ g/ V1 g( @2 _  H% I, BA 33 Gigabyte set of tables are also available: http://umbra.shmoo.com:6969/5 J  G# p0 f8 p4 `$ g8 L1 H
% T- v- F# ^5 w# G0 q( u( A) ^+ B3 s) Y6 d% H  z% r/ r( w7 \6 E# s, i1 _
6 z% R! @; `) {5 [Or you can buy them via DVD, direct from Renderman (initiator of the project): http://www.renderlab.net/projects/WPA-tables/
) @- h6 ]7 e( S6 j' t6 S/ x, G5 d- Y/ N' Y# b1 P# k$ B
回复

使用道具 举报

97

回帖

416

积分

23 小时

在线时间

少尉

注册时间
2009-12-6
金币
316 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 17:19 |显示全部楼层
楼主这是在抢钱啊
回复

使用道具 举报

60

回帖

428

积分

37 小时

在线时间

少尉

注册时间
2007-2-8
金币
353 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-13 20:10 |显示全部楼层
hahoahaoahoahao
回复

使用道具 举报

478

回帖

3643

积分

61 小时

在线时间

少校

注册时间
2007-8-22
金币
2983 个
威望
3 个
荣誉
0 个
累计签到:4 天
连续签到:0 天
[LV.20]漫游旅程
发表于 2009-12-21 13:57 |显示全部楼层
机器要跑好几个光年
回复

使用道具 举报

161

回帖

683

积分

48 小时

在线时间

中尉

注册时间
2008-11-21
金币
475 个
威望
3 个
荣誉
0 个
累计签到:6 天
连续签到:0 天
[LV.20]漫游旅程
发表于 2009-12-21 14:10 |显示全部楼层
有这东西???????????????????????????????????????
回复

使用道具 举报

1036

回帖

4235

积分

369 小时

在线时间

少校

注册时间
2009-2-4
金币
3100 个
威望
3 个
荣誉
1 个
累计签到:138 天
连续签到:0 天
[LV.200]无线新星
发表于 2009-12-23 19:47 |显示全部楼层
骗人的,好像,还是不买了。楼主不厚道
回复

使用道具 举报

47

回帖

117

积分

17 小时

在线时间

上等兵

注册时间
2008-6-10
金币
65 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-23 22:26 |显示全部楼层
这还叫分享吗/
回复

使用道具 举报

58

回帖

651

积分

21 小时

在线时间

中尉

注册时间
2008-10-12
金币
586 个
威望
0 个
荣誉
0 个

尚未签到

发表于 2009-12-24 12:29 |显示全部楼层
是不是真的啊 买的人来回帖一下啊
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册 微信登录

本版积分规则

Archiver | 手机版 | 无线门户 ( 粤ICP备11076993号|粤公网安备44010602008359号 ) |网站地图

GMT+8, 2026-9-7 10:38

返回顶部 返回列表