Live data from Hacker News

How I cracked my neighbor's WiFi password without breaking a sweat

arstechnica.com

31–40 of 144 posts

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#31
post #23

Earlier quoted context omitted.

My review (of wifiprotector.com): dude, this looks like a virus. Spruce up the page! Give me some screenshots! Please, let me trust you!

Thanks! The download link goes to CNET download.com where they make sure all software is trusted. but I understand we should improve the page so people actually feel reassured before they click on download.

download.com does not make me trust you. It's a red flag that makes me think you're even more likely to be malware. Especially given this: http://insecure.org/news/download-com-fiasco.html

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#32
post #23

Earlier quoted context omitted.

My review (of wifiprotector.com): dude, this looks like a virus. Spruce up the page! Give me some screenshots! Please, let me trust you!

Thanks! The download link goes to CNET download.com where they make sure all software is trusted. but I understand we should improve the page so people actually feel reassured before they click on download.

Ehm... if anything CNET will add malware, not remove it.

Was many years since I've downloaded anything off of download.com and I have a hard time believing that I ever will.

http://www.geek.com/articles/geek-pick/nmap-warns-download-c...

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#33
No doubt, this neighbor should have changed his password long ago, but there is a lot to admire about his security hygiene nonetheless.

I think it's taken too much for granted that one should change passwords on a regular basis. If we assume that changing passwords more frequently means that we are more likely to use more rememberable - and, thus, more guessable - passwords, then perhaps this is not a fluke. Perhaps "pick a truly random, long sequence and keep it for a long time" is not actually bad policy.

In short, I find it odd that the author unquestionably says his neighbor should have had different password behavior, yet it was the only password he couldn't crack. That's an opportunity to revisit assumptions.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#34
post #23

Earlier quoted context omitted.

My review (of wifiprotector.com): dude, this looks like a virus. Spruce up the page! Give me some screenshots! Please, let me trust you!

Thanks! The download link goes to CNET download.com where they make sure all software is trusted. but I understand we should improve the page so people actually feel reassured before they click on download.

I want to add to mock's point - I will trust you more if I could download it from your site than from download.com. It has become such a dump that I actively avoid visiting it. Why delegate the user experience of downloading your products to someone whose interests don't align with yours?

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#35
post #28
post #21

What is the command for aircrack-ng to generate the pcap file with the handshake? (For those curious mac users, you can simply type "brew install aircrack-ng")

Note that (I think) Apple typically uses Broadcomm wireless chips, which are not the best choice for this sort of thing.

So far I have been using Macstumbler in passive mode, but it takes a long time. So far I have only hacked my own test 12345 password

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#36

So what do I run now instead of Kismac, since it doesn't support anything > 10.7.2? Aircrack with some GUI frontend?

A Linux distro.

Don't get me wrong, this isn't an anti-apple rant: I've myself tried to my Macbook laptop to learn aircrack and finally desisted. The most important tools, airodump and aireplay, don't work in Mac, even if you have an injection-capable card.

Your best option is try with Linux either in your Mac (I think Backtrack has a Live CD so you don't have to install anything) or in a non-Apple PC.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#37
post #2

You know, at the cost of $2,500 per year, (although I can't actually find where to purchase the software) you'd probably be better to just YouTube some kid's backtrack tutorial.

What software are you talking about? CloudCracker?

Read the article, or view it and press CTRL-F and type $2,500.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#38
post #34
post #23

Earlier quoted context omitted.

Thanks! The download link goes to CNET download.com where they make sure all software is trusted. but I understand we should improve the page so people actually feel reassured before they click on download.

I want to add to mock's point - I will trust you more if I could download it from your site than from download.com. It has become such a dump that I actively avoid visiting it. Why delegate the user experience of downloading your products to someone whose interests don't align with yours?

OK. Point taken. We have done some A/B tests and see that download rate is the same as from our website. The benefit of redirecting to download.com is that with increased rankings we get more users who visit download.com. I know these issues you said and I saw the articles on HN before. However, you can tell download.com to stop injecting offers into the installer which we did and there are no issues.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#39
post #38
post #34

Earlier quoted context omitted.

I want to add to mock's point - I will trust you more if I could download it from your site than from download.com. It has become such a dump that I actively avoid visiting it. Why delegate the user experience of downloading your products to someone whose interests don't align with yours?

OK. Point taken. We have done some A/B tests and see that download rate is the same as from our website. The benefit of redirecting to download.com is that with increased rankings we get more users who visit download.com. I know these issues you said and I saw the articles on HN before. However, you can tell download.com to stop injecting offers into the installer which we did and there are no issues.

However, you can tell download.com to stop injecting offers into the installer which we did and there are no issues.

How are your users supposed to know that?

Also, you are know asking your users to trust both you and CNET.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#40

> To his chagrin, it took CloudCracker just 89 minutes to crack the 10-character, all-numerical password he used... > Remarkably, neither CloudCracker nor 12 hours of heavy-duty crunching by Hashcat were able to crack the passphrase. The secret: a lower-case letter, followed two numbers, followed by five more lower-case letters So an all-number password was easily cracked with this method, but a shorter password with…

I'm assuming the ten character all numerical password was a phone number. Phone numbers have discernable patterns, like area codes.

Yes. The exchange (middle three for US numbers) also has patterns. More on the allowed codes is here:

http://en.wikipedia.org/wiki/North_American_Numbering_Plan

although, in practice, many of the allowed codes are not occupied. For instance, no exchange around LA would be 213, and no exchange near SF would be 415.

Post reply on HN