Hackers ship their exploits directly to their target’s mailroom
51–60 of 172 posts
Re: Hackers ship their exploits directly to their target’s mailroom
#52Could you look at the wireless MAC, contact the manufacturer, figure out where it was sold, contact the seller, and ask for sales records? Guess it wouldn't prevent people from buying on craigslist.
Even if they weren't, its easy enough to buy random $5 wifi enabled dev boards from Aliexpress or somewhere similar, where detailed records tracing individual boards from manufacturer -> distributor -> reseller -> user are highly unlikely to exist.
Re: Hackers ship their exploits directly to their target’s mailroom
#53Earlier quoted context omitted.
If it's not a strong hash and the protocol doesn't include salting, it's not impossible. Rainbow tables exist. And they really only need to find a collision. Wi-Fi protocols, especially WEP, have had vulnerabilities similar to this before. Similar in the sense that if you sniffed enough traffic you could figure out the password (don't recall the specific mechanisms - but this could be one).
It's unfair to say that there is no salting. The PMK is derived from the WiFi network name (SSID) as well as the password [1]. The SSID acts as a salt here. Not perfect as SSIDs are often not unique, but it's certainly better than no salting at all. [1]: https://www.ins1gn1a.com/understanding-wpa-psk-cracking/
Re: Hackers ship their exploits directly to their target’s mailroom
#54>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a reada…
Not really, this is a known "vulnerability" with WPA2 and has been demonstrated to work a lot of times. https://www.aircrack-ng.org/doku.php?id=cracking_wpa#step_4_... This is done completely offline once you have the handshake captured and can be easily scaled.
Re: Hackers ship their exploits directly to their target’s mailroom
#55Earlier quoted context omitted.
If it's not a strong hash and the protocol doesn't include salting, it's not impossible. Rainbow tables exist. And they really only need to find a collision. Wi-Fi protocols, especially WEP, have had vulnerabilities similar to this before. Similar in the sense that if you sniffed enough traffic you could figure out the password (don't recall the specific mechanisms - but this could be one).
It's unfair to say that there is no salting. The PMK is derived from the WiFi network name (SSID) as well as the password [1]. The SSID acts as a salt here. Not perfect as SSIDs are often not unique, but it's certainly better than no salting at all. [1]: https://www.ins1gn1a.com/understanding-wpa-psk-cracking/
Re: Hackers ship their exploits directly to their target’s mailroom
#56Source, without all the TechCrunch "OMG Hackers" stuff: https://securityintelligence.com/posts/package-delivery-cybe... Do everyone a favor, mister mod.
Re: Hackers ship their exploits directly to their target’s mailroom
#57This could be really fun for people who live in apartment complexes. Break your neighbor's wifi by using this little, no-fuss box. You could probably make a killing selling these for $100 - 200 on Etsy or something.
Only the main question remains: why do you need this if you could simply crack your neighbour's wifi by using a high-gain antenna hidden behind the walls of your own flat?
Re: Hackers ship their exploits directly to their target’s mailroom
#58Re: Hackers ship their exploits directly to their target’s mailroom
#59I mean, if a package that looks like it came from NewEgg containing a router shows up, especially if it matches the type the company usually uses, which wouldn't be too hard to figure out, what are the chances it just gets tossed on a shelf to be used next time one is needed? Or do companies have sophisticated controls in place for something like that?