Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow News from the Outside Worldarrow A Wireless Hacking Computer That Can't Be Hacked
Ethical Hacker Community Forums
December 04, 2008, 04:41:53 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: A Wireless Hacking Computer That Can't Be Hacked  (Read 9233 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2383


Editor-In-Chief


View Profile WWW
« on: September 04, 2006, 03:17:26 PM »

Quote
If you think seeing a dozen wireless networks makes your computer the ultimate scanning box, think again. A small security firm has made a portable computer that is capable of scanning 300 networks simultaneously. Dubbed the "Janus Project", the computer also has a unique "Instant Off" switch that renders the captured data inaccessible.

The computer is the brain-child of Kyle Williams from the Janus Wireless Security Research Group in Portland, Oregon. We first spotted Williams sitting quietly and sipping Mountain Dew at the recently held Defcon security convention at the Riviera Casino in Las Vegas, Nevada. While it appeared as if Williams wasn't ver busy, the bright yellow Janus computer in front of him was scanning and capturing data from hundreds of wireless networks in range.

At first glance, the Janus computer looks like a laptop, but Williams said it is much more powerful than that. Inside the rugged yellow case sits a mini-computer motherboard powered by a 1.5 GHz VIA C7 processor and an Acer 17" LCD screen. Ubuntu 6.0 Linux runs the eight Atheros a/b/g Gold mini-PCI cards which continuously scan wireless networks. The mini-PCI cards are connected to two four-port PCI to mini-PCI converter boards. The wireless data is stored onto a 20 GB hard drive.

While the eight Wi-Fi cards are impressive, the Janus box also has two Teletronics 1 watt amplifiers along with external antenna ports in the back of the Pelican case. Williams made every port watertight by sealing them with epoxy and silicone. "When the lid is closed, it is essentially waterproof," said Williams.

So what does all of this wireless firepower provide? The Wi-Fi cards allow Williams to continuously scan and capture traffic from any wireless channel. Williams likes to continuously dump the raw network traffic to the hard drive, while running the Kismet scanner to get a "bird's eye" view of the area. From his Riviera hotel room and using a 1W amplified antenna, Williams said his Janus computer was able to capture data from 300 access points simultaneously. He said over 2000 access points were scanned and 3.5 GB of traffic was captured during the entire convention.

In addition to scanning for wireless traffic, Williams says the computer can break most WEP keys very quickly by focusing all eight wireless cards on the access point. Using a combination of common utilities like airreplay, airdump and aircrack, Willams said, "When I use all 8 radios to focus in on a single access point, [the WEP key] lasts less than five minutes." However, he added that some retail wireless access points will "just die" after being hit with so much traffic.

In addition to the capturing process, the hard drive and memory contents are continuously encrypted with AES 256-bit keys. There is also an "Instant Off" switch that, according to Williams, renders the captured data inaccessible to anyone but him.

Williams and his friend Martin Peck optimized the OS crypto software to take advantage of the C7's hardware crypto engine. During normal operation the operating system loops the XFS file system, along with the swap partition, through the AES 256-bit encryption. For added security, the encryption keys are rotated throughout the entire memory space.

After the Instant Off switch is hit, a USB key with a 2000-bit passkey and a manually entered password are needed to access the computer. Williams said that even if someone managed to grab the USB key, they would still have to "torture or bribe me" to get the password.

Williams is improving the Janus computer to crack wireless networks even faster. He is optimizing software routines to use the C7 chip to crack WPA and WPA2 protected networks without the use of Rainbow tables. He is also working on breaking SHA1 and RSA encryption in a single processor instruction cycle. Previous methods have required multiple clock cycles to go through one cracking pass.

Williams told us that he has spent a few thousand dollars building the Janus computer and hopes to make his money back by selling commercial versions to big companies and government organizations. "Maybe one day I could get the military to be a customer," said Williams.

For original story and a picture of the machine:
http://www.tgdaily.com/2006/08/30/defcon2006_janus_project/

Don
Logged

CISSP, MCSE, CEH, Security+ SME
jimbob
Sr. Member
****
Offline Offline

Posts: 319



View Profile WWW
« Reply #1 on: September 05, 2006, 07:48:35 AM »

That is real science fiction stuff! Now why haven't we seen one of those in the movies?

Jim
Logged
ogenstad
Newbie
*
Offline Offline

Posts: 6


View Profile WWW
« Reply #2 on: September 06, 2006, 05:33:44 AM »

It seems like a cool box. However I fail to see why it can't be hacked? It uses encryption but that's something else.
Logged

pcsneaker
Jr. Member
**
Offline Offline

Posts: 73


View Profile
« Reply #3 on: September 10, 2006, 04:49:30 AM »

Quote
In addition to scanning for wireless traffic, Williams says the computer can break most WEP keys very quickly by focusing all eight wireless cards on the access point. Using a combination of common utilities like airreplay, airdump and aircrack, Willams said, "When I use all 8 radios to focus in on a single access point, [the WEP key] lasts less than five minutes." However, he added that some retail wireless access points will "just die" after being hit with so much traffic.

I canot see the reason why WEP would be cracked more quickly using 8 cards instead of one.

In most cases you'll just capture traffic sent by the access point - so one card will do it. In case that you're running a replay attack with ARP packets  you'll flood the access point with packets at the speed it supports, so where's the advantage of using multiple cards ?

If you are trying to crack multiple access points you'll benefit from that box, but I doubt that you'll get it done quicker when just targeting a single access point.

Logged

MCSA:Security (W2k, W2k3)
MCSE:Security (W2k, W2k3)
CPTS, Network+
oleDB
Full Member
***
Offline Offline

Posts: 231



View Profile WWW
« Reply #4 on: September 11, 2006, 10:42:20 AM »

Anytime your cracking a limited keyspace you will benefit from multiprocessing. It allows you to search different parts of the keyspace simultaneously which is much faster. As long as there is intelligence built in to do that of course, otherwise they are trying to crack the exact same thing at the same time.
Logged
pcsneaker
Jr. Member
**
Offline Offline

Posts: 73


View Profile
« Reply #5 on: September 11, 2006, 11:14:19 AM »

Of course, but you don't need a wireless card to crack the key, you'll use it just to capture data.

Multiple wireless cards won't give you the ability to do multiprocessing as opposed to have multiple processors.
Logged

MCSA:Security (W2k, W2k3)
MCSE:Security (W2k, W2k3)
CPTS, Network+
Kev
Guest
« Reply #6 on: September 11, 2006, 02:00:08 PM »

  I like to use multiple cards when hacking wep. I use one to gather data and the other to inject packets at the same time. Injecting does help speed up with the data gathering which in turn speeds up the cracking process.   Using 2 cards in this instance seems to be more stable and a little faster, but I haven’t really put it to a lab test to really verify that result.
Logged
ryan
Newbie
*
Offline Offline

Posts: 20



View Profile WWW
« Reply #7 on: September 20, 2006, 10:51:49 AM »

Kev's got it here.

The reason more cards allow faster wep cracking is based on WEP Packet Injection. Rather than passively cracking wep keys by just passively grabbing whatever the wep target is sending out, you can actively pressure the target to send out more packets. aircrack can do this, other tools as well. The more cards, the more traffic you can generate.

Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.045 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.