Info

Contact us today to discuss how we can help you successfully achieve your mission-critical objectives!

Tactical Network Solutions, LLC
8825 Stanford Blvd, Suite 308
Columbia, MD 21045-4761

Email: sales [@] tacnetsol.com
Phone: 443-276-6990

Twitter
« Official Reaver Screencast | Main | TNS Partners to Present at the 6th Cyberwatch Mid-Atlantic Collegiate Cyber Defense Competition »

Cracking WiFi Protected Setup with Reaver

UPDATE: Reaver Pro now available on the HakShop

Yesterday, Stefan over at .braindump released a white paper detailing vulnerabilities in the WiFi Protected Setup (WPS) protocol that allows attackers to recover WPA/WPA2 passphrases in a matter of hours.

This is a capability that we at TNS have been testing, perfecting and using for nearly a year. But now that this vulnerability has been discussed publicly we have decided to announce and release Reaver, our WPS attack tool, to the open source community. Reaver is capable of breaking WPS pins and recovering the plain text WPA/WPA2 passphrase of the target access point in approximately 4-10 hours (attack time varies based on the access point).

While we have released Reaver as an open source project, we also offer a commercial version with additional features and functionality as well as a support plan. Since nearly all access points manufactured in the past few years have WPS support enabled by default, attacking WPS provides several advantages over attacking WPA directly:

 

  1. Cracking the WPS pin is, obviously, much faster.
  2. Once you have the WPS pin you can instantly recover the WPA passphrase, even if the owner changes the passphrase.
  3. Access points with multiple radios (2.4/5GHz) can be configured with multiple WPA keys. Since the radios use the same WPS pin, knowledge of the pin allows an attacker to recover all WPA keys.

 

Of course the disadvantage is that WPS can be disabled. However, in our experience even security experts with otherwise secure configurations neglect to disable WPS; further, some access points don't provide an option to disable WPS, or don't actually disable WPS when the owner tells it to.

To learn more about Reaver, visit our product page, or the open source project on Googlecode.

References (59)

References allow you to track sources for this article, as well as articles that were written in response to this article.
  • Response
    WiFi hacking has long been a favorite pastime of hackers, penetration testers, and people too cheap to
  • Response
    Response: diaita astrapi
    thanks for sharing..
  • Response
    Response: Celular Mexico
    Yesterday, Stefan over at .braindump released a white paper detailing vulnerabilities in the WiFi Protected Setup (WPS) protocol that allows attackers to recover WPA/WPA2 passphrases in a matter of hours.
  • Response
    Response: dui lawyers
    This one helped me for a thesis which I am writing. Thank you for giving me another point of view on this difficult situation. Now I can easily complete my article. Thanks
  • Response
    Response: Mike Sweeny
    I would like to thank you for your nicely written post, its informative and your writing style encouraged me to read it till end. Thanks
  • Response
  • Response
  • Response
    Response: water damage
  • Response
    Response: water damage leads
  • Response
    Response: zumba
  • Response
  • Response
  • Response
  • Response
  • Response
    Response: loyalty cards
    There are a lot of sites and articles out there on this particular point, but you have captured another side of the subject. This is good content thank you for adding it here.
  • Response
    This is a terrific article, and I would like more information if you have any. I am fascinated with this topic and your post has been one of the best I have read.
  • Response
    Response: locksmith miami
    I am researching this topic for use in a future business I am thinking about starting. Thank you for this information, it has been educational and helpful to me.
  • Response
    I am interested in this subject matter and would like to explore out some more information as my colleague need information on this topic. Do you have any other post on this? Cheers!
  • Response
    Response: neueseo.com
    Your post had provided me with another point of view on this topic. I had no idea that things can work in this manner as well. Thank you for sharing your perspective.
  • Response
    Response: Wifi hacker
    Tactical Network Solutions - News - Cracking WiFi Protected Setup with Reaver
  • Response
    I would like to thank you for your nicely written content, its useful and your writing style helped me to read it without any difficulty. Thanks
  • Response
    Your post contains useful information on this point as I am working on a college project. Thank you posting relative information and its now becoming easier to complete this topic.
  • Response
    Response: mold testing
  • Response
    I am about to complete a university thesis on this topic and your post has helped me with the facts and figures I needed to accomplish it. Cheers!
  • Response
    Response: Vapor Blogger.com
    I would like to thank you for your best written post, its informative and your writing style helped me to read it till end. Thanks man!
  • Response
    Response: website
    I have been searching for quite some time for information on this topic and no doubt your website saved my time and I got my desired information. Your post has been very helpful. Thanks.
  • Response
  • Response
    Wow! I really appreciate the thought that you put into this article. This topic has been something I have been looking into for a few hours and your post is one of the best I have read.
  • Response
    Response: online doctor
    This topic has always been one of my favorite subjects to read about. I have found your post to be very rousing and full of good information. I will check your other articles shortly.
  • Response
  • Response
    Response: Brighton Cleaner
    Your site contains useful information on this topic as I am working on a school project. Thank you posting relative information and its now becoming easier to complete this topic.
  • Response
    As part of a college thesis for research I have to search sites with relevant information on given topic and provide them to teacher our opinion and the article. Your article helped me a lot.
  • Response
    I am doing a report on this subject. Your article is full of really useful information. I will make sure to come back to check out your posts for my next report. Cheers
  • Response
    Response: Sanowicz
    I like the way you described the topic with such clarity. This is something I have been thinking about for a long time and you really captured the essence of the subject.
  • Response
  • Response
  • Response
    Response: tablet pc with sim
    Your article is very exciting and informational. I am trying to decide on a career move and this has helped me with one aspect. Thank you so much!
  • Response
    Response: modeladores yoga
    As part of an assignment for research I have to find an article with relevant information on this topic and give the teacher our opinion and the article. Your article helped me a lot.
  • Response
  • Response
    I am in the middle of working on a school report on this topic and your post has helped me with the information I needed to complete it. Thanks.
  • Response
    What's up to every one, the contents existing at this website Tactical Network Solutions - News - Cracking WiFi Protected Setup with Reaver are genuinely awesome for people knowledge, well, keep up the nice work fellows.
  • Response
    Response: click here
    I am currently teaching a class and part of the curriculum involves this subject matter. Do you have any other posts I can look at regarding this?
  • Response
    Response: hack wifi android
    Tactical Network Solutions - News - Cracking WiFi Protected Setup with Reaver
  • Response
    Response: curing hemmerhoids
  • Response
  • Response
  • Response
  • Response
  • Response
    Response: flood damage
  • Response
    low price and cheap cell phone plans for smart phones verizon wireless att
  • Response
    Response: mold remediation
  • Response
    Tactical Network Solutions - News - Cracking WiFi Protected Setup with Reaver
  • Response
    Response: baterie ego
    Great info here!
  • Response
    Response: phen375 review
    Tactical Network Solutions - News - Cracking WiFi Protected Setup with Reaver
  • Response
  • Response
  • Response
    Response: flooded basement
  • Response
    Response: Treatment
  • Response
    Response: mold removal

Reader Comments (36)

Nice job!
Please continue, we need much more security-aware people on the internet and I'd say this will help a little to raise awareness.

February 1, 2012 | Unregistered Commenteralfredo ricciotti

What string of commands do I use in reaver to recover the passphrase again once I have the pin?

Do I have to start from scratch or can I use the pin to get the passphase or wpa key?

March 1, 2012 | Unregistered CommenterN00d L

Once you have the pin you can re-run Reaver and it will give you the passphrase.

great, it really helps someone like me who is not a very computer literate person.

Using latest version of Reaver to crack a WPA2 but the MAC addy is ALL numeric and Reaver just kicks back the ' failed to associate'. Any ideas/suggestions?

March 8, 2012 | Unregistered CommenterErOcK

So my router has its WPS enabled, but... when i created the WPA2 PSK connection i didn't use the WPS button, but entered a passfrase in the router's menu. Is my network vulnerable in this case?

March 25, 2012 | Unregistered Commentercmyk

@cmyk If you router has WPS enabled you are vulnerable.

What OS should I use to run Reaver Pro on my win7 pc, I thought it would run from windows?

May 7, 2012 | Unregistered Commentermm

@N00d L if u ran it off a live cd such as ubuntu then reaver will not remeber your pin so u wil have to put a -p 12345678 where the numbers r the pin in ur command so for example
"sudo reaver -i mon0 -b 00:01:02:03:04:05 -L -p 12345670 -vv"

@mm use a linux operating system such as ubuntu or backtrack they both come in live cd versions or u can just use them through vertual machines such as vmware or virtualbox

May 29, 2012 | Unregistered Commentervistazifta

guy i do really need Reaver and where can i download it.?

March 15, 2013 | Unregistered Commenterprince

This is an extremely interesting subject, could you please expand on what exactly happens when WPS is disabled?

March 21, 2013 | Unregistered CommenterJay

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>