Skip to content

Brute force hacking – But why do I have to disable the WPS pin on my home router?

04/01/2013

WPS – What is it?

All routers since 2007, have Wifi Protected Setup [WPS] in order to be certified.  WPS is often a push button on your router – or it may be printed on the bottom of your router.

See the DLink WPS PIN listed.

wps 1

The problem is that the PIN, is divided into two halves – which makes it easy to hack.

The attacker can work on each half of the PIN – to crack the code

wps2

wps 1st half pin

Time to crack

Normally it’s stated that cracking would take between 2 and 10 hours.

The longest I’ve seen anyone take – was 3 hours.

The router literally will hand the hacker your router PIN.

And then they can connect, and download.  They can even disconnect your home pc, and block you out of your own router, as they download child porn.

wps 2nd half pin

Basically, it’s your router, your network, your ISP, but it’s under the attackers control.

Mitigation

Turn off WPS – if you can.

wps mitigation

How I cracked my neighbor’s WiFi password without breaking a sweat

wps pin

Wifi Protected Setup – Routers from 2007

wps defined

References:

https://sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf

WPS Flaw Vulnerable Devices – List of Router Models and whether vulnerable to WPS attacks

https://uwnthesis.wordpress.com/2013/07/21/wps-flaw-vulnerable-devices/

****

BRUTE FORCE HACKING – Brute force Calculator – A Visual Guide

https://uwnthesis.wordpress.com/2014/04/18/bruteforce-hacking-bruteforce-calculator-a-visual-guide/

4 Comments
  1. << Back | Track

    Giving machine guns to monkeys since 2006

    Like

  2. ThisisNotMyName permalink

    Omg your comment made me laugh,the only reason I commented,I never do….
    But this is epic 😀 “<< Back | Track

    Giving machine guns to monkeys since 2006"

    Like

Trackbacks & Pingbacks

  1. WPS Flaw Vulnerable Devices – List of Router Models and whether vulnerable to WPS attacks | University of South Wales: Information Security and Privacy
  2. WPS – How to install and use Reaver to detect the WPS on your home router | University of South Wales: Information Security and Privacy

Leave a comment