• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

A cloud service to crack WPA/WPA2

Joined
Mar 31, 2007
Messages
1,895 (0.30/day)
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
Thought this to be interesting. You can use it to test your wireless security. It probably won't work as easily if you use central auth for wireless.

Rest of the article:http://blogs.techrepublic.com.com/security/?p=4097&tag=results;CR1

In 2008, I speculated about the future of distributed security cracking. That future has arrived, in the form of a $17 “cloud” based service provided through the efforts of a security researcher known as Moxie Marlinspike. It is effective against pre-shared key deployments of both WPA and WPA2 wireless networks.

The mechanism used involves captured network traffic, which is uploaded to the WPA Cracker service and subjected to an intensive brute force cracking effort. As advertised on the site, what would be a five-day task on a dual-core PC is reduced to a job of about twenty minutes on average. For the more “premium” price of $35, you can get the job done in about half the time. Because it is a dictionary attack using a predefined 135-million-word list, there is no guarantee that you will crack the WPA key, but such an extensive dictionary attack should be sufficient for any but the most specialized penetration testing purposes.

If you opt to use the service, you will of course leave a money trail via Amazon Payments — which is probably a bad idea if you are attempting to gain unauthorized access to a secured network illegally. For the good guys testing the security of a client’s network, however, this is an incredibly handy tool to have at one’s disposal.

It gets even better. If you try the standard 135-million-word dictionary and do not crack the WPA encryption on your target network, there is an extended dictionary that contains an additional 284 million words. In short, serious brute force wireless network encryption cracking has become a retail commodity.
 

hat

Enthusiast
Joined
Nov 20, 2006
Messages
21,731 (3.42/day)
Location
Ohio
System Name Starlifter :: Dragonfly
Processor i7 2600k 4.4GHz :: i5 10400
Motherboard ASUS P8P67 Pro :: ASUS Prime H570-Plus
Cooling Cryorig M9 :: Stock
Memory 4x4GB DDR3 2133 :: 2x8GB DDR4 2400
Video Card(s) PNY GTX1070 :: Integrated UHD 630
Storage Crucial MX500 1TB, 2x1TB Seagate RAID 0 :: Mushkin Enhanced 60GB SSD, 3x4TB Seagate HDD RAID5
Display(s) Onn 165hz 1080p :: Acer 1080p
Case Antec SOHO 1030B :: Old White Full Tower
Audio Device(s) Creative X-Fi Titanium Fatal1ty Pro - Bose Companion 2 Series III :: None
Power Supply FSP Hydro GE 550w :: EVGA Supernova 550
Software Windows 10 Pro - Plex Server on Dragonfly
Benchmark Scores >9000
They just use a dictionary? Good luck getting in to mine.
 

Easy Rhino

Linux Advocate
Staff member
Joined
Nov 13, 2006
Messages
15,444 (2.43/day)
Location
Mid-Atlantic
System Name Desktop
Processor i5 13600KF
Motherboard AsRock B760M Steel Legend Wifi
Cooling Noctua NH-U9S
Memory 4x 16 Gb Gskill S5 DDR5 @6000
Video Card(s) Gigabyte Gaming OC 6750 XT 12GB
Storage WD_BLACK 4TB SN850x
Display(s) Gigabye M32U
Case Corsair Carbide 400C
Audio Device(s) On Board
Power Supply EVGA Supernova 650 P2
Mouse MX Master 3s
Keyboard Logitech G915 Wireless Clicky
Software The Matrix
yea, the idea of distributed cracking is intriguing, but their setup is fail. no way anybody is getting into mine just by going through a dictionary.
 
Joined
Jan 14, 2009
Messages
2,644 (0.47/day)
Location
...
System Name MRCOMP!
Processor 5800X3D
Motherboard MSI Gaming Plus
Cooling Corsair 280 AIO
Memory 64GB 3600mhz
Video Card(s) GTX3060
Storage 1TB SSD
Display(s) Samsung Neo
Case No Case... just sitting on cardboard :D
Power Supply Antec 650w
yeah this is not brute force as they claim :*(... its also not much faster then running your own crack on Cuda using your high end video card instead of the CPU.




if your using WPA chances are you wont be using a dictionary word if your smart enough... witch pritty much confirms this service would only be usefull to crackers out there who want to abuse it. its worthless to anyone who would use it to test security.

any WPA encription is pritty much uncrackable over 10 charators long using all forms of charactors (!fh24) ect.. it would take months to years with multiple GPUs/CPUs trying to brute force it.



i toyed with cracking my own Wifi routers, trying all forms of WEP WPA WPA2 tkip aes...
 
Joined
Jan 31, 2005
Messages
2,053 (0.29/day)
Location
Denmark
System Name Commercial towing vehicle "Nostromo"
Processor 5800X3D
Motherboard X570 Unify
Cooling EK-AIO 360
Memory 32 GB Fury 3666 MHz
Video Card(s) 4070 Ti Eagle
Storage SN850 NVMe 1TB + Renegade NVMe 2TB + 870 EVO 4TB
Display(s) 25" Legion Y25g-30
Case Lian Li LanCool 216 v2
Audio Device(s) B & W PX7 S2e
Power Supply HX1500i
Mouse Harpe Ace Aim Lab Edition
Keyboard Scope II 96 Wireless
Software Windows 11 23H2
wait a second....2 month ago I had a network security firm hired to test my company´s wireless networks.

The lowest encryption we use is WPA2 AES/TKIP with a 13 character encryption code.
The highest encryption we use is a mix of radius servers, mac filtering, static ip´s and randomly keys.

WPA2 AES/TKIP: With various packet sniffing and other winky (Linux tools) it took them 13 hours to crack the key.

The high encryption network: The leaved the Linux laptop with all its fabulous tools for 7 days.
They did not succeed .......

And remember - this was a professional network security company

So it sounds to me - that this "cloud" thing is no other than a money machine....:wtf:
 
Joined
Jan 14, 2009
Messages
2,644 (0.47/day)
Location
...
System Name MRCOMP!
Processor 5800X3D
Motherboard MSI Gaming Plus
Cooling Corsair 280 AIO
Memory 64GB 3600mhz
Video Card(s) GTX3060
Storage 1TB SSD
Display(s) Samsung Neo
Case No Case... just sitting on cardboard :D
Power Supply Antec 650w
wait a second....2 month ago I had a network security firm hired to test my company´s wireless networks.

The lowest encryption we use is WPA2 AES/TKIP with a 13 character encryption code.
The highest encryption we use is a mix of radius servers, mac filtering, static ip´s and randomly keys.

WPA2 AES/TKIP: With various packet sniffing and other winky (Linux tools) it took them 13 hours to crack the key.

The high encryption network: The leaved the Linux laptop with all its fabulous tools for 7 days.
They did not succeed .......

And remember - this was a professional network security company

So it sounds to me - that this "cloud" thing is no other than a money machine....:wtf:

this cloud is not doing the same thing that your security company did. there are a few different ways to crack WPA2, this is just a simple large word list.
your security company would not have tried to crack it via a password list if it was long and complex. there is simply to many variations... the word list would be MASSIVE.... over petabytes...... (50 million average words in a .txt file comes 300-500mb uncompressed)


the last time i checked, a GTX260 did about 120000 passwords per second... if you had a complex password just 8 charactors long it would take over 1933 years to break.
or if it was not so complex, just letters and numbers, 59 years.

if you clustered a lot of GPUs together then you may get the time to crack down to a resonable scale.
 
Last edited:

Easy Rhino

Linux Advocate
Staff member
Joined
Nov 13, 2006
Messages
15,444 (2.43/day)
Location
Mid-Atlantic
System Name Desktop
Processor i5 13600KF
Motherboard AsRock B760M Steel Legend Wifi
Cooling Noctua NH-U9S
Memory 4x 16 Gb Gskill S5 DDR5 @6000
Video Card(s) Gigabyte Gaming OC 6750 XT 12GB
Storage WD_BLACK 4TB SN850x
Display(s) Gigabye M32U
Case Corsair Carbide 400C
Audio Device(s) On Board
Power Supply EVGA Supernova 650 P2
Mouse MX Master 3s
Keyboard Logitech G915 Wireless Clicky
Software The Matrix
this cloud is not doing the same thing that your security company did.

yes. more than likely the firm ran a shit ton of programs both on and off your network. some were brute force but others were packet sniffing high traffic areas and snooping out local machines that have lame passwords or weak encryption and trying man in the middle attacks on them.
 
Joined
Jan 14, 2009
Messages
2,644 (0.47/day)
Location
...
System Name MRCOMP!
Processor 5800X3D
Motherboard MSI Gaming Plus
Cooling Corsair 280 AIO
Memory 64GB 3600mhz
Video Card(s) GTX3060
Storage 1TB SSD
Display(s) Samsung Neo
Case No Case... just sitting on cardboard :D
Power Supply Antec 650w
Good luck with my full ASCII 64 character password :D :p

PFT i could crack that.... gimme a 9MM handgun :D job done in 5 minutes

if thats not convincing.. take out the Shotgun
 
Joined
Apr 26, 2008
Messages
1,126 (0.19/day)
Location
london
System Name Staggered
Processor Intel i5 6600k (XSPC Rasa)
Motherboard Gigabyte Z170 Gaming K3
Cooling RX360 (3*Scythe GT1850) + RX240 (2*Scythe GT1850) + Laing D5 Vario (with EK X-Top V2)
Memory 2*8gb Team Group Dark @3000Mhz 16-16-16-36 1.25v
Video Card(s) Inno3D GTX 1070 HerculeZ
Storage 256gb Samsung 830 + 2*1tB Samsung F3 + 2*2tB Samsung F4EG
Display(s) Flatron W3000H 2560*1600
Case Cooler Master ATCS 840 + 1*120 GT1850 (exhaust) + 1*230 Spectre Pro + Lamptron FC2 (fan controller)
Power Supply Enermax Revolution 85+ 1250W
Software Windows 10 Pro 64bit
there're 1.02*10^77 possibilities for my wireles security, and thats using hex. if it was ascii the possible passwords would equal 4.09*10^151. both of these are alot are alot bigger than the meager 370 million word dictionary.
 
Last edited:
Joined
Jul 29, 2007
Messages
392 (0.06/day)
Location
Portugal
System Name Lil'Lighty
Processor Intel Core i3 530 @ Stock
Motherboard Asus P7P55D
Cooling Artic Cooling Freezer Pro Rev.2
Memory Gskill Ripjaw 1600MHz 9-9-9-24 8GB
Video Card(s) MSI GeForce GTX650 OC 1GB
Storage WD Blue 500GB AAKS
Display(s) ASUS 20'
Case Aerocool Aeroengine II // Two 120mm Blue Fans
Audio Device(s) Creative SoundBlaster LE // Logitech X-230
Power Supply Corsair VX450W
Software Windows 8.1 Pro x64
Gosh, it's better to crack it yourself, keep the money even if it takes some days do decipher the password.
 
Joined
Mar 31, 2007
Messages
1,895 (0.30/day)
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
Gosh, it's better to crack it yourself, keep the money even if it takes some days do decipher the password.
$17 is a lot cheaper than having company resources dedicated to running to crack the network. It also takes technician time which can be expensive.
 
Joined
Mar 12, 2009
Messages
1,079 (0.20/day)
Location
SCOTLAND!
System Name Machine XV
Processor Dual Xeon E5 2670 V3 Turbo unlocked
Motherboard Kllisre X99 Dual
Cooling 120mm heatsink
Memory 64gb DDR4 ECC
Video Card(s) RX 480 4Gb
Storage 1Tb NVME SSD
Display(s) 19" + 23" + 17"
Case ATX
Audio Device(s) XFi xtreme USB
Power Supply 800W
Software Windows 10
i tried the gpu cracking on a 9600gso and it done 6000 per second. with a 8 digit a-z password that come with isp's routers it would take a year.

i was thinking of building a gpu server with 4x 9800gx2's so i could do it in under a month. but lack of funds screwed that up
 

Easy Rhino

Linux Advocate
Staff member
Joined
Nov 13, 2006
Messages
15,444 (2.43/day)
Location
Mid-Atlantic
System Name Desktop
Processor i5 13600KF
Motherboard AsRock B760M Steel Legend Wifi
Cooling Noctua NH-U9S
Memory 4x 16 Gb Gskill S5 DDR5 @6000
Video Card(s) Gigabyte Gaming OC 6750 XT 12GB
Storage WD_BLACK 4TB SN850x
Display(s) Gigabye M32U
Case Corsair Carbide 400C
Audio Device(s) On Board
Power Supply EVGA Supernova 650 P2
Mouse MX Master 3s
Keyboard Logitech G915 Wireless Clicky
Software The Matrix
can't you just set your router to block requests from a mac address after it tried a bunch of times?
 
Joined
Mar 31, 2007
Messages
1,895 (0.30/day)
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
Maybe, depends on the flexibility of the firmware. But if that happened they could spoof their MAC every so often.
 

Easy Rhino

Linux Advocate
Staff member
Joined
Nov 13, 2006
Messages
15,444 (2.43/day)
Location
Mid-Atlantic
System Name Desktop
Processor i5 13600KF
Motherboard AsRock B760M Steel Legend Wifi
Cooling Noctua NH-U9S
Memory 4x 16 Gb Gskill S5 DDR5 @6000
Video Card(s) Gigabyte Gaming OC 6750 XT 12GB
Storage WD_BLACK 4TB SN850x
Display(s) Gigabye M32U
Case Corsair Carbide 400C
Audio Device(s) On Board
Power Supply EVGA Supernova 650 P2
Mouse MX Master 3s
Keyboard Logitech G915 Wireless Clicky
Software The Matrix
Maybe, depends on the flexibility of the firmware. But if that happened they could spoof their MAC every so often.

true, but that would mean it would take a lot longer. it would not be worth it for the cracker and they would just move onto a different target. unless of course you have government secrets on your network :laugh:
 
Joined
Mar 31, 2007
Messages
1,895 (0.30/day)
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
The thing to keep in mind with this service too, is that you capture traffic for X amount of hours and then send it to the cloud to analyze it and break the key. So preventative measures such as MAC filtering won't work in this situation.

But if an attacker is trying to brute force a wireless network and gets kicked off. Well they could probably integrate into the script to change MAC every so often. Or they would move to another target if financial gain is not enough.
 

Easy Rhino

Linux Advocate
Staff member
Joined
Nov 13, 2006
Messages
15,444 (2.43/day)
Location
Mid-Atlantic
System Name Desktop
Processor i5 13600KF
Motherboard AsRock B760M Steel Legend Wifi
Cooling Noctua NH-U9S
Memory 4x 16 Gb Gskill S5 DDR5 @6000
Video Card(s) Gigabyte Gaming OC 6750 XT 12GB
Storage WD_BLACK 4TB SN850x
Display(s) Gigabye M32U
Case Corsair Carbide 400C
Audio Device(s) On Board
Power Supply EVGA Supernova 650 P2
Mouse MX Master 3s
Keyboard Logitech G915 Wireless Clicky
Software The Matrix
The thing to keep in mind with this service too, is that you capture traffic for X amount of hours and then send it to the cloud to analyze it and break the key. So preventative measures such as MAC filtering won't work in this situation.

But if an attacker is trying to brute force a wireless network and gets kicked off. Well they could probably integrate into the script to change MAC every so often. Or they would move to another target if financial gain is not enough.

hrm, but to capture traffic you have to be on the network unless using a man in the middle attack. but in that case you already have to know a bunch of information about the network.
 
Joined
Mar 31, 2007
Messages
1,895 (0.30/day)
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
Wireless broadcasts beacons and other SSID information packets. So you can basically sniff that stuff for a long time and then analyze it. The service though is that you do this to your own network, and send the data to the cloud.
 
Joined
Aug 10, 2007
Messages
4,267 (0.70/day)
Location
Sanford, FL, USA
Processor Intel i5-6600
Motherboard ASRock H170M-ITX
Cooling Cooler Master Geminii S524
Memory G.Skill DDR4-2133 16GB (8GB x 2)
Video Card(s) Gigabyte R9-380X 4GB
Storage Samsung 950 EVO 250GB (mSATA)
Display(s) LG 29UM69G-B 2560x1080 IPS
Case Lian Li PC-Q25
Audio Device(s) Realtek ALC892
Power Supply Seasonic SS-460FL2
Mouse Logitech G700s
Keyboard Logitech G110
Software Windows 10 Pro
I don't believe it wouldn't matter. One would only need to grab enough data and have the service (or their own tools) hack away at it. If successful, return and rape the network.

Like WEP, except that WEP fails so fast that you can find a WLAN, sit there, wait for the key to be figured out, then break in.



Edit, heh, a little late hitting the post button.
 

3volvedcombat

New Member
Joined
May 10, 2009
Messages
1,514 (0.28/day)
Location
South California, The desert.
System Name My Computer
Processor Core 2 Q9550 4Ghz 1.23volts
Motherboard Gigabyte
Cooling Corsair
Memory OCZ
Video Card(s) Galaxy
Storage Western Digital
Display(s) Acer
Case Lian li
Audio Device(s) Asus
Power Supply Corsiar
Software Microsoft
Benchmark Scores 25,000 3dmark06 at 4.35Ghz processor, 835core card!
Just take fits mega reg.

equip it with some 4 GTX 480's

Overclock them just a tad and have them on water cooling

You would have alot of cores for a cluster of processing



but that is still not fast enough so.

but just a though hmmm :)
 
Joined
Mar 31, 2007
Messages
1,895 (0.30/day)
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
Might be cheaper to buy a bunch of like 5 year old pcs for $200 each and cluster em or something :p
 
Joined
Aug 11, 2007
Messages
2,313 (0.38/day)
Location
If I told u.. I'd have to kill u
System Name Hogan's Crap
Processor Intel i3-2120 Crap!
Motherboard Dell POS Crap!
Cooling Stock Crap!
Memory 4 GB Kingston DDR3 10600 Crap!
Video Card(s) Stock Crap!
Storage 500 GB 5400 rpm Crap!
Software Windows 10 64bit
PFT i could crack that.... gimme a 9MM handgun :D job done in 5 minutes

if thats not convincing.. take out the Shotgun
That would work. Until you ran into someone (like me) that has bigger and badder guns waiting. :laugh:
I had a friend for shits and giggles try and crack my network. He's cracked it before in about 3 days time. He had a dedicated gpu box with 3 or 4 260's working on it. He bet me $100 that he could crack it under 7 days max. Hahahaha.... I won. Still havent seen a dime from him though. Im more than safe in the area I live in. Its a neighborhood of older retired folks. :)
 
Joined
Mar 31, 2007
Messages
1,895 (0.30/day)
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
That would work. Until you ran into someone (like me) that has bigger and badder guns waiting.
I had a friend for shits and giggles try and crack my network. He's cracked it before in about 3 days time. He had a dedicated gpu box with 3 or 4 260's working on it. He bet me $100 that he could crack it under 7 days max. Hahahaha.... I won. Still havent seen a dime from him though. Im more than safe in the area I live in. Its a neighborhood of older retired folks.

Retired hackers that worked for crimelords in the 80s :p
 
Joined
Apr 10, 2010
Messages
1,831 (0.36/day)
Location
London
System Name Jaspe
Processor Ryzen 1500X
Motherboard Asus ROG Strix X370-F Gaming
Cooling Stock
Memory 16Gb Corsair 3000mhz
Video Card(s) EVGA GTS 450
Storage Crucial M500
Display(s) Philips 1080 24'
Case NZXT
Audio Device(s) Onboard
Power Supply Enermax 425W
Software Windows 10 Pro
Just right now, from my room I can detect 10 WiFi connections: 4 use WPA, 4 use WEP and the other 2 use no security key at all. Most of the people don't know about this and they just set up the router and leave it on a shelf and that's it. By the way they all use the same channels: 1, 6 and 11.
 
Top