[Infusion idea] Offline WPS Cracking


Hey guys!

I just read an interesting article on cracking WPS by doing offline computations and figured I should share with you guys. Although I understand a good portion of this from playing with the Wifi Pineapple, this is still above my skill level to be able to implement myself. I would imagine the Mark V would be able to do this with an infusion, replacing the need for Reaver/Bully for a lot of routers with WPS. The link to the article is: http://www.engadget.com/2014/08/31/wifi-protected-setup-flaw/
Check out the SlideShare presentation for the information. I think this would be a great addition to the Pineapple's capabilities if it could be done.

Problems I see.

1) The guy who has the code for the offline attack may not release it, he is not sure if he will. (I emailed him)

2) I am not sure how much CPU power it would be using and may not play friendly on the Pineapple.

3) Most likely would need cross compiled for openWRT

4) Someone has to make it based off of his research, then refer to 1-3.

This offline attack is been interesting me im surprised it hasn't been released hopefully someone else releases something that works then that person can take the credit for releasing it rather then keeping it private.

  • 3 weeks later...

Sounds like bs to me, and even if it did work, it would only be against a small amount of routers, and they would have to be unpatched, and they would have to be running WPS, which you could already break if it was vulnerable... tell me again why you want an ARM router with limited CPU to mount an offline attack.. against anything? Might as well make a c0wpatty infusion.

Theres a lot more stuff I'd rather see than some vaporware.

