HomePlugAV PLC: Practical attacks and backdooring. Sébastien Dudek 19/10/2014
|
|
|
- Tabitha Gloria Daniels
- 10 years ago
- Views:
Transcription
1 HomePlugAV PLC: Practical attacks and backdooring Sébastien Dudek 19/10/2014
2 Who am I The KODAK attack Sébastien Dudek (@FlUxIuS) Has joined the ESEC R&D lab in 2012 after his internship (subject: Attacking the GSM Protocol Stack) Interests: radiocommunications (WiFi, RFID, GSM, PLC), network, web, and Linux security My story with PLCs: moved out to a shared apartment; angry with my room mate s WiFi (obstacles, perturbations) PLCs are cheap and could solve my problem; and I ve wanted to learn more about these little devices HomePlugAV PLC: Practical attacks and backdooring 2/45
3 Summary The KODAK attack Context The electrical signal The targets 1 Context The electrical signal The targets The KODAK attack 5 HomePlugAV PLC: Practical attacks and backdooring 3/45
4 The KODAK attack Context The electrical signal The targets PLC: Powerline Communication Programmable Logic Controller (known on SCADA and other Apocalypse things) Principle discovered by Edward Davy in 1838 Released in the early 2000s for home applications Evolves a lot in term of speed Other systems like Cenélec ( khz low voltage) are used : meter readings, intruder alarms, fire detection, gaz leak detection, and so on But how does it looks like at home? HomePlugAV PLC: Practical attacks and backdooring 4/45
5 PLC at home The KODAK attack Context The electrical signal The targets The following pictures shows a house equipped with PLC devices: Source: devolo Only one PLC is connected to internet and distributes it to other PLC a user shouldn t worry about it s network topology HomePlugAV PLC: Practical attacks and backdooring 5/45
6 PLC layers The KODAK attack Context The electrical signal The targets A PLC uses layer 1 and 2 of the OSI model IEEE 8023 Collision avoidance Use of CSMA/CA (Carrier Sence Multiple Access/Collision Avoidance) TDMA allocate a period of transmission time for each station 1 TDMA frame used for CSMA/CA frames that don t need QoS HomePlugAV PLC: Practical attacks and backdooring 6/45
7 The KODAK attack Context The electrical signal The targets The hardware: divided in two parts Vendor part HomePlugAV PLC: Practical attacks and backdooring PLC part 7/45
8 Communications The KODAK attack Context The electrical signal The targets Computer PLC Communicate through Ethernet on MAC layer Clear text (no ciphering) PLC PLC Communicate through powerline Data is encrypted (using AES CBC 128 bits on new PLCs) HomePlugAV PLC: Practical attacks and backdooring 8/45
9 The KODAK attack Context The electrical signal The targets Electrical properties: the power-line AC voltage AC voltage at 50 Hz signal do 50 cycles/s Could be represented by the formula: Ps = A 2 sin (2πft) A is 220V in Europe, or 100V in US/Japon, f the number of cycles/sec (50 Hz in Europe for example) HomePlugAV PLC: Practical attacks and backdooring 9/45
10 The KODAK attack Context The electrical signal The targets Electrical properties: adding our signal To transport our data on electrical power we use superposition: Superposition Suppose the carrier is 60 khz: Ca = 2 2 sin (2π60000t) Sum the power supply with the carrier: Ps + Ca = sin (2π50t) sin (2π60000t) But we need error detection, code mapping and multi-carrier modulation! HomePlugAV PLC: Practical attacks and backdooring 10/45
11 The KODAK attack Digital Signal Processing (DSP) Context The electrical signal The targets Steps in brief 1 data scrambling; 2 turbo encoding; 3 modulation of control and data frames; 4 form OFDM symbols by constellation; 5 windowing sourcce: G3-PLC HomePlugAV PLC: Practical attacks and backdooring 11/45
12 Electrical network The KODAK attack Context The electrical signal The targets In france, the distribution network is similar to the telephony network (RTC) source: PLC in Practice by Xavier Carcelle HomePlugAV PLC: Practical attacks and backdooring 12/45
13 The KODAK attack Context The electrical signal The targets Public and private network: myths and reality Myth Counters restrict PLC data spreading Reality No choc-coil we can communicate: from one appartment to another; from the building lobby to someone s flate (3rd and 4th floor) source: PLC in Practice by Xavier Carcelle Old choc-coils are mostly ineffective to block MF/HF frequencies HomePlugAV PLC: Practical attacks and backdooring 13/45
14 Our devices: The KODAK attack Context The electrical signal The targets Model Max Speed Chipset Extra features XAV Mb/s Qualcomm Atheros 7420 XWN Mb/s Qualcomm Atheros 7420 Smart Plug + WiFi N300 TL-PA Mb/s Qualcomm Atheros 7450 FreeplugV1 200 Mb/s INT6300 FreeplugV2 200 Mb/s INT6400 HomePlugAV PLC: Practical attacks and backdooring 14/45
15 The KODAK attack Context The electrical signal The targets PLCs embedded in power supply: example with Freeplugs An ethernet cable is joined with the power supply cable Normally, a default user will connect everything just to be sure that everything will work fine HomePlugAV PLC: Practical attacks and backdooring 15/45
16 Summary The KODAK attack Publications Tools 1 2 Publications Tools 3 4 The KODAK attack 5 HomePlugAV PLC: Practical attacks and backdooring 16/45
17 Publications The KODAK attack Publications Tools Power Line Communications in Practice by Xavier Carcelle a must read! HomePlug AV Security Mechanisms by Richard Newman, Larry Younge, Sherman Gavette, and Ross Anderson, published in 2007 MISC #37 HomePlug Security by Xavier Carcelle HomePlug Security by Axel Puppe and Jeroen Vanderauwera gives an otherview of key bruteforcing for old devices These publications give an overview of HomePlug security mechanisms But just one paper really focuses on possible and pratical attacks HomePlugAV PLC: Practical attacks and backdooring 17/45
18 Tools The KODAK attack Publications Tools plconfig manage PLCs over the network FAIFA by Xavier Carcelle (similar to plconfig) Vendors software (that we used at first) Wireshark has a dissector for HomePlugAV But no scapy Layer exists for HomePlugAV to mess with the HomePlugAV protocol HomePlugAV PLC: Practical attacks and backdooring 18/45
19 Summary The KODAK attack The ethernet interface Basic attacks The ethernet interface Basic attacks 4 The KODAK attack 5 HomePlugAV PLC: Practical attacks and backdooring 19/45
20 The KODAK attack The ethernet interface Basic attacks Vendors utility: example with Netgear 3 different ways to configure our PLC network default configuration (open network/default key); pairing button (easy way); or with a custom key (paranoid way our case) The software retrieves PLC information as follows: HomePlugAV PLC: Practical attacks and backdooring 20/45
21 The KODAK attack The ethernet interface Basic attacks Analysis with our scapy Layer: Device Type message To retrieve devices type, the software broadcasts a Get Device Type Request The software uses a Atheros broadcast address, but just to be sure it will work with all devices (INTELLON, Atheros, Qualcomm), we can broadcast it with ff:ff:ff:ff:ff:ff address HomePlugAV PLC: Practical attacks and backdooring 21/45
22 The KODAK attack The ethernet interface Basic attacks Device Type message: the confirmation If the type request exists, you get a confirmation message with a Status field (0x0 = Success) followed with data: HomePlugAV PLC: Practical attacks and backdooring 22/45
23 The KODAK attack The ethernet interface Basic attacks Network information To get information about the CCo (Central Coordinator) and stations connected, the software send a Network Information Request then we get a Network Information Confirmation packet HomePlugAV PLC: Practical attacks and backdooring 23/45
24 A typical PLC network The KODAK attack The ethernet interface Basic attacks The CCo manages contention-free streams time allocation, period for CSMA access + defines a AVLN node We can talk with other PLC of the same AVLN The software can change the NMK passphrase, sending it to the targeted PLC HomePlugAV PLC: Practical attacks and backdooring 24/45
25 The KODAK attack The ethernet interface Basic attacks Change the passphrase: SetEncryptionKeyRequest We change local device s NMK passphrase: Remotely In remote, we need to precise a DAK (Direct Access Key) to change the NMK (Network Membership Key) This could be interesting HomePlugAV PLC: Practical attacks and backdooring 25/45
26 The KODAK attack The ethernet interface Basic attacks NMK and DAK generation The NMK and DAK keys are generated the same way They use the Password-Based Derivation Function 1 (PBKDF1): DAK or NMK= PBKDF1(P, S, HF, c, dklen); P the passphrase; S the salt; HF the hash function; c the number of iterations; dklen the digest key length The main parameters are known: S = 0x08856DAF7CF58185 for DAK, S = 0x08856DAF7CF58186 for NMK; HF is SHA-256; c = 1000; dklen = 16 (bytes) HomePlugAV PLC: Practical attacks and backdooring 26/45
27 Attacks on NMK The KODAK attack The ethernet interface Basic attacks Interception 1 Listen for broatcasted packets, MITM the administrator or fake the MAC address 2 and sniff the Set Key Encryption Key packet LAN attack Bruteforce the NMK HomePlugAV PLC: Practical attacks and backdooring 27/45
28 Attacks on NMK Interception The KODAK attack The ethernet interface Basic attacks LAN attack a local device can be configured without any DAK But also: every device is connected to a switch/router are considered as local device in the network (don t need DAK) HomePlugAV PLC: Practical attacks and backdooring 27/45
29 Attacks on NMK The KODAK attack The ethernet interface Basic attacks Interception LAN attack Bruteforce the NMK 1 Bruteforce the NMK from a dictionnary; 2 Change local device NMK by the interated one; 3 Send discovery packet to see if we joined any network HomePlugAV PLC: Practical attacks and backdooring 27/45
30 Attacks on NMK Interception LAN attack The KODAK attack Bruteforce the NMK 1 Bruteforce the NMK from a dictionnary; The ethernet interface Basic attacks 2 Change local device NMK by the interated one; 3 Send discovery packet to see if we joined any network NMK bruteforce good Bruteforcing the NMK could be long and difficult depending on user s password policy HomePlugAV PLC: Practical attacks and backdooring 27/45
31 Summary The KODAK attack DAK passphrase pattern smart bruteforce The KODAK attack DAK passphrase pattern smart bruteforce 5 HomePlugAV PLC: Practical attacks and backdooring 28/45
32 Market researches The KODAK attack DAK passphrase pattern smart bruteforce First we need an overview of possible DAK passphrase generation In the markets At ebay, leboncoinfr HomePlugAV PLC: Practical attacks and backdooring 29/45
33 Market researches The KODAK attack DAK passphrase pattern smart bruteforce First we need an overview of possible DAK passphrase generation In the markets At ebay, leboncoinfr there people take pictures of every possible positions of the device these information could be helpful to study the pattern HomePlugAV PLC: Practical attacks and backdooring 29/45
34 Market researches The KODAK attack DAK passphrase pattern smart bruteforce First we need an overview of possible DAK passphrase generation In the markets At ebay, leboncoinfr there people take pictures of every possible positions of the device these information could be helpful to study the pattern Found pattern The DAK passphrase pattern can be represented with this simple regex: [A-Z]{4}-[A-Z]{4}-[A-Z]{4}-[A-Z]{4} HomePlugAV PLC: Practical attacks and backdooring 29/45
35 Market researches The KODAK attack DAK passphrase pattern smart bruteforce First we need an overview of possible DAK passphrase generation In the markets At ebay, leboncoinfr Found pattern The DAK passphrase pattern can be represented with this simple regex: [A-Z]{4}-[A-Z]{4}-[A-Z]{4}-[A-Z]{4} Pattern bruteforce Ṭhe bruteforce of this pattern is painful! Is there any other way? HomePlugAV PLC: Practical attacks and backdooring 29/45
36 The KODAK attack DAK passphrase pattern smart bruteforce TP-Link utility seems to recover DAK passphrases HomePlugAV PLC: Practical attacks and backdooring 30/45
37 The KODAK attack DAK passphrase pattern smart bruteforce A little packet analysis : ReadModuleDataConfirmation Analysing the packet, the only thing we see are the hash of DAK at offset 0x12 (hidden here), and NMK at offset 0x64 with value=0x50d3e4933f855b df815aa8db7(=homeplug) 1 >>> hexdump(pktmoduledata) 2 [] D F F 6D 65 Atheros Home C Plug AV Device D3 E4 93 3F 85 5B D F8 P?[p@xM AA 8D B F tpver_ F F _131217_002 The question? How this software can possibly recover this passphrase in a second? Is it derivated from somewhere? HomePlugAV PLC: Practical attacks and backdooring 31/45
38 Analysing vendor DLLs The KODAK attack DAK passphrase pattern smart bruteforce Looking on vendor software we can found a very interesting string %02X%02X%02X%02X%02X%02X (rdata section) in PLCOperApidll file Good starting point It s called by GetLocalDevInfo that retrieves informations sending a ReadModuleDataRequest for PIB, and derives the MAC address to form the DAK key HomePlugAV PLC: Practical attacks and backdooring 32/45
39 The KODAK attack DAK passphrase pattern smart bruteforce Implementation of the DAK generator Once we have implemented the algorithm, we test it: % python2 gendak py f0 : de : f1 : c0 : f f : ee QFLX EFRE QTGC SZB % python2 PBKDF1 py QFLX EFRE QTGC SZB PBKDF1 print : 13a7af2789ddcc19d97075d8efeaf506 Then we use the key-derivation function PBKDF1 to output the 16 bytes and send it to the device remotely (we can broadcast it): 1 ###[ HomePlugAV ]### 2 version = 10 3 HPtype = 'Set Encryption Key Request' 4 OUI = 0xb052 5 ###[ SetEncryptionKeyRequest ]### 6 EKS = 0x1 7 NMK = '' 8 PayloadEncKeySelect= 0x0 9 DestinationMAC= ff:ff:ff:ff:ff:ff 0 DAK = "\x13\xa7\xaf'\x89\xdd\xcc\x19\xd9pu\xd8\xef\xea\xf5\x06" If the device confirms it we win! HomePlugAV PLC: Practical attacks and backdooring 33/45
40 The KODAK attack How powerful is KODAK? DAK passphrase pattern smart bruteforce Here is a summary table of bruteforcing techniques difficulties: Bruteforce technique Possibilities DAK passphrase KODAK classic KODAK with vendor bytes Devices with a Qualcomm chip are affected We have also found a PLC toolkit in github a, and we can be sure that most of the device could be attacked this way as long as vendors use Qualcomm Atheros DAK passphrase generator a HomePlugAV PLC: Practical attacks and backdooring 34/45
41 Our results The KODAK attack DAK passphrase pattern smart bruteforce Here is a summary table of possible attacks on different PLCs: PLC Providers Ethernet NMK bruteforce KODAK Attack Qualcomm Atheros PLC YES YES YES INTELLON YES YES MAYBE ISP PLC YES YES NOT ALL Devices Freeplugs not affected Freeplugs don t use Qualcomm DAK generator This is reasuring because Freefr serves more than users in France a, and provides PLCs with their router and STBs for years a francois04freefr HomePlugAV PLC: Practical attacks and backdooring 35/45
42 Summary The KODAK attack Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! The KODAK attack 5 Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! HomePlugAV PLC: Practical attacks and backdooring 36/45
43 The KODAK attack Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! The hardware: remember? Vendor part HomePlugAV PLC: Practical attacks and backdooring PLC part 37/45
44 The KODAK attack Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! The strange ports? The two previous ports MII (Media Independent Interface), or GPSI (General Purpose Serial Interface) They connect the PLC MAC/PHY transceiver to IEEE8023 Ethernet MAC controllers UART/serial ports could be present on old models, to respond with AT commands HomePlugAV PLC: Practical attacks and backdooring 38/45
45 The KODAK attack Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! JTAG/serial/UART/ accesses forget about it! With the vendor part, we have read/write accesses to the PIB and IMG parts on the NVM! 3 parameters for the Read Data Module Request 1 part of the memory : MAC Soft-Loader Image (0x0), MAC Software Image (0x01), PIB (0x02); 2 offset; 3 and the length 1 ###[ HomePlugAV ]### 2 version = 10 3 HPtype = 'Read Module Data Request' 4 OUI = 0xb052 5 ###[ ReadModuleData ]### 6 ModuleID = PIB 7 reserved = 0x0 8 Length = Offset = 5120 HomePlugAV PLC: Practical attacks and backdooring 39/45
46 The KODAK attack Writing into the memory example Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! 1 ###[ HomePlugAV ]### 2 version = 10 3 HPtype = 'Write Module Data Request' 4 OUI = 0xb052 5 ###[ WriteModuleData ]### 6 ModuleID = PIB 7 reserved = 0x0 8 DataLen = Offset = 0 0 checksum = ModuleData= '\x05\x07\x00\x008@\x00\x00\xb1\x15)# 2 [] Tip For the PIB region, you need to overwrite it s PIB checksum32 (at offset 0x8) and send a WriteModuleDataToNVMRequest to apply the configuration HomePlugAV PLC: Practical attacks and backdooring 40/45
47 The KODAK attack Other cool functionnalities! Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! The Sniff command that gives details about frame control and beacon Work in progress Other commands could be interesting to discover like VS_WRITE_AND_EXECUTE_APPLET or VS_MICROCONTROLLER_DIAG We will dig a little more to know if we can execute any other applet or try to communicate with the microcontroller HomePlugAV PLC: Practical attacks and backdooring 41/45
48 The KODAK attack Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! Gathering CCos MAC address Enabling the Sniff command we can recover MAC addresses of CCos close to us 2 : 1 ###[ SnifferIndicate ]### 2 SnifferType= Regular 3 Direction = Tx 4 SystemTime= BeaconTime= ShortNetworkID= 0x80 7 [] 8 ###[ Raw ]### 9 load = \x01\xfd40[] 0 [] 1 >>> hexdump(pktload) XX XX XX XX XX XX XX XX XX XX XX XX XX XX E8 94 XXXXXXXXXXXXXX F6 XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XXXXXXXXXXXXXXX 4 [] One CCo MAC address is present at address 0xe (begining with bytes: E8 94 F6) 2 Independently discovered by Ben Tasker: HomePlugAV PLC: Practical attacks and backdooring 42/45
49 The KODAK attack Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! Demos Discovery in and out of a AVLN node Monitoring and targeting CCos Remote CCo configuration to infiltrate a LAN Reading target s memory HomePlugAV PLC: Practical attacks and backdooring 43/45
50 The KODAK attack Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! Archievement We have made a scapy Layer that helps us to mess with HomePlugAV protocol (to be completed) and parse the PIB This layer can be used to fuzz the client side (vendor s utility) HomePlugAV sold in the market are vulnerable to KODAK attack, but not the most used Freeplugs (for the moment) If we know the DAK passphrase or we have any access to the device by it s ethernet interface arbitrary read/write access Work in progress Firmware disassembling add other cool functions We could mess with the authentication messages Learn more about applets that PLC executes HomePlugAV PLC: Practical attacks and backdooring 44/45
51 The KODAK attack Hardware stuff Arbitrary read/write accesses Demos Conclusion & work in progress Thank you! Thank you! ;) Any questions? HomePlugAV PLC: Practical attacks and backdooring 45/45
How To Hack A Powerline Communications 101 Class 101 Class 1 (Powerline) (Powerlines) (Plc) (Pca) (Wired) (Wire) (Wifi) (Lan) (Net) (Network) (H
FAIFA A first OpenSource PLC tool Xavier Carcelle - xavier.carcelle#openpattern.org Florian Fainelli florian.fainelli#openpattern.org Nicolas Thill nico#openwrt.org FAIFA in Lao Langage ³³É¾ = FAIFA ³
WEEE Directive & Product Disposal
User s Manual WEEE Directive & Product Disposal At the end of its serviceable life, this product should not be treated as household or general waste. It should be handed over to the applicable collection
200M PLC User Manual
Contents Contents 1 Introduction... 1 1.1 System Requirements... 1 1.2 Package Contents... 2 2 Safety Notice... 3 3 Getting to Know the Adapter... 5 3.1 Ethernet Interface... 5 3.2 Buttons on the Adapter...
AV1200 TL-PA8030P KIT. 3-Port Gigabit Passthrough Powerline Starter Kit. Highlights
AV1200 3-Port Gigabit Passthrough Powerline Starter Kit Highlights AV1200 HomePlug AV2 standard compliant, high-speed data transfer rates of up to 1200Mbps, supports all your online needs MIMO Technology
NetPlug200 Nano. www.lea-networks.com
www.lea-networks.com HomePlugAV Ethernet Adapter is the smallest ErP and HomePlugAV compliant Ethernet wallmount adapter which provides communication over any electrical wiring, at the maximum speed of
HomePlugAV PLC: practical attacks and backdooring
HomePlugAV PLC: practical attacks and backdooring Sébastien Dudek - [email protected] August 2015 - Additional information after the presentation made at NoSuchCon 2014 Abstract Domestic Powerline
PLI-3310 HomePlug Pro Power Bridge
PLI-3310 HomePlug Pro Power Bridge User Manual Ver. 1.0.0 Safety FCC This equipment has been tested and found to comply with Part 15 Class B of the FCC Rules. Operation is subject to the following two
PLA4231. User s Guide. Quick Start Guide. 500 Mbps Powerline Wireless N Extender. Default Login Details. Version 1.00 Edition 1, 12/2012
PLA4231 500 Mbps Powerline Wireless N Extender Version 1.00 Edition 1, 12/2012 Quick Start Guide User s Guide Default Login Details LAN IP Address http://192.168.1.2 Password 1234 www.zyxel.com Copyright
Powerline Network Utility NA200 Help File
Powerline Network Utility NA200 Help File TABLE OF CONTENTS TABLE OF CONTENTS...1 Powerline Network Utility Overview...2 What situations can Powerline Network Utility help me solve?...2 Case 1: Secure
TL-PA411 AV500 Powerline Adapter
REV1.0.0 1910011029 COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-LINK TECHNOLOGIES CO., LTD. Other brands and product names are trademarks
Chapter 3 Safeguarding Your Network
Chapter 3 Safeguarding Your Network The RangeMax NEXT Wireless Router WNR834B provides highly effective security features which are covered in detail in this chapter. This chapter includes: Choosing Appropriate
TL-PA551 AV500+ Powerline Adapter with AC Pass Through
Rev: 1.0.1 1910010649 COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-LINK TECHNOLOGIES CO., LTD. Other brands and product names are trademarks
PLA Series. User s Guide. Quick Start Guide. Powerline Ethernet Adapters. PLA4101, PLA4111, PLA4201, PLA4201 v2, PLA5205, PLA5215, PLA5206, PLA5405
PLA Series Powerline Ethernet Adapters PLA4101, PLA4111, PLA4201, PLA4201 v2, PLA5205, PLA5215, PLA5206, PLA5405 Utility Version 7.0.1 Edition 1, 05/2014 Default Network Name: HomePlugAV Quick Start Guide
Process Control and Automation using Modbus Protocol
Process Control and Automation using Modbus Protocol Modbus is the fundamental network protocol used in most industrial applications today. It is universal, open and an easy to use protocol. Modbus has
CCNA R&S: Introduction to Networks. Chapter 5: Ethernet
CCNA R&S: Introduction to Networks Chapter 5: Ethernet 5.0.1.1 Introduction The OSI physical layer provides the means to transport the bits that make up a data link layer frame across the network media.
Mobile Security. Practical attacks using cheap equipment. Business France. Presented the 07/06/2016. For. By Sébastien Dudek
Mobile Security Practical attacks using cheap equipment Presented the 07/06/2016 Business France By Sébastien Dudek For Content Security measures Recent publications in the hacking community Practical
Access Point Configuration
Access Point Configuration Developed by IT +46 Based on the original work of: Onno Purbo and Sebastian Buettrich Goals Provide a general methodology to installation and configuration of access points Give
PLA4201 v2. User s Guide. Quick Start Guide. 500 Mbps Mini Powerline Ethernet Adapter. Version 1.00 Edition 1, 01/2013
PLA4201 v2 500 Mbps Mini Powerline Ethernet Adapter Version 1.00 Edition 1, 01/2013 Quick Start Guide User s Guide www.zyxel.com Copyright 2013 ZyXEL Communications Corporation IMPORTANT! READ CAREFULLY
TL-PA251 AV200+ Multi-Streaming Powerline Adapter With AC Pass Through
TL-PA251 AV200+ Multi-Streaming Powerline Adapter With AC Pass Through Rev: 1.0.1 1910010542 COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-LINK
WISE-4000 Series. WISE IoT Wireless I/O Modules
WISE-4000 Series WISE IoT Wireless I/O Modules Bring Everything into World of the IoT WISE IoT Ethernet I/O Architecture Public Cloud App Big Data New WISE DNA Data Center Smart Configure File-based Cloud
TECHNICAL NOTE. GoFree WIFI-1 web interface settings. Revision Comment Author Date 0.0a First release James Zhang 10/09/2012
TECHNICAL NOTE GoFree WIFI-1 web interface settings Revision Comment Author Date 0.0a First release James Zhang 10/09/2012 1/14 Web interface settings under admin mode Figure 1: web interface admin log
Powerline 1200 User Manual
User Manual Models PL1200 PLP1200 January 2016 202-11566-01 350 E. Plumeria Drive San Jose, CA 95134 USA Support Thank you for purchasing this NETGEAR product.you can visit www.netgear.com/support to register
Supporting ZDOs with the XBee API
Supporting ZDOs with the XBee API The ZigBee Device Profile is a management and discovery service layer supported on all ZigBee devices. Like all other profiles, the ZigBee Device Profile defines a set
Data Link Protocols. TCP/IP Suite and OSI Reference Model
Data Link Protocols Relates to Lab. This module covers data link layer issues, such as local area networks (LANs) and point-to-point links, Ethernet, and the Point-to-Point Protocol (PPP). 1 TCP/IP Suite
Overview of broadband powerline communications
January 23, 2015 Overview of broadband powerline communications Jean-Philippe Faure, CEO Progilon Senior consultant at Panasonic System Networks Director Technology Standards at HD-PLC Alliance Biography
Powerline 500 WiFi Access Point XWN5001 Installation Guide
Powerline 500 WiFi Access Point XWN5001 Installation Guide Technical Support Thank you for selecting NETGEAR products. After installing your device, locate the serial number on the label of your product
Powerline 500 WiFi Access Point (XWNB5201) Installation Guide
Powerline 500 WiFi Access Point (XWNB5201) Installation Guide Support Thank you for selecting NETGEAR products. After installing your device, locate the serial number on the label of your product and use
500Mbps Powerline Kit with Dual Band WiFi
500Mbps Powerline Kit with Dual Band WiFi NP508 USER GUIDE Copyright Copyright 2014 NetComm Wireless Limited. All rights reserved. The information contained herein is proprietary to NetComm Wireless. No
Chapter 2 Wireless Settings and Security
Chapter 2 Wireless Settings and Security This chapter describes how to set up the wireless features of your WGT624 v4 wireless router. In planning your wireless network, select a location for the wireless
Demystifying Wireless for Real-World Measurement Applications
Proceedings of the IMAC-XXVIII February 1 4, 2010, Jacksonville, Florida USA 2010 Society for Experimental Mechanics Inc. Demystifying Wireless for Real-World Measurement Applications Kurt Veggeberg, Business,
Chapter 6 CDMA/802.11i
Chapter 6 CDMA/802.11i IC322 Fall 2014 Computer Networking: A Top Down Approach 6 th edition Jim Kurose, Keith Ross Addison-Wesley March 2012 Some material copyright 1996-2012 J.F Kurose and K.W. Ross,
5GHz 300Mbps 13dBi Outdoor CPE
5GHz Mbps 13dBi Outdoor CPE Features Built-in 13dBi 2x2 dual-polarized directional MIMO antenna Adjustable transmission power from to dbm/5mw System-level optimizations for more than 15km+ long range wireless
Introduction To Computer Networking
Introduction To Computer Networking Alex S. 1 Introduction 1.1 Serial Lines Serial lines are generally the most basic and most common communication medium you can have between computers and/or equipment.
Table of Contents. Hardware Installation...7 Push Button Security... 8. Using the Setup Wizard...10. Configuration...11 Main... 12 Security...
Table of Contents Table of Contents Product Overview...3 Package Contents...3 System Requirements... 3 Introduction...4 Features... 4 Hardware Overview...5 LEDs... 5 Connection... 6 Hardware Installation...7
Wireless Networks. Welcome to Wireless
Wireless Networks 11/1/2010 Wireless Networks 1 Welcome to Wireless Radio waves No need to be physically plugged into the network Remote access Coverage Personal Area Network (PAN) Local Area Network (LAN)
Bit Chat: A Peer-to-Peer Instant Messenger
Bit Chat: A Peer-to-Peer Instant Messenger Shreyas Zare [email protected] https://technitium.com December 20, 2015 Abstract. Bit Chat is a peer-to-peer instant messaging concept, allowing one-to-one
CSE331: Introduction to Networks and Security. Lecture 6 Fall 2006
CSE331: Introduction to Networks and Security Lecture 6 Fall 2006 Open Systems Interconnection (OSI) End Host Application Reference model not actual implementation. Transmits messages (e.g. FTP or HTTP)
Chapter 6 Using Network Monitoring Tools
Chapter 6 Using Network Monitoring Tools This chapter describes how to use the maintenance features of your Wireless-G Router Model WGR614v9. You can access these features by selecting the items under
Wireless LAN Security: Securing Your Access Point
IJCSNS International Journal of Computer Science and Network Security, VOL.6 No.5B, May 2006 173 Wireless LAN Security: Securing Your Access Point Sia Sie Tung, Nurul Nadia Ahmad, Tan Kim Geok Faculty
WBS210/WBS510 Datasheet
2.4GHz/5GHz 300Mbps Outdoor Wireless / Datasheet Highlights Broad operating frequency channels ensure less wireless interference Wireless N speed up to 300Mbps Selectable bandwidth of 5/10/20/40MHz Adjustable
JOB READY ASSESSMENT BLUEPRINT COMPUTER NETWORKING FUNDAMENTALS - PILOT. Test Code: 4514 Version: 01
JOB READY ASSESSMENT BLUEPRINT COMPUTER NETWORKING FUNDAMENTALS - PILOT Test Code: 4514 Version: 01 Specific Competencies and Skills Tested in this Assessment: PC Principles Identify physical and equipment
WiFi Security Assessments
WiFi Security Assessments Robert Dooling Dooling Information Security Defenders (DISD) December, 2009 This work is licensed under a Creative Commons Attribution 3.0 Unported License. Table of Contents
500M Powerline Pass-Through Ethernet Bridge
500M Powerline Pass-Through Ethernet Bridge Key Features IEEE Compliant HomePlug AV & LA Designed for high-definition multimedia streaming Data rate up to 500Mbps and distance up to 300 Meters over existing
Table of Contents. Cisco Wi Fi Protected Access 2 (WPA 2) Configuration Example
Table of Contents Wi Fi Protected Access 2 (WPA 2) Configuration Example...1 Document ID: 67134...1 Introduction...1 Prerequisites...1 Requirements...1 Components Used...2 Conventions...2 Background Information...2
Security+ Guide to Network Security Fundamentals, Third Edition. Chapter 6. Wireless Network Security
Security+ Guide to Network Security Fundamentals, Third Edition Chapter 6 Wireless Network Security Objectives Overview of IEEE 802.11 wireless security Define vulnerabilities of Open System Authentication,
Industrial Networks & Databases
Industrial Networks & Databases LONWORKS KNX 1 HVAC and BEMS HVAC - Heating, Ventilation & Air Conditioning BEMS - Building & Energy Management Systems 2 3 4 LONWORKS (Local Operating Networks) Open solution
TL-PA201 200Mbps Powerline Ethernet Adapter
TL-PA201 200Mbps Powerline Ethernet Adapter Rev: 1.0.1 1910010156 COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-LINK TECHNOLOGIES CO., LTD.
SPL 2-00/-01 OPERATION INSTRUCTIONS
SPL 2-00/-01 OPERATION INSTRUCTIONS Powerline Ethernet Adapter 500 Mbps EN Read and keep Operation Instructions SPL 2-00/-01 Safety Notes Do NOT use this product near water, for example, in a wet basement
Securing your Linksys WRT54G
Securing your Linksys WRT54G Abstract Current implementations of the 802.11b and 802.11g wireless LAN standards have several potential pitfalls for security. However, built in security mechanisms in these
Industrial Communication. Securing Industrial Wireless
Industrial Communication Whitepaper Securing Industrial Wireless Contents Introduction... 3 Wireless Applications... 4 Potential Threats... 5 Denial of Service... 5 Eavesdropping... 5 Rogue Access Point...
Chapter 6 Using Network Monitoring Tools
Chapter 6 Using Network Monitoring Tools This chapter describes how to use the maintenance features of your RangeMax Wireless-N Gigabit Router WNR3500. You can access these features by selecting the items
TL-PA6010 AV600 Gigabit Powerline Adapter
REV1.0.0 1910010845 COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-LINK TECHNOLOGIES CO., LTD. Other brands and product names are trademarks
dlan Green PHY Module
dlan Green PHY Module Smart integration of Powerline communication Smarte Integration von Powerline-Kommunikation Technology from the global market leader With 23 million adapters shipped, devolo is leading
EAP9550 11N Wall Mount Access Point / WDS AP / Universal Repeater
EAP9550 is a powerful and multi-functioned 11n Access Point and it can act three modes AP/WDS/Universal Repeater. Smoke detector appearance will minimize visibility. So this model can work properly at
Exercise 1: Set up the Environment
RFID Lab Gildas Avoine, 2014 Contact: [email protected] Objective: Learn how much it is easy to read contactless tags, possibly simulate/clone. Requirement: Hardware: Reader SCL3711 or ACR122, Reader
Sync Security and Privacy Brief
Introduction Security and privacy are two of the leading issues for users when transferring important files. Keeping data on-premises makes business and IT leaders feel more secure, but comes with technical
LAN Switching. 15-441 Computer Networking. Switched Network Advantages. Hubs (more) Hubs. Bridges/Switches, 802.11, PPP. Interconnecting LANs
LAN Switching 15-441 Computer Networking Bridges/Switches, 802.11, PPP Extend reach of a single shared medium Connect two or more segments by copying data frames between them Switches only copy data when
Powerline Network. RPL-85 User Manual RPL-85. Powerline Ethernet Bridge V1.0.0. 2009. All rights reserved. Page 1
RPL-85 User Manual RPL-85 Powerline Ethernet Bridge V1.0.0 2009. All rights reserved. Page 1 PREFACE This document describes installation of the RPL-85 Ethernet Bridge Network products. Please read this
Computer Network. Interconnected collection of autonomous computers that are able to exchange information
Introduction Computer Network. Interconnected collection of autonomous computers that are able to exchange information No master/slave relationship between the computers in the network Data Communications.
N600 WiFi USB Adapter
Model WNDA3100v3 User Manual December 2014 202-11470-01 350 East Plumeria Drive San Jose, CA 95134 USA Support Thank you for selecting NETGEAR products. After installing your device, locate the serial
ECB1220R. Wireless SOHO Router/Client Bridge
Wireless SOHO Router/Client Bridge 2.4GH 802.11 b/g 54Mbps PRODUCT DESCRIPTION ECB-1220R is a 2.4GHz 802.11b/g broadband Wi-Fi Router with advanced AP/Client Bridge/Repeater functions. So you could implement
Ethernet Adapter Owner's Manual
Corinex Intelligent PowerNet Corinex Intelligent PowerNet Ethernet Adapter Owner's Manual This Owner s Manual, as well as the software described in it, is furnished under license and may be used or copied
INTELLIGENT BUILDINGS BUS SYSTEMS, MyHOME. Ján Cigánek, Martin Janáček, Stanislav Števo
INTELLIGENT BUILDINGS BUS SYSTEMS, MyHOME Ján Cigánek, Martin Janáček, Stanislav Števo Slovak University of Technology Ilkovičova 3, 812 19 Bratislava, Slovak Republic Tel.: +421 2 60291111 Fax: +421 2
Introduction to Simple Network Management Protocol (SNMP)
Introduction to Simple Network Management Protocol (SNMP) Simple Network Management Protocol (SNMP) is an application layer protocol for collecting information about devices on the network. It is part
Easy Smart Configuration Utility
Easy Smart Configuration Utility REV1.1.0 1910010977 CONTENTS Chapter 1 About this Guide...1 1.1 Intended Readers... 1 1.2 Conventions... 1 1.3 Overview of This Guide... 1 Chapter 2 Getting Started...4
Linksys E2500 Wireless-N Router Configuration Guide
Linksys E2500 Wireless-N Router Configuration Guide Revision 1.0 Copyright 2012 Maretron, LLP All Rights Reserved Maretron, LLP 9014 N. 23 rd Ave #10 Phoenix, AZ 85021-7850 http://www.maretron.com Maretron
Network FAX Driver. Operation Guide
Network FAX Driver Operation Guide About this Operation Guide This Operation Guide explains the settings for the Network FAX driver as well as the procedures that are required in order to use the Network
Microchip Technology. February 2008 Valerio Moretto Slide 1
Microchip Technology February 2008 Valerio Moretto Slide 1 Connectivity Solutions Wired Wireless February 2008 Valerio Moretto Slide 2 Microchip Solutions More complex software Operating Systems >40 MIPS
TL-PA8030P AV1200 3-Port Gigabit Passthrough Powerline Adapter
REV1.0.0 1910011105 COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-LINK TECHNOLOGIES CO., LTD. Other brands and product names are trademarks
TL-PA2010 AV200 Nano Powerline Adapter
Rev: 1.0.1 1910010708 COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-LINK TECHNOLOGIES CO., LTD. Other brands and product names are trademarks
Lab Module 3 Network Protocol Analysis with Wireshark
Pacific Northwest National Laboratory Lab Module 3 Network Protocol Analysis with Wireshark NATO ASI on Energy Infrastructure Security October 2015 PNNL-##### Lab Module 3 Network Protocol Analysis with
If security were all that mattered, computers would never be turned on, let alone hooked into a network with literally millions of potential intruders. Dan Farmer, System Administrators Guide to Cracking
Lecture 8. IP Fundamentals
Lecture 8. Internet Network Layer: IP Fundamentals Outline Layer 3 functionalities Internet Protocol (IP) characteristics IP packet (first look) IP addresses Routing tables: how to use ARP Layer 3 functionalities
ENHWI-N3. 802.11n Wireless Router
ENHWI-N3 802.11n Wireless Router Product Description Encore s ENHWI-N3 802.11n Wireless Router s 1T1R Wireless single chip can deliver up to 3x faster speed than of 802.11g devices. ENHWI-N3 supports home
9 Simple steps to secure your Wi-Fi Network.
9 Simple steps to secure your Wi-Fi Network. Step 1: Change the Default Password of Modem / Router After opening modem page click on management - access control password. Select username, confirm old password
Powerline AV 200 Nano Adapter XAV2101
Powerline AV 200 Nano Adapter XAV2101 User Manual 350 East Plumeria Drive San Jose, CA 95134 USA March 2011 202-10816-01 v1.0 2011 NETGEAR, Inc. All rights reserved. No part of this publication may be
Powerline 500 WiFi Access Point (XWN5001) Installation Guide
Powerline 500 WiFi Access Point (XWN5001) Installation Guide Support Thank you for selecting NETGEAR products. After installing your device, locate the serial number on the label of your product and use
11/22/2013 1. komwut@siit
11/22/2013 1 Week3-4 Point-to-Point, LAN, WAN Review 11/22/2013 2 What will you learn? Representatives for Point-to-Point Network LAN Wired Ethernet Wireless Ethernet WAN ATM (Asynchronous Transfer Mode)
TL-PA201 200Mbps Powerline Ethernet Adapter
Rev: 2.0.1 1910010323 COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-LINK TECHNOLOGIES CO., LTD. Other brands and product names are trademarks
How To Check If Your Router Is Working Properly
Chapter 6 Using Network Monitoring Tools This chapter describes how to use the maintenance features of your RangeMax Dual Band Wireless-N Router WNDR3300. You can access these features by selecting the
Synapse s SNAP Network Operating System
Synapse s SNAP Network Operating System by David Ewing, Chief Technology Officer, Synapse Wireless Today we are surrounded by tiny embedded machines electro-mechanical systems that monitor the environment
How To Use Allnet Configuration Utility On A Pc Or Mac Or Ipad (Powerline) With A Powerline (Powerbook) With Powerline 2.5 (Powerbee) With An Ipad Or Powerplug (Powerplug) With
Powerline Network Instant Networks for Internet Access and More! Solution for SOHO, SMALL OFFICE AND HOME OFFICE Encryption Management Utility User Guide for ETHERNET BRIDGE ALL1685 Index 1. Introduction...
A6210 WiFi USB Adapter 802.11ac USB 3.0 Dual Band User Manual
802.11ac USB 3.0 Dual Band User Manual August 2014 202-11373-01 350 East Plumeria Drive San Jose, CA 95134 USA Support Thank you for selecting NETGEAR products. After installing your device, locate the
EKT 332/4 COMPUTER NETWORK
UNIVERSITI MALAYSIA PERLIS SCHOOL OF COMPUTER & COMMUNICATIONS ENGINEERING EKT 332/4 COMPUTER NETWORK LABORATORY MODULE LAB 2 NETWORK PROTOCOL ANALYZER (SNIFFING AND IDENTIFY PROTOCOL USED IN LIVE NETWORK)
Configuring Routers and Their Settings
Configuring Routers and Their Settings When installing a router on your home network the routers settings are usually defaulted to automatically protect your home, and simplify setup. This is done because
Hacking. Aims. Naming, Acronyms, etc. Sources
Free Technology Workshop Hacking Hands on with wireless LAN routers, packet capture and wireless security Organised by Steven Gordon Bangkadi 3 rd floor IT Lab 10:30-13:30 Friday 18 July 2014 http://ict.siit.tu.ac.th/moodle/.-----.-----.-----..----.
VIDEO Intypedia012en LESSON 12: WI FI NETWORKS SECURITY. AUTHOR: Raúl Siles. Founder and Security Analyst at Taddong
VIDEO Intypedia012en LESSON 12: WI FI NETWORKS SECURITY AUTHOR: Raúl Siles Founder and Security Analyst at Taddong Hello and welcome to Intypedia. Today we will talk about the exciting world of security
Wireless Pre-Shared Key Cracking (WPA, WPA2)
Wireless Pre-Shared Key Cracking (WPA, WPA2) TABLE OF CONTENTS Introduction... 2 Mechanics Of PSKs And How They Work Demystified... 2 How PSKs Can Be Cracked!... 5 WPA2 PSK Cracking Demonstration.... 6
Chapter 7 Low-Speed Wireless Local Area Networks
Wireless# Guide to Wireless Communications 7-1 Chapter 7 Low-Speed Wireless Local Area Networks At a Glance Instructor s Manual Table of Contents Overview Objectives s Quick Quizzes Class Discussion Topics
PT500 500Mbps Powerline Adapter. User Guide
PT500 500Mbps Powerline Adapter User Guide PT500 500Mbps Powerline Adapter V100R001 User Guide 202593_04 Huawei Technologies Co., Ltd. provides customers with comprehensive technical support and service.
FLYPORT Wi-Fi 802.11G
FLYPORT Wi-Fi 802.11G System on module 802.11g WIFI - Infrastructure mode - softap mode - Ad hoc mode Microchip PIC 24F 16 bit processor Microchip MRF24WG0MA/MB - Native WiFi 802.11g transceiver - PCB
Chapter 2 - The TCP/IP and OSI Networking Models
Chapter 2 - The TCP/IP and OSI Networking Models TCP/IP : Transmission Control Protocol/Internet Protocol OSI : Open System Interconnection RFC Request for Comments TCP/IP Architecture Layers Application
Software Version 7.1.2.7
Technical Information Software Version 7.1.2.7 DDF4220HDV Picodome MDF4220HD DDF4320HD-DN DDF4520HDV-DN English Version 1.0 / 2014-03-20 1 Abstract This document contains information on new features and
A DIY Hardware Packet Sniffer
A DIY Hardware Packet Sniffer Affordable Penetration Testing for the Individual Veronica Swanson: University of California, Irvine CyberSecurity for the Next Generation North American Round, New York 15
User s Manual. Powerline 200M Ethernet Bridge
User s Manual Powerline 200M Ethernet Bridge Index 1. Powerline Networking Installation...2 1.1 Simple step to install Powerline Networking...2 1.2 Application Block Diagram...3 1.3 Benefits...5 1.4 Features...5
How To Configure Voice Vlan On An Ip Phone
1 VLAN (Virtual Local Area Network) is used to logically divide a physical network into several broadcast domains. VLAN membership can be configured through software instead of physically relocating devices
Cisco Aironet Wireless Bridges FAQ
Cisco Aironet Wireless Bridges FAQ Document ID: 16041 Contents Introduction What is the Cisco Aironet Wireless Bridge? What are the different platforms of wireless bridges that Cisco offers? Where can
HP-1000 Powerline Ethernet Adapter
HP-1000 Powerline Ethernet Adapter User s manual BEFORE INSTALLATION Plan ahead the installation of your powerline network. Note: You will need at least two powerline adapters to create a powerline network.
Waspmote Encryption Libraries. Programming guide
Waspmote Encryption Libraries Programming guide Index Document version: v4.3-01/2015 Libelium Comunicaciones Distribuidas S.L. INDEX 1. General Concepts... 4 2. Integrity... 7 2.1. Waspmote Libraries...7
ECB3500 2.4GHz Super G 108Mbps Access Point/Client Bridge/Repeater/WDS AP/
Wireless Long Range Multi-function 7+1 AP ECB3500 2.4GHz Super G 108Mbps Access Point/Client Bridge/Repeater/WDS AP/ EIRP up to 2000mW WDS Bridge/Client Router/AP Router ECB3500 is a powerful, enhanced,
