Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 56 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Wireless
Am I Secure?
EH-Net
May 21, 2013, 07:49:16 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Wireless
(Moderator:
don
) >
Am I Secure?
Pages:
1
[
2
]
Go Down
« previous
next »
Print
Author
Topic: Am I Secure? (Read 22905 times)
0 Members and 1 Guest are viewing this topic.
Kev
Sr. Member
Offline
Posts: 428
Re: Am I Secure?
«
Reply #15 on:
February 05, 2009, 01:45:31 PM »
Please keep in mind there is the practical and there is the reality! There is a big deference! If you never had a Cop or FBI come in your life you are a cherry,LOL !Just kidding , but keep that in mind! Think like that!
Logged
SynJunkie
Jr. Member
Offline
Posts: 71
Re: Am I Secure?
«
Reply #16 on:
February 05, 2009, 02:53:36 PM »
sgt_mjc
in answer to your question, there's a few ways you could do this as i see it. You could move the AP onto the LAN and arp poison between that and the gateway, however this does place your LAN at risk if not done properly. An approach I like which worked well for me in the past was to set up an old box with PFSense on and 3 network interfaces. I then put an AP onto the DMZ interface and used the PFSense box to capture all traffic that flowed from the DMZ to the outside interface. This got me what I wanted and did not put my LAN at risk.
I'm sure there are a load more ways to do this, but this worked for me.
Hope that helps.
Syn
Logged
----------------------------------
http://synjunkie.blogspot.com
CadillacGolfer
Newbie
Offline
Posts: 36
Re: Am I Secure?
«
Reply #17 on:
February 06, 2009, 12:54:02 PM »
Disabling SSID doesn't gain you much. When a client tries to connect it will pass the SSID in clear text to the AP. However, that being said, at least it won't show up for any nosey non techie neighbors to see. MAC filtering, again from a strict security perspective gains you nothing. If you can sniff the traffic between a client and the AP, the MAC addies are passed in clear text. Though it will prevent someone from inadvertantly connecting to it. Make sure your PSK is 20+ non dictionary word characters and you change the SSID name from its default to something unique. If you leave the SSID the default linksys, or wlan, or netgear or simlar commonly used SSIDs and have a dictionary word for your PSK you would be susciptable to cowpatty table attack. and use WPA2 instead of WPA if you can. Some recent weaknesses have been discovered in WPA, but to be honest, I don't know if the attack is practical yet or not or if there are any tools to do so.
Logged
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: Am I Secure?
«
Reply #18 on:
February 06, 2009, 01:43:15 PM »
Well of course I changed the SSID name & use WPA2 I should of been a little more specific. my PSK has been randomly generated guess all I have to do now is make it over 20 characters instead of 17. vijay2 about you asking what am I trying to protect? If my network was like Kev's I'd be trying to protect my 40 Gig porn stash! Joking...Just trying to remain fairly secure here your guys' responses have helped out alot!
Logged
eCPPT, GCIH, OSCP, OSWP
Ne0
Jr. Member
Offline
Posts: 62
Re: Am I Secure?
«
Reply #19 on:
February 11, 2009, 01:48:40 AM »
hi KrisTeason!
actually looking at how u have configured its pretty sure that you r normally secured, Hidden SSID not of any concern as Hidden SSID's can be bruteforced using MDK3, which is one of the best feature is to bruteforcing hideen ESSID's.it works in 2 way one we can try with every possible combination,suitable for short ESSID's or we can try using default/custom created ESSID list , using MDK3 within few seconds you can get the Hidden ESSID's
posting u a post from remote exploit where the Eg., is
Tested using Linksys WUSB54GC adapter and Linksys WRT54G Router.
Commands:
bt~#airodump-ng rausb0
open one more window
#if command supplied without target -t parameter.it will bruteforce for all #hidden ESSID's in range.
bt ~ # mdk3 rausb0 p -f SSID.txt -t 00:21:29:68:16:C2
SSID Wordlist Mode activated!
Waiting for beacon frame from target...
Sniffer thread started
SSID is hidden. SSID Length is: 11.
Trying SSID: linksys
Trying SSID: ascend
Trying SSID: <any ssid>
Trying SSID: mynetwork
Trying SSID: fatport
Trying SSID: 2WIRE975
Trying SSID: 2WIRE186
Trying SSID: 2WIRE707
Trying SSID: 2WIRE774
Trying SSID: 2WIRE436
Packets sent: 1143 - Speed: 120 packets/sec
Got response from 00:21:29:68:16:C2, SSID: "thunderbolt"
Here you got hidden ESSID in less then 10 seconds.
and yeah its good to keep ur firmware upgraded, and check there no port forwardings
regards
Ne0
Logged
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: Am I Secure?
«
Reply #20 on:
February 11, 2009, 02:00:25 AM »
I've got to look into that mdk3 tool & code me up a quick tool to generate 2WIRE + 3NumberHere SSIDs. You guys want the generated 2WIRE SSID .txt list when I'm done?
Logged
eCPPT, GCIH, OSCP, OSWP
Vertigo
Newbie
Offline
Posts: 13
Re: Am I Secure?
«
Reply #21 on:
February 12, 2009, 02:11:57 AM »
Easy way to get out SSID from AP:
1. switch card in monitor(promisc) mode - iwconfig wlan0 mode monitor
or
airmon-ng stop ath0
airmon-ng start wifi0
2. run to airodump - airodump-ng -w dump -c 6 wlan0
3. wait to client connect AP and deauthenticate STA - aireplay-ng -0 10 -a BSSID_MAC -h STA_MAC wlan0
4. Look at airodump-ng console for SSID
Yes, randomly generated 20 characters long PSK passphrase for WPA-PSK authentication and TKIP encryption with rekeying interval less than 1200 sec's or WPA2-PSK authentication with CCMP(AES) encryption without rekeying restrinctions, is good enough.
If You woul like to be paranoidal, You could use 802.1X port based access control with Radius server ( for example FreeRADIUS 2.0.X) and EAP-TTLS/PEAP with MSCHAPV2/MSCHAP/CHAP/MD5/PAP tunneled client authentication. It run fine...airodump-ng shows MGT in authentication column.
Good Luck!
=================
GCIG, Security+
«
Last Edit: February 21, 2009, 07:00:22 AM by Vertigo
»
Logged
Ne0
Jr. Member
Offline
Posts: 62
Re: Am I Secure?
«
Reply #22 on:
February 17, 2009, 04:11:20 AM »
me working on BT4 its tooo cool tools and updated version of older tools hang on for the full versoin of it
Logged
bigthugs0
Newbie
Offline
Posts: 1
Re: Am I Secure?
«
Reply #23 on:
May 13, 2009, 04:31:40 PM »
hey all ... im new to this ..
can anyone tell me how to hack wireless network .. with WPA2 encryption and cipher CCMP and Auth: MGT .... that has usernames and passwords for accounts ?
Logged
UNIX
Hero Member
Offline
Posts: 1235
Re: Am I Secure?
«
Reply #24 on:
May 14, 2009, 12:30:29 AM »
Quote from: vijay2 on February 05, 2009, 06:41:37 AM
For me, the amount of effort I put in to secure something is directly proportional to the data I am trying to protect. SO the question is what are you trying to protect ?
Is that really so? I don't agree with this fully. Although mostly everyone from us has some data which are private (nothing in particular, maybe family photos etc.) I don't like the idea that someone uses my network for whatever without my knowledge and admission to do so.
People who think that nothing will happen to them, e.g. by thinking nobody would hack
their
network or that
they
in particular will be the victim of such an attack, are somehow ignorant (I don't mean you with this). I have often heard people saying that they will surely not become the target of such an attack, but the truth is, that most (non professional) attacks are launched randomly and everybody could be by accident become a target.
Depending on your country it also may become a legal problem when someone is using your network - but not for the attacker but for the victim. In Europe several cases occured where someone broke into someone elses wireless network, downloaded some porns or did some illegal action, and afterwards, the person owning the network was sentenced guilty because it was his/ her computer/ network/ infrastructe which were used and his/ her fault, because they did not secure it properly. If they where just sloppy or lacking the technical knowledge doesn't matter.
So I think it is a good idea for securing a network as good as possible, also if there is no 'danger' (I am not considering things like putting up a honeypot or similar as the average person may not be interested in this).
Logged
Otter
Newbie
Offline
Posts: 41
Re: Am I Secure?
«
Reply #25 on:
May 15, 2009, 09:06:02 PM »
Quote from: bigthugs0 on May 13, 2009, 04:31:40 PM
hey all ... im new to this ..
can anyone tell me how to hack wireless network .. with WPA2 encryption and cipher CCMP and Auth: MGT .... that has usernames and passwords for accounts ?
I'll save you some time: ain't likely to happen. That's best practices wireless config you've found right there. :-) If it's Cisco infrastructure, maybe you'll find some other BSSID's from the same physical access point that are configured more loosely and attempt to join those if you can find clients and or ESSID's that are associated with those.
Alternative approaches: Callback trojan burned onto an autorun configured CD or U3 enabled usb key labeled "private photos" and leave it somewhere the owner of the access point or anyone the lan will pick it up and put it into their computer.
Or if you wanna still stay in the wireless realm, go after the clients. See if the client or network involved has some of those lovely braindead Windows XP machines that bleat for their remembered access points probing out to them hoping they respond. airbase-ng can then be used to set up a trojan access point with an ESSID matching those for which those clients are probing, setup a dhcp server on teh same box serving addresses to the tun interface airbase-ng creates for ya, the "sheep" client box associates, you cheerfully offer it a dhcp address, and then you can attempt to see if it's vulnerable to anything over the network. Or, if you have internet conenctivity you can MITM them with the full karmetasploit ball of wax and capture credentials as they try to go out to the net and instead find your rogue metasploit replicas of popular websites, and they'll give up some credentials in the process, more than likely.
Good luck! And again, this presumes you're going after a network you have written legal permission to attack.
Logged
Pages:
1
[
2
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.