Crack WPA on the cloud
cloudcracker.com
Crack WPA on the cloud
1–10 of 31 posts
Re: Crack WPA on the cloud
#2Formerly known as moxie's wpacracker, now with stripe.com payment processing and an API.
Re: Crack WPA on the cloud
#3I love how they quoted Hacker News, as if Hacker News is some sort of editorial team.
Re: Crack WPA on the cloud
#4Unfortunately pentesters can't send their capture files to third parties, so this has limited uses.
Re: Crack WPA on the cloud
#5Formerly known as moxie's wpacracker, now with stripe.com payment processing and an API.
Previous discussion: http://news.ycombinator.com/item?id=982159
Re: Crack WPA on the cloud
#6I love how they quoted Hacker News, as if Hacker News is some sort of editorial team.
It was actually tptacek: http://news.ycombinator.com/item?id=982197
Re: Crack WPA on the cloud
#7I'm not sure what they're using but if I recall from when this has come up before Amazon's EC2 ToS prohibits this usasge.
Re: Crack WPA on the cloud
#8But if you can't get on Wifi, how do you reach the cloud? :)
Re: Crack WPA on the cloud
#9Ah, so don't use any of the 300,000,000 words in their dictionary - https://www.cloudcracker.com/dictionaries.html
Any simple password generator (say, Apple's Keychain, or pwgen) should be able to generate a non-dictionary key of length 12-16 characters in a few seconds that would withstand this and most similar techniques for the next few years.
Re: Crack WPA on the cloud
#10Unfortunately pentesters can't send their capture files to third parties, so this has limited uses.
Why not? A WPA handshake can be considered public information. Connecting to that particular ESSID yields all that's needed to brute force WPA and would be considered external. There's no limitations this presents to pen testers. However, for $17 this is a relatively small dictionary set. Based on what we use for real world pen testing we have just shy of 1 billion unique words / phrases.