wispi: mini karma router for pentester - rama tri nanda

35
Wispi, Mini Karma Router for Pentester by @smrx86 UPNVeteranYogya, 12 November 2014

Upload: idsecconf

Post on 04-Jul-2015

625 views

Category:

Technology


6 download

DESCRIPTION

Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

TRANSCRIPT

Page 1: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Wispi,  Mini  Karma  Router  for Pentester

by  @smrx86UPN  VeteranYogya,  1-­‐2  November  2014  

Page 2: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Who  am  i

-­‐Member  OpenWrt  Indonesia.  -­‐Ezine  contributor.  -­‐  Idsecconf  2013  speakers.    -­‐  Ordinary  man  not  hacker.  -­‐  twitter  @smrx86

Page 3: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

KARMA

Page 4: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Definitions

KARMA  =  Karma  Attack’s  Radio  Machine  Automatically  (recursive  Acronyms)  

All  Your  layers  belong  to  us,  Dino  A.  Dai  Zovi  and  Shane  A.  Macaulay,  2004.  

Page 5: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

How  old  KARMA  works

Page 6: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

How  old  KARMA  works

Page 7: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

How  old  KARMA  works  (with  deauth)

Page 8: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

New  KARMA

KARMA    /  jasager,  create  by  Digininja  Team  at  2008.  Only    with  patch  for  Hostapd  and  Hostapd_cli  .  It  can  use  for  embeded  OS  device  like  OpenWRT.  

Page 9: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

How  new  KARMA  works

Page 10: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

How  new  KARMA  works  (with  deauth)

Page 11: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

KARMA  on  Openwrt  Router

Page 12: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Fonera=  PIRANHA  ,  JASAGER,  PineappleMK  II

ALFA  AP51  =  Pineapple  MK  III

ALFA  AP121  U/HORNET  UB  =  Pineapple  MK  IVPineapple  MKV

Page 13: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Piranha Jasager MK  II MK  III MK  IV MK  V

Device Fon  2.0 Fon  2.0 Fon  2.0 Alfa  AP51

Alfa  AP121U

Costum

Procie 180  Mhz 180  Mhz   180  Mhz   400Mhz 400Mhz 400Mhz

RAM 16  MiB 16  MiB 16  MiB 32  MiB 32  MiB 64MiB

ROM 8  MiB 8  MiB 8  MiB 8  MiB 8  MiB 16  MiB

WebIF -­‐ Ruby  XML

Ruby  XML

PHP  4 PHP  4 PHP  5

Webserv -­‐ Httpd/  busybox

Httpd/  busybox  

Uhttpd Uhttpd Nginx

Launch 2008 2008 2009 2010 2012 2013

Specification  table

Page 14: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Make  ur  own   KARMA  firmware  distribution

Page 15: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Problem  1.

8  /16  MiB 4  MiB

*without  Extroot

Page 16: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Problem  2.

-­‐Must  have  capability  to  redirect  network  like  DNSSPOOFT.  -­‐ Must  have  capability  to  jamming  the  wireless  network.

*without  Extroot

Page 17: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda
Page 18: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Trick  1.    KARMA

-­‐  Blue  for  the  pineapple,  http://penturalabs.wordpress.com/2013/04/25/blue-­‐for-­‐the-­‐pineapple/  

Page 19: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

KARMA  =  WPAD  +  HOSTAPD_CLI  +  mac80211.sh  

-­‐WPAD,  is  in  /usr/sbin/  wpad.  -­‐  HOSTAPD_CLI,  is  in  /usr/sbin/  hostapd_cli  -­‐  MAC80211.sh,  is  in  /lib/wifi/mac80211.sh  

Page 20: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Trick  2.  DNS  spoof  &  redirection

http://shackspace.de/wiki/doku.php?id=project:minikrebs#profilerick-­‐roller

Page 21: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

-­‐  Edit    firewall  configuration  in  /etc/config/firewall      

Page 22: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

-­‐  Edit  DHCP  configuration  in  /etc/config/dhcp    

Page 23: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Trick  3.  Jamming  

http://www.slideshare.net/idsecconf/24-­‐23130352

Page 24: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Trick  4.  Compile  d  firmware

http://wiki.openwrt.org/doc/howto/obtain.firmware.generate

Page 25: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda
Page 26: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

WISPI,  feature  &  overview

Page 27: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

1.  KARMA

Page 28: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

using  ‘switch’  button  to  start  KARMA

Page 29: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

2.  Spoofhost

Page 30: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

3.  Jammer

Page 31: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

using  ‘wps’  button  to  start  jammer

Page 32: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

DEMO

Page 33: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

firmware

https://sites.google.com/site/semarak2011/dokumen/wispi.7z

Password:  idsecconf_2014

Page 34: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda

Greets

Cindy  Wijaya,  Xopal  Unil,  Tisaros  Kaskus,  Openwrt  Indonesia,  Om  Hero  lirva32,  Brahmanggi  Aditya,  Richy  Hendra,  Ade  Surya,  …all  human  or  not  (^^)  who  always  support  inspired  me.  And  ofcource  it’s  U…  ra’  

Page 35: Wispi: Mini Karma Router For Pentester - Rama Tri Nanda