148 ms·
Crack WPA on the cloud
- kevs 15y agoI'm not sure what they're using but if I recall from when this has come up before Amazon's EC2 ToS prohibits this usasge.
- martey 15y agoFrom a Reuters article about a similar program by German security researcher Thomas Roth [1]: "Nothing in this researcher's work is predicated on the use of Amazon EC2. As researchers often do, he used EC2 as a tool to show how the security of some network configurations can be improved," said Amazon spokesman Drew Herdener. [1]: http://uk.reuters.com/article/2011/01/07/us-amazon-hacking-idUKTRE70641M20110107 http://uk.reuters.com/article/2011/01/07/us-amazon-hacking-i...
- organico 15y agoWhich part of the ToS are you referring to?
- bnewbold 15y agoFormerly known as moxie's wpacracker, now with stripe.com payment processing and an API.
- icebraining 15y agoPrevious discussion: http://news.ycombinator.com/item?id=982159 http://news.ycombinator.com/item?id=982159
- mattmaroon 15y agoI love how they quoted Hacker News, as if Hacker News is some sort of editorial team.
- icebraining 15y agoIt was actually tptacek: http://news.ycombinator.com/item?id=982197 http://news.ycombinator.com/item?id=982197
- AndyKelley 15y agoIf so, they misquoted tptacek.
- abcd_f 15y agoThat's pretty creative even if it's prone to abuse. I bet one can source pretty much any quote from HN, in the worst case linking to one's own post :)
- peterwwillis 15y agoUnfortunately pentesters can't send their capture files to third parties, so this has limited uses.
- windexh8er 15y agoWhy not? A WPA handshake can be considered public information. Connecting to that particular ESSID yields all that's needed to brute force WPA and would be considered external. There's no limitations this presents to pen testers. However, for $17 this is a relatively small dictionary set. Based on what we use for real world pen testing we have just shy of 1 billion unique words / phrases.
- deleted 15y ago[deleted]
- peterwwillis 15y agoTechnically it's public but you need to be responsible with how you deal with your client's data. Even if the NDA says nothing about releasing handshake details, you still have to explain to your client why a WPA-cracking website has details about their infrastructure. I agree the convenience is attractive but I wouldn't want to put myself in that position.
- windexh8er 15y agoInteresting thought, but the reality of the situation is quite different. If something is in the public domain (i.e. something you can see, hear or smell) what provisions within the realm of the law protect you from using that sensory data? A company's parking lot may have provisions for me not entering it (i.e guard, fence, etc), but if I perch myself on a parking ramp across the street and use a camera with a powerful lens I can still take pictures of cars and people within the lot. The same is true for radio, and conversely 802.11. If you expose yourself to data leakage via loud APs / incorrect antenna then it should be well understood that that information is being placed in the public domain (i.e. WPA handshake). A would be malicious user is not bound by any of the restrictions mentioned, and so placing them on people that are knowingly auditing is highly counterproductive unless all the client is going for is a warm fuzzy. This particular way of thinking about pen testing and assessments needs to be at the forefront of the testing itself, because if the client is that misinformed/misled they probably need more help than an incorrectly scoped assessment.
- veverkap 15y agoBut if you can't get on Wifi, how do you reach the cloud? :)
- zdw 15y agoAh, so don't use any of the 300,000,000 words in their dictionary - https://www.cloudcracker.com/dictionaries.html https://www.cloudcracker.com/dictionaries.html Any simple password generator (say, Apple's Keychain, or pwgen) should be able to generate a non-dictionary key of length 12-16 characters in a few seconds that would withstand this and most similar techniques for the next few years.
- sukuriant 15y agoWhere did you get 300m words from? Reading that page, I gathered they had many billion words in their dictionary at the highest price...
- lastkarrde 15y agoThe big sticker in the top right hand corner of the main page (https://www.cloudcracker.com/css/images/sticker3.png https://www.cloudcracker.com/css/images/sticker3.png).
- chris123 15y agoInteresting. Trend.
- thereallurch 15y agoAt least someone found a use for all those old bitcoin mining rigs...
- cypherpunks01 15y agoAnd if you lose your important WPA key and can't recover it via dictionary attack, there's always reaver-wps: http://code.google.com/p/reaver-wps/ http://code.google.com/p/reaver-wps/
- catch23 15y agoonly if they have wps enabled...
- icarus_drowning 15y agoA depressingly large number of recently manufactured routers do, and it is on by default by mandate of the WiFi alliance. If the router is Cisco/Linksys, in many instances you can't disable it, at least as I understand it.
- deleted 15y ago[deleted]
- dfc 15y agoWhat pentest team does not have this capability inhouse?
- jasonzemos 15y agoI <3 Moxie Marlinspike and all of his work. It's great to see this project is alive and well again.
- csomar 15y agoI don't have any knowledge in Wireless networks. Any idea how to use that? Where do I get the handshake file and ESSID?
- nodata 15y agoI'd like to see prices for both WPA and WPA2 encryption.
- philjohn 15y agoIt's times like these I'm glad my WPA password is 63 characters long. It's easy for me to remember though as it's a long sentence. Bit of a pain when setting stuff like Apple TV up though :/