Best approach for auditing networks with modern random default PSKs? #61
Unanswered
kernelheaders
asked this question in
Q&A
Replies: 1 comment
|
I've heard people will rent large GPU clusters to try cracking PSKs. Spend more $ and some keyspaces become more achievable. I don't actually do this since I know the PW's I'm cracking & can crack locally quickly with a small targeted wordlist. But maybe other people can chime in about their setups, maybe wpa-sec or whatever online provider they use to rent GPUs. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hello ,
First of all, thank you for wifit3 — it has become the capture front-end of my home Wi-Fi audit rig, and the user-space driver approach has saved me from a world of kernel driver pain on both Linux and macOS.
I wanted to share a field report and ask for your advice. All of this is testing done strictly on my own equipment and my family's networks, as part of a self-audit.
My setup. A Raspberry Pi 5 runs wifit3 with supported USB adapters for scanning, PMKID harvesting, AutoDeauth, and EvilTwin. Captures are exported as hc22000, synced automatically to a small self-hosted job panel, and cracked with hashcat (mode 22000) on an RTX 3090 at roughly 1.27 MH/s. Early on I learned the hard way that active-association handshakes without M3 are useless, and switched to deauth-genuine-client captures — your documentation was spot on about this.
The 7-stage routine I settled on (ordered cheap → expensive, stop on first hit):
rockyou.txt, plain
A localized Turkish wordlist
A 3WiFi-style default-password list
rockyou + best66.rule
Hybrid: rockyou + two appended digits
Pure numeric 8-digit mask
A ~2.35-billion-entry aggregated WiFi list (WeakPass-class)
What it catches: human-chosen passwords, reliably. A passphrase-style test PSK of mine fell at 71% of stage 7; a plain dictionary-word PSK was found verbatim in stage 7. As a methodology for "did a human pick this key," the routine works.
What it cannot catch: modern ISP default keys. In Turkey, current-generation ISP routers (a ZTE H1601P from Türk Telekom, a Superonline Superbox, and a MikroTik hAP, judging from my own device labels) ship random 10–12 character alphanumeric defaults. I checked them against every known derivation family I could find — SSID suffix, MAC, serial number, WPS PIN substrings — and found no relationship. At 1.27 MH/s, keyspaces of 36¹⁰ to 62¹² mean offline brute force is mathematically dead against these.
My question: for authorized audits of networks whose PSK is a modern random default, what do you consider best practice today? From my reading, the WPS recovery suite (PixieDust, PBC, PIN brute-force) seems to be the only remaining practical vector — the Superbox family at least exposes WPS, while RouterOS devices have none. Do you agree, or is there another approach or wifit3 workflow you'd point me at?
All reactions