{"id":99600,"date":"2014-03-31T14:01:03","date_gmt":"2014-03-31T12:01:03","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=99600"},"modified":"2014-03-31T14:17:08","modified_gmt":"2014-03-31T12:17:08","slug":"wi-fi-hacking-quadcopter-from-sa-security-firm","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/99600-wi-fi-hacking-quadcopter-from-sa-security-firm.html","title":{"rendered":"Wi-Fi hacking quadcopter from SA security firm"},"content":{"rendered":"<p>Wi-Fi, as it is implemented in smartphones and other mobile devices today, has a number of security vulnerabilities that could make it easy to track, and even intercept data from a device.<\/p>\n<p>To raise awareness about these problems, SensePost, an information security firm headquartered in South Africa, built Snoopy.<\/p>\n<p>Snoopy developer Glenn Wilkinson describes it as a \u201cdistributed tracking, profiling, and data interception framework\u201d. Currently it shows what kind of mischief is possible with Wi-Fi, but Wilkinson said that since Snoopy is modular it could easily be extended to Bluetooth, RFID, and NFC.<\/p>\n<p>Wilkinson, a Zimbabwean working out of SensePost\u2019s London offices as lead security analyst, has been working on the technology with his colleagues since 2012, when he and Daniel Cuthbert gave a <a href=\"http:\/\/www.youtube.com\/watch?v=Vsn7_4qUdwk\" target=\"_blank\">talk at 44con<\/a> about the privacy implications of the vulnerabilities in Wi-Fi.<\/p>\n<h3 class=\"my-4\">How your smartphone blabs about where you\u2019ve been<\/h3>\n<p>To understand what Snoopy does, SensePost\u2019s chief technology officer Dominic White said one must first have an idea of how Wi-Fi works.<\/p>\n<p>White explained that there are two \u201cmanagement frames\u201d Snoopy is interested in: beacons, and probes.<\/p>\n<p>Access points (APs) \u2013 the networking equipment to which your smartphone, tablet, or laptop wirelessly connects \u2013 send out messages called beacons on a certain interval.<\/p>\n<p>These beacons identify the wireless network and also help Wi-Fi connected devices avoid \u201ccollisions\u201d which occur if they send data at the same time.<\/p>\n<p>(For a great overview on Wi-Fi beacons, White recommended the following article: <a href=\"http:\/\/www.wi-fiplanet.com\/tutorials\/article.php\/1492071\" target=\"_blank\">802.11 Beacons revealed<\/a>)<\/p>\n<p>APs also send out probe responses, a message sent in reply to a probe request sent by a device.<\/p>\n<p>Together, beacons and probe responses let \u201cwardrivers\u201d (or companies like Google and Skyhook, for that matter) identify wireless networks and upload the identifying information and location of the access point to a database.<\/p>\n<p>Identifying information may consist of the basic service set identification (BSSID), or MAC address of the access point, as well as the extended SSID (ESSID, or just \u201cSSID\u201d for short).<\/p>\n<p>An example of a freely available database that contains such information is Wigle.net, which is what Wilkinson used in his demonstration of Snoopy.<\/p>\n<p>The other \u201cmanagement\u201d message in Wi-Fi Snoopy relies on is the probe request, which is the message devices send out to join a Wi-Fi network.<\/p>\n<p>These probe requests contain the ESSID of the wireless access point the device is trying to join.<\/p>\n<p>Where things get interesting, White explained, is that most devices actively scan for Wi-Fi networks by sending out probe requests on a regular interval for networks they have previously joined, or have been instructed to \u201cremember\u201d.<\/p>\n<p>By simply listening for and recording these probe requests, anyone can build up a list of Wi-Fi devices in the areas and which networks they connected to.<\/p>\n<p>At first this may not seem so scary, until you realise what the networks you have joined in the past may reveal about you.<\/p>\n<div id=\"attachment_99604\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/03\/Snoopy-Maltego-showing-locations-of-APs.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-99604\" class=\" wp-image-99604 \" alt=\"Snoopy Maltego showing locations of APs\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/03\/Snoopy-Maltego-showing-locations-of-APs.jpg\" width=\"600\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/03\/Snoopy-Maltego-showing-locations-of-APs.jpg 1264w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/03\/Snoopy-Maltego-showing-locations-of-APs-640x378.jpg 640w\" sizes=\"(max-width: 1264px) 100vw, 1264px\" \/><\/a><p id=\"caption-attachment-99604\" class=\"wp-caption-text\">Snoopy Maltego showing locations of access points<\/p><\/div>\n<h3 class=\"my-4\">Don\u2019t manually turn off your Wi-Fi? You probably should<\/h3>\n<p>To demonstrate what can be done with Snoopy, Wilkinson wrote a number of \u201ctransforms\u201d for Maltego, a tool developed by another South African company, Paterva.<\/p>\n<p>Wilkinson explained that Maltego lets you visualise data and the relationships between the various entities you might be analysing.<\/p>\n<p>He showed that you can select multiple Snoopy sensors (called \u201cdrones\u201d), then simply right click to activate a transform and bring up a list of Wi-Fi devices in the vicinity of those sensors.<\/p>\n<p>From there you can get the networks all those devices have been probing for.<\/p>\n<p>Another transform uses the public Wi-Fi access point database Wigle.net to geolocate the access points.<\/p>\n<p>If your access point at home or work has a unique name and a \u201cwardriver\u201d had uploaded its details to Wigle.net, then it could very well be used to pin-point exactly where the user of a particular device works or lives.<\/p>\n<p>This data can also be used to analyse whether devices (and perhaps people) were in the same place at one time or another.<\/p>\n<p>Another Maltego transform lets you easily perform this analysis by right clicking on a location and looking up all the devices your sensors have seen that have been at that place.<\/p>\n<div id=\"attachment_99606\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/03\/Snoopy-Maltego-showing-website-info-that-can-be-intercepted.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-99606\" class=\" wp-image-99606 \" alt=\"Snoopy Maltego showing website info that can be intercepted\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/03\/Snoopy-Maltego-showing-website-info-that-can-be-intercepted.jpg\" width=\"600\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/03\/Snoopy-Maltego-showing-website-info-that-can-be-intercepted.jpg 717w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/03\/Snoopy-Maltego-showing-website-info-that-can-be-intercepted-548x400.jpg 548w\" sizes=\"(max-width: 717px) 100vw, 717px\" \/><\/a><p id=\"caption-attachment-99606\" class=\"wp-caption-text\">Snoopy Maltego showing website info that can be intercepted<\/p><\/div>\n<h3 class=\"my-4\">From Wi-Fi tracking to hacking<\/h3>\n<p>While some may not be too concerned about the privacy implications of the vulnerabilities in Wi-Fi, the potential to exploit them for data interception (\u201chacking\u201d) purposes should worry everyone that uses the technology.<\/p>\n<p>Armed with the knowledge of which Wi-Fi networks you are probing for, a hacker can pretend to be that Wi-Fi network and trick you into connecting to them.<\/p>\n<p>White said that these attacks are called \u201ckarma\u201d-type attacks and are also nothing new \u2013\u00a0dating back to at least 2005.<\/p>\n<p>Wilkinson demonstrated that with Maltego, Snoopy can see which services a device is logged into and hijack your session, or exploit vulnerabilities such as SSL degradation to execute man-in-the-middle attacks.<\/p>\n<p>In simple terms, a hacker could get access to everything from your Facebook to sensitive data you\u2019re sending out over the Wi-Fi network.<\/p>\n<p>If your browser is not up-to-date it is even possible to gain access to your PayPal account, Wilkinson said.<\/p>\n<p>White said that modern browsers and websites that use HTTP Strict Transport Security (HSTS) are protected from this kind of attack.\u00a0Most of Google\u2019s authenticated sites are protected in this way, White said.<\/p>\n<p>As an example of the contrary, Wilkinson said that companies like Facebook have to stop sending their authentication cookies out over unencrypted channels.<\/p>\n<h3 class=\"my-4\">Drone-mounted Wi-Fi sensor<\/h3>\n<p><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/UA9-5HNMG-Y\" height=\"338\" width=\"600\" allowfullscreen=\"\" frameborder=\"0\"><\/iframe><\/p>\n<p>The most recent addition to SensePost\u2019s Snoopy project is a remote-controlled quadrotor helicopter that has been mounted with a Wi-Fi sensor that can act as a Snoopy client.<\/p>\n<p>Asked what the quadcopter adds to the demonstration that a network of Snoopy clients doesn\u2019t already provide (besides \u201ccool\u201d factor), Wilkinson said that it:<\/p>\n<ol>\n<li>Lets you cover a large area very quickly and is less impeded than walking around with a snooping Wi-Fi access point in your pocket;<\/li>\n<li>can get past physical security more easily; and<\/li>\n<li>is effectively out of video and audio range (his video above shows that at a height of about 80m you can\u2019t see or hear the drone, Wilkinson said).<\/li>\n<\/ol>\n<h3 class=\"my-4\">Defending against Wi-Fi tracking and hacking<\/h3>\n<p>If the vulnerability is in the very standard for which the Institute for Electrical and Electronic (IEEE) engineers is responsible, what can be done to mitigate its effects?<\/p>\n<p>White said that one of the points of concerns is that there is no clear visible work to change how probe requests work.<\/p>\n<p>\u201cMaybe there\u2019s stuff happening in the background,\u201d White said.<\/p>\n<p>However, <a href=\"http:\/\/www.ieee802.org\/11\/Reports\/tgaq_update.htm\" target=\"_blank\">a new Wi-Fi standard<\/a> being discussed which further encourages the active sending of probe requests seems to contradict this.<\/p>\n<p>This will let a device request a particular service or quality of service and have a network with those parameters respond. If you\u2019re looking for a Wi-Fi network that can handle a voice over IP call your device can then send out a probe request to that effect, White explained.<\/p>\n<p>However, the existing pitfalls inherent in the probe request would then remain unchanged.<\/p>\n<p>The only thing users can do about this is to switch off their Wi-Fi when they move out of their office or home, Wilkinson said.<\/p>\n<p>He added that it is also good practice to delete open Wi-Fi networks from the list of networks your device remembers when you are about to move out of its hotspot. On phones you usually select \u201cforget network\u201d to do this.<\/p>\n<p>You can also make sure your access point is called something generic (such as \u201cInternet\u201d), so the name doesn\u2019t make the location clear, White said.<\/p>\n<p>To prevent hackers from using Karma attacks against users, White said that there are already additional security measures higher up in the networking stack that web services can use.<\/p>\n<p><abbr title=\"HTTP Strict Transport Security\">HSTS<\/abbr>, a standard ratified in 2009, can defeat SSL degradation attacks and is relatively easy to implement, White said.<\/p>\n<p>To defeat man-in-the-middle attacks, White said that web services can use SSL certificate pinning.<\/p>\n<p>Certificate pinning lets an app or web browser expect a specific SSL certificate from a server rather than just checking if the certificate is valid and comes from a trusted authority.<\/p>\n<p>While Chrome has limited support for certificate pinning, it is not something any website can just do, White said.<\/p>\n<p>If you have an app, however, you can specifically certificate pinning into it.<\/p>\n<p>\u201cGood apps use certificate pinning,\u201d Wilkinson said.<\/p>\n<h3 class=\"my-4\">Snoopy availability<\/h3>\n<p>White said that the new version of Snoopy will be made available soon under a non-commercial copyleft license.<\/p>\n<h3 id=\"related\">More information security articles<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/99242-china-demands-us-explanation-on-huawei-spying-report.html\"><strong>China demands US explanation on Huawei spying report<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/99190-e-toll-website-security-flaws-galore.html\"><strong>E-toll website security flaws galore<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/97777-new-computer-virus-spreads-through-wi-fi.html\"><strong>New computer virus spreads through Wi-Fi<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/wireless\/88007-beware-open-wi-fi-networks.html\"><strong>Beware open Wi-Fi networks<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/98390-how-to-stop-government-from-spying-on-your-torrents.html\"><strong>How to stop government from spying on your torrents<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SensePost, an information security company headquartered in South Africa, has demonstrated their framework exploiting tracking and hacking vulnerabilities in Wi-Fi standards<\/p>\n","protected":false},"author":15,"featured_media":99368,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[23159,24326,35,19544],"class_list":["post-99600","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-dominic-white","tag-glenn-wilkinson","tag-headline","tag-sensepost"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/99600"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=99600"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/99600\/revisions"}],"predecessor-version":[{"id":99640,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/99600\/revisions\/99640"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/99368"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=99600"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=99600"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=99600"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}