Virgin Media UK WPA password crack request

WingRust

Member
Feedback: 0 / 0 / 0
Joined
Feb 14, 2026
Messages
13
Reaction score
3
Credits
146
ESSID: VM0957765
BSSID: A4:22:49:9A:E9:46
Country of Origin: UK


Hello


firstly massive thanks to @Sparton for pointing out this great forum and helping me out cracking this hc22000 file.


I've got Hashcat running on the file with just over a day left with a character set of 8 characters including, a..z with no i or o, and altogether it will be four days.


after speaking with @Sparton it looks like the router could be a sagecom hub 5 which has 16 characters and uppercase, lowercase and digits. I have attached the PMKiD file and the handshake cap file both taken from Wifite and the 22000 file taken straight from Angry Oxide.


the more help the better would be great as mentioned i'm already running it against 8 characters from a...z with no i or o.

thanks in advance
WingRust



_
 

Attachments

  • VM.zip
    10.2 KB · Views: 15

WingRust

Member
Feedback: 0 / 0 / 0
Joined
Feb 14, 2026
Messages
13
Reaction score
3
Credits
146
51 Minutes to go before my mask runs out. I’m gonna try 16 digits alphanumeric next although if it says 500 years I might try a wordlist.
 

Sparton

Active member
Contributor
Feedback: 8 / 0 / 0
Joined
Dec 30, 2019
Messages
742
Reaction score
1,995
Credits
4,437
Assuming all 62 letters and digits are used, and you are using a RTX4090 GPU averaging about 2.5 million passwords per second, AI says it would take about 603.75 billion years to complete.
 

WingRust

Member
Feedback: 0 / 0 / 0
Joined
Feb 14, 2026
Messages
13
Reaction score
3
Credits
146
Jesus wept that’s crazy, so there’s no way I’m gonna crack this on my own then! I was so proud of my cracking rig too. I’m gonna try an increment from 8-16 using one rule to use them still and using alphanumeric characters, just for the crack.
 

Dawbs

Super Moderator
Staff member
Super Moderator
Trusted
Feedback: 3 / 0 / 0
Joined
Dec 30, 2019
Messages
4,350
Reaction score
3,700
Credits
19,822
Well I was really hoping for once Sparton was wrong, But nope. seems he's spot on again.

This is almost certainly a new Hub 5 with 16 length pass, going on the MAC & Manufacturer. On a possible good note, (and based on limited available knowledge) the are a few factors that reduce the keyspace.

It seems that within the 16 spaces. 13 are lowercase, 2 are uppercase & 1 is a digit.

i is 100% included and i'm guessing o probably is too.


This probably doesn't help with cracking too much as this still leaves a rather large keyspace. But it does show that patterns are used.
 

WingRust

Member
Feedback: 0 / 0 / 0
Joined
Feb 14, 2026
Messages
13
Reaction score
3
Credits
146
Thanks @Dawbs

Appreciated it also gives me practice writing out commands with the correct syntax for the HASH mask using Hashcat。
Many Thajks WingRust
 

Dawbs

Super Moderator
Staff member
Super Moderator
Trusted
Feedback: 3 / 0 / 0
Joined
Dec 30, 2019
Messages
4,350
Reaction score
3,700
Credits
19,822
Sorry I don't have a big enough sample size to see any more detail.
 

WingRust

Member
Feedback: 0 / 0 / 0
Joined
Feb 14, 2026
Messages
13
Reaction score
3
Credits
146
@Sparton Hello any idea why my handshake.cap file from this thread is being refused by Fluxion the tool says it’s not useable or incomplete, I can’t remember the exact message, I was going to use it to verify the password using fluxions rouge network I’ve exhausted all other ways I know of to get the password. Also strange I’ve not been able to get another handshake from that router no matter which tool I use even hcxdumptool, any input would be appreciated, thanks.
 

Sparton

Active member
Contributor
Feedback: 8 / 0 / 0
Joined
Dec 30, 2019
Messages
742
Reaction score
1,995
Credits
4,437
I am not familiar with Fluxion. Have never used it.

Assuming everything is working ok and you are able to get other handshakes, perhaps you need to be closer.
 

WingRust

Member
Feedback: 0 / 0 / 0
Joined
Feb 14, 2026
Messages
13
Reaction score
3
Credits
146
Ok thanks I don’t know what’s going on I thought I’d sorted it in that I was trying to pass the 5G handshake and realised it was 2.4G channel 6, I’ve loaded it into Fluxion and created a db for it and I’ve verified the handshake using airodump-ng and everything’s good, anyway thanks for the reply appreciated I’ll keep playing with this I’m sure I’ll get sorted somehow.
 
Top