>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a reada…
Hackers ship their exploits directly to their target’s mailroom
11–20 of 172 posts
Re: Hackers ship their exploits directly to their target’s mailroom
#12>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a reada…
Re: Hackers ship their exploits directly to their target’s mailroom
#13>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a reada…
Re: Hackers ship their exploits directly to their target’s mailroom
#14>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a reada…
https://www.aircrack-ng.org/doku.php?id=cracking_wpa#step_4_...
This is done completely offline once you have the handshake captured and can be easily scaled.
Re: Hackers ship their exploits directly to their target’s mailroom
#15That seems like a lot of hassle and a pretty big federal crime for only being able to attack Wi-Fi networks. Why not just park your car outside and use a laptop?
Using repurposed used hardware, this can also be crazy cheap.
Fun idea: buy junk vendor swag (stuffed animal, glass globe, etc) off of ebay in bulk, then mail it to people you know have recently left the company (say, from scanning LinkedIn). They'll probably keep the package around for a while before disposing of it. Or even better, someone else claims it as 'free swag,' and keeps it in the office.
Maybe it'll stay in there a long time: https://en.wikipedia.org/wiki/The_Thing_(listening_device)
Extra points: make it something powered (like a clock) and make them plug it in. Battery charge for initial scan, and if you get lucky, they'll recharge the battery by plugging in the device.
Re: Hackers ship their exploits directly to their target’s mailroom
#16>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a reada…
Re: Hackers ship their exploits directly to their target’s mailroom
#17>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a reada…
Re: Hackers ship their exploits directly to their target’s mailroom
#18If your network security relies on promixity for ultimate security, you've done something very wrong.
Re: Hackers ship their exploits directly to their target’s mailroom
#19That seems like a lot of hassle and a pretty big federal crime for only being able to attack Wi-Fi networks. Why not just park your car outside and use a laptop?
How long can you sit outside a company running Kali Linux and a high gain antenna array before you attract attention? If you ship someone on the DevOps team a WiFi-connected plush toy that listens for webhooks from your CI/CD platform to make happy/sad noises when the build passes/fails -- AND THEY PLUG IT IN AND LEAVE IT ON -- then the ability to have passive access to the network for a long period of time will be l…
Re: Hackers ship their exploits directly to their target’s mailroom
#20You could probably make a killing selling these for $100 - 200 on Etsy or something.