Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                

Type of Attack Description Methods and Tools: War Driving

Download as pdf or txt
Download as pdf or txt
You are on page 1of 5

!

""#$$ "&'()&* +((+",$



-./# &0
!((+",
1#$")2/(2&' 3#(4&5$ +'5 -&&*$
War urlvlng ulscoverlng wlreless LAns
by llsLenlng Lo beacons or
sendlng probe requesLs,
Lhereby provldlng launch
polnL for furLher aLLacks.
Alrmon-ng, uSLumbler,
klsMAC, MacSLumbler,
neLSLumbler,
WellenrelLer,
Wllllolum
8ogue Access
olnLs
lnsLalllng an unsecured A
lnslde flrewall, creaLlng
open backdoor lnLo LrusLed
neLwork.
Any hardware or
sofLware A
Ad Poc
AssoclaLlons
ConnecLlng dlrecLly Lo an
unsecured sLaLlon Lo
clrcumvenL A securlLy or Lo
aLLack sLaLlon.
Any wlreless card or
uS8 adapLer
MAC
Spooflng
8econflgurlng an aLLacker's
MAC address Lo pose as an
auLhorlzed A or sLaLlon.
MacChanger,
SlrMACsAloL, SMAC,
WellenrelLer, wlconLrol
802.1x
8AuluS
Cracklng
8ecoverlng 8AuluS secreL
by bruLe force from 802.1x
access requesL, for use by
evll Lwln A.
ackeL capLure Lool on
LAn or neLwork paLh
beLween A and
8AuluS server

6&'025#'(2+*2(. +((+",$

-./# &0 !((+", 1#$")2/(2&' 3#(4&5$ +'5 -&&*$
Lavesdropplng CapLurlng and decodlng
unproLecLed appllcaLlon
Lrafflc Lo obLaln poLenLlally
senslLlve lnformaLlon.
bsd-alrLools, LLLercap,
klsmeL, Wlreshark,
commerclal analyzers
WL key
Cracklng
CapLurlng daLa Lo recover
a WL key uslng passlve or
acLlve meLhods.
Alrcrack-ng, alroway,
AlrSnorL, chopchop,
dwepcrack, WepALLack,
WepuecrypL, WepLab,
wesslde
Lvll 1wln A Masqueradlng as an
auLhorlzed A by
beaconlng Lhe WLAn's
servlce seL ldenLlfler (SSlu)
Lo lure users.
cqureA, u-Llnk C200,
PermesA, 8ogue
Squadron, Wlfl8Su
A hlshlng 8unnlng a phony porLal or
Web server on an evll Lwln
A Lo "phlsh" for user
loglns, credlL card
numbers.
Alrpwn, Alrsnarf,
PoLspoLLer, karma,
8ClueA
Man ln Lhe
Mlddle
8unnlng LradlLlonal man-
ln-Lhe-mlddle aLLack Lools
on an evll Lwln A Lo
lnLercepL 1C sesslons or
SSL/SSP Lunnels.
dsnlff, LLLercap-nC,
sshmlLm


7'(#8)2(. +((+",$
-./# &0
!((+",
1#$")2/(2&' 3#(4&5$ +'5 -&&*$
802.11
lrame
ln[ecLlon
CrafLlng and sendlng forged
802.11 frames.
Alrpwn, llle2alr,
llbradlaLe, vold11,
WLWedgle, wneL
dln[ecL/reln[ecL
802.11
uaLa
8eplay
CapLurlng 802.11 daLa frames
for laLer (modlfled) replay.
CapLure + ln[ecLlon 1ools
802.1x
LA
8eplay
CapLurlng 802.1x LxLenslble
AuLhenLlcaLlon roLocols
(e.g., LA ldenLlLy, Success,
lallure) for laLer replay.
Wlreless CapLure +
ln[ecLlon 1ools beLween
sLaLlon and A
802.1x
8AuluS
CapLurlng 8AuluS Access-
AccepL or 8e[ecL messages
LLherneL CapLure +
ln[ecLlon 1ools beLween
8eplay for laLer replay. A and auLhenLlcaLlon
server


!9(4#'(2"+(2&' +((+",$

-./# &0
!((+",
1#$")2/(2&' 3#(4&5$ +'5
-&&*$
Shared key
Cuesslng
ALLempLlng 802.11 Shared key
AuLhenLlcaLlon wlLh guessed,
vendor defaulL or cracked WL
keys.
WL Cracklng
1ools
Sk Cracklng 8ecoverlng a WA/WA2 Sk
from capLured key handshake
frames uslng a dlcLlonary aLLack
Lool.
coWALLy,
genpmk, klsMAC,
wpa_crack
AppllcaLlon
Logln 1hefL
CapLurlng user credenLlals (e.g.,
e-mall address and password)
from clearLexL appllcaLlon
proLocols.
Ace assword
Snlffer, usnlff,
Poss, WlnSnlffer
uomaln
Logln
Cracklng
8ecoverlng user credenLlals
(e.g., Wlndows logln and
password) by cracklng neL8lCS
password hashes, uslng a bruLe-
force or dlcLlonary aLLack Lool.
!ohn Lhe 8lpper,
L0phLCrack, Caln
vn Logln
Cracklng
8ecoverlng user credenLlals
(e.g., 1 password or lsec
reshared SecreL key) by
runnlng bruLe-force aLLacks on
vn auLhenLlcaLlon proLocols.
lke_scan and
lke_crack (lsec),
anger and 1PC-
ppLp-bruLer (1)
802.1x
ldenLlLy 1hefL
CapLurlng user ldenLlLles from
clearLexL 802.1x ldenLlLy
8esponse packeLs.
CapLure 1ools
802.1x
assword
uslng a capLured ldenLlLy,
repeaLedly aLLempLlng 802.1x
assword
ulcLlonary
Cuesslng auLhenLlcaLlon Lo guess Lhe
user's password.
802.1x LLA
Cracklng
8ecoverlng user credenLlals
from capLured 802.1x
LlghLwelghL LA (LLA) packeLs
uslng a dlcLlonary aLLack Lool Lo
crack Lhe n1 password hash.
Anwrap, Asleap,
1PC-LLAcracker
802.1x LA
uowngrade
lorclng an 802.1x server Lo offer
a weaker Lype of auLhenLlcaLlon
uslng forged LA-8esponse/nak
packeLs.
llle2alr, llbradlaLe


!:+2*+;2*2(. +((+",$

-./# &0 !((+", 1#$")2/(2&' 3#(4&5$ +'5 -&&*$
A 1hefL hyslcally removlng an A
from a publlc space.
"llve flnger
dlscounL"
Cueensland uoS LxplolLlng Lhe CSMA/CA
Clear Channel AssessmenL
(CCA) mechanlsm Lo make
a channel appear busy.
An adapLer LhaL
supporLs CW 1x
mode, wlLh a low-
level uLlllLy Lo lnvoke
conLlnuous LransmlL
802.11 8eacon
llood
CeneraLlng Lhousands of
counLerfelL 802.11
beacons Lo make lL hard
for sLaLlons Lo flnd a
leglLlmaLe A.
lakeA
802.11 AssoclaLe
/ AuLhenLlcaLe
llood
Sendlng forged
AuLhenLlcaLes or
AssoclaLes from random
MACs Lo flll a LargeL A's
assoclaLlon Lable.
lA1A-!ack, Macfld
802.11 1kl MlC
LxplolL
CeneraLlng lnvalld 1kl
daLa Lo exceed Lhe LargeL
llle2alr, wneL
dln[ecL, LC8CCn
A's MlC error Lhreshold,
suspendlng WLAn servlce.
802.11
ueauLhenLlcaLe
llood
lloodlng sLaLlon(s) wlLh
forged ueauLhenLlcaLes or
ulsassoclaLes Lo
dlsconnecLlng users from
an A.
Alreplay, Alrforge,
Muk, vold11,
commerclal WlS
802.1x LA-SLarL
llood
lloodlng an A wlLh LA-
SLarL messages Lo
consume resources or
crash Lhe LargeL.
CACafe, llle2alr,
llbradlaLe
802.1x LA-
lallure
Cbservlng a valld 802.1x
LA exchange, and Lhen
sendlng Lhe sLaLlon a
forged LA-lallure
message.
CACafe, llle2alr,
llbradlaLe
802.1x LA-of-
ueaLh
Sendlng a malformed
802.1x LA ldenLlLy
response known Lo cause
some As Lo crash.
CACafe, llle2alr,
llbradlaLe
802.1x LA
LengLh ALLacks
Sendlng LA Lype-speclflc
messages wlLh bad lengLh
flelds Lo Lry Lo crash an A
or 8AuluS server.
CACafe, llle2alr,
llbradlaLe

Casl Lodas esLas herramlenLas esLan en el 8ack1rack AudlLor SecurlLy
CollecLlon.

You might also like