Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Default WPA key arrangement enquiry (UPC,Vodafone,eircom,etc)

Options
  • 08-10-2011 7:09pm
    #1
    Registered Users Posts: 60 ✭✭


    Hi.

    I was having a discussion about the various WEP/WPA keys that are generated on various WiFi routers, and I was asked about the best type of WPA router against brute force. I was thinking about compiling a table to see which was the case. I am only talking about the default config that comes with the more popular routers knocking about.

    For example:
    Current Eircom passwords are 12(?) char hex keys (12^16)
    WEP Eircom keys (old) 32 char hex keys (32^16)

    I know that there are patterns amongst the Vodafone and UPC routers, etc. Can anybody fill me in? Thanks

    (I think that the Voda keys are 10 char alphanumeric) Can someone confirm?

    Thanks. :)


Comments

  • Registered Users Posts: 1,775 ✭✭✭Spacedog


    This old chestnut might get you started on eircom's WEP security (if you can call it that)

    Eircom SSID thinger

    ironically, many people replace their routers often use the same SSID and Keys that eircom used on the old routers.


  • Registered Users Posts: 60 ✭✭obviousTroll


    I am aware of the old Eircom thinger. Thanks spacedog!

    I don't know if I am asking the question wrong, so I'll retry. :)

    Let's say we have 3 eircom (black zyxel) routers. Their default passwords are (example) :

    23DBE2A3B126
    8A2B28324EAB
    99231B0A1CC1

    Having a look at the above, they are all 12 character hexdecimal passwords, so the total number of combinations are 16^12. (281 trillion combinations)

    If it was a 10 character uppercase alphanumeric pw, it would be 36^10 (3 million trillion).

    My experiment was to see what is the best default password wifi router out there.

    I know that current generation Eircom routers are 12 character hexdecimal combinations. What is it for UPC, Vodafone, etc?


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    UPC seems to be 8 characters, A-Z, all uppercase.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    UPC seems to be 8 characters, A-Z, all uppercase.

    This might be feasable to bruteforce if you make use of CUDA and apps like crunch and Pyrit: http://www.offensive-security.com/documentation/backtrack-4-cuda-guide.pdf


  • Registered Users Posts: 60 ✭✭obviousTroll


    Thanks Damo. Yeah i'm familiar with Pyrit and crunch. Interesting to see who's the most secure.

    26^8 is "only" 208 billion., but with a machine doing 30,000 pmk/s would take 80 days to crack.

    Interesting.


  • Advertisement
  • Closed Accounts Posts: 235 ✭✭The Outside Agency


    99% of the time, default keys are generated from serial number so if you can dump the firmware through JTAG, you'd find the algorithm fairly quick.

    https://openwrt.org/

    The 2.0A HH in UK which is based on Speedtouch router was unlocked by updating smb.conf for samba. (some developers left this behind)

    Once they got root access, people discovered the default algorithm for wep/wpa and default password but they haven't published details yet.

    The routers are all pretty much the same with regard to default key generation so it's always good to change the key.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    nivekd wrote: »
    99% of the time, default keys are generated from serial number so if you can dump the firmware through JTAG, you'd find the algorithm fairly quick.

    https://openwrt.org/

    The 2.0A HH in UK which is based on Speedtouch router was unlocked by updating smb.conf for samba. (some developers left this behind)

    Once they got root access, people discovered the default algorithm for wep/wpa and default password but they haven't published details yet.

    The routers are all pretty much the same with regard to default key generation so it's always good to change the key.


    The UPC routers seem to be running stock firmware. i.e. no custom branding anyway.

    I will test changing the key and doing a factory reset. If the key reverts back, its generating it. Unless its permanent stored somewhere.


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    The UPC routers seem to be running stock firmware. i.e. no custom branding anyway.

    I guess http://www.boards.ie/vbulletin/showpost.php?p=61132499&postcount=5 proves otherwise.


  • Registered Users Posts: 60 ✭✭obviousTroll


    Interesting.....

    Knowing nothing about JTAG.... if I get my hands on a copy of the firmware... I'll give this a go.

    Damo... aren't you the guy that famously RE'd the Eircom WEP boxes?


  • Closed Accounts Posts: 2,267 ✭✭✭h57xiucj2z946q


    Nah others had it already broke before I looked at that setup CD binary.


  • Advertisement
Advertisement