A Shark on the Network
blog.nodenexus.com
blog.nodenexus.com
He ended up dropping the extra.
Security is not a Dark Art, and there is no harm in teaching people how or why attacks work. If you can find it at a bookstore or via a Google search, it's safe to disseminate to the general public via blog.
What I've been wondering about for a while now is, can wireshark show data on an encrypted network, assuming it has the key? Can wireshark take a known WEP/WPA2 key and use it to decrypt the packets on an encrypted network on the fly? I haven't found any CLI's or GUI's that have been able to do this out of the box. But surely someone has made this somewhere.
Wireshark is straightforward for revealing data on unencrypted wireless, but I haven't discovered how it could be used to monitor network users when someone has deciphered the key unbeknownst to the users who assume they are operating on an encrypted network such as WEP/WPA2.
Does the nature of the encrypted handshake make this impossible?
edit: Now that I see the wiki, I remember correctly that the version of Linux I was using didn't work with this feature in the GUI. Maybe I'll look for the CLI version again soon.
Maybe your new Dlink router comes with an 'app' which generates unique logins (with optional expiration times) that you can give out to users. There's a whole market of coffeeshop/restaurant wifi providers but they usually use no/shared encryption and a captive portal for managing authentication. That's great for dispensing logins and handling expirations, but is horrible for your user's security and user experience.
So all you'd see from me is encrypted stuff being sent to a random IP address.
* The operating system used * Application-specific traffic patterns * Content-specific traffic patterns * The VPN provider and type
First off, I know you're using a phone, because it matches mobile device tcp/ip fingerprints. Second, I can make a reasonable guess about what kind of VPN you're using, both based on the service itself and its traffic or connection pattern. Third, I can make a guess about what kinds of applications you're using, because you are using a phone and the traffic looks a certain way for certain network applications. Fourth, I can guess what kind of content you're looking at, since I have a good idea what kind of browser and application you're using. Fifth, if I can match up all those fingerprints each time, I can identify you as the sole user of that connection, meaning I can now track you whenever I see your traffic. Sixth, by manipulating your traffic in small ways I can also determine more about your host and application(s) by how they respond to network transmission problems.
Based on all that, I can send you a phished e-mail that looks to exploit any of the services or hosts or applications you're using. I don't even need to know who to e-mail; I can just spam tons of addresses and check for results that match the fingerprinted services I discovered earlier.
Another fun attack would be to actually kill every connection you tried to make over a VPN using a specific application and content provider; because it would never work over the VPN, you might eventually try it over your regular connection, giving me a new point of attack.
Hacking is fun!
1. https://www.digitalocean.com/community/tutorials/how-to-inst...
Protected networks require more effort depending on the method used, WEP is utterly broken, WPA/WPA2 can be broken but require considerably more effort and processing power. More concrete methods exists (802.1x) but are almost never used outside enterprise or educational facilities.
Finally, the chances that reversing an ip address will result in a correct hostname is most likely never the case.
The author is either very ill informed on how wireless networks actually work or is trying to make people scared without explaining why these things happen and how they can protect themselves - any of which I really do not like.
WEP stands for wireless equivalent privacy, and it is. its trivial to break. (just like monitoring wired connections)
Can to elaborate? Aside from brute force attacks, my understanding is that WPA2-PSK using AES is secure.
Encryption. Your neighbours hopefully have protected their wifi with a password. This prevents casual snooping but of course can't really keep out a dedicated attacker. There are automated tools to break WPA encryption.
Additionally, if your neighbours are browsing using SSL/TLS then you theoretically cannot eavesdrop on those sessions.
If you are able to get the key or they use no encryption or WEP you can look at the packets and get metadata for SSL sessions and all unencrypted traffic.
And that includes source/destination IP? Didn't know that..
If you can hear the signal, you can capture the traffic.
This is why wifi is segmented into channels: to reduce the number of packets that devices need to sift through.
The upstream router at the ISP is usually connected to an ATM or Frame Relay link, where they create virtual circuits to the DSLAM for each customer/modem (DSLAM is the last "network" device between your DSL modem and the telco -- it's the thing doing the Analog/Digital conversion from ATM/FR/Ethernet to electrical signals on the copper pair).
Since DSL works over a copper pair (phone lines), and you already know phone lines are not shared with your neighbors, there is no chance in intercepting your neighbors traffic over DSL, without someone physically splicing.
However, when ISP router is in plain bridge mode (i doubt anybody does this any longer, RBE so much more effective), there is possibility that the router floods packets for addresses it doesn't know, just like a switch does when it doesnt know where a certain MAC address is. This would broadcast that frame out across all the "virtual circuits". Most DSL modems would then also filter this, so unlikely you would still be able to observe it, unless you had control over the DSL modem/bridge itself.
You still need to known your neighbors' public ip address, but the problem may be significantly reduced: "hey want to check my cool app?" Boom!
My best guess is VPN. Maybe that's how they link Princeton campuses together or something.
I was hoping to read some recommendations on chipsets that are able to monitor multiple channels simultaneously.. but then it was just another misleading headline.