Plugins 2500/2501 and 16800/16801 are deprecated
#41
On 26th of October, a worth reading blog post has been published here:
https://www.cyberark.com/resources/threa...mple-trick
Reply
#42
Can't believe tech savvy people of Israel use phone numbers as pwd. My neighbor's pwd is "It burns when IP" :-) And no I didn't break it, he told me 

(10-28-2021, 08:54 AM)ZerBea Wrote: On 26th of October, a worth reading blog post has been published here:
https://www.cyberark.com/resources/threa...mple-trick
Reply
#43
Guys, you make one old lazy MF blush :-) I didn't port HCXTOOLS to Windows, actually I didn't even change a line of code - it's all ZB's work and people who created CYRWIN. Here are the instruction how to compile:

How to compile HCXTOOLS for Windows OS:
=======================================

1. Install CYRWIN from https://www.cygwin.com/

2. Install these packages. Select "view:full", search by name, under "new" change from "skip" to latest version available. Make sure you pick exactly listed packages - there are many to pick, very confusing

Package Categories
---------------------------
cygwin Base
cygwin-devel Devel
gcc-core Devel
zlib-devel Devel
libcurl-devel Devel, Libs, Net
libssl-devel Devel
make Devel
git Devel

3. Run CYGWIN

4. Type "git clone hcxtools", that will fetch latest source code

5. Type "Make", that will compile and create all EXE files

6. If you want to run EXEs w/o CYGWIN installed - copy these DLLs from cygwin64\bin:

cygcrypto*.dll
cygwin1.dll
cygz.dll

And here is the link to executables:

https://drive.google.com/file/d/14ad4w6I...sp=sharing
Reply
#44
@oayz, good instructions which will help the Windows users.
Reply
#45
very good,  thanks
I found that after putting cygwin1 cygcrypto-1.1 cygz.dll into win\System32
It can support all full path dragging files to cmd, which is very convenient for conversion
But it does not seem to support file names with spaces or some characters from other countries
Code:
hcxpcapngtool -o %*.HC22000 %*
Reply
#46
Windows follows its own rules:
https://www.howtogeek.com/694949/how-to-...mand-line/
Reply
#47
ZerBea Thanks

I used your tool to extract tens of thousands of hashes
In use, I have a problem
I want to sort out the authorization hash from it, but I don’t know how to do it,

It would be great if authorization can be added to the end of each hash

example
Code:
WPA*02************challenge WPA*02************authorized


Or  can use simple numbers to identify,
  challenge use 0 instead
  authorization use 1 instead

example
Code:
WPA*02************0 WPA*02************1
Reply
#48
Exactly this is the purpose of the MESSAGEPAIR field at the and of a WPA*02 line.
It will inform hashcat and the user about the kind of the hash and how to handle it.

Get all authenticated MESSAGEPAIRs:
Code:
$ cat hash.hc22000 | grep WPA.02 | grep 2$

Get all challenge MESSAGEPAIRs:
Code:
$ cat hash.hc22000 | grep WPA.02 | grep 1$

BTW:
Adding something like "challenge or authorized" to a hash line will produce overhead (especially if you have tons of hash lines). It take disc space and will make fread() slow.

Or use hcxhashtool on the hc22000 file:
Code:
--authorized : filter EAPOL pairs by status authorized (M2M3, M3M4, M1M4) --challenge : filter EAPOL pairs by status CHALLENGE (M1M2, M1M2ROGUE) --rc : filter EAPOL pairs by replaycount status checked --rc-not : filter EAPOL pairs by replaycount status not checked --apless : filter EAPOL pairs by status M1M2ROGUE (M2 requested from CLIENT)

To get information about the VENDOR, use hcxhashtool on the hc22000 file:
Code:
--info=<file> : output detailed information about content of hash file not in combination with --vendor, --vendor-ap or --vendor-client --info=stdout : stdout output detailed information about content of hash file not in combination with --vendor, --vendor-ap or --vendor-client --info-vendor=<file> : output detailed information about ACCESS POINT and CLIENT VENDORs not in combination with --vendor, --vendor-ap or --vendor-client --info-vendor-ap=<file> : output detailed information about ACCESS POINT VENDORs not in combination with --vendor, --vendor-ap or --vendor-client --info-vendor-client=<file> : output detailed information about ACCESS POINT VENDORs not in combination with --vendor, --vendor-ap or --vendor-client --info-vendor=stdout : stdout output detailed information about ACCESS POINT and CLIENT VENDORs not in combination with --vendor, --vendor-ap or --vendor-client --info-vendor-ap=stdout : stdout output detailed information about ACCESS POINT VENDORs not in combination with --vendor, --vendor-ap or --vendor-client --info-vendor-client=stdout : stdout output detailed information about ACCESS POINT VENDORs not in combination with --vendor, --vendor-ap or --vendor-client

To get more information, use hcxpcapngtool -D option on the pcapng/pcap/cap file:
Code:
-D <file> : output device information list format MAC MANUFACTURER MODELNAME SERIALNUMBER DEVICENAME UUID
Reply
#49
ZerBea  Ok  thank you


I see some hash numbers at the end of it are 05 80 82 84 and so on
Some are challenges, some are authorizations
Code:
WPA*02****************05 WPA*02****************80 WPA*02****************82 WPA*02****************84

Code:
cat hash.hc22000 | grep WPA.02 | grep 1$ cat hash.hc22000 | grep WPA.02 | grep 2$

you use it, I think that it is impossible to classify by relying on these alone, because there is no unified field for challenges and authorizations, and it is impossible to guess what number will appear in the last paragraph.

If there is a unified replacement field at the end, it will be more complete
As i mentioned above
Reply
#50
The MESSAGEPAIR FIELD is a bitmask field.
Code:
bitmask of message pair field: 2,1,0: 000 = M1+M2, EAPOL from M2 (challenge) 001 = M1+M4, EAPOL from M4 (authorized) - usable if NONCE_CLIENT is not zeroed 010 = M2+M3, EAPOL from M2 (authorized) 011 = M2+M3, EAPOL from M3 (authorized) - unused 100 = M3+M4, EAPOL from M3 (authorized) - unused 101 = M3+M4, EAPOL from M4 (authorized) - usable if NONCE_CLIENT is not zeroed 3: reserved 4: ap-less attack (set to 1) - nonce-error-corrections not required 5: LE router detected (set to 1) - nonce-error-corrections required only on LE 6: BE router detected (set to 1) - nonce-error-corrections required only on BE 7: not replaycount checked (set to 1) - replaycount not checked, nonce-error-corrections mandatory

Once you understand it, it's very easy to use:
There is only one challenge MESSAGEPAIR.
The remaining ones are authorized.

Let's exclude all challenges and get all other MESSAGEPAIR (authorized) combinations:
Code:
$ cat test.hc22000 | grep "$WPA\*02\*" | grep -v 0$ > all_authorized.hc22000
https://linuxconfig.org/bash-scripting-t...-beginners

There is absolutely no need to blow up a hash line with redundant information.

If you really can't read a messagepair field value, bash can make it more visual for you:
Code:
$ cat test.hc22000 | grep "$WPA\*02\*" | grep -v 0$ | sed -e 's/$/ authorized/' > visual_style.hc22000 $ cat test.hc22000 | grep "$WPA\*02\*" | grep 0$ | sed -e 's/$/ challenge/' > visual_style.hc22000

Before feeding hashcat with this line, remove the extension:
Code:
$ cat visual_style.hc22000 | sed -e 's/ authorized//' > hash.hc22000 $ cat visual_style.hc22000 | sed -e 's/ challenge//' > hash.hc22000
Reply