[APP][PENTEST][ROOT][2.2+] SpeedKey - EasyBox WPA key recovery + Reaver-WPS v4.00B5

Does it worked for you to calculate the Key?

  • Yes, right default Key & Connected

    Votes: 48 49.0%
  • Right default Key, but Key was changed

    Votes: 16 16.3%
  • No

    Votes: 34 34.7%

  • Total voters
    98
Search This thread

SOEDI

Senior Member
May 14, 2011
154
354
c38ex2c9.png

SpeedKey 3.10R
EasyBox WPA Key recovery
Discontinued due to high risk of abuse.

Also without ROOT:
Default WPA/WPS Pin recovery
otkhekhv.png



ROOT & bcmon supported device only:
Successful Reaver attack with calculated WPS Pin in 20 Seconds!
w36cggin.png


Info:
EasyBox routers made by Arcadyan are insecure!
It's possible to get the default WPA Key (all EasyBoxes) & WPS Pin (EasyBox A802 & A803) by knowing the MAC of the router.
Knowing the WPSPin you can get the actual WPA Key using Reaver-WPS in less then 20 seconds.
Guess what SpeedKey is able to do...:cool:
To use the Reaver feature please look at the Reaver-Support part first.

Don't know how it is somewhere else, but in Germany, Italia, Spain, USA?, UK,....? EasyBox routers are quite frequent.​


Credits & used tools:

Original Algorythm(WPA Key)
Wotan.
See: wotan.cc
(SpeedKey uses a slighly modified version of it.)

Algorythm for default WPS Pin:
Stefan Viehböck
See: SEC Consult

Monitor-Mode over bcmon.apk:
Omri Ildis, Ruby Feinstein & Yuval Ofir
See: bcmon.blogspot.com

Reaver-WPS:
Tactical Network Solutions
See: code.google.com/p/reaver-wps/


Reaver-Support:
You need a device with Broadcom bcm4329/bcm4330 wifi chipset (like Nexus 7), and the bcmon.apk.
Get it here: bcmon.apk
How-To:
  1. Install bcmon and SpeedKey.
  2. Run bcmon, if it crashes try a second time.
  3. If all runs fine, click on "enable monitor mode"
  4. Now disable monitor mode again.
  5. Turn wifi on, and start SpeedKey.
  6. After selecting an EasyBox router, click on Reaver default WPS
  7. Profit?
Steps 1 - 4 are only for the installation, they don't have to be repeated once done.​


Bugs:
The very new EasyBoxes produced after August 2011 are not compatible.
When the key was changed, it won't work of course, except you are using the new Reaver method and it's a A802 or A803 EasyBox (v 3.10R+)​


Changelog:
Code:
1.5: Ads will hide after clicking once on them and pressing back to return to the App. Very good for smaller screens and my AdMob Account;)
1.6: Added Copy & Connect
1.7: Added Info, when no networks are in range
      When ad failed to load, the free screenspace will be used
      Maybe fixed the bug when there are to many networks
      Added new Vendor-IDs to the compatibility list
      Fixed keytextsize for HVGA devices
1.8: Right SSID and Vendor-ID displays green icon, Right SSID or Vendor-ID display yellow icon
       Added some cool Animations:)
1.9: Fixed no networks in range info
       Added automatic copy function
       Fixed green and yellow network recognition
       Speed up scan
       Removed key textbox because of new automatic copy function
1.95: Fixed no networks in range info again
        Disabled animations for armv6 devices
        Optimized startup
2.00: Added signal strengh
        Added routername and signal strengh to the key display box
        Speed up scan a bit
2.10: Fixed signalstrengh bug
2.15: Fixed minor layout bug
2.30: Added settings
        Added abillity to disable/enable animations
        Fixed layout for HD-Smartphones. Thanks to Stefan W.
        If scan fails, try to increase ScanTime in settings
2.35: Animationsettings are now saved properly
2.40: Now more EasyBoxes are compatible
2.50: Added Scanfix for Galaxy S3 Users
2.55: Fixed some critical bugs
2.56: Fixed not properly saving Settings
2.60: Scan is now more stable
2.65: Changed some icons
2.70: Build with new SDK
2.80: Improved EasyBox recognition, now the results with yellow icons should be more accurate.
        Added "About SpeedKey" under settings
2.95: Added periodic ScanMode
        Changed some Icons
        BugFixes
        Android 4.2 layout improvement
2.96: Periodic-ScanMode Bugfix.
        Xperia SP Layoutfix.
        Code cleanup.
3.00: WPS Pin algorithm by Stefan Viehböck added.
[COLOR="Red"]3.10R: WPS-Pin-Reaver approach! [ROOT!][/COLOR]
[B]4.00B5: Added new algorithms, now compatible with updated EasyBoxes!!!
SpeedKey is now way more powerful![/B]


Now removed from Google Play by Vodafone after Teltarif informed them! Read this on Teltarif.de (German)


Attention: Hacking of networks is illegal without having the permission of the owner! I am not responsible for any damage etc. this app could cause
This software is only intended to show a big security hole, not to be able to surf in the neighbours Wifi;)



When someone finds bugs, post it. I'm a big fan of those and love to collect them.
If you like the app, please consider to click on the small AdMob Banner:)

Tested on:
A. Nexus 7, S.E. Xperia Mini,H. Ideos X5, O. Next, H. Honor, S. Xperia SP.
 

Attachments

  • Screenshot_2013-09-10-00-07-24.jpg
    Screenshot_2013-09-10-00-07-24.jpg
    27.2 KB · Views: 8,932
  • Screenshot_2013-09-10-00-07-58.jpg
    Screenshot_2013-09-10-00-07-58.jpg
    22.1 KB · Views: 8,341
  • Screenshot_2013-09-10-00-08-57.jpg
    Screenshot_2013-09-10-00-08-57.jpg
    35.5 KB · Views: 8,140
  • Screenshot_2013-09-10-00-08-43.jpg
    Screenshot_2013-09-10-00-08-43.jpg
    23.3 KB · Views: 7,318
  • Screenshot_2013-09-10-00-10-46.jpg
    Screenshot_2013-09-10-00-10-46.jpg
    18.9 KB · Views: 7,179
Last edited:

SOEDI

Senior Member
May 14, 2011
154
354
SSID & MAC recognition

It should show a green icon on compatible networks.
It looks for SSID which startswith Easybox-*, Arcor* and Vodafone* and for a specific Vendor-Id in the MAC.
However sometimes it shows a green icon but the router isn't compatible and vice versa:(

Have fun:)
 

SOEDI

Senior Member
May 14, 2011
154
354
Thanks

Featurerequests are always welcome!

By the way I also working on adding support for SpeedPort routers. They were produced by Arcadyan as well.
 
Last edited:

SOEDI

Senior Member
May 14, 2011
154
354
Update

Updated to v 1.7
Mostly fixes and improvements, details in the changelog.
 

SOEDI

Senior Member
May 14, 2011
154
354
Update

Updated to v 1.8
Changes in the Changelog

To all from Germany: Please try it out and report if it worked [or not] for you. I don't have a warehouse full of EasyBoxes at home, so need help;)
 
  • Like
Reactions: dev_harsh1998

SOEDI

Senior Member
May 14, 2011
154
354
Final

Released v 1.9
Now the App is really usable an available on Goolge Play!:good:
 

carlolgb

Senior Member
Aug 13, 2011
89
25
AW: [APP][HACK][Android 2.2+] SpeedKey - EasyBox Router WPA key calculation v2.60

Hey...ill give it a try and report tomorrow

Gesendet von meinem Evo 3D GSM wow
 

Top Liked Posts

  • There are no posts matching your filters.
  • 33
    c38ex2c9.png

    SpeedKey 3.10R
    EasyBox WPA Key recovery
    Discontinued due to high risk of abuse.

    Also without ROOT:
    Default WPA/WPS Pin recovery
    otkhekhv.png



    ROOT & bcmon supported device only:
    Successful Reaver attack with calculated WPS Pin in 20 Seconds!
    w36cggin.png


    Info:
    EasyBox routers made by Arcadyan are insecure!
    It's possible to get the default WPA Key (all EasyBoxes) & WPS Pin (EasyBox A802 & A803) by knowing the MAC of the router.
    Knowing the WPSPin you can get the actual WPA Key using Reaver-WPS in less then 20 seconds.
    Guess what SpeedKey is able to do...:cool:
    To use the Reaver feature please look at the Reaver-Support part first.

    Don't know how it is somewhere else, but in Germany, Italia, Spain, USA?, UK,....? EasyBox routers are quite frequent.​


    Credits & used tools:

    Original Algorythm(WPA Key)
    Wotan.
    See: wotan.cc
    (SpeedKey uses a slighly modified version of it.)

    Algorythm for default WPS Pin:
    Stefan Viehböck
    See: SEC Consult

    Monitor-Mode over bcmon.apk:
    Omri Ildis, Ruby Feinstein & Yuval Ofir
    See: bcmon.blogspot.com

    Reaver-WPS:
    Tactical Network Solutions
    See: code.google.com/p/reaver-wps/


    Reaver-Support:
    You need a device with Broadcom bcm4329/bcm4330 wifi chipset (like Nexus 7), and the bcmon.apk.
    Get it here: bcmon.apk
    How-To:
    1. Install bcmon and SpeedKey.
    2. Run bcmon, if it crashes try a second time.
    3. If all runs fine, click on "enable monitor mode"
    4. Now disable monitor mode again.
    5. Turn wifi on, and start SpeedKey.
    6. After selecting an EasyBox router, click on Reaver default WPS
    7. Profit?
    Steps 1 - 4 are only for the installation, they don't have to be repeated once done.​


    Bugs:
    The very new EasyBoxes produced after August 2011 are not compatible.
    When the key was changed, it won't work of course, except you are using the new Reaver method and it's a A802 or A803 EasyBox (v 3.10R+)​


    Changelog:
    Code:
    1.5: Ads will hide after clicking once on them and pressing back to return to the App. Very good for smaller screens and my AdMob Account;)
    1.6: Added Copy & Connect
    1.7: Added Info, when no networks are in range
          When ad failed to load, the free screenspace will be used
          Maybe fixed the bug when there are to many networks
          Added new Vendor-IDs to the compatibility list
          Fixed keytextsize for HVGA devices
    1.8: Right SSID and Vendor-ID displays green icon, Right SSID or Vendor-ID display yellow icon
           Added some cool Animations:)
    1.9: Fixed no networks in range info
           Added automatic copy function
           Fixed green and yellow network recognition
           Speed up scan
           Removed key textbox because of new automatic copy function
    1.95: Fixed no networks in range info again
            Disabled animations for armv6 devices
            Optimized startup
    2.00: Added signal strengh
            Added routername and signal strengh to the key display box
            Speed up scan a bit
    2.10: Fixed signalstrengh bug
    2.15: Fixed minor layout bug
    2.30: Added settings
            Added abillity to disable/enable animations
            Fixed layout for HD-Smartphones. Thanks to Stefan W.
            If scan fails, try to increase ScanTime in settings
    2.35: Animationsettings are now saved properly
    2.40: Now more EasyBoxes are compatible
    2.50: Added Scanfix for Galaxy S3 Users
    2.55: Fixed some critical bugs
    2.56: Fixed not properly saving Settings
    2.60: Scan is now more stable
    2.65: Changed some icons
    2.70: Build with new SDK
    2.80: Improved EasyBox recognition, now the results with yellow icons should be more accurate.
            Added "About SpeedKey" under settings
    2.95: Added periodic ScanMode
            Changed some Icons
            BugFixes
            Android 4.2 layout improvement
    2.96: Periodic-ScanMode Bugfix.
            Xperia SP Layoutfix.
            Code cleanup.
    3.00: WPS Pin algorithm by Stefan Viehböck added.
    [COLOR="Red"]3.10R: WPS-Pin-Reaver approach! [ROOT!][/COLOR]
    [B]4.00B5: Added new algorithms, now compatible with updated EasyBoxes!!!
    SpeedKey is now way more powerful![/B]


    Now removed from Google Play by Vodafone after Teltarif informed them! Read this on Teltarif.de (German)


    Attention: Hacking of networks is illegal without having the permission of the owner! I am not responsible for any damage etc. this app could cause
    This software is only intended to show a big security hole, not to be able to surf in the neighbours Wifi;)



    When someone finds bugs, post it. I'm a big fan of those and love to collect them.
    If you like the app, please consider to click on the small AdMob Banner:)

    Tested on:
    A. Nexus 7, S.E. Xperia Mini,H. Ideos X5, O. Next, H. Honor, S. Xperia SP.
    5
    SpeedKey 4 Release

    I was able to show how useless vodafones "mac-changer" update was. Thanks to my beta testers for helping me:good:
    Vodafone was notified about these security issues, they said they are releasing(right now) a new update which should solve the problem.
    Since then 2 months passed, so all EasyBoxes *should* be secure now!

    EDIT: Some testers reported, that SpeedKey is still working on their (updated("mac-changer") and non-updated) EasyBoxes...
    I need more data, but it seems like Vodafone failed again...



    That's why I'm now releasing SpeedKey 4, so anyone can test HIS or HER OWN EasyBox-router regarding its security.

    I won't provide to much info here in order to keep those "lets-hack-everyone-kiddies" away;), so here is the basic stuff:

    Icons:
    yellow: might be an EasyBox without "mac-changer" update.
    green: EasyBox without "mac-changer" update.
    violet: EasyBox with "mac-changer" update.

    EasyBoxes with "mac-changer" firmware have about ~20 possible default WPA and WPS Keys.
    If the default WPA-Key is set, the WPA-approach will find it.
    If the WPA-Key was changed, the WPS-approach might work, but you need a bcmon supported device like the Nexus 7 (2012).


    In case YOUR EasyBox is vulnerable, follow this guide to make it secure:
    (You may also help your familly and friends)

    Open in your Browser 192.168.2.1
    USER: root PASS: 123456
    Change your SSID
    Disable WPS
    Change WPA-Key


    Again:
    Use it ONLY for LEGAL purposes!
    YOU are responsible for what YOU are doing with this pentesting app.



    regards,
    SOEDI


    Discontinued due to high risk of abuse, since Vodafone refuses to fix their routers!
    4
    SpeedKey 4

    Guys, SpeedKey 4 is going to be awesome.
    4
    SpeedKey v 3.10R

    Preparing for release of Speedkey v 3.10R(eaver).
    It will use the calculated WPSPin of EasyBoxes, and try to unveil the actual WPA Key with Reaver-WPS!
    It should work with A802 and A803 routers.
    No custom Kernels or self-compiled librarys!

    Dependencies & Compatibility (only for the Reaver-Part):
    ROOT
    Broadcom bcm4329/bcm4330 wireless chipset.
    bcmon.apk installed(alltime) and executed(only first time), so you will know if your device is compatible and bcmon contains all the stuff SpeedKey needs.
    confirmed to work on: Nexus 7(2012)

    Credits:
    All Credit goes to those awesome guys:
    Omri Ildis
    Ruby Feinstein
    Yuval Ofir
    They made Monitoring-Mode on Android possible!
    http://bcmon.blogspot.de/

    Download bcmon.apk
    SpeedKey v 3.10R will follow soon.
    2
    Thanks, will try ;)
    But I never saw an EasyBox before. I'm from the Netherlands.

    Sent from my Galaxy Nexus running Android 4.2 JB