Live data from Hacker News

Crack WPA on the cloud

cloudcracker.com

21–30 of 31 posts

Re: Crack WPA on the cloud

#21

Unfortunately pentesters can't send their capture files to third parties, so this has limited uses.

Why not? A WPA handshake can be considered public information. Connecting to that particular ESSID yields all that's needed to brute force WPA and would be considered external. There's no limitations this presents to pen testers. However, for $17 this is a relatively small dictionary set. Based on what we use for real world pen testing we have just shy of 1 billion unique words / phrases.

[deleted]

Re: Crack WPA on the cloud

#24
post #16

And if you lose your important WPA key and can't recover it via dictionary attack, there's always reaver-wps: http://code.google.com/p/reaver-wps/

only if they have wps enabled...

A depressingly large number of recently manufactured routers do, and it is on by default by mandate of the WiFi alliance. If the router is Cisco/Linksys, in many instances you can't disable it, at least as I understand it.

Re: Crack WPA on the cloud

#29
It's times like these I'm glad my WPA password is 63 characters long. It's easy for me to remember though as it's a long sentence. Bit of a pain when setting stuff like Apple TV up though :/

Re: Crack WPA on the cloud

#30

Unfortunately pentesters can't send their capture files to third parties, so this has limited uses.

Why not? A WPA handshake can be considered public information. Connecting to that particular ESSID yields all that's needed to brute force WPA and would be considered external. There's no limitations this presents to pen testers. However, for $17 this is a relatively small dictionary set. Based on what we use for real world pen testing we have just shy of 1 billion unique words / phrases.

Technically it's public but you need to be responsible with how you deal with your client's data. Even if the NDA says nothing about releasing handshake details, you still have to explain to your client why a WPA-cracking website has details about their infrastructure.

I agree the convenience is attractive but I wouldn't want to put myself in that position.

Post reply on HN