Tmplab hostile wrt-5-hacklu

22
HostileWRT Reclaim Your Spectrum Eugene Parkinson, Philippe Langlois http://www.tmplab.org http://www.p1security.com

Transcript of Tmplab hostile wrt-5-hacklu

Page 1: Tmplab hostile wrt-5-hacklu

HostileWRT

Reclaim Your Spectrum

Eugene Parkinson, Philippe Langlois

http://www.tmplab.org

http://www.p1security.com

Page 2: Tmplab hostile wrt-5-hacklu

Why HostileWRT?

•Wireless Security Audit

•Controlled envt only

•Inside an industrial site

•Big number of AP to audit

•Need for Ultra-Fast setup

•Access to friends’ network

•Beware of the law! Need author.

Page 3: Tmplab hostile wrt-5-hacklu

What is HostileWRT?

•Based on OpenWRT (www.openwrt.org)

•Script to automate WiFi actions

•Packages for aircrack-ng

•WiFi networks: LoveWRT

•Great hardware: FON2

Page 4: Tmplab hostile wrt-5-hacklu

Routeur HADOPI Scandal

•This IS NOT!

•But...

•It may be used this way...

•...if you don’t respect the law

•Of course, you should not

Page 5: Tmplab hostile wrt-5-hacklu

Limitations

•Small Memory

•Slow CPU

•No internet

•or rarefied (IPoICMP, IPoDNS)

Page 6: Tmplab hostile wrt-5-hacklu

Behaviours•== Modes

•Fast Setup

•Auto-join on first crack

•Mass Audit

•Collect and crack

•Key size dependent? (big: crack later, small: crack now)

•Multi-ops mode

•AP / STA / MONITOR

Page 7: Tmplab hostile wrt-5-hacklu

Plug-ins

•Hooks

•For each event

•On start

•On WEP attack working

•On WEP attack start

•On WEP key found

•Open Generic Model

•On client detect

Page 8: Tmplab hostile wrt-5-hacklu

Demo & Internals

Page 9: Tmplab hostile wrt-5-hacklu
Page 10: Tmplab hostile wrt-5-hacklu
Page 11: Tmplab hostile wrt-5-hacklu
Page 12: Tmplab hostile wrt-5-hacklu

Roadmap

•What works

•Scan

•WEP crack

•Client Mode (stability?)

•AP Mode (channel changing)

•What’s next

•Web UI, QA

•Resistant WEPs, WPA with Kalk

Page 13: Tmplab hostile wrt-5-hacklu

Hacks: Mobile

•Batteries

•Car, Bicycle-based

•FridaV example

•Already using OpenWRT

•Thanks to Ljudmila hackerspace

Page 14: Tmplab hostile wrt-5-hacklu

Hacks: Hiding

•Industrial boxes

•Lightpost

•Office ceiling

•Others...

Page 15: Tmplab hostile wrt-5-hacklu

Hacks: Antennas

•Omni

•HSB Mighty Waveguide hacks

•NZ DIY antennas

•Coffee box

•Is THIS ridiculous???

•Yagi

Page 16: Tmplab hostile wrt-5-hacklu

Hacks: Connecting things

•GPIO: SPI, I2C

•Chemical Sensors

•Thanks Sebastien B.

•Radioactivity diodes

•Thanks M

Page 17: Tmplab hostile wrt-5-hacklu

SSID to Wordlists

•New in 0.3.2

•Guess the best dictionaries for your country

•SSID list gives fingerprint

•SSID patterns, FR: Livebox_

•You can contribute for your Country

•Hint: .hr, .pl, .hu, ...

Page 18: Tmplab hostile wrt-5-hacklu

Bugs

•NO STORAGE ON FLASH!!!!

•Pwweez don’t crash your AP

•Newest AP (Fon2N?)

•airdecloak-ng

•None other known... :)

Page 19: Tmplab hostile wrt-5-hacklu

Future

•Mesh networks (BABEL?!)

•Datagram control (BOTmode)

•Captive portal fishing test

•Reliable IPoDNS, IPoICMP

•Anonymous Browsing (TOR?)

•Industrial solution (reporting, mgmt, dual approach)

Page 20: Tmplab hostile wrt-5-hacklu

Help Needed

•Developpers

•Testers

•Real-world experience feedback

•IPoXXX endpoints / exit nodes

•Resistant WEP tricks

•WPA Crypto+FPGA Genius? (K!LK!)

Page 21: Tmplab hostile wrt-5-hacklu

Credits

•The OpenWRT project

•XXX for FONbook on batteries

•Loloster

•All the /tmp/lab crew

Page 22: Tmplab hostile wrt-5-hacklu

Thanks! Merci!Work In Progress @ /tmp/lab

Come meet us

http://www.tmplab.org

http://www.p1security.com