Beginner's Guide to Wi-fi Interception
troyhunt.com
troyhunt.com
GUYS!!! It's titled "BEGINNER'S Guide to WiFi Interception" So OFCOURSE it's basic. It isn't meant for security veterans like you guys. The author is apparently a secuirty guy too, but he just WANTED to explain it in as simple as possible way
Whoa, what? This is really how it works? This implies that anywhere you go with your laptop, someone can sit there and get a list of every wifi you've ever connected to. :(
I don't understand why this disclosure is necessary, since you can list all nearby wifis, even ones you've never connected to. Shouldn't it be possible for a wifi client to get a list of all nearby wifis, then only attempt to connect to the one it knows, without telling the others anything about what it's looking for?
Didn't finish reading the article, because it's going step by step and I don't plan to actually set up a Pineapple, but this surprising bit was the main takeaway for me.
Want to know something scarier? Snoopy - http://www.youtube.com/watch?v=Vsn7_4qUdwk&feature=youtu.be .
Well worth the watch.
It looks like the iPhone is (or was, as of 2012) uniquely bad because it leaks recently used MAC addresses, while it's common for devices to leak names but not MAC addresses:
http://en.wikipedia.org/wiki/Service_set_(802.11_network)#Ba...
Does anything like that exist? Maybe for Android?
P.S. The vague "that article rife with errors" and "it's pretty obvious those screen caps have been photoshopped to try and prove and incorrect point" comments are pitiful and pointless without some explanations. But ooh, I'm sure you are all important and busy with out the time to explain yourself.
And you don't have to know ten year's worth of knowledge to get useful (but probably illegal) stuff out of it.
At least that's what I'm getting out of this article.
I can very easily see a house being raided and this being used against the owner as evidence, though. There are very few legitimate uses for something like this, aren't there?
I can see a house being raided because of other computer crime evidence, and the fact that the suspect owned a Pineapple would be used against him in court.
I've been looking into acquire one for months but I can't think of any use case apart that wouldn't be immoral.
I wonder if I could sit in a coffee shop and provide a faster connection than standard? I'd be like a smaller, slightly more malicious google in that I provide a service in exchange for sweet sweet packets!
Also, what's with all the posts from troy? I've been following him for awhile and it's curious to see these just popping up now.
Don't do any mitm or forwarding, but just sit with the CEO or CIO with one in his office for a few minutes, and show him how his iPhone is suddenly connected to his home network.
Then you can explain all the implications of this. Including that this is a readily available device for low cost. And that this particular attack has been known and documented since 2004.
It would seem unlikely that manufacturers of devices relying on WiFi are unaware of this. Run a bar across their cages to get this fixed.
This is someone looking for a sensational response without taking the time to wonder if the people reading the article, at least here on HN, are ready to call him out on his bull shit.
I'm not super well-versed on Pineapple, so I don't know what's true/not true about what it does/how it does it.
Btw. With Windos 3.0 Trumpet Winsock allowed you directly to snoop IP traffic as well as packet content. So there's nothing new with it either.
I also worked in networking department monitoring network issues, and it was painfully clear, that anyone who used telnet to access bank was easily monitored. (of course) Best thing was that banks didn't offer back then any other alternatives, except traditional POTS modems, which were just being replaced by IP networking.
Oh boy did I laugh about firesheep news, it was so obvious and over 15 years old trick.
I was naturally expecing this post to contain information how to MitM HTTPS and SSH sessions. Yes, users are stupid, and they might continue accessing services and login, even if cert isn't valid. As addition to that, they could have listed tips, how to create own cert authority and create "self signed" certs for every site being accssed with HTTPS. We're currently doing that in corporate environment. Only thing you need to arrange, is to use AD to get devices to trust this new cert. When you access facebook.com you'll get valid https connection with cert signed by IT. Yes, we can evasedrop and virus monitor also https connections, of course.
I'm sure there are many guys who have much more to add to this short list, what can be done.
Often with high security sites we opt to trust predefined exact public key fingerprint instead of any "publicly" signed cert. Because we all know the problems with official publicly signed certs and authorities.
I'm not sure which exact points of article your parent poster has an issue with, though so I can't rebut his arguments.
The first paragraph is relatively straightforward - just posting to HTTPS isn't enough. Your login form has to be HTTPS too, and not mixed-mode. Inject a javascript keylogger into your login form which you served over HTTP? Don't mind if I do.
The rest of the article is just a tutorial on how to get to the point where you can do something like that, by using the Pineapple.
Yes, Karma does actually work like explained in the article, and yes, clients will connect to any AP running Karma or a similar implementation, and it will do it for the exact reason he stated: They will broadcast the SSIDs they 'remember'. Once they're connected to your AP, well, you're on the path between them and anything they try to visit. That's pretty much the definition of being a man in the middle.
The article doesn't go too deep into what you can do and simply mentions that you can take a look at HTTP traffic -- If you can look at it, you can modify it on the fly. If you can do that you can spin up something like SSLstrip[0], or drop in a java driveby or... well, anything you can imagine doing to traffic on the wire.
Note that the pineapple is not the only device that can do this. There's all sorts of things like the expensive and super sneaky Pwn Plug[1] to something like a hand-made minipwner[2] which you can put together with $30 and a bunch of spare time.
[0] http://www.thoughtcrime.org/software/sslstrip/ [1] http://pwnieexpress.com/products/pwnplug-elite [2] http://www.minipwner.com/
Well done.