请输入您要查询的百科知识:

 

词条 Wi-Fi deauthentication attack
释义

  1. Technical details

  2. Usage

      Evil twin access points    Password attacks  

  3. Attacks on hotel guests and convention attendees

  4. Toolsets

  5. See also

  6. References

  7. Further reading

A Wi-Fi deauthentication attack is a type of denial-of-service attack that targets communication between a user and a Wi-Fi wireless access point.

Technical details

Unlike most radio jammers, deauthentication acts in a unique way. The IEEE 802.11 (Wi-Fi) protocol contains the provision for a deauthentication frame. Sending the frame from the access point to a station is called a "sanctioned technique to inform a rogue station that they have been disconnected from the network".[1]

An attacker can send a deauthentication frame at any time to a wireless access point, with a spoofed address for the victim. The protocol does not require any encryption for this frame, even when the session was established with Wired Equivalent Privacy (WEP) for data privacy, and the attacker only needs to know the victim's MAC address, which is available in the clear through wireless network sniffing.[2][3]

Usage

Evil twin access points

One of the main purposes of deauthentication used in the hacking community is to force clients to connect to an Evil twin access point which then can be used to capture network packets transferred between the client and the RAP.

The attacker conducts a deauthentication attack to the target client, disconnecting it from its current network, thus allowing the client to automatically connect to the Evil twin access point.

Password attacks

In order to mount a brute-force or dictionary based WPA password cracking attack on a WiFi user with WPA or WPA2 enabled, a hacker must first sniff the WPA 4-way handshake. The user can be elicited to provide this sequence by first forcing them offline with the deauthentication attack.[4]

In a similar phishing style attack without password cracking, Wifiphisher starts with a deauthentication attack to disconnect the user from his legitimate base station, then mounts a man-in-the-middle attack to collect passwords supplied by an unwitting user.

Attacks on hotel guests and convention attendees

The Federal Communications Commission has fined hotels and other companies for launching deauthentication attacks on their own guests; the purpose being to drive them off their own personal hotspots and force them to pay for on-site Wi-Fi services.[6][7][8][9]

Toolsets

Aircrack-ng suite, MDK3, Void11, Scapy, and Zulu software can mount a WiFi deauthentication attack.[10] Aireplay-ng, an aircrack-ng suite tool, can run a deauthentication attack by executing a one-line command:

  1. {{code|-0}} arms deauthentication attack mode
  2. {{code|1}} is the number of deauths to send; use 0 for infinite deauths
  3. {{code|-a xx:xx:xx:xx:xx:xx}} is the AP (access point) MAC (Media Access Control) address
  4. {{code|-c yy:yy:yy:yy:yy:yy}} is the target client MAC address; omit to deauthenticate all clients on AP
  5. {{code|wlan0}} is the NIC (Network Interface Card)

Pineapple rogue access point can issue a deauth attack.[1][2] Wifijammer can also automatically scan for and jam all networks within its range.[13]{{non-primary source needed|date=June 2017}} An ESP8266 can be used to perform & detect deauth attacks, using Wi-PWN.[14][15] On Android, Nexmon supports Broadcom WLAN chip for deauth attacks.[3]

See also

  • Radio jamming
  • IEEE 802.11w – offers increased security of its management frames including authentication/deauthentication

References

1. ^{{citation|title=Five ways to protect yourself from Wi-Fi honeypots|date=March 10, 2012|author=Declan McCullagh |publisher=CNet|url=http://www.cnet.com/news/five-ways-to-protect-yourself-from-wi-fi-honeypots/#!}}
2. ^{{citation|title=WiFi Deauth Attacks, Downloading YouTube, Quadcopters and Capacitors|work=Hak5|author=Darren Kitchen|id=episode 1722|url=https://hak5.org/episodes/hak5-1722|date=January 14, 2015}}
3. ^https://github.com/seemoo-lab/nexmon
4. ^{{citation|title=FCC Fines Hotel Wi-Fi Provider for Blocking Personal Hotspots|author=Nicholas Deleon|work=Vice|date=August 18, 2015 |url=http://motherboard.vice.com/read/fcc-fines-freedom-hating-hotel-wi-fi-provider-for-blocking-personal-hotpsots}}
5. ^{{citation|title=Order and consent decree — In the Matter of SMART CITY HOLDINGS, LLC|url=http://transition.fcc.gov/Daily_Releases/Daily_Business/2015/db0818/DA-15-917A1.pdf |id=DA 15-917|publisher=Federal Communications Commission|date=August 18, 2015|quote=The complaint charged that its customers could not connect to the Internet using the complainant's equipment at several venues where Smart City operates or manages the Wi-Fi access. Specifically, the complainant alleged that Smart City transmitted deauthentication frames to prevent the complainant's customers' use of their Wi-Fi equipment. ... Smart City's responses [to FCC Letters of Inquiry] revealed that, at several venues where it managed or operated Wi-Fi systems, it automatically transmitted deauthentication frames to prevent Wi-Fi users whose devices produced a received signal strength above a preset power level at Smart City access points from establishing or maintaining a Wi-Fi network independent of Smart City's network. }}
6. ^{{citation|title=FCC Fines Marriott For Jamming Customers' WiFi Hotspots To Push Them Onto Hotel's $1,000 Per Device WiFi|author=Mike Masnick|date=October 3, 2014|work=Tech Dirt|url=https://www.techdirt.com/articles/20141003/12083628721/fcc-fines-marriott-jamming-customers-wifi-hotspots-to-push-them-onto-hotels-1000-per-device-wifi.shtml}}
7. ^{{citation|title=Deauthentication|publisher=Aircrack-ng|url=https://www.aircrack-ng.org/doku.php?id=deauthentication}}
8. ^{{citation|title=Wireless Security Series Part I: Detoolauthentication Attacks by AirMagnet Intrusion Detection Research Team|publisher=Fluke Networks|url=http://www.flukenetworks.com/content/eyeonnetworks-wlan-security-and-analysis}}
9. ^https://github.com/DanMcInerney/wifijammer
10. ^https://github.com/spacehuhn/esp8266_deauther
11. ^https://github.com/Wi-PWN/Wi-PWN
12. ^{{citation|author=Joshua Wright|title=Weaknesses in Wireless LAN Session Containment | year=2005 | url=http://www.willhackforsushi.com/papers/wlan-sess-cont.pdf}}
13. ^{{citation|title=802.11 Denial-of-Service Attacks: Real Vulnerabilities and Practical Solutions|first1=John |last1=Bellardo |first2=Stefan |last2=Savage |date=2003-05-16 |work=Proceedings of the USENIX Security Symposium, Aug 2003|via=Cal Poly|url=http://users.csc.calpoly.edu/~bellardo/pubs/usenix-sec03-80211dos-html/aio.html}} (Deauthentication Attack chapter link)
14. ^{{citation|title=Hacking Techniques in Wireless Networks: Forged Deauthentication| first=Prabhaker |last=Mateti | publisher=Department of Computer Science and Engineering, Wright State University|year=2005|url=http://cecs.wright.edu/~pmateti/InternetSecurity/Lectures/WirelessHacks/Mateti-WirelessHacks.htm#_Toc77524675}}
15. ^{{citation|date=October 4, 2014|author=Thomas Claburn|title=Marriott Pays $600,000 For Jamming WiFi Hotspots|work=Information Week|url=http://www.informationweek.com/mobile/mobile-devices/marriott-pays-$600000-for-jamming-wifi-hotspots/d/d-id/1316354}}
[4][5][6][7][8][9][10][11][12][13][14][15]
}}

Further reading

  • {{citation|title=A Lightweight Solution for Defending against Deauthentication/Disassociation Attacks on 802.11 Networks|first1=Thuc D. |last1=Nguyen|first2=Duc H. M. |last2=Nguyen|first3=Bao N. |last3=Tran|first4=Hai |last4=Vu |first5=Neeraj |last5=Mittal|work=Proceedings of the 17th IEEE International Conference on Computer Communications and Networks (ICCCN)|pp=185–190|location=St. Thomas, Virgin Islands, USA|date=August 2008|isbn=978-1-4244-2389-7|doi=10.1109/ICCCN.2008.ECP.51|citeseerx=10.1.1.310.1319 }}{{paywall}}
    • author's link (no paywall)
  • GPS, Wi-Fi, and Cell Phone Jammers — FCC FAQ

1 : Denial-of-service attacks

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/11/13 10:09:04