Pixiewps sometimes gets the password and sometimes doesn’t

To learn more about pixiedust, I enabled WPS on my Tenda WiFi router(static pin) and started exploring. I found this GitHub project called oneshot that uses wpa_supplicant to get the necessary handshake data and then cracks the pin with good old pixiewps.

What is weird is that the attack doesn’t always succeed although all the necessary handshake data is always provided to pixiedust.

I even gathered the data myself and ran it manually. Roughly 10/100 tries succeed, Given my every 3 attempts are 30 minutes apart (Doing it back to back just keeps failing and triggers router rate limit). The problem seems to be somewhere in how the router is generating the hashes at a certain time or a bug in pixiewps. However I’m not sure what is actually causing this. What could it be?

submitted by /u/invoked_vilgax
[link] [comments]

April 9, 2023
Read More >>