Need help with this new cap style.. seeing more of these and nowhere to start

Dawbs

Super Moderator
Staff member
Super Moderator
Trusted
Feedback: 3 / 0 / 0
Joined
Dec 30, 2019
Messages
4,161
Reaction score
3,428
Credits
18,251
Just looks like a normal .cap file. A poor quality one. Not sure what you mean by 'new cap style'?

Attached the file for anyone who doesn't want to visit the tracking host website.
 

Attachments

  • Wifi-040c.zip
    479.4 KB · Views: 5

Steal the Joy

Active member
Feedback: 0 / 0 / 0
Joined
Nov 28, 2023
Messages
59
Reaction score
70
Credits
354
Just looks like a normal .cap file. A poor quality one. Not sure what you mean by 'new cap style'?
believe these are Xfinity Routers and looks like they sent out an update to change the stock username BSSID and password.. seeing more and more of these in my hood lately!
 

Steal the Joy

Active member
Feedback: 0 / 0 / 0
Joined
Nov 28, 2023
Messages
59
Reaction score
70
Credits
354
Sorry meant to say they changed the ESSID name and Password from stock... noticing many of these now! beginning with Essid WIFI-
 

Sparton

Active member
Feedback: 7 / 0 / 0
Joined
Dec 30, 2019
Messages
584
Reaction score
1,467
Credits
3,543
You might want to try running it thru your beta version cap validator program that you wrote.
Comes up a dud on my end.
 

Sparton

Active member
Feedback: 7 / 0 / 0
Joined
Dec 30, 2019
Messages
584
Reaction score
1,467
Credits
3,543
It is corrupt in that it will not convert to the 22000 format. Nor the 2500 format.
EAPOL ANONCE error corrections (NC)......: not detected
EAPOL M1 messages (total)................: 8
EAPOL M1 messages (KDV:0 AKM defined)....: 8 (PMK not recoverable)
EAPOL M2 messages (total)................: 4
EAPOL M2 messages (KDV:0 AKM defined)....: 4 (PMK not recoverable)
EAPOL M3 messages (total)................: 2
EAPOL M3 messages (KDV:0 AKM defined)....: 2 (PMK not recoverable)
EAPOL M4 messages (total)................: 6
EAPOL M4 messages (KDV:0 AKM defined)....: 6 (PMK not recoverable)
RSN PMKID (total)........................: 8
RSN PMKID (KDV:0 AKM defined)............: 8 (PMK not recoverable)

Since you do not use hashcat to crack there might be some validity left in the cap for your use. I do not know.
Your 2nd post is invalid for conversion also.
 

Steal the Joy

Active member
Feedback: 0 / 0 / 0
Joined
Nov 28, 2023
Messages
59
Reaction score
70
Credits
354
there is a slight chance it could be corrupt.. Ill get another good one just to verify
 

Sparton

Active member
Feedback: 7 / 0 / 0
Joined
Dec 30, 2019
Messages
584
Reaction score
1,467
Credits
3,543
I think it is time for you to re-visit how you capture these files. 107mb is absurd. No wonder you are cleaning them.
The majority of good captures are under 500kb. Most conversion programs will not handle that large of a file. So I did it the old fashioned way using hcxpcapngtool. It still does not have the valid handshakes to convert.
Maybe try something basic like wifite2. Easy to install and works great. https://github.com/kimocoder/wifite2
What program are you using to capture? It is not working. Looks like the cleaning is not corrupting them (even though you should never clean cap files), but the capturing is.
You say these cap files are tested as valid. Perhaps in some way they are, but not for M1, M2, M3, and M4 handshakes.
 

Steal the Joy

Active member
Feedback: 0 / 0 / 0
Joined
Nov 28, 2023
Messages
59
Reaction score
70
Credits
354
im open to anything at the moment with these.. you could be onto something here why i cant crack these.
im using aircrack and just leaving them on monitor until I get a handshake as these mesh systems wont allow a Deauth.
 

Nikolia

Active member
Feedback: 6 / 0 / 0
Joined
Sep 13, 2021
Messages
1,057
Reaction score
3,020
Credits
5,686
Steal the Joy said: ↑

WIFIDE7C
Out of sequence timestamps!
This dump file contains frames with out of sequence timestamps.
That is a bug of the capturing/cleaning tool.
 

Steal the Joy

Active member
Feedback: 0 / 0 / 0
Joined
Nov 28, 2023
Messages
59
Reaction score
70
Credits
354
hmm could be one of the reasons I cant crack these... ill keep tryin.. thanx
 

freeroute

Community Manager
Staff member
Community Manager
Super Moderator
Trusted
Feedback: 8 / 0 / 0
Joined
Dec 30, 2019
Messages
22,953
Reaction score
5,125
Credits
22,932

freeroute

Community Manager
Staff member
Community Manager
Super Moderator
Trusted
Feedback: 8 / 0 / 0
Joined
Dec 30, 2019
Messages
22,953
Reaction score
5,125
Credits
22,932
Summary: "If you use old, outdated, crappy tools to run an attack on a target you have to live with this crappy consequences." :)
 

Attachments

  • Summary.txt
    6.9 KB · Views: 11
Last edited:

Steal the Joy

Active member
Feedback: 0 / 0 / 0
Joined
Nov 28, 2023
Messages
59
Reaction score
70
Credits
354
wont argue with you there.. im gettin old and trying to keep up with everything is gettin overwhelming! Just wait til your my age and then youll understand lol.. I just do this for a fun hobby now. But now understand why i couldnt crack these, Appreciate the feedback
 

freeroute

Community Manager
Staff member
Community Manager
Super Moderator
Trusted
Feedback: 8 / 0 / 0
Joined
Dec 30, 2019
Messages
22,953
Reaction score
5,125
Credits
22,932
wont argue with you there.. im gettin old and trying to keep up with everything is gettin overwhelming! Just wait til your my age and then youll understand lol.. I just do this for a fun hobby now. But now understand why i couldnt crack these, Appreciate the feedback
Don't take this as a personal attack. I believe I’m much older than you. But you should always use the latest software version. That’s my humble suggestion
 
Top