1 wireless hacking joffrey czarny, src telindus [email protected] state of the art wireless...

21
1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS [email protected] State of the Art Wireless Hacking Workshop

Upload: augustus-doyle

Post on 17-Jan-2016

221 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

1

Wireless Hacking

Joffrey Czarny, SRC TELiNDUS

[email protected]

State of the Art Wireless Hacking Workshop

Page 2: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

2

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Agenda

> Wireless tools> LIVE Demos > Questions & Answers

Page 3: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

3

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Wireless tools

> Wardriving tools

> Traffic analyzer

> WEP keys cracker

> WPA Pre-shared keys cracker

Page 4: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

4

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Wireless tools

> Wardriving tools:

> Active Detection : Netstumbler

> Passive Detection : Kismet; Dstumbler; Airsnort…

> Traffic analyzer: Airtraf

> WEP keys cracker: Airsnort; Aircrack; wepcrack Dwepcrack…

> WPA Pre-shared keys cracker : cowpatty, Aircrack

Page 5: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

5

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Wardriving tools

Page 6: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

6

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Wardriving tools

> Passive detection: Listening to all wireless traffic and extract

information from packets obtained.

> Active detection: Sending wireless probe requests and

analyze the network answers.

Page 7: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

7

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Network Stumbler

ACTIVE DETECTION

Page 8: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

8

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Kismet

PASSIVE DETECTION

Page 9: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

9

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Dstumbler BSD_airtools

PASSIVE DETECTION

Page 10: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

10

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Traffic analyzer

Page 11: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

11

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Traffic analyzer

> Airtraf is a Wireless traffic analyzer

> It is possible to:

> Detect Wireless networks

> Identify Access Points and clients

> Analyze TCP connections

> Generate statistics from protocol and users

> Bandwidth use

Page 12: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

12

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Airtraf

Page 13: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

13

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

WEP keys cracker

Page 14: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

14

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

WEP keys cracker> Statistic attacks on weak initialization vector value (IV )

> Airsnort

> Aircrack

> Wepcrack ( perl script )

> Dwepdump & Dwepcrack bsd_airtools

Page 15: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

15

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

WEP keys cracker> Bruteforce or dictionary attacks:

> weplab

> wepdecrypt

Page 16: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

16

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

WPA Pre-shared keys cracker

Page 17: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

17

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

WPA Pre-shared keys cracker

> Dictionary attacks

> Aircrack (release 2.2)

> Cowpatty

Page 18: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

18

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

LIVE Demos

Wardriving

WEP keys cracker

WPA Pre-shared keys cracker

FakeAP & Bluetooth attack (if enough time)

>

<<

>>

Page 19: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

19

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Questions & Answers

Page 20: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

20

Sta

te o

f th

e A

rt

Wir

ele

ss

Ha

ck

ing

14

/15

.10

.20

05

Additional Resources> NetStumbler > www.netstumbler.com

> Kismet > www.kismetwireless.net

> Bsd_airtools > www.dachb0den.com/projects/bsd-airtools.html

> Airtraf > airtraf.sourceforge.net

> Airsnort > airsnort.shmoo.com

> Aircrack > www.cr0.net:8040/code/network/aircrack/

> Weplab > weplab.sourceforge.net

> Wepdecrypt > wepdecrypt.sourceforge.net

> Cowpatty > new.remote-exploit.org/index.php/Codes_main

> Void11 > www.wlsec.net/void11

Page 21: 1 Wireless Hacking Joffrey Czarny, SRC TELiNDUS jczarny@src.telindus.com State of the Art Wireless Hacking Workshop

21

Thank you for your attention

Joffrey [email protected]