|
I'll be honest, our research was driven by being utterly stunned this past
winter when a group of academics were reported
on as having "discovered" what many of us knew
for quite some time--stand up a rogue access point
and people will give you important, private, and in
many cases, lucrative information. A couple years
earlier, when Bruce and I demo'd "Airsnarf"
at DefCon
11, the kicker was showing it running from an
overpowering Zaurus PDA in my pocket--not the old
news (back then even) that you could steal usernames
and passwords from hotspot users with a Linux box
and hostap drivers.
There's no badass discovery here, folks. Even if "Evil
Twin" research made Slashdot. There wasn't anything
badass about "Airsnarf" back then--it was a shell
script and a few lines of Perl to play DNS tricks.
There's nothing badass about rogue AP attacks now.
Well, that just invalidates my presentation, doesn't
it? Crap.
Regardless, I felt it was important to not only cover
the rogue AP basics for anyone who's just heard of
this trickery, but to get people thinking about the
more advanced havoc one can wreak with a rogue AP.
Yes, usernames and passwords are nice, but there's
a slew of social engineering subtleties available
to you when you have a user hop on to YOUR access
point. My talk will cover all of that and more-including
release of a new tool called "Rogue Squadron".
Yes, I'm a Star
Wars nut, so feel free to talk with me about impressions
of Episode III while we're in Vegas--if you can't
find me at the bar or blackjack tables, I'll be at
the movie theater again. Now, if I can finish another
project or two,
not get killed while racing
this Summer, and manage to keep all my demo ducks
in a row, this should be nifty for people to see.
If anything, I'll give away a bunch of Shmoo
stickers in advance of DefCon to attendees of my Black
Hat talk. heh. Seed the audience, so to speak. If
you'd like to see what I'll be recycling / plagiarizing
in advance of my talk, here are some links you should
check out:
"Airsnarf" -DefCon XI presentation
"Rogue
AP 101" - Black Hat Federal presentation
and code "802.1x
eap" Google query ;)
|