Уязвимость в протоколе Wi-Fi Protected Setup

Discussion in 'Беспроводные технологии/Wi-Fi/Wardriving' started by gpuhash, 30 Dec 2011.

  1. Rahmon

    Rahmon Member

    Joined:
    8 Nov 2017
    Messages:
    14
    Likes Received:
    6
    Reputations:
    0
    Помогите пожалуйста...
    [*] Audit started at 2018.05.21 15:40:45 (UTC+05:00).
    [*] Associating with AP...
    [+] Associated with BC:EE:7B:34:d6:58 (ESSID: BOYGONY).
    [*] Trying pin "00681278"...
    [*] Sending EAPOL Start...
    [-] Request timed out.
    [*] Trying pin "00681278"...
    [*] Sending EAPOL Start...
    [*] Received Identity Request.
    [*] Sending Identity Response...
    [*] Received WPS Message M1.
    [*] E-Nonce: 1B7756FA8F6E55BA33E52E83712A6EC4
    [*] PKE: 635135EE29AEF97782690DE6871D5F7F3E4F9AC67DB81DFB93152F0ABE1B2C6E8F82F3CA611EAD6AB34F73634CE5BA841BA22A68347B5B160A123F111149E62861C53ED25088B18767193991887615ECBA46DEBA4CA58F5CE96A4CCAE7974652BBACE9C6C930D96121690B2D8C4F5C3419063B86D637970157A92EA36C1F9AB44EA5B12EF9A150D53CAA9BF643246D6ADD3B0360EE75B738BD7B53291ED4EB4F53B4679A10570D3A7C874CD1B2EF314E79E129E21CA9E13C43AD663637556728
    [*] Manufacturer: ASUSTeK Computer Inc.
    [*] Model Name: Wi-Fi Protected Setup Router
    [*] Model Number: RT-N66U
    [*] Serial Number: bc:ee:7b:34:d6:58
    [*] Device Name: RT-N66U
    [*] Sending WPS Message M2...
    [*] PKR: 97B9803CC4BBBC8F8FBED71237080C3B5BED564A64B4DC07861C2409E92D38D03B1568058625D1F34D9B6B22245C1004F84DBEEE9F96F63A758852A3782DF9BCA9C4C3B7CBB9BBF27EF1B89367633EC36E67998D1CEAE55771F5F608795A8820B34C6B00850F3EAA3B8E6588AF472B08CE223FB073B483ACA20B9193CCAFD67B0C71E92BDC4E1512489D9C71ED3C7F78B720CFE492BC559E977E66661DE1929B8322E0778DEA98177420A66C5AA3D572478101F2A4BCED8F3DD5AC20C94C2F4E
    [*] AuthKey: 7B7A448F542F76ED4FC38E47AD9E0DDB3024663C770771BBA02BACE2A9A6A009
    [*] Received WPS Message M3.
    [*] E-Hash1: 7BC1382BDF8AA8606F494202D812834FAA817AACAE342F45A3FE69F182A8198F
    [*] E-Hash2: 1F5EC2E3E4AB8EB4248D40E0866585DA5555D29AAF6E7212AA8AA3F6C06DBE74
    [*] Sending WPS Message M4...
    [*] Received WSC NACK.
    [-] Error: Wrong PIN code.
    [*] EAP session closed.
    [*] Starting Pixie Dust attack...
    [*] Audit stopped at 2018.05.21 15:41:40 (UTC+05:00).
    [-] Pixie Dust PIN not found.
     
  2. DSL2650NRU

    DSL2650NRU Well-Known Member

    Joined:
    12 Apr 2016
    Messages:
    467
    Likes Received:
    306
    Reputations:
    1
    66122067
     
    Rahmon likes this.
  3. Rahmon

    Rahmon Member

    Joined:
    8 Nov 2017
    Messages:
    14
    Likes Received:
    6
    Reputations:
    0
    Спасибо большое. Вот ещё
    [*] Audit started at 2018.05.22 02:15:12 (UTC+05:00).
    [*] Associating with AP...
    [+] Associated with 04:8D:38:4F:A2:EA (ESSID: Netis 2.4G).
    [*] Trying pin "86250320"...
    [*] Sending EAPOL Start...
    [*] Received Identity Request.
    [*] Sending Identity Response...
    [*] Received WPS Message M1.
    [*] E-Nonce: 5BAD179821EC77800471CB2F4CC85249
    [*] PKE: D0141B15656E96B85FCEAD2E8E76330D2B1AC1576BB026E7A328C0E1BAF8CF91664371174C08EE12EC92B0519C54879F21255BE5A8770E1FA1880470EF423C90E34D7847A6FCB4924563D1AF1DB0C481EAD9852C519BF1DD429C163951CF69181B132AEA2A3684CAF35BC54ACA1B20C88BB3B7339FF7D56E09139D77F0AC58079097938251DBBE75E86715CC6B7C0CA945FA8DD8D661BEB73B414032798DADEE32B5DD61BF105F18D89217760B75C5D966A5A490472CEBA9E3B4224F3D89FB2B
    [*] Manufacturer: Realtek Semiconductor Corp.
    [*] Model Name: RTL8xxx
    [*] Model Number: EV-2010-09-20
    [*] Serial Number: 123456789012347
    [*] Device Name: RTK_AP
    [*] Sending WPS Message M2...
    [*] PKR: 40EFC4A45E5A1EC75F288BEE4BE275FD32CCAE023F85D8276C3242DC98DFE86A58C14964765B57DB1CD15EB473418D15CF2216155011F8C86C9E343111F798CDDE166A36C5297D27421181F64C20B514D987687AB3BD357C58558C7D7EEE3D5E00BDD04A9BA361E74803E27BCAE595CF1D86EB6CE943AB0F41497A570AAE2B1F82F47DF9756EAE517E3E0CC7604336B30D06B4587EAAB001DAAA287DE4C43573890A0E1B909D850559605B14315E5CCD7A133CFE7595A8182DEB763834A81396
    [*] AuthKey: F9CFD488D64161FB24A84E685EDD050A157B31CFE2CEE80F834E471C03B75760
    [*] Received WPS Message M3.
    [*] E-Hash1: 2723341D7A519D6BCFA6D367F4EC496C3C95C7A128C0A5F77FFBEC913772C4CC
    [*] E-Hash2: 2723341D7A519D6BCFA6D367F4EC496C3C95C7A128C0A5F77FFBEC913772C4CC
    [*] This AP is potentially vulnerable to the "empty string" pin.
    [*] To specify <empty> pin, add empty line to PINs list and disable checksum calculation.
    [*] Also in this case the pin can have two same halfs (e.g. 00000000).
    [*] Sending WPS Message M4...
    [*] Received WSC NACK.
    [-] Error: Wrong PIN code.
    [*] Sending WSC NACK...
    [*] EAP session closed.
    [*] Starting Pixie Dust attack...
    [*] Audit stopped at 2018.05.22 02:15:22 (UTC+05:00).
     
  4. binarymaster

    binarymaster Elder - Старейшина

    Joined:
    11 Dec 2010
    Messages:
    4,717
    Likes Received:
    10,195
    Reputations:
    126
    Прочитай и осознай вот это.
     
  5. Rahmon

    Rahmon Member

    Joined:
    8 Nov 2017
    Messages:
    14
    Likes Received:
    6
    Reputations:
    0
    [*] Audit started at 2018.05.22 22:48:38 (UTC+05:00).
    [*] Associating with AP...
    [+] Associated with 04:8D:38:4F:A2:EA (ESSID: Netis 2.4G).
    [*] Trying pin ""...
    [*] Sending EAPOL Start...
    [*] Received Identity Request.
    [*] Sending Identity Response...
    [*] Received WPS Message M1.
    [*] E-Nonce: 4DCFBDE762CA4BB7355BCCAF31D1D4D2
    [*] PKE: D0141B15656E96B85FCEAD2E8E76330D2B1AC1576BB026E7A328C0E1BAF8CF91664371174C08EE12EC92B0519C54879F21255BE5A8770E1FA1880470EF423C90E34D7847A6FCB4924563D1AF1DB0C481EAD9852C519BF1DD429C163951CF69181B132AEA2A3684CAF35BC54ACA1B20C88BB3B7339FF7D56E09139D77F0AC58079097938251DBBE75E86715CC6B7C0CA945FA8DD8D661BEB73B414032798DADEE32B5DD61BF105F18D89217760B75C5D966A5A490472CEBA9E3B4224F3D89FB2B
    [*] Manufacturer: Realtek Semiconductor Corp.
    [*] Model Name: RTL8xxx
    [*] Model Number: EV-2010-09-20
    [*] Serial Number: 123456789012347
    [*] Device Name: RTK_AP
    [*] Sending WPS Message M2...
    [*] PKR: 323855877FA97B6BDDD6FFE4D4771754798A3BDCE786D1A6B92FEFEBF8B7F765DDB3D46D5282277308EA041E56C87FEF681A13FFF0F6C5F251C68B1C5C6DFD0A0FC3BDF958F1EE1663F45541D4614257A2A853347DF00D0E59D0CC40038D5BAA1CC23410BD2B06B7B76042F894BC69BB912C8EA36256E9A54C9DE5E33FD2956EE8D75E464B811D8C08642B2C5E909690425AD54C37DE6B9DBFD72627C03427FCDC57AA59472D0018163E0B6B1B02120D4316B2F22F330CE6C337AD8C1C3EFD78
    [*] AuthKey: 18D88215B9F432923B87A8886EDC676126172250A22C8DC2EE9CBAC7EBE22DDF
    [*] Received WPS Message M3.
    [*] E-Hash1: 090A23C2D8B406248711F723E65E60B12682B923F42FBEC224D2F26AA4E00EBD
    [*] E-Hash2: 090A23C2D8B406248711F723E65E60B12682B923F42FBEC224D2F26AA4E00EBD
    [*] Sending WPS Message M4...
    [*] Received WSC NACK.
    [-] Error: Wrong PIN code.
    [*] Sending WSC NACK...
    [*] EAP session closed.
    [*] Starting Pixie Dust attack...
    [*] The AP /might be/ vulnerable.
    [*] Try again with --force or with another (newer) set of data.
    [*] Also ensure that the date time and time zone on your computer are set correctly.
    [*] Audit stopped at 2018.05.22 22:49:03 (UTC+05:00).
    [*] Audit started at 2018.05.22 22:49:57 (UTC+05:00).
    [*] Associating with AP...
    [+] Associated with 04:8D:38:4F:A2:EA (ESSID: Netis 2.4G).
    [*] Trying pin ""...
    [*] Sending EAPOL Start...
    [*] Received Identity Request.
    [*] Sending Identity Response...
    [*] Received WPS Message M1.
    [*] E-Nonce: 75F440237407301C29E6E2C416FE9E9A
    [*] PKE: D0141B15656E96B85FCEAD2E8E76330D2B1AC1576BB026E7A328C0E1BAF8CF91664371174C08EE12EC92B0519C54879F21255BE5A8770E1FA1880470EF423C90E34D7847A6FCB4924563D1AF1DB0C481EAD9852C519BF1DD429C163951CF69181B132AEA2A3684CAF35BC54ACA1B20C88BB3B7339FF7D56E09139D77F0AC58079097938251DBBE75E86715CC6B7C0CA945FA8DD8D661BEB73B414032798DADEE32B5DD61BF105F18D89217760B75C5D966A5A490472CEBA9E3B4224F3D89FB2B
    [*] Manufacturer: Realtek Semiconductor Corp.
    [*] Model Name: RTL8xxx
    [*] Model Number: EV-2010-09-20
    [*] Serial Number: 123456789012347
    [*] Device Name: RTK_AP
    [*] Sending WPS Message M2...
    [*] PKR: A03834310445FF4CEC466C749837E4817ACDAC9FE7D7681969918855CEE1143CE0C8FC06BE7BC60F87C68EE60E4D8683E3D6FF5C48D4DD02826338E2B47925CE5E986DF5F44E011540032F434D6290B635720B67FCB9B48B659D4904C5BEC01C10492352E62AD4D37C805DFD930F1F03C9B65E0F6EC3F8CAD07E53C37C5D955DEFBE04CE223F02776DCCF47578553299651A172690FAE5735FD28B4475B7452824E41BF1E80CEA69D62373D354160DD7FDAD810A153FDBA70830F5B10D2BD081
    [*] AuthKey: B665DDCD433499519FC3A5A22ADC20256793DC490DA6D4B6E5AE800FD79F44D2
    [*] Received WPS Message M3.
    [*] E-Hash1: B0E40E40E042E20901D769D2B35F3D005667855C9FB98C63F1F8D72B90369297
    [*] E-Hash2: B0E40E40E042E20901D769D2B35F3D005667855C9FB98C63F1F8D72B90369297
    [*] Sending WPS Message M4...
    [*] Received WSC NACK.
    [-] Error: Wrong PIN code.
    [*] Sending WSC NACK...
    [*] EAP session closed.
    [*] Starting Pixie Dust attack...
    [*] The AP /might be/ vulnerable.
    [*] Try again with --force or with another (newer) set of data.
    [*] Also ensure that the date time and time zone on your computer are set correctly.
    [*] Audit stopped at 2018.05.22 22:50:22 (UTC+05:00).
    [*] Audit started at 2018.05.22 22:53:15 (UTC+05:00).
    [*] Associating with AP...
    [+] Associated with 04:8D:38:4F:A2:EA (ESSID: Netis 2.4G).
    [*] Trying pin ""...
    [*] Sending EAPOL Start...
    [*] Received Identity Request.
    [*] Sending Identity Response...
    [*] Received WPS Message M1.
    [*] Manufacturer: Realtek Semiconductor Corp.
    [*] Model Name: RTL8xxx
    [*] Model Number: EV-2010-09-20
    [*] Serial Number: 123456789012347
    [*] Device Name: RTK_AP
    [*] Sending WPS Message M2...
    [*] Received WPS Message M3.
    [*] Sending WPS Message M4...
    [*] Received WSC NACK.
    [-] Error: Wrong PIN code.
    [*] Sending WSC NACK...
    [*] EAP session closed.
    [*] Associating with AP...
    [+] Associated with 04:8D:38:4F:A2:EA (ESSID: Netis 2.4G).
    [*] Audit stopped at 2018.05.22 22:53:31 (UTC+05:00).
     
  6. DSL2650NRU

    DSL2650NRU Well-Known Member

    Joined:
    12 Apr 2016
    Messages:
    467
    Likes Received:
    306
    Reputations:
    1
    The AP /might be/ vulnerable.
    Try again with --force or with another (newer) set of data - означает пробуй пикси с --force. Также можно проверить с пустым пином роутерсканом. На всякий случай
     
    #4366 DSL2650NRU, 22 May 2018
    Last edited: 22 May 2018
  7. binarymaster

    binarymaster Elder - Старейшина

    Joined:
    11 Dec 2010
    Messages:
    4,717
    Likes Received:
    10,195
    Reputations:
    126
    Тогда попробуй ещё с нулями... хотя конечно лучше прогнать pixiewps в --force режиме.
    С пустым он уже попробовал.
     
  8. Rahmon

    Rahmon Member

    Joined:
    8 Nov 2017
    Messages:
    14
    Likes Received:
    6
    Reputations:
    0
    в RS попробовать или загрузится с linux?
     
  9. Rahmon

    Rahmon Member

    Joined:
    8 Nov 2017
    Messages:
    14
    Likes Received:
    6
    Reputations:
    0
    Ваш предлагаемый пин не сработал. 66122067
    [*] Audit started at 2018.05.23 12:11:11 (UTC+05:00).
    [*] Associating with AP...
    [-] Association failed.
    [*] Associating with AP...
    [-] Association failed.
    [*] Associating with AP...
    [+] Associated with BC:EE:7B:34:d6:58 (ESSID: BOYGONY).
    [*] Trying pin "66122067"...
    [*] Sending EAPOL Start...
    [*] Received Identity Request.
    [*] Sending Identity Response...
    [*] Received WPS Message M1.
    [*] E-Nonce: 4E7B69106D8D09308246EF2B45B7E7B4
    [*] PKE: D597BF310CDB0B30FD7A475A7AADB1E2D0FAC14208100A7C2B793B104A801DD692574CB4707978D767B587F3A082134857470D21E41E7CA388ACEA87742DE118A22B13FC57A44326B11D3806200B14194F582CA2A2C132A75E6BF098FE6BB31DB7782D87519AF85AE59A352D17BF1CE52A7767123BE14C8E36B4E0AC6208B32696698AAE331491CF6E03C8B091ACD5971370E4C5F3E02A94C012816A8E7520530BF05965268250F7EDECE1B105BFEBD7AB0D8484BB36B113E48EB61A3051CF42
    [*] Manufacturer: ASUSTeK Computer Inc.
    [*] Model Name: Wi-Fi Protected Setup Router
    [*] Model Number: RT-N66U
    [*] Serial Number: bc:ee:7b:34:d6:58
    [*] Device Name: RT-N66U
    [*] Sending WPS Message M2...
    [*] PKR: 8CEC70FBA93402CCB4B65E2483B682AC25D29AF624AE9732FC06482A4CEC35AE77D67117AB7E5B6040EFA37F72E7D8A7F0D6BABC63A4FEC621F25F0320A062447249CFC03E82E79C08075BC9F49CA53E3F65E6AA4F00010A355EAA30DB5671369EBFB35CDC5334688FF03ECE11E39D7D9817AB96B8FF105C56EDFD25AD4152CCD9F3B9019F95965683B621692A6865186F76C0F2E7441D97826B414B968B4826B2814478DF1C27467E3A9CC4878FAB8B18CC9A3F965895F344E269CC350294AD
    [*] AuthKey: DFA0A948605D9A689A073A4D09DF31C731E5634A504E8DF906A6E752624F7744
    [*] Received WPS Message M3.
    [*] E-Hash1: AAA666F4446E68D1AB4B6D14D86007EFFBDFAB7A7E8C7C42FD85F0757CEA46EF
    [*] E-Hash2: CA9C4D8F5FDF49C5B77CAED37F7496ECE242DFF9D788A8F93D8834A5AF369768
    [*] Sending WPS Message M4...
    [*] Received WSC NACK.
    [-] Error: Wrong PIN code.
    [*] EAP session closed.
    [*] Associating with AP...
    [*] Starting Pixie Dust attack...
    [+] Associated with BC:EE:7B:34:d6:58 (ESSID: BOYGONY).
    [-] Pixie Dust PIN not found.
    [*] Audit stopped at 2018.05.23 12:15:47 (UTC+05:00).
     
  10. binarymaster

    binarymaster Elder - Старейшина

    Joined:
    11 Dec 2010
    Messages:
    4,717
    Likes Received:
    10,195
    Reputations:
    126
    Без разницы. Но одно известно точно - у пина первая и вторая половины должны совпадать.
     
  11. DSL2650NRU

    DSL2650NRU Well-Known Member

    Joined:
    12 Apr 2016
    Messages:
    467
    Likes Received:
    306
    Reputations:
    1
    Алгоритм не известен
     
    Gashek likes this.
  12. maus

    maus Active Member

    Joined:
    30 May 2015
    Messages:
    409
    Likes Received:
    102
    Reputations:
    0
    - а Дампер нашёл пин к TP-LINK.
    [​IMG]
     
  13. WELK

    WELK Member

    Joined:
    14 Jan 2017
    Messages:
    96
    Likes Received:
    8
    Reputations:
    0
    Бо там RT2860 - Ralink
     
    binarymaster likes this.
  14. maus

    maus Active Member

    Joined:
    30 May 2015
    Messages:
    409
    Likes Received:
    102
    Reputations:
    0
    - понятно, именно поэтому Роутер Скан ничего не показывает?
    [​IMG]
     
  15. DSL2650NRU

    DSL2650NRU Well-Known Member

    Joined:
    12 Apr 2016
    Messages:
    467
    Likes Received:
    306
    Reputations:
    1
    24-bit PIN подходит для адсл тп-линков.
     
    4Fun likes this.
  16. DSL2650NRU

    DSL2650NRU Well-Known Member

    Joined:
    12 Apr 2016
    Messages:
    467
    Likes Received:
    306
    Reputations:
    1
    Выберите 24-bit PIN - покажет
     
  17. WELK

    WELK Member

    Joined:
    14 Jan 2017
    Messages:
    96
    Likes Received:
    8
    Reputations:
    0
    через пикси в роутер скане прогоните и тож покажет...
     
  18. TOX1C

    TOX1C Elder - Старейшина

    Joined:
    24 Mar 2012
    Messages:
    1,135
    Likes Received:
    1,931
    Reputations:
    24
    Гадалка в роутер скане смотрит на bssid а не на wps info теги, поэтому ничего и не показывает. На тп линк алгоритма нет. Дампер смотрит на то, что это rt2860 и подсказывает, что возможен их стандартный mac2pin, он же 24бит пин.
    Не для всех и не всегда, адсл вариантов есть 4 - стандартный на Ralnik rt63365, который вскрывается, новые медиатеки с другим алгоритмом, микро дсл с чипсетами броаком, которые хоть и адсл, но не вскрывались генераторами пин-кодов никогда, и еще есть вариант на микро дсл с мозгами broadcom, а wifi у него atheros, и мопед гордо о себе в wps info заявляет, что он не adsl модем, а TL-WA701N.
     
    quite gray, Triton_Mgn, WELK and 2 others like this.
  19. Kakoluk

    Kakoluk Banned

    Joined:
    14 Aug 2015
    Messages:
    514
    Likes Received:
    704
    Reputations:
    4
    https://3wifi.stascorp.com/wpspin
     
    Slayer likes this.
  20. binarymaster

    binarymaster Elder - Старейшина

    Joined:
    11 Dec 2010
    Messages:
    4,717
    Likes Received:
    10,195
    Reputations:
    126
    Вскрываются pixie dust из Router Scan, если конечно WPS включён.
     
    Slayer and user100 like this.