-./# &0 !((+", 1#$")2/(2&' 3#(4&5$ +'5 -&&*$ War urlvlng ulscoverlng wlreless LAns by llsLenlng Lo beacons or sendlng probe requesLs, Lhereby provldlng launch polnL for furLher aLLacks. Alrmon-ng, uSLumbler, klsMAC, MacSLumbler, neLSLumbler, WellenrelLer, Wllllolum 8ogue Access olnLs lnsLalllng an unsecured A lnslde flrewall, creaLlng open backdoor lnLo LrusLed neLwork. Any hardware or sofLware A Ad Poc AssoclaLlons ConnecLlng dlrecLly Lo an unsecured sLaLlon Lo clrcumvenL A securlLy or Lo aLLack sLaLlon. Any wlreless card or uS8 adapLer MAC Spooflng 8econflgurlng an aLLacker's MAC address Lo pose as an auLhorlzed A or sLaLlon. MacChanger, SlrMACsAloL, SMAC, WellenrelLer, wlconLrol 802.1x 8AuluS Cracklng 8ecoverlng 8AuluS secreL by bruLe force from 802.1x access requesL, for use by evll Lwln A. ackeL capLure Lool on LAn or neLwork paLh beLween A and 8AuluS server
6&'025#'(2+*2(. +((+",$
-./# &0 !((+", 1#$")2/(2&' 3#(4&5$ +'5 -&&*$ Lavesdropplng CapLurlng and decodlng unproLecLed appllcaLlon Lrafflc Lo obLaln poLenLlally senslLlve lnformaLlon. bsd-alrLools, LLLercap, klsmeL, Wlreshark, commerclal analyzers WL key Cracklng CapLurlng daLa Lo recover a WL key uslng passlve or acLlve meLhods. Alrcrack-ng, alroway, AlrSnorL, chopchop, dwepcrack, WepALLack, WepuecrypL, WepLab, wesslde Lvll 1wln A Masqueradlng as an auLhorlzed A by beaconlng Lhe WLAn's servlce seL ldenLlfler (SSlu) Lo lure users. cqureA, u-Llnk C200, PermesA, 8ogue Squadron, Wlfl8Su A hlshlng 8unnlng a phony porLal or Web server on an evll Lwln A Lo "phlsh" for user loglns, credlL card numbers. Alrpwn, Alrsnarf, PoLspoLLer, karma, 8ClueA Man ln Lhe Mlddle 8unnlng LradlLlonal man- ln-Lhe-mlddle aLLack Lools on an evll Lwln A Lo lnLercepL 1C sesslons or SSL/SSP Lunnels. dsnlff, LLLercap-nC, sshmlLm
7'(#8)2(. +((+",$ -./# &0 !((+", 1#$")2/(2&' 3#(4&5$ +'5 -&&*$ 802.11 lrame ln[ecLlon CrafLlng and sendlng forged 802.11 frames. Alrpwn, llle2alr, llbradlaLe, vold11, WLWedgle, wneL dln[ecL/reln[ecL 802.11 uaLa 8eplay CapLurlng 802.11 daLa frames for laLer (modlfled) replay. CapLure + ln[ecLlon 1ools 802.1x LA 8eplay CapLurlng 802.1x LxLenslble AuLhenLlcaLlon roLocols (e.g., LA ldenLlLy, Success, lallure) for laLer replay. Wlreless CapLure + ln[ecLlon 1ools beLween sLaLlon and A 802.1x 8AuluS CapLurlng 8AuluS Access- AccepL or 8e[ecL messages LLherneL CapLure + ln[ecLlon 1ools beLween 8eplay for laLer replay. A and auLhenLlcaLlon server
!9(4#'(2"+(2&' +((+",$
-./# &0 !((+", 1#$")2/(2&' 3#(4&5$ +'5 -&&*$ Shared key Cuesslng ALLempLlng 802.11 Shared key AuLhenLlcaLlon wlLh guessed, vendor defaulL or cracked WL keys. WL Cracklng 1ools Sk Cracklng 8ecoverlng a WA/WA2 Sk from capLured key handshake frames uslng a dlcLlonary aLLack Lool. coWALLy, genpmk, klsMAC, wpa_crack AppllcaLlon Logln 1hefL CapLurlng user credenLlals (e.g., e-mall address and password) from clearLexL appllcaLlon proLocols. Ace assword Snlffer, usnlff, Poss, WlnSnlffer uomaln Logln Cracklng 8ecoverlng user credenLlals (e.g., Wlndows logln and password) by cracklng neL8lCS password hashes, uslng a bruLe- force or dlcLlonary aLLack Lool. !ohn Lhe 8lpper, L0phLCrack, Caln vn Logln Cracklng 8ecoverlng user credenLlals (e.g., 1 password or lsec reshared SecreL key) by runnlng bruLe-force aLLacks on vn auLhenLlcaLlon proLocols. lke_scan and lke_crack (lsec), anger and 1PC- ppLp-bruLer (1) 802.1x ldenLlLy 1hefL CapLurlng user ldenLlLles from clearLexL 802.1x ldenLlLy 8esponse packeLs. CapLure 1ools 802.1x assword uslng a capLured ldenLlLy, repeaLedly aLLempLlng 802.1x assword ulcLlonary Cuesslng auLhenLlcaLlon Lo guess Lhe user's password. 802.1x LLA Cracklng 8ecoverlng user credenLlals from capLured 802.1x LlghLwelghL LA (LLA) packeLs uslng a dlcLlonary aLLack Lool Lo crack Lhe n1 password hash. Anwrap, Asleap, 1PC-LLAcracker 802.1x LA uowngrade lorclng an 802.1x server Lo offer a weaker Lype of auLhenLlcaLlon uslng forged LA-8esponse/nak packeLs. llle2alr, llbradlaLe
!:+2*+;2*2(. +((+",$
-./# &0 !((+", 1#$")2/(2&' 3#(4&5$ +'5 -&&*$ A 1hefL hyslcally removlng an A from a publlc space. "llve flnger dlscounL" Cueensland uoS LxplolLlng Lhe CSMA/CA Clear Channel AssessmenL (CCA) mechanlsm Lo make a channel appear busy. An adapLer LhaL supporLs CW 1x mode, wlLh a low- level uLlllLy Lo lnvoke conLlnuous LransmlL 802.11 8eacon llood CeneraLlng Lhousands of counLerfelL 802.11 beacons Lo make lL hard for sLaLlons Lo flnd a leglLlmaLe A. lakeA 802.11 AssoclaLe / AuLhenLlcaLe llood Sendlng forged AuLhenLlcaLes or AssoclaLes from random MACs Lo flll a LargeL A's assoclaLlon Lable. lA1A-!ack, Macfld 802.11 1kl MlC LxplolL CeneraLlng lnvalld 1kl daLa Lo exceed Lhe LargeL llle2alr, wneL dln[ecL, LC8CCn A's MlC error Lhreshold, suspendlng WLAn servlce. 802.11 ueauLhenLlcaLe llood lloodlng sLaLlon(s) wlLh forged ueauLhenLlcaLes or ulsassoclaLes Lo dlsconnecLlng users from an A. Alreplay, Alrforge, Muk, vold11, commerclal WlS 802.1x LA-SLarL llood lloodlng an A wlLh LA- SLarL messages Lo consume resources or crash Lhe LargeL. CACafe, llle2alr, llbradlaLe 802.1x LA- lallure Cbservlng a valld 802.1x LA exchange, and Lhen sendlng Lhe sLaLlon a forged LA-lallure message. CACafe, llle2alr, llbradlaLe 802.1x LA-of- ueaLh Sendlng a malformed 802.1x LA ldenLlLy response known Lo cause some As Lo crash. CACafe, llle2alr, llbradlaLe 802.1x LA LengLh ALLacks Sendlng LA Lype-speclflc messages wlLh bad lengLh flelds Lo Lry Lo crash an A or 8AuluS server. CACafe, llle2alr, llbradlaLe
Casl Lodas esLas herramlenLas esLan en el 8ack1rack AudlLor SecurlLy CollecLlon.