3 ms·
Wait you already have the wpa preshared key? Why would you go the trouble of creating a clone network when you can already join the actual network and arpspoof
by jpablo 6y ago
Wait you already have the wpa preshared key? Why would you go the trouble of creating a clone network when you can already join the actual network and arpspoof at will?
- jedberg 6y agoIt's a way to capture them away from the office.
- jpablo 6y agoSo the attack is: 1. Have access to their computer to retrieve the wpa key. 2. Create a clone of the wifi network, spoof a bunch of sites and hope to catch one that doesn't use http. Why can't I replace step 2 with: Install a root kit since I already have access to their machine.
- jedberg 6y agoNo, it's "have access to any of their co-worker's computers". Or be a former coworker who still has the access key. Or even be a current coworker.
- jpablo 6y agoSeems a bit complicated: 1. Find some one to steal a key from but which I don't care about. 2. Locate a third person that I want to target and move close to them in non office hours. 3. Create a clone of their wifi and try to spoof some website. Hopefully I can be close enough to their device that it would join my clone instead of their other preferred networks. At step 2 seems like a better idea to move close to the office and start probing around?
- jedberg 6y agoTo get that close to the office would be very obvious. You'd have to loiter all day or set up a remote host with some power. To get near a target in the wild isn't that hard, especially if you know where they like to go on a regular basis. It's lot easier than a lot of other methods, especially for a high level target like a C-level exec who might have access to bank accounts with millions of dollars and like to work at a local coffee shop on weekends.
- ChuckMcM 6y agoYou don't have to spoof sites. If you capture the client they will invariably use DHCP to get an address and you can pass along that you are the web proxy for HTTP/HTTPS. Voila, all your bases are belong to us, right?
- Chickenosaurus 6y agoThat might work nicely for plain TCP traffic, but it's not very useful for TLS encrypted connections by itself. An attacker wants to decrypt the packets passed on as the man in the middle without alerting the victim. A big red "insecure connection" browser warning due to an untrusted certificate used by the MITM can easily thwart the attack. To make this work, the attacker needs access to a CA the victim trusts to sign certificates on the fly. If the attack is limited to a single target page, stealing the associated private key from the legitimate website operator is an option, too.
- iso1210 6y agoBlock port 443 and hope sites aren't configured to upgrade insecure requests. Redirect all traffic to a site which looks like the corporation you're spoofing, asking for corporate login credentials, how many will enter them reflexively, especially with poor corporations that ask for authentication on a frequent basis. From memory captive hotspot popups on apple devices at least don't even show the URL they have loaded, but www.targetcorp.com-secure.com etc works well in many cases.
- redprince 6y ago* It may have client isolation enabled though that thwarts certain critical use cases like having those private, wifi enabled boom boxes on the corporate WLAN... * The goal stated in the article is to lure clients onto a rogue AP far away from the office anyway.
- ChuckMcM 6y agoOne might choose to do this because the admins thought they were "smart" and said, "Oh, I know, we will only allow 'known' MAC addresses to connect to the network! That will fix it." And it does, kinda. Except it doesn't stop you from capturing clients on your "fake" network, and the goal isn't necessarily to be on the "real" network, the goal might be to just man-in-the-middle a juicy site or two, with is on the big Internet (say, the company's bank) Capture the controller's login into the bank and win "free money"
- jpablo 6y agoMac address restriction provide zero access control. It's trivial to sniff and spoof them.
- ChuckMcM 6y agoNot disagreeing with you here, I am wondering however if you have ever surveyed or even had casual conversation with people who self identify as "an IT person at company <X>." In my discussions with such people[1], I have found that a preponderance of them believe that a MAC address filter is a strong protection against unauthorized equipment on their wireless network. [1] I have had many occasions in my career where I have hired people in the IT/Ops role and during the interview process I have often probed their understanding of the plumbing of IT beyond the parameters necessary to enter on a screen in order to get something "up." My admittedly non-scientific sampling suggests that "knowing the plumbing" is not a valued skill for many of these people.