Wireless Security (Hacking Wifi)
by
Wiker M Sinambela
Josh email at gadjahmada.edu
website http://josh.staff.ugm.ac.id
Wifi networks have more weakness than with the cable network. Current
wifi technology development is very significant in line with the needs of the information system
mobile. Many wireless service providers such as commercial hotspot, ISP, Garnet, campuses
and the office has started to use the wifi network each, but the very
a few are considering the security of data communications on the wireless network. This is
make the hacker be interested to mengexplore keamampuannya
various illegal activities, which are usually use the wifi.
In this article will discuss various types of activities and methods that do the hackers
wireless or the newcomer in their wardriving. Wardriving is an activity or
activities to obtain information about a wifi network and gain access to
the wireless network. Generally, aims to connect to the Internet, but many
also make for a specific purpose, meaning from the sense of curiosity, try try,
research, lab work, crime and others.
Wireless Weakness
Cons wireless networks in general can be divided into 2 types, namely, the weakness in the
configuration and the weakness in the type of encryption used. One example of the causes of
weakness in the current configuration as to build a wireless network enough
easy. Many vendors that provide facilities that ease the user or admin
network, so often found that the wireless still use the default wireless configuration
default vendor. Writers often find that wireless networks are installed in
using default settings, such as vendor default SSID, IP Address, remote management, DHCP
enable, frequency channel, without encryption and even user / password for the wireless administration.
WEP (wired equivalent privacy) is a wireless security standard, the current
can easily be solved with the various tools available for free on the Internet. WPA-PSK
LEAP and is considered to be the solution that replaces WEP, is currently also have to be resolved
Attack with the method dictionary offline.
Some of the activities and the activities conducted for mengamanan wireless network, among others:
1. Hide the SSID
Many administrators hide Services Set Id (SSID) wireless network with their
meaning that only the know the SSID to connect to their network. This
is not correct, because the SSID can not actually disembuyikan perfectly. At the time
or especially when the client will connect (assosiate) or when the resignation will be decided
(deauthentication) from a wireless network, then the client will still send the SSID
the form of plain text (although the use of encryption), so if we menyadapnya means,
could easily find information. Some tools that can be used for
ssid get the dihidden among others, kismet (kisMAC), ssid_jack (airjack), aircrack,
void11 and many more.
2. Wireless security only with the WEP key
WEP is a standard security and encryption first used in wireless, WEP
have various weaknesses include:
? The key problem is weak, the RC4 algorithm used can be solved.
? WEP key using a static
? Initialization vector problem (IV) WEP
? The problem of message integrity Cyclic Redundancy Check (CRC-32)
WEP consists of two levels, namely, the key 64 bit, and 128 bits. In fact, the key secret
64 bit WEP key only 40 bits, is a 24bit Initialisation Vector (IV). Similarly
in the 128-bit WEP key, the key secret of 104bit.
Attacks on the weakness of the WEP, among others:
- Weaknesses initialising attacks against vectors (IV), often called the FMS Attack. FMS
abbreviation of the name of the third inventor weakness, namely IV Fluhrer, Mantin, and Shamir.
The attack was carried out by a weak IV collect as much as possible.
The more IV weak obtained, the more quickly found the key that is used
(Www.drizzle.com/ aboba/IEEE/rc4_ksaproc.pdf!)
- Obtain IV through a unique packet of data to be processed for the process
cracking the WEP key more quickly. This is called chopping Attack, first
found by h1kari. This technique only requires a unique IV will reduce the
IV needs to do in a weak WEP cracking.
- Both attacks over time and packing enough, to shorten
time, the hackers usually do the sort of injection. Traffic is often Injection
is done by collecting ARP packet and send back
to the access point. This resulted in the collection of the initial vectors more easily and quickly.
Contrasting with the first and second attack, to attack traffic injection, is required
specification tools and applications that start rarely found in shops, from the
chipsets, firmware version, and version of the driver and not infrequently have to do patching
against the driver and application.
3. Only with the wireless security key WPA-PSK, or WPA2-PSK
WPA is a temporary security technology that was created to replace the key
WEP. There are two types of personal namely WPA (WPA-PSK), and WPA-radius.
While this may have on Crack is WPA-PSK, namely, the brute force method with force
Attack offline. Brute force using force to try-try a lot of words
dictionary. This attack will be successful if the passphrase used the wireless
terapat in the dictionary used the word hacker.
To prevent any attacks against the security of wireless use WPA-PSK,
use the passphrase long enough (one sentence).
Tools that are used to make known this attack is CoWPAtty (
http://www.churchofwifi.org/) and aircrack (http://www.aircrack-ng.org). These tools
requires a list of words or wordlist, can be taken from http://wordlist.sourceforge.net/
4. MAC filtering
Almost any wireless router or access point facilitated by the MAC security
Filtering. This is actually not much help to secure the communication
wireless, because the MAC address is very easy dispoofing or even amended.
Ifconfig tools on a Linux OS / Unix, or a variety of tools, ie the network utilitis, regedit, smac,
machange windows on the OS easily be used to replace or spoofing
MAC address.
I still often find wifi in the office and even the ISP (which usually
used by the cafe-cafe), which only use MAC filtering protection. With
use wardriving applications such as kismet / kisMAC or aircrack tools, can
information obtained MAC address of each client that is connected to an Access Point.
After getting the information, we can connect to the Access to the point
change the MAC in accordance with the client was. In the wireless network, duplicate MAC adress
does not lead to conflict. IP, which requires only vary with the client that was.
5. Captive portal
Infrastructure captive portal originally designed for the needs of the community
allows all people can connect (open network). Actual captive portal
the engine is a router or gateway, or the beauty and not allow any traffic
users to perform registration / authentication. Here's how to work captive portal:
? users with a wireless client allowed to connect to wireless IP
address (DHCP)
? block all traffic except that the captive portal (Registration / Authentication based
web), which is located on the cable network.
? belokkan or redirect all traffic to a captive web portal
? after the user to make registration or login, allow access to the network (the Internet)
Seminar on Open Source Hacking Wifi and 23 January 2007 Yogyakarta AMIKOM @
Wiker M Sinambela
Several things need to be, that the captive portal only connection tracking
client based on the IP and MAC address after authentication. This makes captive
portal is still possible to be used without authentication because the IP and MAC adress can dispoofing.
Attacks do with the MAC and IP spoofing. Spoofing the MAC adress like that
described in section 4 above. Moderate to IP spoofing, the more effort is needed, namely
by using ARP cache poisoning, we can redirect traffic from the client
has been connected before.
Other attacks that are easy enough to use Rogue AP, which is set up Access
Point (usually use HostAP) using the same component information such as
AP targets such as the SSID, BSSID canal to the frequency used. So when a client
which will be connected to the AP made us, we can divert traffic to the actual AP.
Not infrequently captive portal built on a Hotspot have weaknesses in the configuration
or network design. For example, authentication is still using plain text (http), management
network can be accessed via wireless (located on a network), and many more.
Another weakness of the captive portal is that the communications traffic data, or when they have been
do authentication (connected to the network) will be sent is still not encrypted, so
can easily disadap by hackers. The need to be careful to make the connection
Hotspot network, to organize the use of secure communication protocols such as
https, pop3s, ssh, etc. imaps.
Seminar on Open Source Hacking Wifi and 23 January 2007 @ AMIKOM Yogyakarta
Wiker M Sinambela
Links
- ALJAZEERA TV
- ANTARA
- Bali`s Blogger
- BBC
- BERITANET.COM
- CHIP ONLINE
- CNN
- DETIK.COM
- E-BOOK
- Economic
- Friends
- Friendster's Blog
- Habibieafsyah
- HARVARD UNIVERSITY
- ILMU KOMPUTER
- INFO LINUX
- KICK ANDY
- LINUX OpenSuse
- LINUX SLAX
- Linux Temanggung
- LINUX UBUNTU
- LIPUTAN 6 SCTV
- MASTER BLOGGER
- METROTV NEWS
- MUSIC DOWNLOAD
- My Class
- Robotic AMIKOM
- SMA N 3 TEMANGGUNG
- SMART E-LEARNING
- SOFTPEDIA
- STMIK AMIKOM
- SUPPORTED BLOGGER
- TIPS TRICKS
- TRIAL FILM
- TV ONE ONLINE
Blog Archive
-
►
2009
(38)
- ► 05/31 - 06/07 (1)
- ► 02/15 - 02/22 (1)
- ► 01/11 - 01/18 (11)
- ► 01/04 - 01/11 (25)
-
▼
2008
(70)
- ► 11/30 - 12/07 (22)
- ► 11/16 - 11/23 (18)
- ► 11/09 - 11/16 (1)
- ► 10/26 - 11/02 (5)
-
▼
10/19 - 10/26
(16)
- Indonesia exports prospective in Middle East, New ...
- Emerging Global recession concerns, the World Stoc...
- Construct A New Currency
- Maya Soetoro, Barack Obama Secret Weapon
- Barack Obama
- Program interuption
- Chipertext part1
- Hacking WiFi
- Linux part 4
- Linux part 3
- C ++ part 4
- C ++ part 3
- C ++ part 2
- C ++ part 1
- Basic Policy Linux part 3
- Basic Policy Linux part 2
- ► 10/12 - 10/19 (4)
- ► 10/05 - 10/12 (4)


0 comments:
Post a Comment