4 ms·
As mentioned in the top answer, not only will the AP know the MAC address of your device, it will also know the SSID you are looking for. There are exploits al
by nmc 13y ago
As mentioned in the top answer, not only will the AP know the MAC address of your device, it will also know the SSID you are looking for.
There are exploits allowing an AP to dynamically switch SSID, in order to impersonate the "known AP" you were scanning for. (Looking for a reference...)
EDIT: reference (student paper) -> https://www.os3.nl/_media/2012-2013/courses/ssn/open_wifi_ssid_broadcast_vulnerability.pdf https://www.os3.nl/_media/2012-2013/courses/ssn/open_wifi_ss...
- deleted 13y ago[deleted]
- NKCSS 13y agoVery cool paper, thanks!
- jonmrodriguez 13y agoThe slang term you want is "wifi pineapple". You can even buy pre-programmed ones online. https://www.google.com/search?q=wifi+pineapple https://www.google.com/search?q=wifi+pineapple
- vezzy-fnord 13y agoThe attack in particular is named KARMA.
- noselasd 13y agoAnd it's even very easy to exploit. You connected your phone/whatever to an open wifi network once ? Well, now it'll probably go looking for that network wherever you go, since the device will basically go and broadcast "Where is SSID XYZ ?". Making it easy for anyone to switch the SSID on their AP, turn off authentication , and your phone connects to it - and probably starts pulling updates from your services. Just hope that's done over SSL/HTTPS and that the app validates the certificates.
- uptown 13y agoSo with this technique, would someone be able to change the SSID of their router to match that of another nearby router where devices are likely to be attempting to connect in an effort to intercept the passwords being supplied to establish the connection to the router originally using that SSID?
- user24 13y agoYes, doesn't have to be a nearby router though. The point is: your device broadcasts the names of all routers it's connected to. You just need to listen, then spoof the name, then the device will connect to you. If the target device is already connected, you just need to DoS the router it's connected to and the device will reset the connection and start looking again. There are probably more elegant ways to force a reconnect than a simple DoS attack too.
- user24 13y agorepledit to mention that this only works for open routers.
- maxerickson 13y agoThe WPA handshake is such that the password won't be leaked to an imposter router.
- user24 13y agoNot only that but also, as SSIDs are often unique, it's possible to completely passively track all the locations your device has been. More info in this talk: https://www.youtube.com/watch?v=03iEaKPRb9A https://www.youtube.com/watch?v=03iEaKPRb9A
- VMG 13y agoWhy wouldn't the default behavior be to not connect with the AP if the required authentication doesn't match the stored one? Then the attacker would at least have to try different auth modes until the device connects.
- 7952 13y agoIt would be interesting to build something to detect an impersonating AP. You could just search for a random non-existent SSID and log when a connection is made.
- stygiansonic 13y agoThis would be a good honeypot. Randomly generate a 32-character SSID and send out a probe request with that. To have greater confidence, you could randomly generate another SSID and send out another probe request. If both are accepted with a similar signal and noise level, perhaps it is one of these karma APs. (The process could be fine-tuned, generating N number of random SSIDs and specifying the range for signal noise levels) You could then war drive to amass a location of suspected karma APs.
- inoop 13y agoAnd here's a neat trick: as soon as you detect a device from overhearing its probe request, spam it with CTS messages. As per 802.11 spec, it will have to reply with an RTS as long as its not associated. You'll be able to track devices if you have multiple APs deployed, or just detect whether someone is within a ~100-meter radius.
- dzhiurgis 13y agoHow are shops not doing this yet? If you are shop owner, you could pretty accurately know where are your customers living.
- syntheticnature 13y agoLess technical know-how needed to get customers to sign up for the store rewards card, and no one will complain about you using that data.
- maxerickson 13y agoI've been asked for an address when making a $5 cash purchase. I have the baseless impression that it is marketing seminar advice that small specialty businesses get (That is, collecting addresses).
- MrUnknown 13y agoThey are http://lifehacker.com/how-retail-stores-track-you-using-your-smartphone-and-827512308 http://lifehacker.com/how-retail-stores-track-you-using-your... They use it to track your movements in the store. I forget the name of the most popular provider.