detrojones / reaver-wps

Automatically exported from code.google.com/p/reaver-wps
0 stars 0 forks source link

WHR-HP-G300N & AES #126

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
my main router is the Buffalo WHR-HP-G300N ( 
http://www.dd-wrt.com/wiki/index.php/WHR-HP-G300N ) setup 2 use wpa2 personal 
aes, it totally ignores aircrack-ng & reaver to date with tests i've ran so 
far, can anyone confirm this?, from what i read aes wasnt vulnerable, fyi i'm 
using an Alfa AWUS036H (RTL8187) with a an alfa 9 dbi omni ant (sorry if this 
is the wrong place to ask this) also can u please suggest a test for this 
router please? from wikipedia :

AOSS (AirStation One-Touch Secure System) is a system by Buffalo Technology 
which allows a secure wireless connection to be set up with the push of a 
button. Recent AirStation residential gateways incorporate a button on the unit 
to let the user initiate this procedure. AOSS is designed to use the maximum 
level of security available to both connecting devices including both Wired 
Equivalent Privacy (WEP) and Wi-Fi Protected Access (WPA). (which sounds the 
same as wps)

Original issue reported on code.google.com by lauriepa...@gmail.com on 12 Jan 2012 at 12:21

GoogleCodeExporter commented 9 years ago
numerous typos in this post, i wasnt done n hit post 2 early, sorry

Original comment by lauriepa...@gmail.com on 12 Jan 2012 at 12:28

GoogleCodeExporter commented 9 years ago
I haven't tested AOSS; it may not support the WPS registrar functionality that 
Reaver targets. 

You said that the Buffalo router "totally ignorers aircrack-ng & reaver". Can 
you elaborate? Can you not associate with the AP using these tools, or do the 
attacks not succeed, or what?

Original comment by cheff...@tacnetsol.com on 12 Jan 2012 at 12:42

GoogleCodeExporter commented 9 years ago
ive ran besside-ng n pointed it at its bssid started my laptop up so it can 
find something connected, it see's the connected client but goes nowhere, same 
deal with reaver 2 date

Original comment by lauriepa...@gmail.com on 12 Jan 2012 at 1:14

GoogleCodeExporter commented 9 years ago
root@UniMatrix0: pts/2: 2 files 552Kb -> walsh -i mon0 -u

Walsh v1.4 WiFi Protected Setup Scan Tool
Copyright (c) 2011, Tactical Network Solutions, Craig Heffner 
<cheffner@tacnetsol.com>

BSSID                  Channel       WPS Version       WPS Locked        ESSID
--------------------------------------------------------------------------------
--------------
00:26:44:8A:A2:98       1            1.0               N                 
Thomson8AA298
84:C9:B2:B9:41:98       1            1.0               N                 
TALKTALK-B94198
A0:21:B7:E2:02:83       1            1.0               N                 
virginmedia7880455
C4:3D:C7:D2:25:06       1            1.0               N                 
Orange594a95
00:E0:4D:29:3B:5A       1            1.0               N                 
TALKTALK-293B58
F4:EC:38:CB:B9:67       1            1.0               N                 dereks 
network
A0:21:B7:DE:0A:04       1            1.0               N                 
virginmedia9596992
7C:03:4C:B9:2D:44       6            1.0               N                 
SKY92D43
C4:3D:C7:2F:D3:BE       6            1.0               N                 
virginmedia6951353
00:FE:F4:79:E3:60      11            1.0               Y                 
BTHub3-CFSF
CC:96:A0:30:8B:22      11            1.0               N                 
BTHub3-CKX7
90:01:3B:29:8B:D8      11            1.0               N                 
SKY98BD7
00:1E:58:00:62:48      13            1.0               N                 Snape
^C

Original comment by lauriepa...@gmail.com on 12 Jan 2012 at 1:15

GoogleCodeExporter commented 9 years ago

 CH 13 ][ Elapsed: 24 s ][ 2012-01-12 01:17                                         

 BSSID              PWR  Beacons    #Data, #/s  CH  MB   ENC  CIPHER AUTH ESSID                                                                                      

 C0:3F:0E:C2:34:7E   -1        0        0    0 108  -1                    <length:  0>                                                                               
 00:24:A5:B4:8C:EB  -27       54        0    0   6  54e. WPA2 CCMP   PSK  LYS                                                                                        
 92:96:A0:30:8B:24  -54       24        0    0  11  54e  OPN              BTFON                                                                                      
 CC:96:A0:30:8B:22  -54       20        0    0  11  54e  WPA2 CCMP   PSK  BTHub3-CKX7                                                                                
 92:96:A0:30:8B:23  -54       24        0    0  11  54e  OPN              BTOpenzone                                                                                 
 C0:D0:44:47:66:5D  -59       14        0    0   1  54   WPA  TKIP   PSK  SKY26204                                                                                   
 C4:3D:C7:2F:D3:BE  -62        3        0    0   6  54e  WPA2 CCMP   PSK  virginmedia6951353                                                                         
 7C:03:4C:B9:2D:44  -65        6        0    0   6  54e  WPA2 CCMP   PSK  SKY92D43                                                                                   
 84:C9:B2:B9:41:98  -64        3        0    0   1  54e. WPA2 CCMP   PSK  TALKTALK-B94198                                                                            
 00:FE:F4:79:E3:60  -64        7        0    0  11  54e. WPA2 CCMP   PSK  BTHub3-CFSF                                                                                
 00:14:6C:6E:9E:10  -64       11        0    0  11  54 . WEP  WEP         NETGEAR                                                                                    
 C4:3D:C7:D2:25:06  -66       10        1    0   1  54e. WPA2 CCMP   PSK  Orange594a95                                                                               
 02:FE:F4:79:E3:60  -66       11        0    0  11  54e. OPN              BTOpenzone                                                                                 
 00:E0:4D:29:3B:5A  -66       10        0    0   1  54e  WPA2 CCMP   PSK  TALKTALK-293B58                                                                            
 90:01:3B:29:8B:D8  -66       13        0    0  11  54e  WPA2 CCMP   PSK  SKY98BD7                                                                                   
 12:FE:F4:79:E3:60  -67        9        0    0  11  54e. OPN              BTFON                                                                                      
 00:18:4D:98:91:96  -67        3       77    5   6  54   OPN              bozley                                                                                     
 00:1B:2F:E5:5C:CC  -67       10        0    0  11  54 . WPA  TKIP   PSK  barnesnet                                                                                   
 00:1F:33:08:5A:C6  -67        8        2    0  11  54e. WEP  WEP         november                                                                                    
 A0:21:B7:DE:0A:04  -68       10        0    0   1  54e  WPA2 CCMP   PSK  virginmedia9596992                                                                          
 00:1E:58:00:62:48  -69        6        0    0  13  54e. WPA2 CCMP   PSK  Snape                                                                                       
 00:14:7F:57:6C:85  -69        9        0    0   1  54e  WEP  WEP         BTHomeHub-0AD2                                                                             
 A0:21:B7:E2:02:83  -69        3        1    0   1  54e  WPA2 CCMP   PSK  virginmedia7880455                                                                          
 00:18:4D:11:93:C6  -69        3        0    0   6  54e. WPA  TKIP   PSK  SKY34709                                                                                    
 F4:EC:38:CB:B9:67  -70        6        0    0   1  54e  WPA2 CCMP   PSK  dereks network                                                                              

 BSSID              STATION            PWR   Rate    Lost    Frames  Probe                                                                                            

 C0:3F:0E:C2:34:7E  00:23:4E:21:CD:C2  -69    0 - 1      2        2                                                                                                   
 (not associated)   00:23:6C:86:96:FA  -65    0 - 1      0        4                                                                                                   
 (not associated)   60:FB:42:63:F6:75  -67    0 - 1     98        8  SKY92D43                                                                                         
 (not associated)   14:8F:C6:82:A6:D0  -68    0 - 1      0        1                                                                                                   
 (not associated)   90:00:4E:C7:9E:79  -72    0 - 1      0        1  SKY62346                                                                                         
 00:18:4D:98:91:96  00:C0:CA:4A:A5:27   -9    0 -24      0       77       

Original comment by lauriepa...@gmail.com on 12 Jan 2012 at 1:17

GoogleCodeExporter commented 9 years ago
[deleted comment]
GoogleCodeExporter commented 9 years ago
 CH 13 ][ Elapsed: 24 s ][ 2012-01-12 01:17                                         

 BSSID              PWR  Beacons    #Data, #/s  CH  MB   ENC  CIPHER AUTH ESSID                                                                                      

 C0:3F:0E:C2:34:7E   -1        0        0    0 108  -1                    <length:  0>                                                                               
 00:24:A5:B4:8C:EB  -27       54        0    0   6  54e. WPA2 CCMP   PSK  LYS 

root@UniMatrix0: pts/2: 2 files 556Kb -> reaver -i mon0 -a -vv 0 -b 
00:24:A5:B4:8C:EB

Reaver v1.4 WiFi Protected Setup Attack Tool
Copyright (c) 2011, Tactical Network Solutions, Craig Heffner 
<cheffner@tacnetsol.com>

[+] Waiting for beacon from 00:24:A5:B4:8C:EB
[+] Switching mon0 to channel 2
[+] Switching mon0 to channel 3
[+] Switching mon0 to channel 6

Original comment by lauriepa...@gmail.com on 12 Jan 2012 at 1:20

GoogleCodeExporter commented 9 years ago
just got [!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS), 
nothing happens after that, i'll leave it going all night but i dont think 
anythings going to change

Original comment by lauriepa...@gmail.com on 12 Jan 2012 at 1:22

GoogleCodeExporter commented 9 years ago
update:

root@UniMatrix0: pts/2: 2 files 556Kb -> reaver -i mon0 -a -vv 0 -b 
00:24:A5:B4:8C:EB

Reaver v1.4 WiFi Protected Setup Attack Tool
Copyright (c) 2011, Tactical Network Solutions, Craig Heffner 
<cheffner@tacnetsol.com>

[+] Waiting for beacon from 00:24:A5:B4:8C:EB
[+] Switching mon0 to channel 2
[+] Switching mon0 to channel 3
[+] Switching mon0 to channel 6
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[+] Switching mon0 to channel 4
[+] Switching mon0 to channel 6
[+] Switching mon0 to channel 5
[+] Switching mon0 to channel 6
[+] Switching mon0 to channel 6
[+] Switching mon0 to channel 7
[+] Switching mon0 to channel 6
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[+] Switching mon0 to channel 8
[+] Switching mon0 to channel 6
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)
[!] WARNING: Failed to associate with 00:24:A5:B4:8C:EB (ESSID: LYS)

Original comment by lauriepa...@gmail.com on 12 Jan 2012 at 1:44

GoogleCodeExporter commented 9 years ago
Buffalo runs dd-wrt as firmware and dd-wrt doesn't support WPS!

Original comment by efs...@gmail.com on 12 Jan 2012 at 4:48

GoogleCodeExporter commented 9 years ago
[deleted comment]
GoogleCodeExporter commented 9 years ago
My understanding is that the firmware DD-WRT made for Buffalo supports AOSS, 
but the standard DD-WRT firmware does not.

Original comment by cheff...@tacnetsol.com on 12 Jan 2012 at 5:35

GoogleCodeExporter commented 9 years ago

Original comment by cheff...@tacnetsol.com on 17 Jan 2012 at 1:13