Announcement

Collapse
No announcement yet.

WRT54G Spoofed AP Guide

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • WRT54G Spoofed AP Guide

    For Defcon, I developed a few tricks that I hoped would give my team an edge in the wardriving contest, including an easy way to make my own Spoofed target AP's to confuse and distract other teams.

    It took a bit of research, but I now have the instructions nessecary for changing the MAC on the wireless side to whatever you want! Coupled with a matching SSID you now have your own embedded 'Evil Twin' (hate that term), spoofed AP for doing whatever the hell it is you want to do. No more HostAP mode and laptops, just a small blue box, easily hidden inside a teddy bear :)

    Not the most spectacular thing in the world, but figured I'd share.

    Personally, I see potential of extending this research further and ending up with my own embedded airsnarf box, but my scripting skills suck.

    For now, have fun with what I have posted at http://www.renderlab.net/projects/wr...54g-spoof.html

    Questions, comments and improvements are welcome.
    Never drink anything larger than your head!






  • #2
    Originally posted by renderman
    For Defcon, I developed a few tricks that I hoped would give my team an edge in the wardriving contest, including an easy way to make my own Spoofed target AP's to confuse and distract other teams.

    It took a bit of research, but I now have the instructions nessecary for changing the MAC on the wireless side to whatever you want! Coupled with a matching SSID you now have your own embedded 'Evil Twin' (hate that term), spoofed AP for doing whatever the hell it is you want to do. No more HostAP mode and laptops, just a small blue box, easily hidden inside a teddy bear :)

    Not the most spectacular thing in the world, but figured I'd share.

    Personally, I see potential of extending this research further and ending up with my own embedded airsnarf box, but my scripting skills suck.

    For now, have fun with what I have posted at http://www.renderlab.net/projects/wr...54g-spoof.html

    Questions, comments and improvements are welcome.

    Dude...that's slick. Thanks for posting.
    perl -e 'print pack(c5, (41*2), sqrt(7056), (unpack(c,H)-2), oct(115), 10)'

    Comment


    • #3
      Originally posted by Chris
      Dude...that's slick. Thanks for posting.
      No shit. That's definitely worth a beer next year :)

      Comment


      • #4
        I came up with all these ideas, did'nt get to use many of them, so might as well share them and see what everyone else does with them and what else happens.

        Did'nt want to use the hotel net access otherwise it would have been a drunken Defcon release. Had it waiting on the server already :)

        Glad you guys like.
        Never drink anything larger than your head!





        Comment


        • #5
          Renderman: The Definitive Hacker. Good job.

          Comment


          • #6
            you give love a bad name
            if it gets me nowhere, I'll go there proud; and I'm gonna go there free.

            Comment


            • #7
              Very cool stuff. Guess I'll be buying a third one of these things now.

              -zac
              %54%68%69%73%20%69%73%20%6E%6F%74%20%68%65%78

              Comment


              • #8
                http://airsnarf.shmoo.com/rogue_squadron/index.html

                Fuck, Fuck, Fuck, Fuck, Fuck, Fuck, Fuck, Fuck, Fuck.

                You know, I really should have been watching Beetles talk at Blackhat. Could have saved myself some trouble. To many damn secret projects.

                "Airsnarf: Rogue Squadron" is a proof-of-concept rogue AP firmware for the Linksys WRT54G, based on the Ewrt firmware v0.3 beta 1 by Portless Networks, which is based on the Linksys 3.01.3 codebase. With this firmware you can quickly turn a Linksys WRT54G into a rogue access point that "authenticates" users and "provides" Internet access.
                There goes a day's worth of project time.
                Never drink anything larger than your head!





                Comment


                • #9
                  Originally posted by renderman
                  http://airsnarf.shmoo.com/rogue_squadron/index.html

                  Fuck, Fuck, Fuck, Fuck, Fuck, Fuck, Fuck, Fuck, Fuck.

                  You know, I really should have been watching Beetles talk at Blackhat. Could have saved myself some trouble. To many damn secret projects.



                  There goes a day's worth of project time.
                  Shit.. Ahh well, I learnt a bit from what I did so far.
                  Why not go ahead anyways ? Diversity is the spice of life, and giving folks a choice can only be good. AFAIU the shmoo version will be a selfcontained firmware, while your idea was to make a package that could be added to the OpenWRT firmware, and transform it into an instant Airsnarf. I'm still game, so say the word.

                  Dutch
                  All your answers are belong to Google. Search dammit!!!

                  Comment


                  • #10
                    Originally posted by Dutch
                    Shit.. Ahh well, I learnt a bit from what I did so far.
                    Why not go ahead anyways ? Diversity is the spice of life, and giving folks a choice can only be good. AFAIU the shmoo version will be a selfcontained firmware, while your idea was to make a package that could be added to the OpenWRT firmware, and transform it into an instant Airsnarf. I'm still game, so say the word.

                    Dutch
                    I'm still game. Need the practice anyways. Anyone else?
                    Never drink anything larger than your head!





                    Comment


                    • #11
                      Originally posted by renderman
                      I'm still game. Need the practice anyways. Anyone else?
                      I agree with Dutch, keep it going. Your experience and tutorials have saved a lot of time for people wondering how to do whatever with their WRT54Gs.
                      "\x74\x68\x65\x70\x72\x65\x7a\x39\x38";

                      Comment


                      • #12
                        hello !
                        i search Airsnarf - Rogue Squadron
                        someone could send me this firmware ?
                        my email: admin @ warchalking.pl

                        best redags, Michal 'scOti'
                        www.warchalking.pl

                        Comment


                        • #13
                          Originally posted by test
                          hello !
                          i search Airsnarf - Rogue Squadron
                          someone could send me this firmware ?
                          my email: admin @ warchalking.pl


                          best redags, Michal 'scOti'
                          www.warchalking.pl
                          Looks like they (re)moved the files from the server. Google cache still shows what was there, but the tarballs are not cached.
                          google cache

                          [Added content:]
                          However, a further search of the cache from google reveals this page which tells us, after url examination that the name of the tarball is/was "airsnarf-0.2.tar.gz" and a google search of that file provides a md5sum file that suggests it may be an archive, and directory traversal back, shows us a page of files that includes a fiule with the same name and download works.

                          Comment


                          • #14
                            Any idea what the hell is happening to the shmoo site?

                            looks like something major.
                            Never drink anything larger than your head!





                            Comment


                            • #15
                              Originally posted by test
                              hello !
                              i search Airsnarf - Rogue Squadron
                              someone could send me this firmware ?
                              my email: admin @ warchalking.pl

                              best redags, Michal 'scOti'
                              www.warchalking.pl
                              Users have complained about you spamming them. This is a warning; do not spam people in PM in addition to a thread with the same content. Be patient. Ask the question once in the thread, and see what happens.

                              Now I feel bad for giving you a site that seems to have your archived file. I do not like encouraging spammers. >:-|

                              (Posted here instead of PM because this matter was made public, and to show other users this behavior is not acceptable.)

                              Comment

                              Working...
                              X