10 ms·
How I cracked my neighbor's WiFi password without breaking a sweat
- nickpresta 14y agoSo what do I run now instead of Kismac, since it doesn't support anything > 10.7.2? Aircrack with some GUI frontend?
- gjulianm 14y agoA Linux distro. Don't get me wrong, this isn't an anti-apple rant: I've myself tried to my Macbook laptop to learn aircrack and finally desisted. The most important tools, airodump and aireplay, don't work in Mac, even if you have an injection-capable card. Your best option is try with Linux either in your Mac (I think Backtrack has a Live CD so you don't have to install anything) or in a non-Apple PC.
- ryanmolden 14y ago>What's more, WPA and WPA2 passwords require a minimum of eight characters, eliminating the possibility users will pick shorter passphrases that could be brute forced in more manageable timeframes Should I point out that 'password' is 8 characters :) Have there been studies done that attempt to test the hypothesis that when forced to pick passwords that meet some arbitrary complexity threshold most common users pick things like "password1"? I have a hard time believing most non-techies (heck, even a lot of techies) pick secure passwords.
- chimeracoder 14y agoAnecdotally, most people I know without secure WIFI passwords pick things like: - Their address (sometimes with numerals spelled out) - Their last name - Their child's name - single (common) dictionary word - single (common) dictionary word + one or two digits.
- simba-hiiipower 14y agofor about 80% of protected home networks i’ve accessed the password ends up being someone in the home’s phone number.. not sure if it’s just because it’s often the only 8+ character string of numbers people readily have memorized or if it’s just lazy isp’s that set it that way (and lazy owners who never change it afterwards)..?
- nivloc 14y agoIt's the ISPs. Every time I move the tech resets my password to my home phone number. I'm sure it cuts down their support, but it usually means brute forcing only need worry about the last four digits.
- moxie 14y agoYep, in public compromises of large sets of WPA passphrases, more than 50% of them are phone numbers. This is why we offer a CloudCracker dictionary which includes every valid NANP number in it: https://www.cloudcracker.com/dictionaries.html https://www.cloudcracker.com/dictionaries.html
- commandar 14y agoOne of the things I try very hard to drive home to people is that WPA2 uses a passphrase and not a password. I highly encourage people to use something like a favorite movie quote or a line from a book. Something like "Alas, poor Yorick! I knew him Horatio;" is both harder to crack and easier for a human to remember than something like "v3$bk:j". You're essentially taking natural language, which is something humans are pretty adept at remembering, and turning it into a direct mnemonic for a more complicated passphrase.
- peterwwillis 14y agoPeople are still really surprised when I offer to crack their neighbors' wifi passwords for them - "You can do that?". We've only been at it for over 10 years now.
- rel 14y agoYou know, at the cost of $2,500 per year, (although I can't actually find where to purchase the software) you'd probably be better to just YouTube some kid's backtrack tutorial.
- jetti 14y agoOr get better at social engineering.
- sil3ntmac 14y agoWhat software are you talking about? CloudCracker?
- relix 14y agoRead the article, or view it and press CTRL-F and type $2,500.
- brown9-2 14y agoUsing the Silica wireless hacking tool sold by penetration-testing software provider Immunity for $2,500 a year, I had no trouble capturing a handshake established between a Netgear WGR617 wireless router and my MacBook Pro.
- joshuahedlund 14y ago> To his chagrin, it took CloudCracker just 89 minutes to crack the 10-character, all-numerical password he used... > Remarkably, neither CloudCracker nor 12 hours of heavy-duty crunching by Hashcat were able to crack the passphrase. The secret: a lower-case letter, followed two numbers, followed by five more lower-case letters So an all-number password was easily cracked with this method, but a shorter password with letters was untouchable? Edit: I get that 10^10 is less than 36^8. I was more wondering how the cracker assumes, without knowing already if it's all-numeric or not, that it should try longer numerics before shorter alphanumerics and when it decides to give up on the numbers. I guess it's just known to be more likely for a good number of characters.
- rheide 14y agoMost likely all the numbers up to 10 digits long were in the dictionary. tl;dr of this article: don't use stupid passwords. Edit: the article mentions it was a phone number, so that narrows it down a lot.
- spicyj 14y agoSurprising considering that the latter has less than 2 bits more entropy.
- ajross 14y agoBy my math, a 10 byte sequence of decimal numbers has 33.2 bits of entropy, while a 8 byte sequence of lower case numerals and decimals has 41.3 bits. That's almost 300x as hard to crack. There's also the issue of pattern heuristics. Number-only passwords seem like they'd be common, and thus a reasonable pattern to try out to ~35 bits or so (something that corresponds roughtly to "can be tried in a perceptively short time"), but it's not as clear that there's a significant fraction of passwords in the wild that use alphanumerics but no capitals. So they wouldn't try the passwords from the 36-character alphabet, more likely using a slower heuristic like things where the leading alpha character might be capital, or there might be punctuation between "words", etc...
- peterwwillis 14y ago
- forcer 14y agoDon't really want to hijack this thread so feel free to downvote me if you feel its not appropriate. We launched a product that protects you from these attacks - more discussion here - http://news.ycombinator.com/item?id=4444478 http://news.ycombinator.com/item?id=4444478
- sil3ntmac 14y agoMy review (of wifiprotector.com): dude, this looks like a virus. Spruce up the page! Give me some screenshots! Please, let me trust you!
- tomwalker 14y agoI agree- have a few "learn more" buttons, videos etc
- forcer 14y agoThanks! The download link goes to CNET download.com where they make sure all software is trusted. but I understand we should improve the page so people actually feel reassured before they click on download.
- mock 14y agodownload.com does not make me trust you. It's a red flag that makes me think you're even more likely to be malware. Especially given this: http://insecure.org/news/download-com-fiasco.html http://insecure.org/news/download-com-fiasco.html
- tjoff 14y agoEhm... if anything CNET will add malware, not remove it. Was many years since I've downloaded anything off of download.com and I have a hard time believing that I ever will. http://www.geek.com/articles/geek-pick/nmap-warns-download-com-bundles-malware-with-its-software-2011126/ http://www.geek.com/articles/geek-pick/nmap-warns-download-c...
- mikle 14y ago
- pc86 14y agoAm I the only one that's bothered by seeing that red dotted underline for ANonce, SNonce and Ack?
- pal_graham 14y agoit bothers me too.
- smackfu 14y agoNo, you would think an editor would notice that kind of thing.
- guilhermetk 14y ago>To capture a valid handshake, a targeted network must be monitored while an authorized device is validating itself to the access point. I think it's a really noob question, but how do you monitor a network if you are not connected to it?
- coob 14y agoThe same way you tune into a radio station, these packets are in the air for everyone to see. Many wifi chips can be put into 'promiscuous mode' which allows them to monitor a channel and capture all traffic on it.
- Zenst 14y agoIts wireless so the same way you can overhear two people talking.
- efraim 14y agoThe network card sees all packets that go through the air but discards the ones not meant for your computer. Unless you tell the card not to which is called promiscuous mode, then all the packets are available to the OS.
- rvid 14y agoYou're also screwed if you have WiFi Protected Setup enabled (Its enabled by default in most routers). Once can easily crack a WPA2 passphrase easily in a few hours using a tool like reaver.
- chadyj 14y agoWhat is the command for aircrack-ng to generate the pcap file with the handshake? (For those curious mac users, you can simply type "brew install aircrack-ng")
- eli 14y agoNote that (I think) Apple typically uses Broadcomm wireless chips, which are not the best choice for this sort of thing.
- freshbreath 14y agoThat will install 'aircrack-ng', which can crack WEP ivs packets or a WPA/2 handshake. You will need airodump-ng to actually capture the handshake. I don't think the entire aircrack suite has been ported in homebrew.
- phusion 14y agoAs one of the comments mentions, you can bypass this whole step by using Reaver, which attacks the WPS pin number instead of the encryption scheme. It's not 100% and it takes 8-12 hours to complete, but it does work.
- scott_s 14y agoNo doubt, this neighbor should have changed his password long ago, but there is a lot to admire about his security hygiene nonetheless. I think it's taken too much for granted that one should change passwords on a regular basis. If we assume that changing passwords more frequently means that we are more likely to use more rememberable - and, thus, more guessable - passwords, then perhaps this is not a fluke. Perhaps "pick a truly random, long sequence and keep it for a long time" is not actually bad policy. In short, I find it odd that the author unquestionably says his neighbor should have had different password behavior, yet it was the only password he couldn't crack. That's an opportunity to revisit assumptions.
- Xurinos 14y agoOne should change passwords on an irregular basis (a regular basis is weaker protection than an irregular basis). This is just an additional layer of security, not a perfection. If the password has ever been compromised, a password change policy removes the key from bad hands. Discovered passwords are not always immediately used; in many situations, they are stored for later use, perhaps even sold/traded.
- scott_s 14y agoWe shouldn't make such proclamations based on reasoning along. Security policy that involves human behavior depends extensively on what humans do. So while a particular security policy may be the safest, most rational thing to do, it may fail in practice if people execute it poorly. So, if it is true that when people regularly change their passwords, they pick poorer passwords, then perhaps those poor passwords are a larger risk than the risk of maintaining a compromised password. Again, this is not a question of what is the most rational policy. It is a question of human behavior, which means in order to find an answer, we need to study what people actually do. I googled to see if I could find studies on this, and I did: "The True Cost of Unusable Password Policies: Password Use in the Wild" by Philip Inglesant & M. Angela Sasse: http://www.cl.cam.ac.uk/~rja14/shb10/angela2.pdf http://www.cl.cam.ac.uk/~rja14/shb10/angela2.pdf I have yet to read it in full, but they do touch on this idea at least some.
- mgualt 14y agoA couple of naive questions about the design of the security system: 1. Why is it possible to do the password tests remotely? Why would the key on the router be allowed to be transmitted? Even a 6 character password should be safe if you don't allow multiple tries. 2. Why isn't the handshake protocol encrypted?
- jdthomas 14y ago1. The attack is to brute force the shared secret (password). This can be done offline because by capturing the exchange you have the ANonce and SNonce and all other information required to generate the same key -- except the shared secret. Try lots of passwords and check if you generate the same PTK as the two stations do. 2. Encrypted with what? This is the key exchange stage that is attacked here. 802.11w adds signing to management frames which eliminates the deauth attack -- makes it harder to capture the EAPOL frames. Also, IIRC, WPA2-enterprise would not be susceptible to this sort of attack; you've pre-shared a key rather than a (short) password for generating one. edit: spelling
- delackner 14y agoHonest question: since all devices connecting to a WIFI network are by definition within a short distance of the router itself, is there a WIFI solution that uses pre-shared key cryptography? That seems to me to be the only truly unbreakable option.
- caspianm 14y agoPassword authenticated key exchange should do what we want. I was hoping WPA2 would have have used it already. http://en.wikipedia.org/wiki/Password-authenticated_key_agreement http://en.wikipedia.org/wiki/Password-authenticated_key_agre...
- MichaelGG 14y agoThe key isn't being transmitted, but a hash of it with a nonce is. You could do a DH key exchange and encrypt it, but I doubt that would help that much: An attacker would just need to transmit their own auth packets.
- praveenhm 14y agoThis is very interesting read.
- smackfu 14y agoI would place good money that most AT&T wireless routers (SSID = 2WIREXXX) are using the same 10-digit password that is printed on the sticker on the unit. Yes, it's more secure than the old days of a default password being "default" or "admin" but not so great if 10-digit passcodes are easily broken.
- moxie 14y agoIt's a pretty big keyspace, but not quite big enough these days. I haven't noticed any lack of uniformity across it, but I don't really have enough samples yet to be sure. We have a dictionary specifically for those devices, just because they're so common: https://www.cloudcracker.com/dictionaries.html https://www.cloudcracker.com/dictionaries.html
- smackfu 14y agoVery cool. The obvious question I have after looking at that is why the largest 2WIRE dictionary has 4.8 billion entries when the keyspace is 10 billion. Is the keyspace really not all 10 billion, or is there a 50% chance my key won't be in the dictionary?
- moxie 14y agoYep, 50% chance of success. I'll probably be able to adjust this to 100% in the coming months, but in the current setup that's the maximum space we can cover for our estimate of the maximum price elasticity.
- zerohm 14y agoI found this article to be a bit sensational. It should be titled, "how I paid some experts to crack my neighbor’s Wifi." I’m not trying to dismiss the threat, just put it in perspective. The use of these tools is either expensive ($2500 a year?) or requires a non-trivial amount of expertise (Aircrack-ng). I did find the article linked within to be more interesting and informative. http://arstechnica.com/security/2012/08/passwords-under-assault/ http://arstechnica.com/security/2012/08/passwords-under-assa...
- moxie 14y agoThere's also an in-between. Many CloudCracker users employ tools like KisMAC (which are fairly user-friendly) to get a capture, and then simply upload the output to CloudCracker (also fairly user-friendly).
- ctdonath 14y agoWhen addressing various physical home security issues, I came to the realization that if a trained team of attackers equipped with body armor and night vision broke into my home, the issue escalated beyond anything I could sensibly prepare for. The article reminded me of that. If someone attacks my home wifi with network sniffing hardware, sophisticated password guessing tools, hours of planning and execution, etc then, well, the issue escalated beyond anything I could sensibly prepare for. I realize these computing tools are easy to come by and not terribly hard to use. Ditto body armor, night vision, and combat training. And if someone is inclined to apply them against my pathetic existence, I'm screwed. Planning for such events is pretty pointless, I have other things to do.
- brigade 14y agoA physical assault carries a high chance of being noticed, and unless carried out by law enforcement, a significant chance of being punished with jail time. So it's not something that has a high chance of happening. Additionally, it's hard to defend against, and you definitely don't want to defend against a SWAT team. Whereas a bored teenage neighbor could attack your wireless network with a very small chance of being detected. Or with a sensitive directional antenna it doesn't even have to be your neighbor if the goal is just to sniff traffic. Plus, the only cost to you in defending against this attack is entering a more complex password on new devices. Stick a note on the fridge or choose a phrase.
- SiVal 14y agoI'm no security expert, but after I saw each new wifi password standard cracked within days of its release, I stopped passwording my wifi and used a little script I put on a home linux server to watch the router and if it spotted any unrecognized MAC addresses getting an IP address from DHCP, it would throw them out within a few seconds. These days, I just turn on the MAC address filter that's built in to most wifi base stations. Now, unless I've manually entered your MAC address into my whitelist, my router won't connect you. My wifi shows up as "open" to any machine that passes by, yet it won't connect. Many (most?) of you know more about security than I do. How secure is the MAC address whitelist approach compared to a password approach?
- frankus 14y agoMy strategy is to use a human-readable password for my guest network (which I actually considered leaving completely open), and a crazy-long random password that I copy and paste from my password manager for my internal network.
- robertskmiles 14y agoWhy did you decide not to leave it open?
- frankus 14y agoI felt like it would make me responsible for monitoring it for abuse. It could be something as innocent as a cheapskate neighbor using enough bandwidth to run afoul of my cap, or someone using it for nefarious purposes either on a continuous or drive-by basis.
- laxk 14y agoIs there way to measure WiFi signal quality between router and connected devices? any API on linux side? An easy generic protection can be done in the following way (if there is api): Ban all unknown MAC addresses with WiFi signal quality below the specific treshhold. In that case if hacker decides to use fake MAC address he cannot fake signal quality on my side. Does it work?
- icebraining 14y agoYou can measure the signal quality, but that doesn't buy you much. If you only ban unknown MACs, then he can just clone yours, and signal quality is easy to evade with a cheap (< $20) higher gain antenna. In my home, I often get a better signal using my laptop with an external antenna two walls from the AP than with my phone just a couple of meters away from it.
- recursive 14y agoThe only reason I even have a password is on my router is that it crashes more often under traffic if I leave it open. I intentionally made the password easy to guess.
- X-Istence 14y agoThat is why a passphrase is so important. No longer it is a dictionary word, now it is multiple dictionary words together.
- debacle 14y agoWas it correct battery horse staple or battery horse correct staple? I use passphrases almost exclusively. The key is picking words at random - phrases are easy to guess, though sometimes I pick them because, to me, they're easy to remember. "Areyouopposingshadowmoon?" is an incredibly secure password, and it's very likely that no one would ever 'guess' that phrase, but it's also highly easy to remember (because 1997 engrained it into my head).
- X-Istence 14y agoI use things I remember from movies/books. Stuff that has always stuck in my head to the point that there is no way for me to forget it.
- koevet 14y agoI have successfully cracked a couple of Routers using Reaver. Reaver Leverages a bug in WPS (wifi protected setup) http://arstechnica.com/business/2012/01/hands-on-hacking-wifi-protected-setup-with-reaver/ http://arstechnica.com/business/2012/01/hands-on-hacking-wif... It's way faster than brute force or dictionary attacks.
- stonefroot 14y agore: MAC spoofing I don't use WiFi as a matter of practice, but I'm curious: What if you could keep all the "whitelisted" MAC's continually logged in to your network, or, at least, you could keep track of when they log out. The idea being that MAC spoofing is not possible if the particular MAC that the attacker wants to spoof is currently logged in. This is generally true with Ethernet, correct? Is this true with WiFi as well? (Assume the traffic is encrypted.) And in fact, it seems this guy's hack relies on someone "rejoining" the network, triggered by a deauth frame. Without that "rejoining" step, I don't think he could get very far. If his target is continually connected, and there's no way to force a "rejoin", and all the traffic is encrypted, then what can he do? The problem to me sounds like the fact that someone can send a "deauth" frame and have it be accepted, and the Apple Mac gives no warnings that the connection underwent a "rejoin".
- olalonde 14y ago> To his chagrin, it took CloudCracker just 89 minutes to crack the 10-character, all-numerical password he used, although because the passcode wasn't contained in the entry-level, 604 million-word list, I relied on a premium, 1.2 billion-word dictionary that costs $34 to use. There are 10 billion (10^10) possible 10-character all-numerical passwords. Can anyone explain how it was cracked using a 1.2 billion-word dictionary?
- githulhu 14y agoMaybe they assume that a 10-number password is likely to be a phone number, and so constrain the three most significant numbers to just valid US area codes. Add in other rules, like the fourth digit never being a zero, etc...and the space is pared down quite a bit.