18
SkyJacker Theft from Above Imagine RIT 2014

SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless

Embed Size (px)

Citation preview

Page 1: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless

SkyJackerTheft from Above

Imagine RIT 2014

Page 2: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless

• Service Set Identifier (SSID)o human readable “network name”

• Devices store past SSID connections

Wireless Basics

Page 3: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless

• Steps for connectiono Probingo Authenticationo Association

• Probingo activeo passive

Wireless Basics

Page 4: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless

Wireless Basics (Probing)

• Active Directed Probeo client sends a named-specific SSID

AP with that SSID replies with probe response

Page 5: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless
Page 6: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless

Wireless Basics (Probing)

• Active Broadcast Probeo client sends a null SSID

all APs send probe response

Page 7: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless
Page 8: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless
Page 9: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless

More About Probe Requests

• Sent by devices seeking connection

• Devices will automatically connect to previously associated access points

• Requests are NOT secret

Page 10: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless

Mobile Devices Probe Requests

• iPad o probes for last three associated APs

• iPhoneo probe based on movement

• Androido probe based on movement

Page 11: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless
Page 12: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless

Why Should I Care?

• Unique SSID given in probe requesto use www.wigle.net to determine physical location

• Rogue Access Point with same SSIDo device will automatically connecto redirection of traffic/traffic injection

Page 13: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless
Page 14: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless
Page 15: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless

Enter SkyJacker

• Capture and display probe requests

• Imitate access pointo create rogue APo redirection of traffic

Page 16: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless
Page 17: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless
Page 18: SkyJacker Theft from Above Imagine RIT 2014. Service Set Identifier (SSID) o human readable “network name” Devices store past SSID connections Wireless