Unfortunately pentesters can't send their capture files to third parties, so this has limited uses.
Why not? A WPA handshake can be considered public information. Connecting to that particular ESSID yields all that's needed to brute force WPA and would be considered external. There's no limitations this presents to pen testers. However, for $17 this is a relatively small dictionary set. Based on what we use for real world pen testing we have just shy of 1 billion unique words / phrases.
Crack WPA on the cloud
21–30 of 31 posts
Re: Crack WPA on the cloud
#22Re: Crack WPA on the cloud
#23Re: Crack WPA on the cloud
#24And if you lose your important WPA key and can't recover it via dictionary attack, there's always reaver-wps: http://code.google.com/p/reaver-wps/
only if they have wps enabled...
Re: Crack WPA on the cloud
#25Re: Crack WPA on the cloud
#26Re: Crack WPA on the cloud
#27I'm not sure what they're using but if I recall from when this has come up before Amazon's EC2 ToS prohibits this usasge.
Re: Crack WPA on the cloud
#28Re: Crack WPA on the cloud
#29Re: Crack WPA on the cloud
#30Unfortunately pentesters can't send their capture files to third parties, so this has limited uses.
Why not? A WPA handshake can be considered public information. Connecting to that particular ESSID yields all that's needed to brute force WPA and would be considered external. There's no limitations this presents to pen testers. However, for $17 this is a relatively small dictionary set. Based on what we use for real world pen testing we have just shy of 1 billion unique words / phrases.
I agree the convenience is attractive but I wouldn't want to put myself in that position.