Site Network: Home | Security @ iTrain |

Fonera (part 1)

Guess what came thru mail today? My Fonera Router! I managed to get only ONE for now... (note : must source more for Mr AW).

For those who are wondering, Fonera-what? It is a wifi-router. But it is not an ordinary wifi router... it has be used for EVIL! This router uses an atheros chip and we all know that atheros chipset are widely supported in wireless hacking (aircrack-ng). So there is a guide on the web that teaches how to transform your fonera router into a hacking router. It wont be easy, but it will lots of fun!

For now, I will tempt you all by few pictures that I took today ....


The router came! From Hong Kong... looks like it took a beating on the way down to Malaysia...


Tada! Opening ceremony! You can see that the inner box is in good shape, thanks to the nice packaging they did...



What's inside? CD, Stickers, Fonera, cables and power adapter (240v!)



And this is how small the router is! Compare it to a normal household blade...


That's all for today... If I managed to squeeze some time, I should have a Fonera Router to add to my collection of WRT54g drone and WRT54g Faizura


I think by now Cain and Abel makers (oxid) are on to us. Their downloading mechanism looks like has improved. Last time we could download direct from the link. Guess they have some-kind of link protector.

But fret not. This posting is not to rant about the download mechanism found on cain and abel but about cain and abel + wireless sniffing.

We all know Cain and Abel works wondrous on wired LAN. The question is, what about the ever-popular wireless? (aka "wifi"). This idea came on while chatting with a particular someone after work (name? We will call him Mr AW, for now... :) ).

We were contemplating on the idea of Arp spoofing on wireless. Stealing password across wireless network (how cool is that?). So, we did some testing and here are the result.


CAIN AND ABEL WIRELESS SNIFFFING
- software used : Cain and Abel v Cain & Abel 4.9.14(used the Winpcap that was bundled in the software)
- wireless card : Linksys WUSB54g and Buffalo WLI-CB-G54HP
- result: Sniffing on wireless network (unencrypted, WEP, WPA) = SUCCESS!

Further investigation shows a link for the reported working wireless card (good news to Intel 3945, you guys are supported!) --> Click here to visit the link

Will try on my other wireless card (Netgear WG511t, Ubiquiti SRC 300mW,)

Events!


iTrain is hosting their highly-successful rm50 event (again). Why they called it rm50? Cause that what the course fee is! Spend your Saturday with them to gain knowledge in programming or security, for only rm50.

And for this month, is a combo! Programming and Security! For those Silverlight, Widget or Wireless Nut, don't miss this opportunity.



To register for the event, click on this link.


History

Another case study. Today we will be looking at devices that you plug into your computer. Mp3 players, usb toys, digital frames

There is W32.Rajump, which deposits the same piece of malware that infected some of Apple's video iPods during manufacturing in October 2006. It gathers Internet Protocol addresses and port numbers from infected PCs and ships them out, according to Symantec. One destination is registered to a service in China that allows people to conceal their own IP addresses.


Makes you kinda think twice when anyone gives you a usb based present, eh?


image courtesy of cain and abel

Cain and Abel, which can be found over here -> Cain and Abel , is indeed a wonderful tool to have. It has many features that can be used to exploit a Windows based pc.

The latest version is faster and contains a lot of new features like APR (Arp Poison Routing) which enables sniffing on switched LANs and Man-in-the-Middle attacks. The sniffer in this version can also analyze encrypted protocols such as SSH-1 and HTTPS, and contains filters to capture credentials from a wide range of authentication mechanisms.


Cain and Abel can do wondrous thing. From cracking passwords, deploying backdoor services to a remote computer to sniffing password across network (HTTPS included!), Cain and Abel can do it with ease...

We all know and lead to believe that HTTPS is the answer to the weakness found in the ol' HTTP (where password are sent in clear text). HTTPS tries to change the weakness by deploying a certificate, used to decrypt and encrypt HTTP data transfer.

Cain and Abel manages to decrypt HTTPS traffic due to its ability to perform a Man-In-The-Middle attack (MiTM). This attack is quite well-known and have been much discussed by many. In a nutshell, just say that you are making a phone call to your girlfriend. The person that would have the ability to record and hear your conversation with your girlfriend would be your telco provider, wont it? So that how MiTM works. By placing himself / hacker between you and the webserver, he can read and monitor your data transfer. Sounds scary, eh? What about online banking?

A lot of online banks uses HTTPS to encrypt the password send across network and many social networking website like friendster, myspace, facebook just use good ol' HTTP.

To learn more about the attack, you can view Brian Wilson video on Cain and Abel, sniffing password across the network over here. Now remember that in this kind of attack, you are flooding your switch to become a hub. And in HTTPS traffic capture, the end user will receive a pop-up, asking them to accept a certificate. If the end user doesnt accept the certificate, he/she couldnt view the webpage. So needless to say, the end user have to accept the certificate popup in order to view his online banking page.

In short, you can deploy new algorithm of encryption on today widely used protocols (HTTP, FTP, POP, SMTP). But if the protocol itself has problems, don't expect the new encryption would mask the weakness. It would still be there. So unless someone creates a new protocol to replace HTTP TCP Stack, your password can be sniffed....



SecurAsia Congress 2008

It's back! Held at the Matrade Exhibition & Convention Centre, KL on the 25th and 26th march 2008!



more info here


It reminded me of the time I spoke for them in the first Securasia Congress Event. I even demo-ed thumbdrive hacking there...

History

Case Study time! And this time we are looking at thumbdrive, boon or bane?


Let's learn from our mistakes, shall we?