Keyspace List for WPA on Default Routers
(01-19-2023, 06:56 PM)alexmax62 Wrote: Do you have default keyspace for ZTE routers - ZXHN F680?

Hmm, a google image search shows 12 chars ?l?d
But there also seems to be 8 chars ?u?l?d but that might be an older model.
Probably need to develop a keygen unless you got some serious hardware!
Reply
More from Australia
TP-Link VX420-G2v: (TPG NBN bundled WiFi 6 modem, quite common)
WiFi-XXXX [0-9][len8]
WiFi-XXXX-5G [0-9][len8]

TP-Link AX1500:
TP-LINK_XXXX [0-9][len8]
TP-LINK_XXXX_5G [0-9][len8]

TelstraXXXX [0-9][len10]
TelstraXXXXXX [0-9a-z][len10]
TelstraXXXXXX-5G [0-9a-z][len10]

BelongXXXXXX [0-9a-z][len12]
BelongXXXXXX-5G [0-9a-z][len12]
Reply
(07-02-2023, 08:32 PM)drsnooker Wrote: July 2023 update on the zyxel keygens
...

Wow, amazing work, thanks Dr. Snooker, et al
Reply
Can anyone figure out how they generate password
Or what type of hash
[Image: Screenshot-20231208-220001-You-Tube.jpg]
[Image: 20231208-215623.jpg]
[Image: 20231208-215053.jpg]
[Image: img-2-1702062517125.jpg]
Reply
Last I looked ZTE does not include their keygen in the firmware. Next to impossible to guess the hashing mechanism without it.
Reply
But if you do find a ZTE (or Huawei) firmware that does include the keygen, please post it here. A lot of people are interested in them!
Reply
(12-11-2023, 08:30 PM)drsnooker Wrote: But if you do find a ZTE (or Huawei) firmware that does include the keygen, please post it here. A lot of people are interested in them!

Normal firmware from website or that who extracted by special tools
?
Reply
This router use a specific table to convert ssid to password
Can you explain to me how this schema work

[Image: s-l1600.jpg]

[Image: 20231212-124301.jpg]
Reply
It is not a translation table. The last 3 bytes of the MAC (ebd340) are negated.
Take a look at the source code of hcxpsktool:
https://github.com/ZerBea/hcxtools/blob/...ol.c#L2489

More algo's are here:
https://github.com/routerkeygen/routerke...algorithms
Reply
(12-12-2023, 12:10 PM)brahim7 Wrote: Normal firmware from website or that who extracted by special tools?

The firmware from various websites that do include a "reset to factory defaults" function pull the WIFI password from NVRAM rather than recalculate it from a seed. That does not mean the keygen is not included on the physical hardware, but far less likely.
Reply