Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 72 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow WIFI WPS brute forace attack Faster than cracking WPA/WPA2
EH-Net
May 26, 2012, 08:48:30 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: WIFI WPS brute forace attack Faster than cracking WPA/WPA2  (Read 6796 times)
0 Members and 1 Guest are viewing this topic.
Jamie.R
Hero Member
*****
Offline Offline

Posts: 626



View Profile WWW
« on: December 30, 2011, 08:39:06 AM »

Hi all did anyone else see this .




http://sviehb.wordpress.com/2011/12/27/wi-fi-protected-setup-pin-brute-force-vulnerability/
Logged

OSWP | eCPPT | HackingDojo Nidan
www.jamierougive.co.uk
Seen
Jr. Member
**
Offline Offline

Posts: 96


View Profile
« Reply #1 on: December 30, 2011, 08:58:24 AM »

Yeah I saw it yesterday.  I kinda want to try it out and see how easy it is to crack, but will have to wait until people leave the house in case I break their Internet!
Logged

Sec+, eCPPT
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #2 on: December 30, 2011, 09:11:43 AM »

Yeah I saw it yesterday.  I kinda want to try it out and see how easy it is to crack, but will have to wait until people leave the house in case I break their Internet!

LOL!  At least you're going to be ethical and test on your own systems.  <props  Wink>
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
Seen
Jr. Member
**
Offline Offline

Posts: 96


View Profile
« Reply #3 on: December 30, 2011, 01:16:38 PM »

Yeah, not a fan of jail hayabusa!
Logged

Sec+, eCPPT
dbest
Jr. Member
**
Offline Offline

Posts: 68


View Profile
« Reply #4 on: January 10, 2012, 10:12:57 AM »

Tested reaver at home and it worked well.
Tested at a client and didnt succeed.. Sad
Logged

CISM, CEH, CISA, ISO 27001 LA
DragonGorge
Newbie
*
Offline Offline

Posts: 36


View Profile
« Reply #5 on: March 15, 2012, 01:49:47 PM »

I tried this at home with a spare Linksys router - it was scarily easy. What made it worse was that the Linksys lets you think you've turned WPS without really doing so. That is, I turned WPS off, ran Reaver, and it still cracked my WPS PIN and WPA2 password in under 3 hours.

In my limited experience, Reaver is easier to use and more successful than cracking WEP with no client attached (which I've been unsuccessful in even though my target router is just in the next room.) And Reaver v1.4 comes with a tool called wash that allows you to scan your local area for WPS enabled routers. There wasn't a single router in my local area with WPS off.

One thing I found though was running Reaver caused a DoS on my primary wi-fi router, even though I'd turned the txpower way down. The significant other was not pleased.
Logged
Deadpool614
Newbie
*
Offline Offline

Posts: 27

He who dares, wins


View Profile
« Reply #6 on: April 04, 2012, 03:36:30 PM »

I think that this is the most exciting part about security, well for me anyways. Stuff like this gives people like us a reason to think outside of the box to overcome these security shortcuts. I'm looking forward to trying to find a way to patch this flaw. But even after you shut one door another opens. Nothing is ever stopped, only hindered.
Logged

CIO/G-6 C|EH ....Taking the first steps down a long path.
DragonGorge
Newbie
*
Offline Offline

Posts: 36


View Profile
« Reply #7 on: April 04, 2012, 05:09:48 PM »

AFAIK, Linksys/Cisco are the only ones that don't actually turn WPS off (while letting you think you did). And they've been really slow in coming out with patches. The other brands (e.g. Netgear) actually do turn it off (confirmed). Another plus is that it takes a pretty strong signal to succeed. I asked my neighbor two houses over to plug in my router and Reaver failed in that case.

The sad fact is less than 10% of the routers in my neighborhood use WPA/2 in the first place. Most use WEP and one or two have no authentication at all. Still, for smaller companies the WPS vulnerability could be exploited and cause serious harm.
Logged
rocketscientist
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #8 on: April 09, 2012, 03:25:46 AM »

the fastest one i cracked was in 3 seconds. lol. reaver is just absolutely awesome. but if there is mac filtering don't forget to use --mac= or -A
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.248 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.