Efficient Wi-Fi Phishing Attacks
tripwire.com
tripwire.com
What I somehow forgot to consider is that when my phone autoconnects to a network (or attempts to), the AP owner or anyone nearby might also be able to crack the WPA2 password. Good thing it uses PBKDF2 because I know some terrible ones.
I don't have time to read the full spec now unfortunately (I might later). Does anyone know what parameters are used for pbkdf2, specifically the number of iterations?
That's such a great idea! Could you give more details of how are you doing that? Which tools did you use?
tcpdump -i wlan0 -c 1 arp; aplay isd/media/0/*.mp3
This waits on the wifi interface for one ARP packet, which will surely come when a new device connects, and then plays some mp3 that's on my internal sdcard (hence the mountpoint "isd").It's also interesting how much information your personal wireless devices give out. If you use a program like airodump, you'll usually see at least one or two client devices with a long ESSID probe list from various restaurants, coffee shops etc.
Incidentally, this is how I came to realise how google use wifi to 'improve location accuracy' (although technically I think it's resolution time): their mapping vans would have catalogued router mac addresses/BSSIDs and bound them to locations. So google know that if someone's phone can 'see' a certain router, they must be within 100m or so of <location>. So a GPS fix can happen much quicker...
As for how practical it is to crack a WPA2 passphrase: by far the best protection is a totally random password (one that wasn't supplied by the manufacturer). Once you get up to a 10-12 character password (that's totally random), cracking it will take an infeasibly long time. If you're interested, you should check out some of the conversation of the hashcat forums. Some of the folks there use a number of very sophisticated ways of 'shrinking the search space', like statistical analysis of big password DB dumps. It turns out most people use passwords like 'Camero87' or 'Mystreetname1987'...
Oh, and disable WPS.
There are plenty of other hacks I'd be susceptible to before this one. (Please black hats don't target me)
Edit: Would it be feasible to instead just mimic the target AP with a WPA2 passphrase, listen to connection attempt by target user, and when the first attempt at login fails, set your AP to that passphrase and let him/her through? It's not completely transparent, but I feel typoing your password is more acceptable as "normal" than a lot of layers of emulated graphics that has to convince your target at every stage.