Gaming Cracking wifi networks

  • Thread starter Thread starter Pyrmon
  • Start date Start date
  • Views Views 3,221
  • Replies Replies 25
I really love how it works in the rest of the world. Here in Italy most of the people working in school doesn't even know what an Access Points is!
biggrin.gif


And btw 2 of the major ISP here fucked up big time with the default configuration of their routers and made WEP/WPA based on a formula calculated over the SSID (this one is on the form ISP-).
So once the formula went public it was nice to see a lot of apps out there which actually just calculate the WPA from the provided SSID.
tongue.gif
 
Originality said:
doyama said:
Originality said:
QUOTE said:
I'm an admin and if you're on my wifi and think I can't find you, you're in for a big surprise when my AirMagnet software can pin point your location to within a few meters by triangulating your wifi signal between several APs. There's stuff out there custom designed to find rouge APs and unauthorized people connecting to the network. Whether anyone is LOOKING at that stuff is a different story
My phone can do that too, although my school had the added benefit of having CCTV in every corridor, so it would be easier to track down exactly who was doing it even after the event.

I prefer to do the tracking from the comfort of my office. Then send my hired goons to beat you up in the washroom once I track you down. I just wish this stuff didn't cost an arm and a leg to buy and implement. Though with the spate of wifi security breaches its a bit easier to justify the cost these days.
Who'd need goons? I would hack the school computers right in front of your eyes, then show you all the computers/accounts on the system with clear evidence of them downloading illegal music/videos/games/porn. Sure, hacking school networks is a criminal act, but I think I would be forgiven if it brings to light worse criminal activity taking place in the school (kids should not be downloading porn at school).
you're thinking wrong there now.
 
Sysadmins can see the name of the iPods on their network, so tell your friends to rename their touches.

What I did with my school network is I ran backtrack in the bathroom, then put it in my backpack and took it out after several minutes (teacher, can i go to my locker, etc) to write down the code. I had a netbook so heat wasn't an issue.
 
doyama said:
Berthenk said:
Coto said:
doyama said:
Cracking WEP is pretty easy using backtrack. The only way to really crack WPA/WPA2 is to use rainbow tables or massive dictionary attacks.

I think you should speak more about that right now..

=p
Because it's really hard to look it up on Wikipedia.

Well here's the 10,000ft view for the illiterate. Rainbow tables are used to quickly hack keys that fit particular criteria. In this case, WPA/WPA2 keys that are

1) in a list of well known SSID
2) have a weak password that is in a dictionary

Rainbow tables compile lists of these so you can quickly (within a few minutes) determine the key. So the person setting up the WPA needs to be pretty stupid on 2 fronts, not changing the default SSID (linksys, dd-wrt, default, etc), and then subsequently chooses a crappy password that's in a dictionary. These tables are usually 10-15GB in size so definitely a big chunk to download.

Think of it this way, rainbow tables are like having the answers to a test, but only a very specific kind of test that is multiple choice(easy if the test fits the criteria, but you're screwed otherwise). Dictionary attacks are more like having a cheat sheet for an essay style test (more generic to fit many situations, but requires more work on your end).

--------------------

Now that we've discussed how to do this I think I really need to reiterate something

DO THIS AT YOUR OWN RISK!!!!!

I've done it and it took me a few days to figure it out the first time. It was a lot of fun to try and figure stuff out and understand what each script was doing and how it fed into each other. Also just the technical aspects were fascinating as well. It's fun and all.

But at the end of the day once I had 'hacked' a WEP point, I realized, hey do I really want to keep going here? I can see their computers, even how many DVR setups they had. It really felt wrong after that. I wasn't just hacking some soulless corporation. It was some family with some kids by the names on their computers.

The process was fun and all, but in the end I decided not to continue using the AP. I had learned what I needed to and really that was worth more than 'free wifi'

Doyama, I see your point =)

I´ve been practicing these techniques for ages and there´s a long road we´ve taken. I´d do this because it´s fun to learn "the way you could change a value, and it would overreact into a different formula" much like chemistry.

So no worries, here and thanks for yer explanation. I have learned a new term
 
pyrmon24 said:
I was considering aircrack-ng, but I wanted to know if there were any better alternatives.
That takes a minute and you have to inject all of your packets and learn all the commands for it. I may be wrong but last time i tried to use it on an iphone it took some time to learn.

pyrmon24 said:
QUOTE(Fishaman P @ Apr 8 2011, 12:23 PM) Not just suspended, expelled AND criminally charged.

Although they probably have VERY nice download speeds...
My school is in my state's 99th percentile, and the U.S.'s 98th percentile.
I don't think they will be able to trace me if they don't know I have a laptop...
If your school is smart on the subject they will make you login if you plug a foreign device in to the network and if not they could always seize everyones property and search through all of them for the correct MAC address.
 
A lot of schools require all users to log in to access the internet (and the user name they log in as defines what level of permissions they get). I've also encountered a couple schools where, if you didn't have a certain type of security software running on your device, it would not let you use the internet even if you did log in using your own name.

There are ways to prevent anybody from stealing school internet. It just depends on how the security is set up.
 

Site & Scene News

Popular threads in this forum