ygoltsev dcg 21_08_wifiineapple

28
Автономный сетевой шпион. WiFi Pineapple usage in the wild 21/08/2012 DCG #7812 г. Санкт-Петербург by @ygoltsev @d0znpp @d_olex

Upload: ygoltsev

Post on 27-May-2015

369 views

Category:

Travel


5 download

DESCRIPTION

Ygoltsev dcg 21_08_wifiineapple

TRANSCRIPT

Page 1: Ygoltsev dcg 21_08_wifiineapple

Автономный сетевой шпион. WiFi Pineapple usage in the wild

21/08/2012DCG #7812

г. Санкт-Петербург by@ygoltsev@d0znpp@d_olex

Page 2: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 2

Few words about myself

Security expert/

Penetration testing team

Community member

PHDays g00n

Editor

Page 3: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 3

WiFi Pineapple

http://cloud.wifipineapple.com/

by

Page 4: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 4

Functionality

• Stealth Access Point for Man-in-the-Middle attacks • Mobile Broadband connectivity (3g/4g via USB) • Manage from afar with persistent SSH tunnels and

meterpreter • Relay or Deauth attack with auxiliary WiFi adapter • Web-based management simplify MITM attacks • Easily concealed and battery powered • Expandable with community modules

Page 5: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 5

Based on

AP121U (http://bit.ly/NAvaq9)- 45 $

+Jasager (OpenWRT) (http://bit.ly/EgvNV)- free

Page 6: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 6

AP121U

• 93 x 70 x 26mm• 74g• IEEE 802.11b/g/n• 2x Ethernet• USB 2.0• 400 MHz

Page 7: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 7

Jasager

- Linux (kernel 3.2)- hostapd (http://hostap.epitest.fi/hostapd/)

hostapd is a user space daemon for access point and authentication servers.

- Karma (http://www.digininja.org/karma/)Patch for hostapd.Set of patches to access point software to get it to

respond to probe requests not just for itself but for any ESSID requested.

Page 8: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 8

Equalness

=

Page 9: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 9

But

• 93 x 70 x 26mm• 74g

and 100 $...

Page 10: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 10

money - not so important

Page 11: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 11

Yammi!!

Page 12: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 12

Usage

- As a home router- As a tool for penetration testing- As an energy independent network spy

Page 13: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 13

Some statistics

• Location: Big Mall, Food Court• Wi-Fi SSID –

‘Ne_podkluchaytes_k_etoy_to4ke’• Action:

Respond to all probe request.Disconnect.Ignore MAC next time.

Page 14: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 14

Over 9000….

P.S. Over 100

Page 15: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 15

More interesting

~ 189 minutes

Page 16: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 16

More interesting

• Mobile Juice pack

~ More than 6 hours

Page 17: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 17

And what if?

Page 18: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 18

Other stuff

• More than 20 add-ons (modules)• Build in web/dns/ssh services• tcpdump/air*/ettercap/sslstrip

Page 19: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 19

Cover story: fairy tale

Page 20: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 20

Cover story: legendary legend

Page 21: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 21

Cover story: box location

Page 22: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 22

Cover story: box location

Page 23: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 23

Cover story: packing the box

• Pelican boxes – the best choice

Page 24: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 24

Cover story: setting up environment

• Setting up SSH tunnel• …• Do the stuff

Page 25: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 25

Cover story: Catch me if you can

• Wipe all shit!

+

Page 26: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 26

Bonus track: Wipe video

Page 27: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 27

Bonus track: Wipe

Page 28: Ygoltsev dcg 21_08_wifiineapple

Defcon Russia (DCG #7812) 28

Thanks for your attention!

@[email protected]