[Discuss] comcast wifi question

Richard Pieri richard.pieri at gmail.com
Sat Nov 8 19:24:47 EST 2014


On 11/8/2014 5:29 PM, Edward Ned Harvey (blu) wrote:
> If you don't have the password to some network, the key is derived
> using pbkdf2 with 4096 iterations.  This means a single cpu core can
> guess around 36 guesses per second.

Pyrit w/ coWPAtty on a dual RADEON HD 69xx series can exhaustively 
search 1-6 character PSK in a hair over 3 days:
http://www.tomshardware.com/reviews/wireless-security-hack,2981-8.html
That's substantially faster than coWPAtty's author's 45-60 passwords per 
second on a 2005 vintage Intel box.

There are also several precomputed SSID/PSK tables available to 
accelerate the process:
http://www.renderlab.net/projects/WPA-tables/

Keep in mind that these are exhaustive searches. A more sophisticated 
attack against TKIP can compromise session keys in a matter of a few 
minutes. Like the man says, attacks only get better.

-- 
Rich P.



More information about the Discuss mailing list