Weaponizing and Gamifying AI for WiFi Hacking: Presenting Pwnagotchi 1.0.0
evilsocket.net
evilsocket.net
1) You need a device that can connect to wifi
2) Approach your neighbor/shop owner/coffee owner
3) Ask: "Can I connect to your wifi, please?"
4) It takes about 4-5 seconds to get the password to the ssid
5) Works on WPA2, WPA / TKIP/AES and WEP
6) Success rate: 70-80%
Cheers
Public, municipality-sponsored Wi-Fi is usually a joke (slow, non functioning, requiring you to like a certain facebook page or follow a twitter account, etc.)
In Greece I suggest trying the business' phone number, you can find it on discarded receipts on the ground or on tables.
It's always worth it to try and snoop the password hanging by the counter.
Other good combos are companynamewifi, wirelesscompanyname, wireless, internet, internet123.
t. scrooge that never wastes money on mobile internet subscription and survives on leeched public Wi-Fi
Also when I see NLP, my first thought is Neuro-Linguistic Programming (https://en.m.wikipedia.org/wiki/Neuro-linguistic_programming) , not Natural Language Processing.
- a mesh-based social network - a cute character - a builtin game - adjusts to the environment
It sounds like an awesome social game, even if it doesn't have any purpose, and turning this into a mesh communication network would even give it an aspect of usefulness. I can see two ways this could blow up:
- at big parties, think Burning Man or Chaos Communication Congress, where people get embedded devices (like the CardIO) which encourage meeting others - everyday, to find connections in unlikely places, with a similar app running on your phone (the Librem5 would be a good starting point)
Everything else is trivial to compromise if a sufficiently motivated person wants to access it.
My WiFi router was programmed with a 55 bit key in the factory. (Represented as a 11 letter alphanumeric word).
[1]: https://hashcat.net/wiki/doku.php?id=combination_count_formu...
You don't need to bruteforce the password if another device tells you what it is.
Read the article if you don't believe it.
WPA handshakes do not tell you the network password.
You use e.g. hashcat to brute force the network password using a stored handshake.
As a previous comment had pointed out before as well:
You wait for handshakes, fake a deauth packet of the handshaking client, spoof an access point with the same SID and wait for the deauth'd client to try a reconnect.
Voila, cleartext PSK without any bruteforcing.
And it's not solveable either. You can't use fingerprinting as this would make mesh lans and quick access point failover impossible.
Pwnagotchi does not do this, despite your errant assertions. E.g. source code: https://github.com/evilsocket/pwnagotchi/blob/64e677f5df8f9b...
> Voila, cleartext PSK without any bruteforcing.
Pretending to be an access point and going through a handshake doesn't let you retrieve the pre-shared key. (Unless the client is vulnerable to downgrade attacks-- which hasn't been a big consideration in more than a decade). Evil twin attacks are powerful but don't achieve what you say.
The station sends to the access point a message authentication code based on nonces and the pairwise master key, which in turn is based on the "network password". It's produced using a series of HMACs and isn't an operation that can be inverted without brute force.
https://en.wikipedia.org/wiki/IEEE_802.11i-2004#/media/File:...
What can we glean about how to secure a password?
You would have to pre-generate them for each possible SSID. You're much better off using a small targeted dictionary with rules.
A sufficiently high entropy password will keep you secure against this attack.
0. https://security.stackexchange.com/questions/66008/how-exact...