Skip the navigation
Opinion

Inside the hacker's toolbox

By Brian Moran
July 17, 2003 12:00 PM ET

Computerworld -

Hackers—as well as white hat researchers—are notorious for quickly breaking the new security standards soon after the standards are released and they did so again with the standards for wireless LANs. The following are a few examples of the hardware and freeware tools available on the Internet.


  • Freeware tools: New WLAN hacking tools are introduced every week and are widely available on the Internet for anyone to download. Rather than wait for a hacker to attack your network, security managers should familiarize themselves with tools and learn how to defend against them. The table on this page gives a few examples of widely available freeware tools.






















































  • Tool Description
    NetStumbler Freeware wireless access point identifier – listens for SSIDs & sends beacons as probes searching for access points
    Kismet Freeware wireless sniffer and monitor – passively monitors wireless traffic & sorts data to identify SSIDs, MAC addresses, channels and connection speeds
    Wellenreiter Freeware WLAN discovery tool – Uses brute force to identify low traffic access points; hides your real MAC; integrates with GPS
    THC-RUT Freeware WLAN discovery tool – Uses brute force to identify low traffic access points; “your first knife on a foreign network”
    Ethereal Freeware WLAN analyzer – interactively browse the capture data, viewing summary and detail information for all observed wireless traffic
    WEPCrack Freeware encryption breaker – Cracks 802.11 WEP encryption keys using the latest discovered weakness of RC4 key scheduling
    AirSnort Freeware encryption breaker – passively monitoring transmissions, computing the encryption key when enough packets have been gathered
    HostAP Converts a WLAN station to function as an access point; (Available for WLAN cards that are based on Intersil's Prism2/2.5/3 chipset)





  • Antennas: To connect with WLANs from distances greater than a few hundred feet, sophisticated hackers use long-range antennas that are either commercially available or built easily with cans or cylinders found in a kitchen cupboard and can pick up 802.11 signals from up to 2,000 feet away. The intruders can be in the parking lot or completely out of site.

  • Breaking encryption tools: The industry's initial encryption technology, Wired Equivalent Privacy (WEP), was quickly broken by published tools WEPCrack and AirSnort, which exploit vulnerabilities in the WEP encryption algorithm. WEPCrack and AirSnort passively observe WLAN traffic until they collect enough data to recognize repetitions and break the encryption key.

  • Breaking 802.1x authentication tools: The next step in the evolution of WLAN security was the introduction of 802.1x for port-based authentication. However, University of Maryland professor William Arbaugh published a research paper in February 2002 that demonstrated how the newly proposed security standard can be defeated. The IEEE is now working on a new standard, 802.11i, which is expected to be ratified in 2004.

  • War driving tools: To locate the physical presence of WLANs, hackers developed scanning and probing tools that introduced the concept of "war driving" -- driving around a city in a car to discover unprotected WLANs. User-friendly Windows-based freeware tools, such as Netstumbler, probe the airwaves in search of access points that broadcasted their service set identifiers (SSID) and offer easy ways to find open networks. More advanced tools, such as Kismet, were then introduced on Linux systems to passively monitor wireless traffic. Both Netstumbler and Kismet work in tandem with a Global Positioning System to map exact locations of the identified WLANs. These maps and data are posted on Web sites such as www.wigle.net and www.wifinder.com where wireless freeloaders and other hackers can locate these open networks.
Attacks at DefCon

One of the best ways to study what kind of attacks you can expect and what tools attackers will use is to study what happens at DefCon. At DefCon X in August 2002, AirDefense surveyed the WLAN at the Las Vegas convention for two hours and identified more than 10 previously undocumented methods for wireless attacks. That information showed us that hackers had become a lot more creative in learning how to manipulate 802.11. The result was a new flavors of denial-of-service attacks, identity thefts and man-in-the-middle attacks.


During the two hours of monitoring the conference's WLAN, AirDefense identified eight sanctioned access points, 35 rogue access points and more than 800 different station addresses.


AirDefense's 802.11 security experts estimated that 200 to 300 of the station addresses were fakes because roughly 350 people were in the WLAN network room at a single time.


AirDefense discovered 115 peer-to-peer ad hoc networks and identified 123 stations that launched a total of 807 attacks during the two hours.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Mobile and Wireless White Papers
Digital Transformation: Creating New Business Models Where Digital Meets Physical
Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil...
Empowering Your Mobile Worker
Today's most productive employees are mobile, and your company's IT strategy must be ready to support them with 24/7 access to the business...
An Interactive Guide: Bring Your Own Device
BYOD presents significant security and management challenges to IT departments who want to take advantage of the trend, but still protect corporate assets....
Calculating ROI for Mobile Client Acceleration
As mobile devices continue to expand in business use, ensuring these devices have optimal performance is becoming an IT imperative. This EMA paper...
Tablet Computing Without Compromise
This paper provides an overview of how and why that migration-from any old tablet to Windows tablets-came to be.
All Mobile and Wireless White Papers
Mobile and Wireless Webcasts
Live Webcast
North Pole to South Seas: Overcoming the Pitfalls of remote Performance
In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
Supporting Mobile Productivity With A Limited IT Budget
Join us and hear from Kaseya mobile IT management experts as we discuss core strategies for supporting the mobile revolution on a shoestring...
North Pole to South Seas: Overcoming the Pitfalls of remote Performance
In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
Unified Communications 101
What's the best way to implement a unified communications solution for your organization?
QNX® and BlackBerry® PlayBook™ Tablet.
RIM's multi-processor, multi-tasking BlackBerry PlayBook runs a new Tablet OS powered by QNX, a bullet-proof microkernel operating system. This track will take a...
A Close Look at Tablets
Learn More
All Mobile and Wireless Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs