Author Message Status: n/a Joined: Fri, 07 Jun 2013 Posts: 2 Team: Reputation: 2 Offline Fri, 07 Jun 2013 @ 10:35:32 Hello guys, I have a new CHALLENGE for you! I have a new serie of Technicolor Routers data, and I would like to have a PIN generator if possible. I know guys what you are capable of Here is the link to data, And here is the list of the six last caracters of MAC address with their associated pin code. 91591 941A8D;79489515 948BE4;370E8;90467912 96C99F;12456789 A4CAFF;71095837 97145 Good Luck Guys Admin / Owner Status: Trusted Joined: Tue, 05 Jul 2011 Posts: 2859 Team: Reputation: 3774 Offline Wed, 12 Jun 2013 @ 15:59:49 Nice xD lots of pics for TNCAP routers although finding the correct algo will be difficult. If you can post all the Serial Numbers, MACs, SSID and WPA Keys in a list it would be a huge help. I accept private hash lists, with forum donations only.
BTC: 15qF9WUeFUD63ishxyAMiEgGqTcYzk4j9b GPU Power: 7x GeForce GTX 1070 and My Brain Status: Cracker Joined: Sat, 09 Jun 2012 Posts: 149 Team: Reputation: 274 Offline Wed, 12 Jun 2013 @ 16:29:56 I was having a look at this too but I'm not having any luck with it. Here's a list of all the info off them pics that unsuns06 posted.
CPU: Intel Core i7 2600k GPU: GeForce GTX 1060 6GB Attachments: to view attachments. Status: n/a Joined: Fri, 07 Jun 2013 Posts: 2 Team: Reputation: 2 Offline Thu, 13 Jun 2013 @ 18:58:02 Thanks for your help! When you say serial number in the quote above do you actually mean PIN? I mean the serial number: SSID: TNCAP 9388E8 SN: 1150A1D05173 SSID: TNCAP 948BE4 SN: 1150A1D18433 Anyway your type of router is different your serial is something like: CPXXXXXXXXX. That's why I didn't post in the other thread.
Status: Trusted Joined: Tue, 02 Aug 2011 Posts: 4598 Team: Reputation: 3003 Offline Sat, 09 Nov 2013 @ 16:07:53 Aw heck I am sorry, I have removed my last post as I was so desperate to break this damn WPA I didn't read it all properly Desperation can do funny things to a guy Thanks hash-ire BTC: 1MmWESN5bKZ1YSuHrm5uNwnQYxWyQnEQ6E Status: n/a Joined: Sun, 24 Nov 2013 Posts: 1 Team: Reputation: 0 Offline Sun, 24 Nov 2013 @ 15:51:18 hi guys i have a router TNCAP5CF25D with mac A4:B1:E9:5C:F2:5D can you found the key with a program? Thnks Status: n/a Joined: Mon, 02 Sep 2013 Posts: 139 Team: Reputation: 27 Offline Wed, 04 Dec 2013 @ 20:39:43 I had a thought. The password is 10 characters long (ABCDEF). But every password never contains more than 5 alphabetic characters (ABCDEF). How can I create a dictionary with words 10 letters long (ABCDEF) and a maximum of 5 alpha characters? Status: Trusted Joined: Tue, 02 Aug 2011 Posts: 4598 Team: Reputation: 3003 Offline Wed, 04 Dec 2013 @ 22:12:11.
I had a thought. The password is 10 characters long (ABCDEF). But every password never contains more than 5 alphabetic characters (ABCDEF). How can I create a dictionary with words 10 letters long (ABCDEF) and a maximum of 5 alpha characters?
You would not normally make a dictionary as it would be enormous Use this command with oclhashcat -1 ABCDEF?1?1?1?1?1?1?1?1?1?1 It will takes months or years BTC: 1MmWESN5bKZ1YSuHrm5uNwnQYxWyQnEQ6E Status: n/a Joined: Mon, 02 Sep 2013 Posts: 139 Team: Reputation: 27 Offline Wed, 04 Dec 2013 @ 22:21:59 I'm sorry, I think I wasn't clear. Your command is good to generate a COMPLETE dictionary, with password like or AAAAAAAABB. I suppose that this password doesn't exist in the TNCAP range! Mp64.exe -2 ABCDEF -output-file 10carhex.txt?d?d?d?2?d?d?2?2?2?2 -combinations the result is 777600000, at 30000 k/s I can try it in 7 hours!
I'd like to know how generate.all the password with max 5 ABCDEF., not all the password with 6-7-8-9-10 alpha. Status: n/a Joined: Mon, 02 Sep 2013 Posts: 139 Team: Reputation: 27 Offline Fri, 06 Dec 2013 @ 12:28:03 mp64.bin -2 ABCDEF -output-file 10carhex.txt?d?2?d?d?2?d?2?d?d?d -q 3 this command is correct to limit to 2 (two) sequential chars? AAA - NO ABA - YES BBA - YES Status: Trusted Joined: Tue, 02 Aug 2011 Posts: 4598 Team: Reputation: 3003 Offline Fri, 06 Dec 2013 @ 16:50:44 Yes thats right the -q option.
This however does not solve your problem. In fact I have wanted an intelligent brute force generator for quite sometime. I haven't forgotten your posts, I am just looking for a way to do it I do know someone who is very clever with this sort of thing, I will beg and plead with him to perhaps help us out.
BTC: 1MmWESN5bKZ1YSuHrm5uNwnQYxWyQnEQ6E Status: n/a Joined: Mon, 02 Sep 2013 Posts: 139 Team: Reputation: 27 Offline Fri, 06 Dec 2013 @ 17:00:02 Ok, many thanks for your effort! Status: n/a Joined: Mon, 02 Sep 2013 Posts: 139 Team: Reputation: 27 Offline Sat, 07 Dec 2013 @ 14:08:55 A few more info: length: 10 characters from UPPER HEX (ABCDEF) no more than 5 alpha chars in the password (yes ABCDE01234 no ABCDEF0123) no more than 2 consecutive chars (yes AABCDEF012 no AAABCDEF01) no more than 2 equal numbers in the password (yes A1A123456 no A1A123451) no more than 3 equal alpha chars in the password (yes 8017C24CCF, no C017C24CCF) Status: Cracker Joined: Sat, 09 Jun 2012 Posts: 149 Team: Reputation: 274 Offline Sat, 07 Dec 2013 @ 18:04:52. A few more info: length: 10 characters from UPPER HEX (ABCDEF) no more than 5 alpha chars in the password (yes ABCDE01234 no ABCDEF0123) no more than 2 consecutive chars (yes AABCDEF012 no AAABCDEF01) no more than 2 equal numbers in the password (yes A1A123456 no A1A123451) no more than 3 equal alpha chars in the password (yes 8017C24CCF, no C017C24CCF) I think you may find this Perl script helpful. A few more info: length: 10 characters from UPPER HEX (ABCDEF) no more than 5 alpha chars in the password (yes ABCDE01234 no ABCDEF0123) no more than 2 consecutive chars (yes AABCDEF012 no AAABCDEF01) no more than 2 equal numbers in the password (yes A1A123456 no A1A123451) no more than 3 equal alpha chars in the password (yes 8017C24CCF, no C017C24CCF) I think you may find this Perl script helpful. The script is very good, but also very slow.
Can someone please try it and tell me how many keys generates in one minute? WINDOWS/LINUX perl wg.pl -c 2 -l 10 -o 3 -n 1 -r 1 -u 10 -v 'ABCDEF' dictionary.txt With the line above I do about 360,448 a minute. CPU: Intel Core i7 2600k GPU: GeForce GTX 1060 6GB Status: n/a Joined: Mon, 02 Sep 2013 Posts: 139 Team: Reputation: 27 Offline Mon, 09 Dec 2013 @ 17:01:38 many thanks!
Status: Trusted Joined: Tue, 02 Aug 2011 Posts: 4598 Team: Reputation: 3003 Offline Mon, 09 Dec 2013 @ 17:09:44 You could probably pipe that into gzip.exe to save space. When you want to run it using oclhashcat do this. Gzip.exe -d -c passlist.txt.gz oclHashcat-plus64.exe -m 0 -force 'your-MD5-hash-here' BTC: 1MmWESN5bKZ1YSuHrm5uNwnQYxWyQnEQ6E Status: n/a Joined: Mon, 02 Sep 2013 Posts: 139 Team: Reputation: 27 Offline Mon, 09 Dec 2013 @ 22:19:48 Ok, I splitted the dictionary in 4000 pieces. I hope the password is in the first half. You could probably pipe that into gzip.exe to save space. When you want to run it using oclhashcat do this.
Gzip.exe -d -c passlist.txt.gz oclHashcat-plus64.exe -m 0 -force 'your-MD5-hash-here' Nice command! +1 reputation - I used lzma instead of zip. Lzma shrinked 1 GB file to 15 MB! - Another program in C for TNCAP - A windows password generator for TNCAP - I compared a specific generator like technicolor.exe and maskprocessor with the switch -q 3. Technicolor.exe 750849753 KB 716 GB maskprocessor.exe 781682234 KB 745 GB Status: n/a Joined: Sat, 01 Feb 2014 Posts: 3 Team: Reputation: 0 Offline Sat, 01 Feb 2014 @ 09:18:28 hi everyone i'm new at this forum! I've read all these posts since i'm interested to find a way to break this tough router:ss!
I'd like first to thanks everyone for their efforts i have some questions, how did you know that the password respect these rules: no more than 5 alpha chars in the password (yes ABCDE01234 no ABCDEF0123) no more than 2 consecutive chars (yes AABCDEF012 no AAABCDEF01) no more than 2 equal numbers in the password (yes A1A123456 no A1A123451) no more than 3 equal alpha chars in the password (yes 8017C24CCF, no C017C24CCF) @eftecno: what is the size of wordlist did you succeed to create? Status: n/a Joined: Mon, 02 Sep 2013 Posts: 139 Team: Reputation: 27 Offline Sat, 01 Feb 2014 @ 14:10:48. @eftecno: what is the size of wordlist did you succeed to create? 16^10 = 776 combination, 11TB Status: n/a Joined: Thu, 03 Jul 2014 Posts: 7 Team: Reputation: 0 Offline Mon, 07 Jul 2014 @ 15:43:49 hi can any one help me i want pin of tncap2c57c2 and tncap694069 and tncap2c7248?????????? How can i hack tncap?????? I am from morocco plz help me Status: n/a Joined: Wed, 09 Jul 2014 Posts: 6 Team: Reputation: 0 Offline Wed, 09 Jul 2014 @ 12:18:18 I i'm trying tohack my tncap, can someone help me please? It's TNAP99C73D the mac address should be a4:b1:e9:99:c7:3d thanks a lot.
103 Results - Page 1 of 4.