Thursday September 9, 2010 5:35 PM AEST
 
Latest Comments
PKI

Ethical hacker starts WPA cloud cracking service

  • Email a Friend
  • Print Page
Ethical hacker starts WPA cloud cracking service
By Iain Thomson
Dec 8, 2009 3:45 PM | 1 Comment
Tags: dictionary | run | service | attack | check | cloud
Checks passwords using dictionary attack.

A renowned security researcher has started a new service allowing companies to check the strength of their WPA-PSK encryption passwords.

Moxie Marlinspike, one of the team who revealed the possibility of hacking the Secure Socket Layer (SSL) at this year’s Black Hat conference, has started the WPA Cracker service for security testers and auditors.

The system uses a 400 processor cloud node to run a dictionary attack on WPA-PSK passwords. Marlinspike has developed the 135 million word dictionary specifically for this purpose.

“We offer two different cracking modes at two different prices. You can run your job against half of our CPU cluster for US$17, or you can run it against the entire cluster for US$34,” the service said in a statement.

“The half-mode will take at most 40 minutes to exhaust the entire 135 million word dictionary file (but hopefully we'd find your password before that), where as the full-mode will take at most 20 minutes.”

Marlinspike points out that a standard PC would take about a week to run a similar attack and the service would allow security audits in particular to check the strength of their WPA passwords.

Copyright ©v3.co.uk

 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 1
This type of brute-force attack does not apply to WPA/WPA2-Enterprise networks, which use 802.1X authentication. Even small businesses and consumers can now easily implement this advanced security using outsourced services like AuthenticateMyWiFi: http://www.NoWiresSecurity.com
SC Magazine - comments icon Posted by Eric GeierDec 22, 2009 9:27 AM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Comments have been disabled on this article.
 
 
Access Control Whitepapers