El libre pensamiento para un internet libre

No estas registrado.  

#1 18-09-2018 13:13:14

kcdtv
Administrator

Registrado: 14-11-2014
Mensajes: 5,730

Probable wordlists y BEWgor (generador por ingeniera social)

Probable wordlists y BEWgor

probablewordlists_1.jpg

  Husmeando por la web he visto que se había integrado la captura y el crack de PMKID en la conocida herramienta "all in one" Wifite2.
Para efectuar el ataque usan las herramientas de hashcat
La obtención de la PMKID es instantánea lo que reaviva sin dudas el interés para el ataque por diccionario: Podemos probar wordlists a nuestro antojo contra la mayoría de los PA modernos sin necesidad de capturar el dichoso handhsake.
  Así que los de wifite2 han adjuntado un diccionario para WPA en la versión que brinda soporte para el ataque PMKID

BEWgor_1.jpg

  Una pequeña lista de 4800 palabras que se pasa al instante.
  Por curiosidad me he ido al repositorio del creador y valió la pena

Probable wordlists

  ¡Para crear sus diccionarios berzek0 ha repasado más de 350GB de "leaks" de los últimos años!
Ha creado varios diccionarios según varios tipos de criterios.
  Para hablar de lo nuestro, el crack WPA, ha tenido la buena idea de crear wordlists dedicadas.
Las contraseñas son las que tienen de 8 a 40 caracteres: son "passwords" que se pueden usar como "passphrase WPA"
  La wordlist que usa wifite es la "top 4800" (las 4800 contraseñas las más empleadas)
  La tenemos a mano en formato texto con el repositorio github,
  Si queremos la "megalist" con todos los password que se pueden usar como contraseña wifi, debemos descargar un fichero comprimido desde MEGA

All files are composed of __*exclusively WPA-Length*__ lines.

* 25.3 GB Uncompressed
* Max 7.48 GB Compressed


You have the option to download all the files, or get them one at a time.


  ## Real-WPA-Password MegaLinks
  *Exclusively WPA-Length*


| Compression Method | Link |
| --- | --- |
| __tar.gz__ <br> 7.48 GB total | *https://mega.nz/#F!vZhEkazB!mVGqVVDQi8sFXyWgDkU2vw* |
| __7z__ <br> 4.27 GB total |*https://mega.nz/#F!eVAGAArR!k5Lso87x7a4wrP03np_Eaw* |

__If any of these links are dead, please open an issue as soon as possible.__


#### Recommended Unarchivers:
* Windows: __7Zip__
* Mac: __Keka__
* Linux: Command Line, __p7zip__

Habréis notado que hablamos de 25.3 GB, big_smile
Me temo que es demasiado incluso por los que tienen una buena tarjeta video compatible con hashcat
Pero es una excelente base para hacer depuraciones y crear nuestras listas.

BEWGor - Bull's Eye Wordlist Generator
  ___          _   _   _          ___
 | _ )  _  _  | | | | ( )  ___   | __|  _  _   ___
 | _ \ | || | | | | | |/  (_-<   | _|  | || | / -_)
 |___/  \_,_| |_| |_|     /__/   |___|  \_, | \___|
 __      __                 _   _   _   |__/ _
 \ \    / /  ___   _ _   __| | | | (_)  ___ | |_
  \ \/\/ /  / _ \ | '_| / _` | | | | | (_-< |  _|
   \_/\_/   \___/ |_|   \__,_| |_| |_| /__/  \__|
  / __|  ___   _ _    ___   _ _   __ _  | |_   ___   _ _
 | (_ | / -_) | ' \  / -_) | '_| / _` | |  _| / _ \ | '_|
  \___| \___| |_||_| \___| |_|   \__,_|  \__| \___/ |_|

El ser humano es a veces (¿a menudo?) previsible. El estudio de los 350GB de contraseñas confirma lo que sabemos todos: La gente tiende a pasar por los mismos recursos para elaborar sus contraseñas. Nombre de mascota, nacionalidad, nombre de la mama o de la nobia... La "ingeniería social" no es un método infalible pero puede dar resultados.

Does your password sound like the answer to a security question?

Passwords often include information like:

    Mother’s Maiden Name
    Name of a Childhood Pet
    Birthdays of the password holder or a loved one
    The password holder’s nationality

Due to Social Media use and the strength of modern day Open-Source Intelligence (OSINT), this information is NOT HARD TO COME BY. Therefore, including it in your password is NOT SECURE

Es verdad que muchas veces la gente da mucha información en su perfil facebook... A lo mejor basta con mirar el nombre en el buzón para llegar al perfil facebook y saber todo sobre la vida del dueño de un router. 
Si tenemos algo de información podemos probar BEWGor. Nos hará pregunta y creará un diccionario utilizando los elementos que hemos dado

BEWGor asks for information about a person, and those they associate with, and generates potential passwords based on that data.

Did your subject have a dog named Spot?
Was your subject born in 1980?

BEWGor will come up with many variations of these two pieces of information:

spot1980, 1980spot, SPOT80, 80Spot and more.

En el ejemplo se ve la idea: un perro llamado spot +  una fecha de nacimiento 1980 = se crean varias contraseñas combinando estos elementos.
Es muy facíl:

  1. Hacemos un clone de la rama github

    git clone https://github.com/berzerk0/BEWGor.git
  2. Nos situamos

    cd BEWGor
  3. Ejecutamos el script

    python BEWGor

Nos hace las preguntas (en inglès) y respondimos. Dejamos en blanco y prensamos <Enter> para pasar a la pregunta siguiente. Dejo una muestra para que os hagáis una idea:

 | _ ) __\ \    / / __|___ _ _
 | _ \ _| \ \/\/ / (_ / _ \ '_|
 |___/___| \_/\_/ \___\___/_| 

 You will be asked a series of questions about your Subject.
 Your answers will be used to generate a wordlist.
 The lists are generated using all permutations of inputted numbers and words.

 If you are unable or uninterested in providing input for a specific prompt...
 
      ***ANY PROMPT CAN BE LEFT BLANK BY PRESSING ENTER***

 If you do not know how to answer a prompt, more research may be needed.
 Use  --- http://wwww.osintframework.com/ --- to find many useful tools.
 
	           ***PAY ATTENTION***
	
   Many prompts include specific details about input - read carefully.
   Failing to do so will result in a poor quality wordlist!

 Let's begin!
 
Press enter to continue...     
---------------------------------------------------------------

------------------Section A: Main Subject Information----------------------

---------------------------------------------------------------
> Enter The Main Subject's Full Name, separated by spaces - or as much as you have >:pedro ramirez
---------------------------------------------------------------
> Enter Pedro Ramirez's Maiden Name - if applicable >:josefa gonzalez
---------------------------------------------------------------
 For nicknames, think about common name shortenings,
 such as 'Michael' into 'Mike'
 Also enter usernames and online handles.
 
> Enter one of Pedro Ramirez's Nicknames or usernames, or simply press enter to move on >:pepe
> Enter one of Pedro Ramirez's Nicknames or usernames, or simply press enter to move on >:pepe1851
> Enter one of Pedro Ramirez's Nicknames or usernames, or simply press enter to move on >:lordwar
> Enter one of Pedro Ramirez's Nicknames or usernames, or simply press enter to move on >:
---------------------------------------------------------------
 Be Aware BEWGor uses DDMM formatting!
 Winter Solstice falls on  21/12, 22/12, or 23/12 in this format.
> Enter Pedro Ramirez's Birthday (without year, DDMM) >:1212
---------------------------------------------------------------
> Enter Pedro Ramirez's Birth year (YYYY) >:1988
---------------------------------------------------------------
Would you like to include Pedro Ramirez's Greek Zodiac Sign? (Y/N) >:y

 [+] Recorded Pedro Ramirez's Greek Zodiac sign as 'Sagittarius' 

---------------------------------------------------------------
Would you like to include Pedro Ramirez's Birthstone (Y/N) >:y

 Is Pedro Ramirez more likely to use a Birthstone from a Western or Hindu list?
> Enter 1 for Western, 2 for Hindu, or 3 to use both >:1

 [+] Recorded Pedro Ramirez's Birthstone as 'Turquoise' 

---------------------------------------------------------------
Would you like to include Pedro Ramirez's Chinese Zodiac Sign? (Y/N) >:y

 [+] Recorded Pedro Ramirez's Chinese Zodiac sign as the 'Dragon'

---Pedro Ramirez's Gender Identity, in all relevant forms---
 
     MALE and FEMALE are the most commonly identified genders.
 BEWGor can include (English) synonyms for these two choices if 
 they are entered. You may wish to inlcude synonyms in the
 Subject's native language. For example, a Spanish speaker might
 include "chico" in their password. A German speaker may include "Frau"
    Transgendered or transsexual people may identify as male,
 female, trans, queer or something else. Some people do not identify with
 the concept of a binary Male/Female gender system.
    Note that sexuality is different than gender identity,
 and that there will not be a prompt requesting information
 about sexuality specifically. If you have information you
 wish to include about your subject's sexuality do so in the
 "ADDITIONAL WORDS" prompt at the end of the profiling process.
 
    Use 'male' or 'female' to bring up a prompt to include synonyms.
 
> Enter a value for Pedro Ramirez's Identified Gender, or press enter to move on >:male
> Would you like to include 10 English synonyms for Male? (Y/N) >:y

 [+] Synonyms for Male added 

> Enter a value for Pedro Ramirez's Identified Gender, or press enter to move on >:male

 [+] Synonyms for Female added 

 [-] That input has already been added to the list.
  Some inputs are added automatically, try again.
> Enter a value for Pedro Ramirez's Identified Gender, or press enter to move on >:
---------------------------------------------------------------
---Pedro Ramirez's Country of Origin, in all relevant alternate forms---

 For example, an English speaker might refer to 'Germany',
 while a German speaker calls it 'Deutschland.'
 Countries also may have abbreviated forms, such as 'USA', 'U.S.A" or "The US"
 Include Spaces and apostrophes as necessary.
 
 Capitalization will be handled automatically.
 
> Enter a value for Pedro Ramirez's Country of Origin, or press enter to move on >:Spain
> Enter a value for Pedro Ramirez's Country of Origin, or press enter to move on >:España       
> Enter a value for Pedro Ramirez's Country of Origin, or press enter to move on >:Catalunya
> Enter a value for Pedro Ramirez's Country of Origin, or press enter to move on >:
---------------------------------------------------------------
---Adjectives or Nouns to Describe a Person From Pedro Ramirez's Country---

 These are known as National Demonyms.
 A person from Germany is both 'German' and can be called 'a German.'
 Consider demonyms in that country's native language as well, which
 may have gender. Not just "Cuban" but "Cubano" or "Cubana." You may
 want to inlcude nicknames for the demonym as well - such as "Aussie"
 or "Ozzy" for an Australian.
 Capitalization will be handled automatically.
 
> Enter Pedro Ramirez's National Demonyms, or press enter to move on >:Español
> Enter Pedro Ramirez's National Demonyms, or press enter to move on >:catala
> Enter Pedro Ramirez's National Demonyms, or press enter to move on >:
---------------------------------------------------------------
---Pedro Ramirez's National Day---

 These are often the date the nation got independence, won a battle,
 or the day the nation celebrates a religious or royal figure.
 In the US, the national day is 4 July 1776, the day the country declared
 independence. In Oman, the day is 18 November to celebrate the
 Sultan's Birthday. In Ethiopia, the day is 28 May, to celebrate the defeat
 of a ruling party seen as corrupt.
 
> Enter Pedro Ramirez's National Day in DDMMYYYYY or DDMM format >:1111
---------------------------------------------------------------
---Pedro Ramirez's Ethnonyms, in all relevant alternate forms---

 For example, there is a large number of ethnic Chinese living in Malaysia.
 These people are ethnically Chinese, but their nationality is Malaysian.
 The ethnonym in this case would be 'Chinese' or 'Malaysian-Chinese.'
 An ethnic group can exist independent of geography, consider
 the Jewish or Romani Peoples.
    In some countires, such as the US, it is common for people to consider their
 racial identity as a part of or the whole of their ethnic identity
 - and vice versa. For example, it is common practice in the US for
 some younger people of East Asian descent to include the nickname abbreviation
 "AZN" in their usernames and passwords. 
    Nicknames for ethnicities are often unfriendly, but some groups
 co-opt these offensive terms to take the sting out of them.
 You may want to consider adding these to the list.
    Even if a person's family has been living in one nation for generations,
 they may consider their ethnic identity to be the same as their ancestors.
   Enter nouns and adjectives here, such as "Gael" AND "Gaelic"
   In many cases, nationality and ethnicity are the same.
 If that is so, simply move on.
 
 Capitalization will be handled automatically.
 
> Enter an ethnonym for Pedro Ramirez, or simply press enter to move on >:ES
> Enter an ethnonym for Pedro Ramirez, or simply press enter to move on >:
---------------------------------------------------------------
---Pedro Ramirez's Birthplace---

 Consider the name of cities, neighborhoods and more.
 Consider nicknames for these places, such as 'Chi-Town' for 'Chicago'
 or 'The Heights' for a neighborhood like 'Washington Heights'

Cuando hemos acabado de responder a las preguntas nos propone varios niveles de permutaciones

Permutation length of 1 will produce 98 lines.
Permutation length of 2 will produce 9604 lines.
Permutation length of 3 will produce 922180 lines.
Permutation length of 4 will produce 87616900 lines.
Permutation length of 5 will produce 8236920580 lines.

Importante para crack WPA: después indicar el nivel de permutaciones podemos definir una longitud mínima.
Recuerdo que para WPA son 8 caracteres

---------------------------------------------------------------
    ---- MINIMUM Line Length ----
 BEWGor will create all permutations of the items inputted.
 This can be unweildy, and you might not want to keep them all.
 The default --MINIMUM-- line length is 1
 You may set a minimumline length below:
 
> Enter the minimum line length >:8

Las preguntas son buenas y podemos entrar todas las palabras que queremos al final del cuestionario.
Dos aportes interesantes para crack WPA.

Desconectado

#2 18-09-2018 18:58:25

juandiegomu
Usuario

Registrado: 31-05-2015
Mensajes: 105

Re: Probable wordlists y BEWgor (generador por ingeniera social)

ya abia probado wifite2,y es una buena herramienta,pero no sabia lo de BEWGor.tiene buena pinta.un saludo

Desconectado

Temas similares

Tema Respuestas Vistas Ultimo mensaje
2 171 Hoy 15:25:52 por Patcher
Pegado:
521 340002 10-05-2023 18:24:28 por Betis-Jesus
Hospital clinic dump por wifiyeah  [ 1 2 ]
27 1242 09-05-2023 21:32:44 por kcdtv
Hacktivismo por CHARGER22
1 205 08-05-2023 19:53:26 por kcdtv
Pegado:
Pegado:: Script multiuso wifi para Kali y otras distros por v1s1t0r  [ 1 2 3 18 ]
447 66090 22-04-2023 15:31:13 por kcdtv

Pie de página

Información del usuario

Ultimo usuario registrado: klurosu
Usuarios registrados conectados: 0
Invitados conectados: 14

Estadisticas de los foros

Número total de usuarios registrados: 2,446
Número total de temas: 1,637
Número total de mensajes: 15,586

Máx. usuarios conectados: 373 el 30-09-2019 15:04:36