On 26th of October, a worth reading blog post has been published here:
https://www.cyberark.com/resources/threa...mple-trick
https://www.cyberark.com/resources/threa...mple-trick
|
Plugins 2500/2501 and 16800/16801 are deprecated
|
|
On 26th of October, a worth reading blog post has been published here:
https://www.cyberark.com/resources/threa...mple-trick
10-28-2021, 08:27 PM
Can't believe tech savvy people of Israel use phone numbers as pwd. My neighbor's pwd is "It burns when IP" :-) And no I didn't break it, he told me
(10-28-2021, 08:54 AM)ZerBea Wrote: On 26th of October, a worth reading blog post has been published here:
10-30-2021, 06:26 AM
Guys, you make one old lazy MF blush :-) I didn't port HCXTOOLS to Windows, actually I didn't even change a line of code - it's all ZB's work and people who created CYRWIN. Here are the instruction how to compile:
How to compile HCXTOOLS for Windows OS: ======================================= 1. Install CYRWIN from https://www.cygwin.com/ 2. Install these packages. Select "view:full", search by name, under "new" change from "skip" to latest version available. Make sure you pick exactly listed packages - there are many to pick, very confusing Package Categories --------------------------- cygwin Base cygwin-devel Devel gcc-core Devel zlib-devel Devel libcurl-devel Devel, Libs, Net libssl-devel Devel make Devel git Devel 3. Run CYGWIN 4. Type "git clone hcxtools", that will fetch latest source code 5. Type "Make", that will compile and create all EXE files 6. If you want to run EXEs w/o CYGWIN installed - copy these DLLs from cygwin64\bin: cygcrypto*.dll cygwin1.dll cygz.dll And here is the link to executables: https://drive.google.com/file/d/14ad4w6I...sp=sharing
10-30-2021, 08:33 AM
@oayz, good instructions which will help the Windows users.
10-30-2021, 09:06 AM
(This post was last modified: 10-30-2021, 09:07 AM by CUwindows00.)
very good, thanks
I found that after putting cygwin1 cygcrypto-1.1 cygz.dll into win\System32 It can support all full path dragging files to cmd, which is very convenient for conversion But it does not seem to support file names with spaces or some characters from other countries Code: hcxpcapngtool -o %*.HC22000 %*
10-30-2021, 04:19 PM
Windows follows its own rules:
https://www.howtogeek.com/694949/how-to-...mand-line/
11-01-2021, 02:05 AM
(This post was last modified: 11-01-2021, 02:11 AM by CUwindows00.)
ZerBea Thanks
I used your tool to extract tens of thousands of hashes In use, I have a problem I want to sort out the authorization hash from it, but I don’t know how to do it, It would be great if authorization can be added to the end of each hash example Code: WPA*02************challenge
WPA*02************authorizedOr can use simple numbers to identify, challenge use 0 instead authorization use 1 instead example Code: WPA*02************0
WPA*02************1
Exactly this is the purpose of the MESSAGEPAIR field at the and of a WPA*02 line.
It will inform hashcat and the user about the kind of the hash and how to handle it. Get all authenticated MESSAGEPAIRs: Code: $ cat hash.hc22000 | grep WPA.02 | grep 2$Get all challenge MESSAGEPAIRs: Code: $ cat hash.hc22000 | grep WPA.02 | grep 1$BTW: Adding something like "challenge or authorized" to a hash line will produce overhead (especially if you have tons of hash lines). It take disc space and will make fread() slow. Or use hcxhashtool on the hc22000 file: Code: --authorized : filter EAPOL pairs by status authorized (M2M3, M3M4, M1M4)
--challenge : filter EAPOL pairs by status CHALLENGE (M1M2, M1M2ROGUE)
--rc : filter EAPOL pairs by replaycount status checked
--rc-not : filter EAPOL pairs by replaycount status not checked
--apless : filter EAPOL pairs by status M1M2ROGUE (M2 requested from CLIENT)To get information about the VENDOR, use hcxhashtool on the hc22000 file: Code: --info=<file> : output detailed information about content of hash file
not in combination with --vendor, --vendor-ap or --vendor-client
--info=stdout : stdout output detailed information about content of hash file
not in combination with --vendor, --vendor-ap or --vendor-client
--info-vendor=<file> : output detailed information about ACCESS POINT and CLIENT VENDORs
not in combination with --vendor, --vendor-ap or --vendor-client
--info-vendor-ap=<file> : output detailed information about ACCESS POINT VENDORs
not in combination with --vendor, --vendor-ap or --vendor-client
--info-vendor-client=<file> : output detailed information about ACCESS POINT VENDORs
not in combination with --vendor, --vendor-ap or --vendor-client
--info-vendor=stdout : stdout output detailed information about ACCESS POINT and CLIENT VENDORs
not in combination with --vendor, --vendor-ap or --vendor-client
--info-vendor-ap=stdout : stdout output detailed information about ACCESS POINT VENDORs
not in combination with --vendor, --vendor-ap or --vendor-client
--info-vendor-client=stdout : stdout output detailed information about ACCESS POINT VENDORs
not in combination with --vendor, --vendor-ap or --vendor-clientTo get more information, use hcxpcapngtool -D option on the pcapng/pcap/cap file: Code: -D <file> : output device information list
format MAC MANUFACTURER MODELNAME SERIALNUMBER DEVICENAME UUID
11-01-2021, 01:15 PM
(This post was last modified: 11-01-2021, 01:46 PM by CUwindows00.)
ZerBea Ok thank you
I see some hash numbers at the end of it are 05 80 82 84 and so on Some are challenges, some are authorizations Code: WPA*02****************05
WPA*02****************80
WPA*02****************82
WPA*02****************84Code: cat hash.hc22000 | grep WPA.02 | grep 1$
cat hash.hc22000 | grep WPA.02 | grep 2$you use it, I think that it is impossible to classify by relying on these alone, because there is no unified field for challenges and authorizations, and it is impossible to guess what number will appear in the last paragraph. If there is a unified replacement field at the end, it will be more complete As i mentioned above
The MESSAGEPAIR FIELD is a bitmask field.
Code: bitmask of message pair field:
2,1,0:
000 = M1+M2, EAPOL from M2 (challenge)
001 = M1+M4, EAPOL from M4 (authorized) - usable if NONCE_CLIENT is not zeroed
010 = M2+M3, EAPOL from M2 (authorized)
011 = M2+M3, EAPOL from M3 (authorized) - unused
100 = M3+M4, EAPOL from M3 (authorized) - unused
101 = M3+M4, EAPOL from M4 (authorized) - usable if NONCE_CLIENT is not zeroed
3: reserved
4: ap-less attack (set to 1) - nonce-error-corrections not required
5: LE router detected (set to 1) - nonce-error-corrections required only on LE
6: BE router detected (set to 1) - nonce-error-corrections required only on BE
7: not replaycount checked (set to 1) - replaycount not checked, nonce-error-corrections mandatoryOnce you understand it, it's very easy to use: There is only one challenge MESSAGEPAIR. The remaining ones are authorized. Let's exclude all challenges and get all other MESSAGEPAIR (authorized) combinations: Code: $ cat test.hc22000 | grep "$WPA\*02\*" | grep -v 0$ > all_authorized.hc22000There is absolutely no need to blow up a hash line with redundant information. If you really can't read a messagepair field value, bash can make it more visual for you: Code: $ cat test.hc22000 | grep "$WPA\*02\*" | grep -v 0$ | sed -e 's/$/ authorized/' > visual_style.hc22000
$ cat test.hc22000 | grep "$WPA\*02\*" | grep 0$ | sed -e 's/$/ challenge/' > visual_style.hc22000Before feeding hashcat with this line, remove the extension: Code: $ cat visual_style.hc22000 | sed -e 's/ authorized//' > hash.hc22000
$ cat visual_style.hc22000 | sed -e 's/ challenge//' > hash.hc22000 |
|
« Next Oldest | Next Newest »
|