Hacking Netgear Wi-Fi Router Default Passwords

5,649
2
Published 2023-10-04
In this video, I demonstrate an attack on the default password scheme on many Netgear Wi-Fi routers in the wild today.

github repo:
github.com/nmatt0/netgear-wpa-wordlist

IoT Hackers Hangout Community Discord Invite:
discord.com/invite/vgAcxYdJ7A

πŸ› οΈ Stuff I Use πŸ› οΈ

πŸͺ› Tools:
XGecu Universal Programmer: amzn.to/4dIhNWy
Multimeter: amzn.to/4b9cUUG
Power Supply: amzn.to/3QBNSpb
Oscilloscope: amzn.to/3UzoAZM
Logic Analyzer: amzn.to/4a9IfFu
USB UART Adapter: amzn.to/4dSbmjB
iFixit Toolkit: amzn.to/44tTjMB

🫠 Soldering & Hot Air Rework Tools:
Soldering Station: amzn.to/4dygJEv
Microsoldering Pencil: amzn.to/4dxPHwY
Microsoldering Tips: amzn.to/3QyKhrT
Rework Station: amzn.to/3JOPV5x
Air Extraction: amzn.to/3QB28yx

πŸ”¬ Microscope Setup:
Microscope: amzn.to/4abMMao
Microscope 0.7X Lens: amzn.to/3wrV1S8
Microscope LED Ring Light: amzn.to/4btqiTm
Microscope Camera: amzn.to/3QXSXsb

About Me:
My name is Matt Brown and I'm an Hardware Security Researcher and Bug Bounty Hunter. This channel is a place where I share my knowledge and experience finding vulnerabilities in IoT systems.

- Soli Deo Gloria

πŸ’» Social:
twitter: twitter.com/nmatt0
linkedin: www.linkedin.com/in/mattbrwn/
github: github.com/nmatt0/

#iot #hacking #wifi #router

All Comments (21)
  • @monophonic_og
    Was it saying eight days because you actually had two handshakes in the file and it counted four days per handshake?
  • @hasanmehmedov
    The highlight of my day. Please keep the videos coming.
  • @hesh8100
    I really love your content keep it up bro πŸ–€
  • @jeremyl7504
    Was just checking out a similar netgeat router!
  • @hexkin4547
    Hi Matt just would like to say great videos thank you, also what microscope do you use as I'm looking to buy a new one thanks again
  • @isamaliyadipak
    You are making great informative video. Please make how to install firmware on bricked ubnt switch via console or other way.
  • @brettlaw4346
    Can I persuade you to analyze the $24 j-link knock-offs?
  • @opsec
    How did you compile the wordlists? I was wanting to make a similar tool for this purpose. From searching the nouns wordlist I see that the noun on a netgear router I have to test on isnt included. That would be "teapot". The adj is there, but not the noun. wonder if there is an efficient way to make the list better for these routers.
  • @maykelsantos5501
    Could you find a way to extract the firmware or super user from the Nokia G-1425G-A ONT?
  • My brother can you please do an experiance about to get firmware from ZKteco F18 fingerprint because its really hard to get baud rate i did choose from 9600 to 115200 but without hope thank you
  • @Myself-yh9rr
    I wonder if there is a router that would automatically connect you to a different channel when someone may have knocked you off the network. This way if someone was looking at just one channel they would get nothing hehehe. I know that WPA3 can help also but it is not as secure as someone may think. We need a router that will not allow WPA2 so that WPA3 can be more secure.
  • @Sayed-hw8xo
    Could you recommend books for hardware firmware hacking and reverse engineering from beginner to advanced level
  • @im4uk
    Hi, can you make a video tplink 8mb spi flash change to 16mb with full capacity work in openwrt firmware, make a uboot modified capacity 8mb to 16mb Please make a video for it if it's possible... I'm trying to make 8mb flash to 16mb tp-link WR902ac router but I'm fail always. Hope you do it . I'm waiting your reply...
  • @Gary-ve6ll
    Dump a cable modem and show us how to find the private rsa key lol
  • @mnageh-bo1mm
    I think you are doing something wrong, cracking such default patterns doesn't usually take but hours , plus you should have used masks no need to write a python script for that
  • @AndreChee
    Hello , how i can contact you ? I am interested for make flashing firmware . If you good use IDAPRO , please i need your contact . Thanks