Plugins 2500/2501 and 16800/16801 are deprecated
#51
ZerBea
Thank you

Code:
*0$

I understand, the last field is 0 is the challenge,  all the rest are authorization
Thanks Thanks
Reply
#52
Glad to read that.

BTW:
Due to the new format (ASCII instead of binary), there are much more possibilities to filter wanted/unwanted hashes.
E.g., if you would like to speed up hashcat, you can filter out all hashes that require NC:
Code:
5: LE router detected (set to 1) - nonce-error-corrections required only on LE 6: BE router detected (set to 1) - nonce-error-corrections required only on BE 7: not replaycount checked (set to 1) - replaycount not checked, nonce-error-corrections mandatory

NC is explained here:
https://hashcat.net/forum/thread-6361.html
Reply
#53
[quote="ZerBea" pid='53971' dateline='1635778082']
Glad to read that.

BTW:
Due to the new format (ASCII instead of binary), there are much more possibilities to filter wanted/unwanted hashes.
E.g., if you would like to speed up hashcat, you can filter out all hashes that require NC:
Code:
5: LE router detected (set to 1) - nonce-error-corrections required only on LE 6: BE router detected (set to 1) - nonce-error-corrections required only on BE 7: not replaycount checked (set to 1) - replaycount not checked, nonce-error-corrections mandatory




How can  classify the need for NC hash ?
Reply
#54
Mostly NC is required on:
- cleaned dump files (there is no need to clean a dump file)
- wrong/missing timestamps (bug of the dump tool)
- passive capturing due to possible packet loss
- running excessive deauthentications (AP increment ANONCE instead of replaycount)

hcxpcapngtool is able to detect this:
Code:
Warning: out of sequence timestamps! This dump file contains frames with out of sequence timestamps. That is a bug of the capturing tool. Warning: excessive number of deauthentication/disassociation frames detected! That can cause that an ACCESS POINT change channel, reset EAPOL TIMER, renew ANONCE and set PMKID to zero. This could prevent to calculate a valid EAPOL MESSAGE PAIR or to get a valid PMKID. Warning: missing frames! This dump file does not contain undirected proberequest frames. An undirected proberequest may contain information about the PSK. It always happens if the capture file was cleaned or it could happen if filter options are used during capturing. That makes it hard to recover the PSK.

In addition to that, hcxpcapngtool will give you an information about the elapsed time between 2 EAPOL MESSAGES. It will detect if NC is possible and it will give a recommendation for the value:
Code:
EAPOLTIME gap (measured maximum usec)....: 12808 EAPOL ANONCE error corrections (NC)......: working REPLAYCOUNT gap (recommended NC).........: 8
Reply
#55
(11-02-2021, 09:09 AM)ZerBea Wrote: Mostly NC is required on:
- cleaned dump files (there is no need to clean a dump file)
- wrong/missing timestamps (bug of the dump tool)
- passive capturing due to possible packet loss
- running excessive deauthentications (AP increment ANONCE instead of replaycount)

hcxpcapngtool is able to detect this:
Code:
Warning: out of sequence timestamps! This dump file contains frames with out of sequence timestamps. That is a bug of the capturing tool. Warning: excessive number of deauthentication/disassociation frames detected! That can cause that an ACCESS POINT change channel, reset EAPOL TIMER, renew ANONCE and set PMKID to zero. This could prevent to calculate a valid EAPOL MESSAGE PAIR or to get a valid PMKID. Warning: missing frames! This dump file does not contain undirected proberequest frames. An undirected proberequest may contain information about the PSK. It always happens if the capture file was cleaned or it could happen if filter options are used during capturing. That makes it hard to recover the PSK.

In addition to that, hcxpcapngtool will give you an information about the elapsed time between 2 EAPOL MESSAGES. It will detect if NC is possible and it will give a recommendation for the value:
Code:
EAPOLTIME gap (measured maximum usec)....: 12808 EAPOL ANONCE error corrections (NC)......: working REPLAYCOUNT gap (recommended NC).........: 8


OK....
Reply
#56
Hello, I am installing hcxdumptool and it gives me the following error

<pre>cc -O3 -Wall -Wextra -std=gnu99 -o hcxdumptool hcxdumptool.c -DVERSION_TAG=\&quot;6.2.9-107-gd7a673c\&quot; -DVERSION_YEAR=\&quot;2023\&quot; -DSTATUSOUT -DNMEAOUT
<b>hcxdumptool.c:</b> In function ‘<b>nl_scanloop</b>’:
<b>hcxdumptool.c:2616:25:</b> <font color="#D33682"><b>warning: </b></font>ignoring return value of ‘<b>read</b>’ declared with attribute ‘<b>warn_unused_result</b>’ [<font color="#D33682"><b>-Wunused-result</b></font>]
2616 | <font color="#D33682"><b>read(fd_timer1, &amp;timer1count, sizeof(u64))</b></font>;
| <font color="#D33682"><b>^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</b></font>
<b>hcxdumptool.c:</b> In function ‘<b>show_realtime</b>’:
<b>hcxdumptool.c:548:1:</b> <font color="#D33682"><b>warning: </b></font>ignoring return value of ‘<b>system</b>’ declared with attribute ‘<b>warn_unused_result</b>’ [<font color="#D33682"><b>-Wunused-result</b></font>]
548 | <font color="#D33682"><b>system(&quot;clear&quotWink</b></font>;
| <font color="#D33682"><b>^~~~~~~~~~~~~~~</b></font>
<b>hcxdumptool.c:</b> In function ‘<b>nl_scanloop_rca</b>’:
<b>hcxdumptool.c:2701:25:</b> <font color="#D33682"><b>warning: </b></font>ignoring return value of ‘<b>read</b>’ declared with attribute ‘<b>warn_unused_result</b>’ [<font color="#D33682"><b>-Wunused-result</b></font>]
2701 | <font color="#D33682"><b>read(fd_timer1, &amp;timer1count, sizeof(u64))</b></font>;
| <font color="#D33682"><b>^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</b></font>
<b>hcxdumptool.c:</b> In function ‘<b>show_realtime_rca</b>’:
<b>hcxdumptool.c:509:1:</b> <font color="#D33682"><b>warning: </b></font>ignoring return value of ‘<b>system</b>’ declared with attribute ‘<b>warn_unused_result</b>’ [<font color="#D33682"><b>-Wunused-result</b></font>]
509 | <font color="#D33682"><b>system(&quot;clear&quotWink</b></font>;
| <font color="#D33682"><b>^~~~~~~~~~~~~~~</b></font>
</pre>
Reply
#57
This are only warnings and I'm going to remove them soon.

Which gcc version do you use!

This warnings should not appear on gcc 12
[/code]
$ git clone https://github.com/ZerBea/hcxdumptool
Cloning into 'hcxdumptool'...
remote: Enumerating objects: 4745, done.
remote: Counting objects: 100% (280/280), done.
remote: Compressing objects: 100% (138/138), done.
remote: Total 4745 (delta 166), reused 237 (delta 142), pack-reused 4465
Receiving objects: 100% (4745/4745), 1.51 MiB | 1.97 MiB/s, done.
Resolving deltas: 100% (3194/3194), done.

$ cd hcxdumptool

$ make
cc -O3 -Wall -Wextra -std=gnu99 -o hcxdumptool hcxdumptool.c -DVERSION_TAG=\"6.2.9-107-gd7a673c\" -DVERSION_YEAR=\"2023\" -DSTATUSOUT -DNMEAOUT

$ sudo make install
install -D -m 0755 hcxdumptool /usr/bin/hcxdumptool
[/code]
Reply
#58
Hello, thank you.
gcc version 11.3.0
Reply
#59
Thanks for reporting the warnings.
Should be fixed since this commit:
https://github.com/ZerBea/hcxdumptool/co...ee30bee9cd
Reply
#60
Hi how to identify the hash type of an .hc22000 wpa2 handshake


[Hash removed by Moderators, please don't post hashes]
Plzz help
Reply