4 ms·
Well thank you, but that's not useful. Would you mind pointing out some examples of wrong statements? Otherwise I'm none the wiser :(
by ipince 13y ago
Well thank you, but that's not useful. Would you mind pointing out some examples of wrong statements? Otherwise I'm none the wiser :(
- hug 13y agoTo be honest, the article isn't really all that wrong or sensationalist - It's a little bit simplified in some spots but for the most part is an accurate depiction of how simple it is to perform man-in-the-middle attacks on the unsuspecting with a device running Karma. I'm not sure which exact points of article your parent poster has an issue with, though so I can't rebut his arguments. The first paragraph is relatively straightforward - just posting to HTTPS isn't enough. Your login form has to be HTTPS too, and not mixed-mode. Inject a javascript keylogger into your login form which you served over HTTP? Don't mind if I do. The rest of the article is just a tutorial on how to get to the point where you can do something like that, by using the Pineapple. Yes, Karma does actually work like explained in the article, and yes, clients will connect to any AP running Karma or a similar implementation, and it will do it for the exact reason he stated: They will broadcast the SSIDs they 'remember'. Once they're connected to your AP, well, you're on the path between them and anything they try to visit. That's pretty much the definition of being a man in the middle. The article doesn't go too deep into what you can do and simply mentions that you can take a look at HTTP traffic -- If you can look at it, you can modify it on the fly. If you can do that you can spin up something like SSLstrip[0], or drop in a java driveby or... well, anything you can imagine doing to traffic on the wire. Note that the pineapple is not the only device that can do this. There's all sorts of things like the expensive and super sneaky Pwn Plug[1] to something like a hand-made minipwner[2] which you can put together with $30 and a bunch of spare time. [0] http://www.thoughtcrime.org/software/sslstrip/ http://www.thoughtcrime.org/software/sslstrip/ [1] http://pwnieexpress.com/products/pwnplug-elite http://pwnieexpress.com/products/pwnplug-elite [2] http://www.minipwner.com/ http://www.minipwner.com/
- alan_cx 13y agoGiven that it is a "beginners guide to....", it would be simplified and not go deep.