Your wifi shows me where you live, work and travel
blog.viraptor.info
blog.viraptor.info
Lets say you go to starbucks and I've got my honeypot running, you will automatically connect to my laptop and I'll just spoof your probes into thinking I'm your network. While connected to my smartphone or even starbucks wifi I can see everything you do in clear text, spoof ssl, and then with driftnet see all the images you look at, and use ettercap to steal your sessions if need be.
And the best part, if I show up and starbucks is already full of people I'd like to play with, I can just deauthenticate them all for a moment, and when I turn off the kill switch they all connect to me. None the wiser.
Wifi security is a misnomer.
Here is an example I made in 2008.
It's early and I may be forgetting something....but assuming their home network isn't an open network, how would you get a client to authenticate to your rogue network? Even though the client would think it was the same network, authentication should fail because the client would attempt to use the stored credentials, and you almost certainly wouldn't know their passkey. Thus, causing the client to receive a message indicating an issue with authentication.
Are you inferring that you would brutal force the WPA2 passkey for their network with something like cowpatty? Are dictionary attacks really that easy to pull off these day? Mind you, it's been almost ten years since I've played around with WiFi cracking.
Usually in a place like starbucks the open wifi is open so I can just pretend to be that network and force everyone to connect to me instead.
I just checked my wireless controller to verify my thought process, and each time I switched wireless profiles (all of which are saved on my device) the 802.1x auth(EAPOL) process is used. I'm a little rusty on my wireless security, but wouldn't this same process occur for the rogue network?
Like you said though, if you sit in an area with existing open wireless, none of that will come into play.
Or am I missing something here?
As someone else said, for WPA, you can't simply spoof the home base. You have to know whatever password the device is configured for. And even if you did know that, you'd have to spoof the same MAC address for most computers to communicate with the device, which is more likely to just break everyone's internet connection, since the whole communication protocol relies on MAC addresses being unique.
> And the best part, if I show up and starbucks is already full of people I'd like to play with, I can just deauthenticate them all for a moment, and when I turn off the kill switch they all connect to me. None the wiser.
Once again, the only way they're going to auto-connect to your network is if you have the same MAC address and password, and the interference would kill you. You're more likely to get fish on the hook if you make an AP with the same name and hope you trick some people who are frustrated with you shutting down the other network into trying it.
> Wifi security is a misnomer.
Not if you actually use WPA2, pick a good password, and make sure your users aren't connecting to random unsecured networks with the same name.
If you are sniffing the 802.11 frames (and you should assume someone is) and you catch the entire 4-way handshake and the nonce generation is predictable you could reverse-engineer it, but then again you can say the same thing about a TLS connection too.
The whole standard it a mess; it should have opportunistic encryption on open networks, then clients can display a warning if this doesn't happen for whatever reason ("Anything you send or receive over this network may be readable by others" or similar).
About that ...
MAC addresses are not checked unless you use an extra tool for this. For example, a large institution (university, company, etc) can have many access points, each with a unique MAC address. However the SSID is unique among all Access Points. Your device will only check the SSID, try to connect (using mutual authentication), but no MAC address checks take place. You don't need to know or use the MAC address of the target network to clone it. You can just use any MAC address you want, that is if you know the password of it, or are cloning an unprotected network.
I believe this would be more clearly understood as 'the SSID is identical across all access points'.
Either way, Wi-Fi security certainly != "a misnomer."
http://www.aircrack-ng.org/doku.php?id=airbase-ng
MAC address, password, none of that matters. Interference? You operate on a different channel.
Jasager is the other utility I forgot about that solves all the WPA problems.
You don't have to believe me, but I can tell you that I've done this, without fail, and have no reason to lie.
[1] https://en.wikipedia.org/wiki/ARP_spoofing
[2] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
But sniffing can work even if the connection is WPA2 encrypted and there are untrusted users on the same network.
That's why you should use a secure VPN on any public network.
>spoof ssl
Only if either they blindly accept invalid certs, or you somehow already installed a root CA on their boxen.
Sounds to me like you found an all-in-one tool, which doesn't make you understand how the process works or its limitations. I would agree that many wireless networks are hideously insecure (why I SSH tunnel my traffic when I'm on one), but it isn't that bad unless you're either running unauthenticated or using WEP.
There's an app called "WiFi Advanced Config Editor" (https://play.google.com/store/apps/details?id=org.marcus905....) which shows in detail how a saved wifi network is configured. I believe that whether it will broadcast the network name or not is displayed as the "Hidden SSID" checkbox.
Edit: after trawling through the Android source code, I found the code which apparently sets the scan_ssid= value in the wpa_supplicant config file. It seems to be this one: http://androidxref.com/5.1.0_r1/xref/frameworks/opt/net/wifi...
If I'm reading that code correctly, it sets the "scan_ssid" variable (WifiConfiguration.hiddenSSIDVarName is a public static final String containing "scan_ssid") according to the value of the WifiConfiguration.hiddenSSID variable. As documented in the WifiConfiguration class (http://androidxref.com/5.1.0_r1/xref/frameworks/base/wifi/ja...):
"This is a network that does not broadcast its SSID, so an SSID-specific probe request must be used for scans."
See for instance the post at http://forum.xda-developers.com/showthread.php?t=2634042 ("Any network added manually with the '+' icon will have scan_ssid=1. Any network picked from the list of scan results will not have a scan_ssid property.")
Did you try the "WiFi Advanced Config Editor" or similar to see what Android thinks about these networks, to see if there's a pattern?
scan_ssid
SSID scan technique; 0 (default) or 1. Technique 0 scans for the
SSID using a broadcast Probe Request frame while 1 uses a
directed Probe Request frame. Access points that cloak them-
selves by not broadcasting their SSID require technique 1, but
beware that this scheme can cause scanning to take longer to com-
plete.Looks like you found the bug, thanks: https://www.eff.org/deeplinks/2014/07/your-android-device-te...
So it's a bug after all.
The amount of data you can gain from WiFi probes is extremely high.
I can imagine market researchers using this to measure phone brand usage in places, travel statistics (Airport WiFi), coffee shops.
Some phones (many) even add extended attributes that directly identify the phone model.
For example, take this guy (actual data from Postgres aggregation Query):
{bwin_ICE,"City Hotel","_Heathrow Wi-Fi",hhonors-public,HolidayInn_Guest,HotelCityNewFloor_1,HP_WL_01,Kramola456,Mani_Chrisi,"O2 Wifi",OEBBfree,OpenNet,"Sofia A irport Public","The Diner",WirelessViennaAirport,wonderland,NULL}
I know he was in London, at the Airport in Vienna, in a German Train, in Sofia, in a specific hotel.
So imagine that you travel, go to a few hotels and use their wifi networks. Once you're back home, the fact that you used these networks is still broadcast everywhere, and there is no way in the interface to turn that off.
Simply using something like Kismet[0] yields a lot of information, even before any rigorous analysis is done. You'll see some probe requests with huge lists of SSIDs. Some of those SSIDs are comprised of an address (presumably a home address), others are obviously office/work SSIDs and still others are public ones. (Starbucks, etc.) From this you can infer a device's movement and thus likely a person's. This is all from a superficial analysis.
Others have done much more research into large-scale collection and analysis of WiFi probes. The information you can collect is immense. See Snoopy[1] and this research paper entitled, "Signals from the Crowd: Uncovering Social Relationships through Smartphone Probes". [2]
Some of these use a SSID-to-geolocation database to assign a physical location to specific SSIDs. WiGLE is an example.[3] Google, Apple, et al. maintain their own databases that are likely more accurate, used to provide geolocation services to mobile users.
0. https://www.kismetwireless.net/
1. http://www.sensepost.com/blog/7557.html
2. http://conferences.sigcomm.org/imc/2013/papers/imc148-barber...
There was a devious little company called WiFast that provided WiFi hotspots to local businesses. You'd have to authenticate with e-mail or Facebook to get access. The devious part is that they could then match your device's MAC address to your identity and track you as you moved throughout any city where they had merchants in their network. They built personalized profiles by spying on exactly where you moved throughout the day. This model is a big reason Apple started randomizing disconnected MAC addresses in newer versions of iOS.
I don't understand why devices are responsible for broadcasting by default in WiFi. Naively, it seems like the default case should have base stations broadcasting their IDs, and your device should only try to connect when it recognizes one. (This also seems like it would be more efficient for battery life.)
Obviously, hidden could SSIDs pose a problem, but does anyone know why WiFi devices broadcast so much data before they've even found a base station to pair with?
This always comes in a cycle.
The solution is to use Pry-fi: https://play.google.com/store/apps/details?id=eu.chainfire.p... . It also has a nice feature where it randomly cycles your MAC address quickly to ruin datasets of places who spy on wireless probes to track people's locations.
The main drawback is that it doesn't work on Windows (wpa_supplicant on Linux already does this by default); on my laptops I just remove all networks when I am finished with them - entering a 15-20 char password every couple of months isn't so bad, especially as I only really use my laptop when travelling.
> sudo tcpdump -l -e -I -i en0 | grep 'Probe Request ([^)]'
Not at all a tcpdump expert - fuddled around with manpages to make it work so others should please chime in with improvements.
sudo tcpdump -l -e -I -i en0 'type mgt subtype probe-req'
Way more efficient to use bpf instead of grep.
http://newsoffice.mit.edu/2015/identify-from-credit-card-met...
http://www.nature.com/srep/2013/130325/srep01376/full/srep01...
But aren't nearly all APs configured to broadcast SSID? So why is that probing necessary in general?