RSS

The sweet theory behind WiFi Hacking / Wardriving

Sat, Jul 5, 2008

Blackhat, Whitehat, WiFi, security

If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

I reside in Delhi, where Internet is still not that cheap. One has to shell out INR 800-1000 per month for a decent enough internet connection.

One day while going around the terrace I discovered that the laptop was catching somebody’s wireless connection. Alas to my surprise! I found that wireless connection so dependable and now I use it 24×7 , free :-)
The WiFi AP admin, whom I don’t know now uses WEP, a weak encryption technique, which i could bypass without much trouble.

After arpanet, the internet evolved, wires everywhere, Now its gone wireless.

Wireless/Bluetooth are fairly new technologies and the encryption algorithms behind are fairly easy to crack (WPA2 is latest though)
this internet connection I found floating all around the air near me.
On the terrace , and the fourth storey room.

The High Speed internet was around me, but I couldn’t get onto it/surf it.
REASON: The connection was ENCRYPTED.

The laptop’s WIFI LAN card catches the singal, so the Access Point is around,
We have a transmitting point.

Normally the router here on in to be referred to as the AP.
My machine, Laptop and similar machines are the clients,,
We’ve data flowing(incoming and out) between the Access Pt. and Router (packets).

So why can’t we just jump on the connection, just as we do with cable TV, or electricity.
Well the network and its packets is
encrypted.
To get on the network we need to get authorized by AP, using a
passkey.

Normally in ASCII but some AP’s accept Hex keys.

[So how do we crack/discover this key]
Its simple, little fragments of this key are inside each packet.
So we need to sit in the network range.
And get us a copy of these packets. (i.e. Random data)

For that:
set the wireless card into monitor mode. (Requires special drivers)
And running a packet sniffer (Wireshark)

Once enough packets are gatherd, we can send them all off in one big go to the decryptor.
The decryptor will juice out the useful info from it

several types of encryption standards exist for WiFi.
WEP, WPA, WPA2 or WPA-PSK.
As with every encryption these can be broken by one of three methods.
Brute force (theoretically should work everytime but time consuming) , Dictionary(luck matters) or Rainbow Tables.

Each encryption standard has different qualities, you may say “Strengths”
WEP today is by far the weakest one, but 128 bit key should help.
WPA is also lame, until better length key is used.
WPA2 , you may say is one generation ahead.

Measures against getting wardriven. :Use WPA,

WPA-PSK can be broken only by trying BF combination. Just ensure your passkey is something that’s NOT on the dictionary and its 512 bit.
something like gr3yh4t1nd14i55om3th1ng_1′4m .  .  .I would love to see a dictionary with that on it.

Thats it
Thats the simple laymen style boiled down theory behind war-driving.
In my next article on WiFi we’ll get little on the black hat side and actually break and enter a network.

Notice the long pole, there’s a black box on top, I suspect this is my free AP

i suspect this pole throws the Wifi connection
the WLAN card that juices the free Internet

Share if you like the post :-)
  • Digg
  • StumbleUpon
  • del.icio.us
  • Slashdot
  • Mixx
  • Facebook
  • Google
  • Spurl
  • co.mments
  • Furl
, , , , , , ,

This post was written by:

admin - who has written 8 posts on Grey Hat India.


Contact the author

9 Comments For This Post

  1. fickle minded Says:

    Why you putting pic of AP near you? Secondly there is one wifi security hack by nasa n fbi easily searchable on net and many tools also.

  2. Rohit Singh Says:

    Welcome to the world of blogging fickle minded, people do blog about what already exists around: its sometime like a critic. i dun think there’s any such hack by NASA.
    nevertheless , this is an article written “about” WiFi snooping not “over” it: so who’s stopping you to use those tools. go ahead , make a life outta thm. cheers

  3. Arun Devil Says:

    Hello Fickle,

    The pic of the the AP gives in more localized feel to the article.
    When you see soccer match news reports, you get an explanation with pics around.
    and hey do you write your daily dairy .hehe

  4. ashwin Says:

    lol :P

  5. ashwin Says:

    hey, we don’t have a tradition of chalking out the areas that have free and open wifi hotspots in India. something like a mumbai map should be there where people come and mark open WiFi areas.

    some should also contain, WEP and ecrypted ones..

    that would be good ::P

  6. Rohit Singh Says:

    only helpful in big cities .

  7. Shitiz Says:

    abe, is that ethical that youre connecting to such open wifi ?

  8. Rsj Says:

    i have window mobile 6 Is that possible to use free internet from office or other place..mostly i just can use when i m home coz i have smc wireless..but want to use outside for free internet would like to know how u r going to hacking for that..thz ..like ur post…

  9. zwanderer Says:

    Hi Rsj,
    Use a Laptop to first make sure that the Wifi access point really works. If it fails directly, the crack the wep encryption and recover the WiFi key. After you get the key , it’ll be an easy job to configure it on your WM6 phone.
    Cheers :-)

2 Trackbacks For This Post

  1. Bookmarks about Wardriving Says:

    [...] - bookmarked by 3 members originally found by lukeprog on 2008-09-07 The sweet theory behind WiFi Hacking / Wardriving http://www.greyhatindia.com/2008/07/05/the-sweet-theory-behind-wifi-hacking-wardriving/ - [...]

  2. Recent Links Tagged With "wardriving" - JabberTags Says:

    [...] "Wardriving" in the era of overpriced gasoline Saved by liah24 on Sat 25-10-2008 The sweet theory behind WiFi Hacking / Wardriving Saved by mayloverbunni356 on Fri 24-10-2008 Wardriving Lahore Saved by MissSoojinx3 on Mon [...]

Leave a Reply