Some information security experts still suggested to hide your SSID and set MAC address filtering in addition to WPA2, AES and strong passphrase setting in order to keep your wireless network secure.
However, most wireless hacking tools can unhide the hidden SSID, meanwhile, MAC address can be easily spoofed. Fortunately, there is a feature that can be used to harden your wireless network. It is namely Protected Management Frames or IEEE 802.11w even it is still not a standard since 2009.
What are Protected Management Frames (IEEE 802.11w) ?
Wi-Fi CERTIFIED WPA2 with Protected Management Frames provides WPA2 protection for unicast and multicast management action frames. Unicast management action frames are protected from both eavesdropping and forging, and multicast management action frames are protected from forging. WPA2 with Protected Management Frames augments WPA2 privacy protections already in place for data frames with mechanisms to improve the resiliency of mission-critical networks.
In order to understand how does it work for the security of a wireless network, I did some experiments for the purpose.
Hardware
(1) Home wireless router with the feature of Protected Management Frames;
(2) Android 6.0 at 2.4GHz smartphone;
(3) Android 7.0 at 5GHz smartphone;
(3) Macbook Pro (Retina Mid 2012) with macOS High Sierra (10.13.4) at 5GHz;
(4) Macbook Air (Mid 2013) with macOS High Sierra (10.13.4) at 5GHz;
(4) Lenovo Thinkpad X201s (as 2.4GHz attacker); and
(5) TP-Link Archer T4UHP (as 2.4/5GHz attacker)
Software
(1) Parrot Security OS 4.0.1 64-bit;
(2) WAIDPS 1.0 R6j; and
(3) Aircrack-NG 1.2
Lenovo Thinkpad X201s installed Parrot Security OS 4.0.1 with the latest update and running WAIDPS which is powered by Aircrack-NG 1.2 as attacker.
The home wireless router and the testing wifi devices are set to WPA2 and AES encryption. The firmware of the wireless router is up-to-date. Since the home wireless router is dual bands, 2.4GHz and 5GHz, I set some of the testing devices to 5GHz. The home wireless router is set to AP mode as I already have a wired router in the network.
Once the 4-way handshake is captured from wireless router and devices, attackers can brute force the captured packets to obtain the passphrase of the wireless router.
Experiment
The Protected Management Frames can be set to "disabled", "capable" and "required" on the home wireless router.
(a) Disabled
When the Protected Management Frames (PMF) at the wireless router is set to "Disabled". All wireless devices can be disassociated and the 4-way handshake can be captured.
(b) Capable
When the PMF is set to "Capable" at the wireless router, all devices can connect to the router without problem. However, the wireless devices can be disassociated and the 4-way handshake can be captured.
(c) Required
When the PMF is set to "Required", only Macbook Pro and Macbook Air can be connected to the wireless router and it cannot be disassociated as well as the 4-way handshake cannot be captured.
(d) extra
When the PMF is set to "Capable" and all the devices are disconnected as well as re-connected to the wireless router, the 4-way handshake can be captured.
When the PMF is set to "Required" and Macbook Pro as well as Macbook Air are disconnected and re-connected to the wireless router, the 4-way handshake cannot be captured.
Conclusion
Purchase a wireless router that equipped with Protected Management Frames feature and set it to WPA2, AES and PMF to "Required" with wireless devices that compatible to PMF, such as macOS 10.13.4.
However, not all wireless routers and/or wireless devices are equipped with this feature even it is an expensive/high-end or commercial model.
Finally, when you find a wireless router that equipped with this feature, make sure to update the firmware to the latest version often.
By the way, I am unwilling to provide the brand name of the home wireless router that I tested. Sorry for that!
That's all! See you.
Open Source is a great idea and it has changed the world!
Open Source forever ....
While you do not know attack, how can you know about defense? (未知攻,焉知防?)
Do BAD things .... for the RIGHT reasons -- OWASP ZAP
It is easier to port a shell than a shell script. -- Larry Wall
Most of you are familiar with the virtues of a programmer. There are three, of course: laziness, impatience, and hubris. -- Larry Wall
为天地立心, 为生民立命, 为往圣继绝学, 为万世开太平。 -- 王炜
Showing posts with label Aircrack-ng. Show all posts
Showing posts with label Aircrack-ng. Show all posts
Monday, May 28, 2018
Tuesday, December 05, 2017
HOWTO : Wifi Penetration Testing Without Tears
Wifi everywhere! There are a lot of private and public wifi access points around you. Almost everyone will use wifi at anytime. The security of wifi should be taken into account.
The most common wifi frequencies are 2.4GHz and 5GHz at the time of this writing. 2.4GHz frequency channel range is between 1 and 14 while 5GHz frequency channel range is between 34 and 165. That's include a/b/g/n/ac modes.
You can even find some access points still using WEP but it is not common. Almost all access points are using WPA/WPA2. To get passphrase of WEP from access point is very easy. However, WPA/WPA2 is not very hard indeed.
When access point and client communicate, they will carrying out a four-way handshake in which the encrypted passhrase will also be transmitted between them. When attacker captures the four-way handshake, the encrypted passphrase is also captured in which it can get the passphrase by wordlists brute forcing.
To complete the capture steps, you need a tool namely Aircrack-ng. It is a very powerful wifi auditing tool. Furthermore, there is a good tool to brute forcing WPA/WPA2 key, it is Hashcat. Hashcat is very powerful tool for password recovery. Hashcat requires GPU to do the brute forcing job. The more powerful the GPU, the faster the process of brute forcing.
However, to carry out the wifi penetration testing is somehow very hard for some people. It is because it will involve a lot of steps and procedure to complete. In addition, you also need a workable wifi USB dongle or card to make the job done.
Current version of Aircrack-ng 1.2 RC4 does not fully compatible to 5GHz frequency. It is required to patch it and compile it yourself in Kali Linux.
Realtek 8812au chipset wifi USB dongle is ready for 5GHz frequency and penetration testing. The driver is required to compile and install on Kali Linux yourself too.
One of the automated tools for penetration testing wifi is WAIDPS. It also can act as intrusion detection and prevention system for wifi. It just a few keystrokes to complete the wifi penetration testing.
Reference
[1] List of WLAN channels
[2] Kali Linux
[3] Aircrack-ng Official Site
[4] WAIDPS - Wireless Auditing, Intrusion Detection and Prevention System
[5] Install Realtek 8812au Linux Driver
[6] Patch Aircrack-ng For 5GHz Band On Kali Linux 2017.3
[7] Hashcat Official Site
[8] Install Hashcat on Ubuntu 16.04.3
[9] TP-Link Archer T4UHP (Realtek 8812au chipset)
[10] ALFA AWUS036NH (Realtek 8812au chipset)
[11] D-Link DWA-171 Nano USB Adapter (Realtek 8812au chipset)
That's all! See you.
The most common wifi frequencies are 2.4GHz and 5GHz at the time of this writing. 2.4GHz frequency channel range is between 1 and 14 while 5GHz frequency channel range is between 34 and 165. That's include a/b/g/n/ac modes.
You can even find some access points still using WEP but it is not common. Almost all access points are using WPA/WPA2. To get passphrase of WEP from access point is very easy. However, WPA/WPA2 is not very hard indeed.
When access point and client communicate, they will carrying out a four-way handshake in which the encrypted passhrase will also be transmitted between them. When attacker captures the four-way handshake, the encrypted passphrase is also captured in which it can get the passphrase by wordlists brute forcing.
To complete the capture steps, you need a tool namely Aircrack-ng. It is a very powerful wifi auditing tool. Furthermore, there is a good tool to brute forcing WPA/WPA2 key, it is Hashcat. Hashcat is very powerful tool for password recovery. Hashcat requires GPU to do the brute forcing job. The more powerful the GPU, the faster the process of brute forcing.
However, to carry out the wifi penetration testing is somehow very hard for some people. It is because it will involve a lot of steps and procedure to complete. In addition, you also need a workable wifi USB dongle or card to make the job done.
Current version of Aircrack-ng 1.2 RC4 does not fully compatible to 5GHz frequency. It is required to patch it and compile it yourself in Kali Linux.
Realtek 8812au chipset wifi USB dongle is ready for 5GHz frequency and penetration testing. The driver is required to compile and install on Kali Linux yourself too.
One of the automated tools for penetration testing wifi is WAIDPS. It also can act as intrusion detection and prevention system for wifi. It just a few keystrokes to complete the wifi penetration testing.
Reference
[1] List of WLAN channels
[2] Kali Linux
[3] Aircrack-ng Official Site
[4] WAIDPS - Wireless Auditing, Intrusion Detection and Prevention System
[5] Install Realtek 8812au Linux Driver
[6] Patch Aircrack-ng For 5GHz Band On Kali Linux 2017.3
[7] Hashcat Official Site
[8] Install Hashcat on Ubuntu 16.04.3
[9] TP-Link Archer T4UHP (Realtek 8812au chipset)
[10] ALFA AWUS036NH (Realtek 8812au chipset)
[11] D-Link DWA-171 Nano USB Adapter (Realtek 8812au chipset)
That's all! See you.
Labels:
Aircrack-ng,
hashcat,
Kali Linux,
Realtek,
WAIDPS
HOWTO : Patch AirCrack-NG For 5GHz Band On Kali Linux 2017.3
Since AirCrack-NG release 1.2rc4 and github repository commit number 7552fdc do not detect 5GHz channel number properly, you need to use jpmv27's repository for the workaround till official is patched in the next release.
The following is the best way than this as it uses the latest source of AirCrack-NG from GitHub.
Step 1 :
Step 2 :
To patch for 5GHz band :
Step 3 :
To fix a typo :
Replace line 709 where
to
Step 4 :
Important
Make sure not to uninstall aircrack-ng by "apt" command as it will also uninstall some useful packages at the same time.
Kali Linux's Aircrack-ng is installed at /usr/bin and /usr/sbin while GitHub's Aircrack-ng is installed at /usr/local/bin and /usr/local/sbin. The $PATH will search for /usr/local first. Therefore, you will run GitHub version instead of original one.
When Kali Linux updated AirCrack-ng, you can uninstall the GitHub version by the following command when the source code is still there :
Remarks :
If using WAIDPS, make sure to use v1.0 R.6d (or newer) as it fixed for the newer aireplay-ng display.
Reference
5GHz Patch
Typo Patch
That's all! See you.
The following is the best way than this as it uses the latest source of AirCrack-NG from GitHub.
Step 1 :
apt install pkg-config libssl-dev libsqlite3-dev libnl-3-dev libnl-genl-3-dev libpcre3-devStep 2 :
To patch for 5GHz band :
git clone https://github.com/aircrack-ng/aircrack-ng
cd aircrack-ng/src
wget https://github.com/jpmv27/aircrack-ng/commit/8199c04357ea05daaf2de2ae7eebb28d30baef87.patch
patch < 8199c04357ea05daaf2de2ae7eebb28d30baef87.patchStep 3 :
To fix a typo :
nano bessid-ng.cReplace line 709 where
err(1, "wi_wirte()");to
err(1, "wi_write()");Step 4 :
make
make installImportant
Make sure not to uninstall aircrack-ng by "apt" command as it will also uninstall some useful packages at the same time.
Kali Linux's Aircrack-ng is installed at /usr/bin and /usr/sbin while GitHub's Aircrack-ng is installed at /usr/local/bin and /usr/local/sbin. The $PATH will search for /usr/local first. Therefore, you will run GitHub version instead of original one.
When Kali Linux updated AirCrack-ng, you can uninstall the GitHub version by the following command when the source code is still there :
cd aircrack-ng
make clean
make uninstallRemarks :
If using WAIDPS, make sure to use v1.0 R.6d (or newer) as it fixed for the newer aireplay-ng display.
Reference
5GHz Patch
Typo Patch
That's all! See you.
Labels:
Aircrack-ng,
Kali Linux
Sunday, December 03, 2017
HOWTO : Install Forked AirCrack-NG on Kali Linux 2017.3
Since AirCrack-NG release 1.2rc4 and github repository commit number 7552fdc do not detect 5GHz channel number properly, you need to use jpmv27's repository for the workaround till official is patched in the next release.
Step 1 :
Step 2 :
Step 3 :
Make sure not to uninstall aircrack-ng by "apt" command as it will also uninstall some useful packages at the same time.
That's all! See you.
Step 1 :
apt install pkg-config libssl-dev libsqlite3-dev libnl-3-dev libnl-genl-3-dev libpcre3-devStep 2 :
git clone https://github.com/jpmv27/aircrack-ng
cd aircrack-ngStep 3 :
make
make installMake sure not to uninstall aircrack-ng by "apt" command as it will also uninstall some useful packages at the same time.
That's all! See you.
Labels:
Aircrack-ng
Sunday, May 19, 2013
HOWTO : Aircrack-ng on Ubuntu Desktop 12.04 LTS
Aircrack-ng is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured. It implements the standard FMS attack along with some optimizations like KoreK attacks, as well as the all-new PTW attack, thus making the attack much faster compared to other WEP cracking tools.
In fact, Aircrack-ng is a set of tools for auditing wireless networks.
Step 1 :
Step 2 :
To run it with ALFA AWUS036NH (802.11 b/g Long-Range USB Adapter), you can run the command at any directory.
To test it if is is injectable or not.
Step 3 (Optional) :
For Intel Corporation PRO/Wireless 5100 AGN [Shiloh], you need the following commands :
Remarks
At this writing, I cannot find a way to solve the problem in airmon-ng or airmon-zc for ALFA AWUS036NHR. However, Pentoo 2013.0 RC1.1 is working perfectly for that adapter.
That's all! See you.
In fact, Aircrack-ng is a set of tools for auditing wireless networks.
Step 1 :
sudo apt-get install build-essential sqlite3 subversion ethtoolsudo -sH
cd /opt
svn co http://trac.aircrack-ng.org/svn/trunk aircrack-ng
cd /opt/aircrack-ng
make sqlite=true ext_scripts=true unstable=true
make sqlite=true ext_scripts=true unstable=true install
airodump-ng-oui-updateStep 2 :
To run it with ALFA AWUS036NH (802.11 b/g Long-Range USB Adapter), you can run the command at any directory.
sudo -sH
airmon-ng
airmon-ng start wlan1
airodump-ng mon0 -c 1To test it if is is injectable or not.
aireplay-ng -9 mon0Step 3 (Optional) :
For Intel Corporation PRO/Wireless 5100 AGN [Shiloh], you need the following commands :
sudo -sH
airmon-zc
airmon-ng start wlan3
airodump-ng wlan3mon -c 1Remarks
At this writing, I cannot find a way to solve the problem in airmon-ng or airmon-zc for ALFA AWUS036NHR. However, Pentoo 2013.0 RC1.1 is working perfectly for that adapter.
That's all! See you.
Labels:
Aircrack-ng,
Ubuntu
Subscribe to:
Posts (Atom)
