Fetching default wpa2 keys for speedtouch + thomson routers

Postby vegeta » Sat Mar 19, 2011 7:59 am

Hacking Thomson and Speedtouch routers with THC HackSuite

In this tutorial we're going to get access to a WLAN and get free internet access.

- wamp server(or any other webserver): http://www.wampserver.com/en/download.php
- CSS3 compatible browser: don't use crap like IE, instead try Firefox, Safari or RockMelt.
- THC_HS 0.1.3: http://www.hacksuite.com/downloads/cmse ... suite.html
- THC_SB 0.0.6: http://www.hacksuite.com/downloads/modu ... brute.html

Run the server and extract the zip files, so you will have:
- thc_hacksuite
- thc_sb

Put the thc_hacksuite folder in a webdirectory of your server eg C:\WAMP\www, in the thc_hacksuite folder you place the THC_SB folder.

Open the suite in your browser eg 127.0.01/thc_hacksuite/index.php
This should give you the program.

Navigate to the top right where you see a dropdown menu, click on it and select "THC Speedtouch Brute".

This will show the module's web interface, now check out your available wireless networks to see whether you have a speedtouch or thomson router eg ThomsonBA9713
or SpeedtouchBA9713, waiting to be exploited. ;)

You need to pick the hex part that comes right after Thomson or Speedtouch, so in the case above that would be BA9713, enter this value in the bssid field.

Select the years(of course this is a guess) in which the router may have been produced, your best bet is to start around the last 3 or 4 years.

Start brute forcing. :)

- The WPA key might not be found
- There maybe collisions with the algorithm, so there are more than one WPA key possible, try them all
- The generated WPA key may be incorrect, the admin of the network may have changed the key.

This video shows you how the thing is done and will start at step 3, also it will show you a neat trick of the THC Hacksuite, it will allow you to run tasks in the background.

Postby Cool_Fire » Mon Mar 21, 2011 6:03 am

It's a pretty webinterface for sure, but I thought there were standalone tools that could calculate the possible WPA keys for these routers in a few seconds, and that they've existed for years now?
Or am I thinking of a different device?
