ãµã€ã¯ã«ã®æåã®éšå㯠habrasocietyã«ãã£ãŠéåžžã«é®®æã«æè¿ãããŸããã ååã®èšäºã«ã¯å€ãã®è³¢æãªã³ã¡ã³ããæ®ãããŠããŸããããå¿ããæè¬ããŠããŸãã 圌ããèšãããã«ãããªããããªãã®ç¥èã®æ¬ é¥ãèŠã€ããããªãã°ãHabrã«é¢ããèšäºãæžããŠãã ããã
ãã®èšäºã§ã¯ããé ãããããããã¯ãŒã¯ãæ€åºããæ¹æ³ãã¢ã¯ã»ã¹ãã€ã³ãã§MACãã£ã«ã¿ãªã³ã°ããã€ãã¹ããæ¹æ³ãããã³WPSïŒTP-LINKçšèªã§ã¯QSSïŒãããã¹ãŠã®å®¶åºã®ããã¯ãã¢ãã§ããçç±ã«ã€ããŠèª¬æããŸãã ãã®åã«ãã¯ã€ã€ã¬ã¹ã¢ããã¿ãŒãšã¢ã³ãããã©ã®ããã«æ©èœãã Kali Linux ïŒäŸïŒ Backtrack ïŒãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãžã®äŸµå ¥ãã¹ãã«ã©ã®ããã«åœ¹ç«ã€ããç解ããŸãã
ãã®ãã¹ãŠã¯ãäœããã®åœ¢ã§ããããšä»ã®ãªãœãŒã¹ã®äž¡æ¹ã§ãã§ã«ä»¥åã«èª¬æãããŠããŸããããã®ãµã€ã¯ã«ã¯ãæ確ãªçµè«ã§ãç°¡åãªèšèªã§ç°ãªãçè«ãšå®è·µãäžç·ã«åéããããšãæå³ããŠããŸãã
ãããèªãåã«ã ææã«ç²Ÿéããããšã匷ããå§ãããŸã-ããã¯çãã§ããããã¹ãŠã®ç§ãã¡ã®ãããªãè¡åãšçµè«ã¯ããã«åºã¥ããŠããŸãã
ç®æ¬¡ïŒ
1ïŒ çŽ æ
2ïŒã«ãŒãªãŒã SSIDãé衚瀺ã«ããŸãã MACãã£ã«ã¿ãªã³ã°ã Wps
3ïŒ WPAã OpenCL / CUDAã ãããã³ã°çµ±èš
Kali ... Kali Linux
æåã®éšåã§çŸåšã®ã¯ã€ã€ã¬ã¹ã»ãã¥ãªãã£ã¡ã«ããºã ã«ã€ããŠåŠç¿ããã®ã§ ãå®éã«ãã®ç¥èã䜿çšããŠãäœãïŒåœç¶ãç§ãã¡ã®ãã®ïŒããããã³ã°ããããšããŸãã ããŸãããã°ãç§ãã¡ã®é²åŸ¡ã¯è¯ããããŸããã
ãã¹ãŠã®æäœã¯ã Kali Linux-kali.orgã䜿çšããŠå®è¡ãããŸãã ããã¯ã以åã¯BacktrackãšåŒã°ããŠããDebianããŒã¹ã®ãã«ãã§ãã ãã®ã·ã¹ãã ã«æ £ããã®ããããåããŠã®å Žåã¯ã Backtrackã«ãã£ããã®ããã¹ãŠææ°ã®åœ¢åŒã§ãããããããã«Kaliããå§ããããšããå§ãããŸãã
ïŒèªè ã¯ã wifiway.orgãªã©ãä»ã®åæ§ã®ã¢ã»ã³ããªãããããšã瀺åããŠããŸããããããç§ã¯ãããã䜿çšããŸããã§ãããïŒ
Windowsã§ã¯ã説æãããŠããããšã®å€ããè¡ãããšãã§ããŸãããäž»ãªåé¡ã¯ãã¯ã€ã€ã¬ã¹ã¢ããã¿ãŒã®ã¢ãã¿ãŒã¢ãŒãã®ãµããŒãã®äžè¶³/äžååã§ããããã±ããããã£ããããã®ãé£ãããªããŸãã èå³æ·±ãã®ã¯ã CommViewãšElcomsoftãŠãŒãã£ãªãã£ã«æ³šæããŠãã ãã ã ãããã¯ãã¹ãŠç¹å¥ãªãã©ã€ããŒãå¿ èŠãšããŸãã
Kaliã¯ãã©ãã·ã¥ãã©ã€ããã䜿çšããã®ã«éåžžã«äŸ¿å©ã§ã-Debian Wheezyããç¶æ¿ããŸã ïŒ
ãããããã¡ããããããããŒããã£ã¹ã¯ã«ã€ã³ã¹ããŒã«ããã人ã¯èª°ã§ããããŒãããŒããŒãšæ¢ã«å®è¡äžã®ã·ã§ã«ã®äž¡æ¹ããç°¡åã«ãããè¡ãããšãã§ããŸãã OSïŒLVMïŒã¯æå·åãããããŒãã£ã·ã§ã³ããµããŒãããŸãã ããã«ãç¬èªã®Kaliã¢ã»ã³ããªãäœæã§ããŸã-ããã±ãŒãžã®è¿œå ãããŒãããŒããŒã®æ§æãªã©ã ãããã¯ãã¹ãŠããã¥ã¡ã³ãã§è©³çŽ°ã«èª¬æãããŠãããåé¡ã¯çºçããŸããããã¢ã»ã³ããªã«ã¯æ°æéããããŸãã
ãããã£ãŠã ISOãããŠã³ããŒãããŠUSBãã©ãã·ã¥ãã©ã€ãã«æžã蟌ãã ãšããŸãããïŒ* nix-
dd
å ŽåãWindowsã®å Žå-Win32DiskImager ïŒã 次ã¯ïŒ
æç¶ã¢ãŒã
ãã®èšäºã¯Linuxã®ããã¥ã¢ã«ã§ã¯ãããŸããããç§èªèº«ããã®ã¢ãŒããèµ·åããã®ã«åé¡ããã£ãããããã®æäœãå ·äœçã«èª¬æããããšã«ããŸããã
KaliãLive CDã¢ãŒãã§äœ¿çšããããšã¯éåžžã«å¯èœã§ãããåèµ·åïŒããŒã¿ãšèšå®ïŒã®éã«ã·ã¹ãã ã®ç¶æ ãä¿åã§ããããã«ããå Žåã¯ãååãpersistenceã®ãã©ãã·ã¥ãã©ã€ãã«å¥åã®ext2-ããŒãã£ã·ã§ã³ãäœæããå¿ èŠããããŸããäœæ¥äžã®USBãã©ãã·ã¥ãã©ã€ãã ããŒãã£ã·ã§ã³ãäœæããããããããããŠã³ããã persistence.confãšããååãšæ¬¡ã®å 容ãæã€ãã¡ã€ã«ã®ã¿ãæžã蟌ã¿ãŸãã
/ union
次ã«ã Kaliãèµ·åãããã³ã«ãã·ã¹ãã ãèµ·åããã¢ãŒããæå®ããå¿ èŠããããŸãã ãããè¡ãã«ã¯ãããŒãããŒããŒã§ãæåã®
Live (i686-pae)
ã¢ã€ãã
Live (i686-pae)
ïŒx64ãšåæ§
Live (i686-pae)
éžæããŠTabãæŒããŸã -ã«ãŒãã«ããŒãè¡ã衚瀺ãããŸãã ããã§ãæåŸã«ã¹ããŒã¹ãšè² è·ã®ã¿ã€ããè¿œå ããŸãã
- persistence ããå®å šãªäžå€æ§ã-ããŒãã£ã·ã§ã³äžã®ãã¹ãŠã®ããŒã¿ãããŒãããäœæ¥äžã«å€æŽãããããŒã¿ãä¿åãã
- persistence persistence-read-only ããå€æŽãä¿åããªãæ°žç¶æ§ã-ãããã¯2ã€ã®åèªã§ãããã¹ããŒã¹ã§åºåã£ãŠäž¡æ¹ãæå®ããå¿ èŠãããããšã«æ³šæããŠãã ãããæåã®ã¢ãŒãããªããšããã®ã¢ãŒãã¯éå§ããŸããïŒã©ã€ãã¢ãŒãããããŸãïŒã ãã®ã¢ãŒãã§ã¯ã以åã«ã»ã¯ã·ã§ã³ã«ä¿åãããããŒã¿ãããŠã³ããŒããããŸããããã®ã»ãã·ã§ã³äžã®å€æŽã¯ä¿åããããã·ã£ããããŠã³åŸãé åžã¯å ã®ç¶æ ã«æ»ããŸã
ããŒãã®ã¿ã€ããæå®ããªãå Žåãã·ã¹ãã ã¯ã©ã€ãïŒããã©ïŒã¢ãŒãã§èµ·åããŸã- æ°žç¶ã»ã¯ã·ã§ã³ã¯äœ¿çšããããããŒãåŸã«ããŠã³ãããŠå€æŽããããšãã§ããŸãã ã©ã€ãã¢ãŒãã§ã®æäœäžã®ãã¹ãŠã®ããŒã¿ãšèšå®ã¯ä¿åããããäžæã¡ã¢ãªã«ã®ã¿å«ãŸããŸãã
èµ·åãããã³ã«ãããã®ã¢ãŒããé§åããªãããã«ãç¬èªã®Kaliã¢ã»ã³ããªãäœæã§ããŸãïŒ ãµã€ãã®æ瀺ãåç §ïŒ-å¿ èŠãªã¢ãŒãã«å ¥ãããšãã§ããããŒãããŒããŒèšå®ãããã
persistence persistence-read-only
ã«
persistence persistence-read-only
ããŒããããããã«-ç§ã®æèŠã§ã¯ããããæãå¿ èŠãªãã®ããã¹ãŠæåã«èšå®ããŠãããåã»ãã·ã§ã³ãæåããéå§ããã®ã§äŸ¿å©ã§ãã
ããŒã«ã䜿çšãã«ãŒã¯
ããŠãããã§ã¿ãŒããã«ã«çããŸããã ç§ãã¡ã®åšãã®èª°ãè¶ é³æ³¢ã§èŒããŠããã®ãèŠãŠã¿ãŸãããã
Wi-Fiã¢ããã¿ãŒã¢ãŒã
ãã ããæåã«ã¯ã€ã€ã¬ã¹ã¢ããã¿ïŒãããã¯ãŒã¯ã«ãŒãïŒããããã«ãŒã¢ãŒãã- ã¢ãã¿ãŒã¢ãŒãã«ç§»è¡ããå¿ èŠããããŸã ã
å®éãç©çã¬ãã«ã§ã®åWi-Fiã¢ããã¿ãŒããŸãã¯ãããã¢ã³ããã¯ãç¯å²å ã®ããã€ã¹ã«ãã£ãŠéä¿¡ãããä¿¡å·ãæŸããŸãã ã¢ã³ããã¯ãç¡é¢ä¿ãªãã±ããããåãå ¥ããªããããšã¯ã§ããŸããã ãã ãããã©ã€ããŒã¯3ã€ã®ã¢ãŒãã§åäœã§ããŸãïŒ å®éã«ã¯6ã§ãããããã¯ãã®èšäºã®ç¯å²å€ã§ãïŒã
- ã¯ã©ã€ã¢ã³ãã¢ãŒã ïŒ ç®¡çã¢ãŒãã§ããããŸã ïŒ-ãã®ã¢ããã¿ãŒåãã§ã¯ãªããã±ãã-ã¯ç Žæ£ãããæ®ãã¯ãåä¿¡ããšããŠOSã«è»¢éãããŸãã ãã®ã¢ãŒãã§ã¯ãç Žæãããã±ãããç Žæ£ãããŸãã éåžžã®åäœã¢ãŒãã¯ããã€ãã¹ã«ãªããã§ãã
- ã¢ãã¿ã¢ãŒã ïŒ rfmonã¢ãŒããïŒ-ãã©ã€ãã¯ãã±ããããã£ã«ã¿ãªã³ã°ãããã¢ã³ãããæŸã£ããã¹ãŠãOSã«è»¢éããŸãã ãã§ãã¯ãµã ãæ£ãããªããã±ããã¯ç Žæ£ããã ãããšãã°Wiresharkã§èŠãããšãã§ããŸãã
- ç¡å·®å¥ã¢ãŒã -ã¢ãã¿ãŒã¢ãŒãã¯ãååãã§ãã ãã©ã€ããŒã¯ãçŸåšæ¥ç¶ãããŠããïŒé¢é£ä»ããããŠããïŒãããã¯ãŒã¯å ã§åä¿¡ãããã±ãããOSã«éä¿¡ããŸãããéåžžã¢ãŒããšã¯ç°ãªãããã®ãããã¯ãŒã¯ã®ä»ã®ã¯ã©ã€ã¢ã³ãå®ãŠã®ãã±ããã¯ç Žæ£ãããŸããã ä»ã®ãããã¯ãŒã¯ã®ãã±ããã¯ç¡èŠãããŸãã ããã¯ãäœããã®ãããã¯ãŒã¯ã«æ£åžžã«æ¥ç¶ããŠãã°ã€ã³ã§ããïŒéããŠãããã©ããã«ãããããïŒå Žåã«ã®ã¿æ©èœããããšã¯æããã§ãã ã¢ãã¿ãŒãšã¯ç°ãªãããã®ã¢ãŒãã¯ããå°ãªãã¢ããã¿ãŒã§ãµããŒããããŠããŸãã ãã®ã¢ãŒãããã³ã¯ã©ã€ã¢ã³ãã¢ãŒãã§äœæ¥ããŠããå Žåããã©ã€ããŒã¯OSã«éä¿¡ããããã±ããããäœã¬ãã«ã®ãã£ãã«ããããŒãåé€ããŸãã
ç£èŠã¢ãŒããå¿ èŠãªã ãã§ããã¯ã©ã€ã¢ã³ãã¢ãŒãã§ã¯ãèªåå®ãŠã®ãã±ãããèŠãããšã«èå³ã¯ãããŸããããææãªã¢ãŒãã§ã¯ããŸãäœããã®ãããã¯ãŒã¯ã«æ¥ç¶ããå¿ èŠããããŸãã ç Žæãããã±ãããš802.11ããããŒã®ååšã¯å¥ãšããŠãã¢ãã¿ãŒã¢ãŒãã¯ä¹±éãªã¢ãŒããšåãã§ããå¯èœæ§ããããã¢ããã¿ãŒã®å€§éšåããµããŒãããŠããŸãã å¯äžã®åé¡ã¯ããã¹ãŠã®ã¢ããã¿ãŒãã¢ãã¿ãŒã¢ãŒãã§åæã«ããŒã¿ãéä¿¡ã§ããããã§ã¯ãªãããšã§ãããç§ã¯å人çã«ã¯ããã«åé¡ã¯ãããŸããã§ããã
äžã®åçã§ã¯ã倪ç·ã¯ç°ãªãã¢ãŒãã§ã€ã³ã¿ãŒã»ãããããã±ããã瀺ããç Žç·ã¯ã¢ã³ããã§ãã£ãããããããéžæãããã¢ãŒãã®ããã«ãã©ã€ããŒã«ãã£ãŠç Žæ£ããããã±ããã§ãã
ã¿ãŒããã«ãéããŠå®è¡ããŸãïŒ
airmon-ng start wlan0
wlan0ã¯ãã¢ããã¿ãŒããã€ã¹ã®èå¥åã§ãã * nixã§ã¯ãããã¯wlan +ã·ãªã¢ã«çªå·ïŒ wlan0ãwlan1ãwlan2ãªã©ïŒã§ãã ifconfigãŸãã¯iwconfigãå®è¡ãããšãã¢ããã¿ãŒçªå·ã確èªã§ããŸãïŒããã«ãããã¯ã€ã€ã¬ã¹ã¢ããã¿ãŒããã€ã¹ãšãã®ç¹å®ã®æ å ±ã®ã¿ã衚瀺ãããŸãïŒã
airmon-ngãã¡ãã»ãŒãžã衚瀺ããå ŽåïŒ mon0ã§
(monitor mode enabled on mon0)
ãã¢ããã¿ãŒã¯æ£åžžã«ã¢ãã¿ãŒã¢ãŒãã«ãªããŸããã
åŸãã³ãã³ãã§ã¯ãã¢ããã¿ãŒã®èå¥åã瀺ãããŠããŸãããä»®æ³èå¥åã¯mon0 ïŒ
mon1
ãªã©ïŒã§ãããå ã®èå¥å
mon1
ã§ã¯ãããŸããã mon0ã¯ãã¢ãã¿ãŒæ©èœã§åäœããããã«èšèšãããairmon-ngã«ãã£ãŠäœæãããã¢ããã¿ãŒã§ãã
çŸåšããã®ã¢ãŒãã¯ïŒç§ã®çµéšã§ã¯ïŒãã¹ãŠã®ã¢ããã¿ãŒã®80-90ïŒ ã§ãµããŒããããŠãããæãäžè¬çãªãã®ã¯AtherosãIntelãTP-LINKã§ãã åŸè ã¯ãæ倧30ãã«ã®äº€æå¯èœãªã¢ã³ãããåããå€éšã¢ããã¿ãŒãçç£ããŸãïŒç§ã¯TL-WN722NC + TL-ANT2408CLã䜿çšããŸãã - ããã« ãUSBã®ãããã§VMwareã«æ¥ç¶ã§ããŸãïŒã ãµããŒããããŠããã¢ããã¿ãŒã®ãªã¹ãã¯ã Aircrack-ng wikiã«ãããŸã ã
ç¡ç·ãã£ã³ãã«
Wi-Fiã¯ãç¡ç·ãã£ãã«ãä»ããŠããŒã¿ãéä¿¡ããããã®æè¡ã§ãã
åèš13ã®ãã£ãã«ããããŸããã13çªç®ã®æåŸã®ãã£ãã«ã¯
ããã«ã14çªç®ã®ãã£ãã«ïŒæ¥æ¬äººã¯ãã€ãã®ããã«åºå¥ãããŸãïŒãš5 GHzã®åšæ³¢æ°ããããããã«23ã®ãã£ãã«ããããŸãã äžè¬ã«ã2.4 GHzãã£ãã«ã¯éšåçã«ãªãŒããŒã©ããããããã«ãã®å¹ ã¯20ããã³40 MHzã«ãªããŸãã ãã®ãããã¯ã¯ãããŸããŸãªããŒãžã§ã³ã®æšæºãå©çšå¯èœã§ãããããæ··ä¹±ãæããŸããèå³ããã人ã¯èª°ã§ããŠã£ãããã£ã¢ã§èªãããšãã§ããŸãã ãã§ã«èšãããããšã¯ååã«ãããŸãã ãããŸã§ã®ãšããã5 GHzã¯ããŸã䜿çšãããŠããŸãããã以äžã§èª¬æããææ³ã¯ãã®åšæ³¢æ°ã«ãé©çšãããŸãã
äžéšã®ãŠãŒã¶ãŒã¯ãã£ãã«13ã䜿çšããŠãããã¯ãŒã¯ãé ããŠããŸããããã®æ¹æ³ã¯ãã¢ããã¿ãŒãç®çã®é åã«è»¢éããã ãã§ååãªã®ã§ãããã§ã¯èæ ®ããŠããŸããã äŸïŒ
ifconfig wlan0 down iw wlan0 reg set BO ifconfig wlan0 up iwconfig wlan0 channel 13
ã¯ã€ã€ã¬ã¹ã¢ããã¿ã¯ãäžåºŠã«1ã€ã®ãã£ãã«ã§ã®ã¿ããŒã¿ãéåä¿¡ã§ããŸãã ãã ããçŸåšã®ãã£ãã«ã¯ä»»æã«é »ç¹ã«å€æŽã§ããŸã-airodump-ngã®åšå²ã®ã¯ã€ã€ã¬ã¹äŒéã«é¢ããå®å šãªæ å ±ãååŸããããïŒä»¥äžã®
NetworkManager
for GNOMEã¯ãå³äžé ã«ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ãªã¹ãã衚瀺ããŸãã
ãã£ãã«ãåºå®ãããŠããªãå Žåãäžéšã®ãã±ããã倱ãããå¯èœæ§ããããŸããã¢ããã¿ãé£æ¥ãã£ãã«ã«åãæ¿ããããã®æç¹ã§æ°ãããã±ãããåã®ãã£ãã«ãééããŸãããããã®ã¢ã³ããã¯ãã£ããããŸããã§ããã ããã¯ããã³ãã·ã§ã€ã¯ãååããããšããå Žåã«éèŠã§ãããããã£ãŠãã¯ã€ã€ã¬ã¹ã¢ããã¿ã䜿çšãããã£ãã«ã®ããã¯ãèš±å¯ããªããã¹ãŠã®ããã°ã©ã ãç¡å¹ã«ããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã
airmon-ng check kill
killã䜿çšããªãå Žåããã¹ãŠã®çãããããã»ã¹ã®ãªã¹ãã衚瀺ããã killã䜿çšãããšããããå®äºããŸãã ãã®åŸãã¢ããã¿ãŒã¯å®å šã«èªç±ã«äœ¿çšã§ããŸãã ã¯ã€ã€ã¬ã¹ã¢ããã¿ã¯äžè¬çãªãªãœãŒã¹ã§ããããããããã¯ãŒã¯ã®ç°¡åãªæŠèŠãé€ããã¢ã¯ã·ã§ã³ã®åã«äžèšã®ã³ãã³ããå®è¡ããããšããå§ãããŸãã è€æ°ã®ããã°ã©ã ãåæã«äœ¿çšã§ããŸãïŒããšãã°ã airodump-ngã§ãããã¯ãŒã¯ã®ãªã¹ããååŸããåæã«reaverã§WPSãéžæã§ããŸãïŒãããããããã£ãã«ãåãæ¿ããããšãã§ãããããéå§æã«ä¿®æ£ããããšãéèŠã§ãïŒéåžžããã©ã¡ãŒã¿ã¯-cãŸãã¯-ãšåŒã°ããŸãïŒ ãã£ã³ãã« ïŒã
ã¢ã³ãããªãŒããŒã¯ããã¯
é åã®æäœã«å ããŠã ifconfigã¯ãããã©ã«ããããé«ãé»åã§ã¢ããã¿ãŒãåäœãããããšãã§ããŸãã çµæã¯ã¢ããã¿ãŒãšå°åã®ã¿ã€ãã«å€§ããäŸåããé·æé䜿çšãããšããã€ã¹ãç Žæã
ifconfig wlan0 down # . iw reg set BO iwconfig wlan0 txpower 500mW # : iwconfig wlan0 txpower 30 ifconfig wlan0 up
éåžžã®é»åã¯15ã20 dBmã§ãã ãšã©ãŒãããå Žåã
Invalid argument
ã¿ã€ãã®ã¡ãã»ãŒãžã衚瀺ãããŸããã衚瀺ãããªãå ŽåããããŸããå®è¡åŸã iwconfigã®txpowerå€ã確èªããŠãã ããã
圌ãã¯ç§ãã¡ã®äžã«ãã
ç§ãã¡ã¯å®æœããŸãïŒ
airodump-ng mon0
airodump-ng-ãªã³ãšã¢ã§ãã±ãããåéããã³ãã³ãã ã³ã³ãœãŒã«ã«2ã€ã®ããŒãã«ã衚瀺ãããŸãã èŠã€ãã£ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã¯äžéšã«è¡šç€ºãããã¯ã©ã€ã¢ã³ãã¯æ¥ç¶ãããŠãããã©ããã«ããããããããã€ãã®ãã±ããããããŒããã£ã¹ãããã¢ã¯ãã£ããªã¯ã€ã€ã¬ã¹ã¢ããã¿ãŒïŒããšãã°ãç¹å®ã®ååã®ãããã¯ãŒã¯ã®æ€çŽ¢ïŒã衚瀺ãããŸãã
ã¡ãªã¿ã«ãåŸè ã¯ç¹ã«èå³æ·±ããã®ã§ããåžæãããããã¯ãŒã¯ã芪åã«æäŸãããªããã¯ã©ã·ããã§ä»æµè¡ããŠãããã®ãèŠãããšãã§ããããã§ãã å æ¥ã Karmaã® èšäºãåäž»é¡KarasikovSergeyã«ãã£ãŠãã®äž»é¡ã§å ¬éãããŸãã-ããããããã¯ãã§ã«ãã®ã·ãªãŒãºã§æ害ãªæµžéã®å±æ©ã«onããŠããããããã®ãããã¯ã«ã€ããŠã¯è§ŠããŸããã ããããããã¯æ¬åœã«åé¡ã§ãããããç¥ãããŠãããã®ãå«ããããã€ã¹ãèš±å¯ãªããã¹ãŠã®ãããã¯ãŒã¯ã«åºå·ããªãããã«æ³šæãã䟡å€ããããŸããã¢ã¯ã»ã¹ãã€ã³ãã®ä¿¡é Œæ§ã¯ãã§ãã¯ããããäŸµå ¥è ã®ãããã¯ãŒã¯ã«ããå¯èœæ§ããããŸãã ããããæå³ã§ã
ãããŠãããã§ç§ãã¡ã¯XP SP2ã«ããŸã...
ãããã¯ãŒã¯ãã¢ã¯ãã£ãã§ãªããšãã«ãããã¯ãŒã¯ã¢ããã¿ãŒãåæãã代ããã«ãã©ã³ãã ãªæåã»ããã§æ§æãããESSIDãèŠæ±ãå§ããWindows XP SP2ãæãåºããŠãã ããã ãã®çµæã airodump-ngã§ãã¬ãŒã¹ããããååã§ãã€ã³ããè¿ãã«äœæãããšãXPã¯ããã«æ¥ç¶ããŸãããæ¥ç¶ã¹ããŒã¿ã¹ãèŠããšããŠãŒã¶ãŒã¯ãããç¥ãããšãã§ããŸããïŒãéã¢ã¯ãã£ããã§ããããïŒãæçµçã«ã¯éåžžã«Skypeãæ©èœããŠããããšãšãã¹ã¯ãŒããæŒæŽ©ããŠããããšã«é©ããã ã¹ããŒã¹ãšã®çŽæ¥æ¥ç¶ïŒ
ããããç§ãã¡ã®æ³¢ã«æ»ããŸãããã airodump-ngã®åºåäŸã次ã«ç€ºããŸãã
CH 1 ][ Elapsed: 6 mins ][ 2014-06-06 12:45 BSSID PWR Beacons #Data, #/s CH MB ENC CIPHER AUTH ESSID 00:18:E7:xx:xx:xx -67 108 0 0 11 54e. WPA2 CCMP PSK infolan22451 F8:1A:67:xx:xx:xx -88 132 0 0 1 54e. WPA2 CCMP PSK TP-LINK 48:5B:39:xx:xx:xx -1 0 0 0 5 -1 <length: 0> BSSID STATION PWR Rate Lost Frames Probe (not associated) 4C:B1:99:xx:xx:xx -73 0 - 1 0 66 dlink 48:5B:39:xx:xx:xx 1C:7B:21:xx:xx:xx -81 0 - 1 0 21
䜿çšå¯èœãªã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãããæåã®è¡šã®åïŒ
- BSSIDã¯ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®äžæã®MACã¢ãã¬ã¹ã§ãã ãããã¯ãŒã¯ã«ãŒãã®MACã¢ãã¬ã¹ãšåæ§ã«ããããã¯ã³ãã³ã§åºåããã16é²åœ¢åŒã®6ã€ã®æ°åã§ããäŸïŒ
AA:00:BB:12:34:56
ä»ã®ã»ãšãã©ã®ããŒã ã«æž¡ãããŸãã - PWR-ä¿¡å·åŒ·åºŠã ããã¯è² ã®æ°ã§ãã 0ã«è¿ãã»ã©ãä¿¡å·ã¯åŒ·ããªããŸãã éåžžãå¿«é©ãªä»äºã®ããã«ããã®æ°ã¯æ倧-50ããããªéä¿¡ã§ã¯æ倧-65ãVoIPã§ã¯æ倧-75ã§ãã -85æªæºãç¹ã«-90æªæºã®å€ã¯ãéåžžã«åŒ±ããšèŠãªãããšãã§ããŸãã ãã®æ°ã¯ãéä¿¡æ©ã®åºåãšã¢ããã¿ãŒã®ã¢ã³ããã²ã€ã³ã«ãã£ãŠç°ãªããŸãïŒå€éšã¢ããã¿ãŒã®ã²ã€ã³ã¯0ã12 dBãå€éšã®1-2ã¡ãŒãã«å šæ¹åæ§ã¢ã³ãã-æ倧24 dBïŒ
- ããŒã³ã³ -ãã®ã¢ã¯ã»ã¹ãã€ã³ãã«ãã£ãŠéä¿¡ããããããŒã³ã³ãã®æ°âãã®ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ååšãä¿¡å·åŒ·åºŠããã®ååïŒBSSID / ESSIDïŒããã³ãã®ä»ã®æ å ±ãè¿ãã®ããã€ã¹ã«éç¥ãããã±ããã æ¥ç¶ã«äœ¿çšããŸãã ããã©ã«ãã§ã¯ãã¢ã¯ã»ã¹ãã€ã³ãã¯éåžž100ããªç§ïŒ1ç§ããã10åïŒããšã«ããŒã³ã³ãéä¿¡ããããã«èšå®ãããŠããŸãããééã¯1ç§ã«å¢ããããšãã§ããŸãã ããŒã³ã³ãååšããªãããšã¯ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãååšããªãããšã瀺ããã®ã§ã¯ãããŸãããé衚瀺ã¢ãŒãã§ã¯ãã¢ã¯ã»ã¹ãã€ã³ãã¯ããŒã³ã³ãéä¿¡ããŸãããããããã¯ãŒã¯ã®æ£ç¢ºãªååãããã£ãŠããå Žåã¯æ¥ç¶ã§ããŸãã ãã®ãããªãããã¯ãŒã¯ãæ€åºããæ¹æ³ã«ã€ããŠ-以äžã
- #Data-ãã®ã¢ã¯ã»ã¹ãã€ã³ãããéä¿¡ãããããŒã¿ãã±ããã®æ°ã ããã«ã¯ãHTTPãã©ãã£ãã¯ãARPèŠæ±ãèš±å¯èŠæ±ïŒãã³ãã·ã§ã€ã¯ïŒãªã©ããããŸãã ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããã¯ã©ã€ã¢ã³ãããªãå ŽåããŸãã¯äœãéä¿¡ããªãå Žåããã®å€ã¯å€æŽãããã0ã«ãªãå ŽåããããŸãã
- ïŒ/ sã¯ã1ç§ãããã®ããŒã¿ãã±ããæ°ã§ãã ïŒãã®ãããã¯ãŒã¯ãç£èŠãããæéã§å²ã£ãããŒã¿ã
- CHã¯ãã£ãã«çªå·ã§ãã ãã§ã«äžã§èª¬æããããã«ãWi-Fiã®å©çšå¯èœãªç¯å²å šäœã14ãã£ãã«ã«åå²ãããŠããŸãã ã¢ã¯ã»ã¹ãã€ã³ããšãããã«å¿ããŠãã¯ã©ã€ã¢ã³ãã¯ç¹å®ã®ãã£ãã«ã§ããŒã¿ãéä¿¡ãããã®åã¯ããã®ã¢ã¯ã»ã¹ãã€ã³ããšãã®ã¯ã©ã€ã¢ã³ããã©ã®ãã£ãã«ã«é¢é£ä»ããããŠãããã瀺ããŸã
- MBã¯ãMbpsåäœã®äŒéé床ïŒãã£ãã«å¹ ïŒã§ãã æ«å°Ÿã®ãããã¯ãã¢ã¯ã»ã¹ãã€ã³ããçãããªã¢ã³ãã«ããµããŒãããŠããããšã瀺ããŸãã å€11ã54ã54eã確èªã§ããŸãã éåžžãããã¯ããŸãæ°ã«ããŸããã
- ENC-ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ã¿ã€ã-OPNïŒãªãŒãã³ïŒãWEPãWPAãWPA2ã ãã®ãã©ã¡ãŒã¿ãŒã«åºã¥ããŠãé©åãªæ»æã¹ããŒã ãéžæããŸãã
- CIPHER-ãã³ãã·ã§ã€ã¯åŸã®ããŒã¿æå·åã®ã¿ã€ãã TKIPãšCCMPãããå ŽåããããŸãïŒ ååã®æŠèŠãåç §ïŒã
- AUTHã¯ãäžæããŒãéä¿¡ããããã®èªèšŒã¡ã«ããºã ã§ãã PSKïŒWPAïŒ2ïŒã®å ±éãã¹ã¯ãŒãèªèšŒïŒãMGTïŒRADIUSããŒãåããå¥ã®ãµãŒããŒãåããWPAïŒ2ïŒãšã³ã¿ãŒãã©ã€ãºïŒãOPNïŒãªãŒãã³ïŒã®ããããã§ãã
- ESSIDã¯ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ååã§ãã ããã¯ãWindowsã®ãã¯ã€ã€ã¬ã¹ãããŒãžã£ãŒãã«è¡šç€ºãããã¢ã¯ã»ã¹ãã€ã³ãã®èšå®ã§æå®ãããã®ã§ãã ããã¯ãŠãŒã¶ãŒåã§ãããããäžæã§ã¯ãªãå Žåãããããã¹ãŠã®å éšæäœã§BSSIDïŒã¢ã¯ã»ã¹ãã€ã³ãã®ã¢ããã¿ãŒã®MACã¢ãã¬ã¹ïŒã䜿çšãããããã¯åãªã衚瀺åã§ãã
å Žåã«ãã£ãŠã¯ãäžéšã®åã§æ°å€-1ãèŠãããšãã§ããæåŸã®å
<length: 0>
èŠãããšãã§ããŸãã ãããã¯ãããŒã¿ãæ確ãªåœ¢åŒã§ãããŒããã£ã¹ãããªãããã¯ã©ã€ã¢ã³ããæ£ããESSIDãšãã¹ã¯ãŒãã䜿çšããŠæ瀺çãªæ¥ç¶èŠæ±ãè¡ã£ããšãã«ã®ã¿å¿çããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®å åã§ãããŸããã¢ã¯ã»ã¹ãã€ã³ãã¯ããŒã³ã³ããŸã£ãããããŒããã£ã¹ããããååãç¥ã£ãŠããã¯ã©ã€ã¢ã³ããããŒã³ã³ã«æ¥ç¶ãããšãã«ã®ã¿ã¢ã¯ãã£ãã«ãªããŸããairodump-ngãååé·ãæéå®è¡ããããŸãŸã§ããã®æéã«æ°ããã¯ã©ã€ã¢ã³ããé衚瀺ã®ãããã¯ãŒã¯ã«æ¥ç¶ãããšããé衚瀺ããããã¯ãŒã¯ã«å¯Ÿå¿ããè¡ãèªåçã«éããããã£ãã«çªå·ãESSIDãããã³ä¿è·ããŒã¿ã衚瀺ãããŸãããã®å Žåãæ¥ç¶ã®ç¬éãèŠéããªãããã«ãã£ãã«ãä¿®æ£ããå¿ èŠãããå ŽåããããŸãïŒä»¥äžãåç §ïŒã
ã¯ã€ã€ã¬ã¹ã¯ã©ã€ã¢ã³ããå«ã2çªç®ã®ããŒãã«ã®åïŒ
- BSSID-ã¯ã©ã€ã¢ã³ããæ¥ç¶ãããŠããã¢ã¯ã»ã¹ãã€ã³ãã®MACã¢ãã¬ã¹ïŒæåã®è¡šãåç §ïŒãïŒé¢é£ä»ããããŠããªãïŒãæå®ãããŠããå Žåãã¯ã©ã€ã¢ã³ãã¯ãã¹ãŠã®ãããã¯ãŒã¯ããåæãããŸãããã¢ããã¿ãŒã¯æ©èœããŠããŸãïŒããããã䜿çšå¯èœãªãããã¯ãŒã¯ãæ¢ããŠããŸãïŒã
- STATION â MAC- . - , . Linux/Mac ., Windows . MAC- , , , MAC .
- PWR â . 0, / (. ).
- Rate â airodump-ng (. ), ( ) ().
- ãã¹ãã®ç§ãã¡ã®ã·ã¹ãã ïŒã¯ã©ã€ã¢ã³ãã§ã¯ãªãïŒãç»é²ãããŠããªãããšãã倱ããããã±ããã®æ°- ãéä¿¡ããããã±ããã«ã¯ã«ãŠã³ã¿ãŒããããããããã¯ç°¡åã«èšç®ã§ããŸãã
- ãã¬ãŒã ãŸãã¯ãã±ãã -ãã®ã¯ã©ã€ã¢ã³ããããã£ããããããŒã¿ãã±ããã®æ°ïŒæåã®è¡šã®#Dataãåç §ïŒã
- ãããŒã -ã¯ã©ã€ã¢ã³ããæ¥ç¶ããããšããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ESSIDåã®ãªã¹ããåšå²ã«è¡šç€ºããããããã¯ãŒã¯ã§ã¯ãªããã¯ã©ã€ã¢ã³ãã以åã«æ¥ç¶ãããããã¯ãŒã¯ããŸãã¯é衚瀺ã®ãããã¯ãŒã¯ããªã¹ããããŠããå ŽåããããŸããããã«åºã¥ããŠãåè¿°ã®ããã«Karmaã®ãããªæ»æãæŽçã§ããŸãã
Airodump-ngã®èµ·åãªãã·ã§ã³ïŒçµã¿åãããããšãã§ããŸãã詳现ã¯ä»¥äžã®éšåã§ïŒïŒ
-
airodump-ng -c 3 mon0
â â3 â (- ). -
airodump-ng -w captures.pcap mon0
âcaptures.pcap
â offline- WEP/WPA ( ). -
airodump-ng --essid " " mon0
â (/) . , . -
airodump-ng --bssid 01:02:03:AA:AA:FF mon0
â MAC- (BSSID). --essid .
âŠ
æ¥åžžç掻ã§ã¯ãé ãããããã¯ãŒã¯ã®æ€åº/æ¥ç¶/ãããã³ã°/奪åãéåžžã«å°é£ã§ããããšããããããŸãïŒå¿ èŠã«å¿ããŠäžç·ãåŒãïŒããã ãããã§ã«ç€ºããããã«ããé ãããããããã¯ãŒã¯ã¯ããã®ååšã«é¢ããããŒã³ã³ã1ç§éã«10åéä¿¡ãŸãã¯éä¿¡ããªããã空ã®ESSIDããã³ãã®ä»ã®ãã£ãŒã«ããæã€ãããã¯ãŒã¯ã«ãããŸããããããéãã®çµããã§ãã
ã¯ã©ã€ã¢ã³ãããã®ãããªãããã¯ãŒã¯ã«æ¥ç¶ãããšããã«ãESSIDãšãã¹ã¯ãŒããéä¿¡ããŸãããã®ãããªãããã¯ãŒã¯ãç¯å²å ã«ååšããå Žåãã¢ã¯ã»ã¹ãã€ã³ãã¯èŠæ±ã«å¿çããèªèšŒãšããŒã¿è»¢éã®ãã¹ãŠã®éåžžã®æé ãå®è¡ããŸãããŸããã¯ã©ã€ã¢ã³ãããã§ã«æ¥ç¶ãããŠããå Žå-ã¢ã¯ãã£ããªã¢ããã¿ãŒã®ãªã¹ãã«è¡šç€ºãããåæãããŸãã
æ¥ç¶ãããåã¯ã©ã€ã¢ã³ãã¯ããã®BSSIDã«ãã£ãŠããŒã¹ã¹ããŒã·ã§ã³ãšéä¿¡ããŸããããã¯ãæ£ç¢ºã«äž¡æ¹ã®airodump-ngããŒãã«ã«è¡šç€ºããããã®ã§ãããã¯ã©ã€ã¢ã³ãããããã¯ãŒã¯ãããåæãããããšãã§ããŸãããã®åŸãåæ¥ç¶ããå¿ èŠããããŸã-ãã®ç¬éã«airodump-ngã¯ãã¹ãŠã®èå¥åãšããŒã§ãã³ãã·ã§ã€ã¯ãã€ã³ã¿ãŒã»ããããŸãããŸãã¯ãç®çã®ãã£ãã«ã§airodump-ngã䜿çšããŠã©ãããããã®é»æºãæ°æéãªã³ã®ãŸãŸã«ããŠåŸ æ©ããããšãã§ããŸããã¡ãªã¿ã«ãå³äžé ã®ãæ€æ»ããæåãã
[ Decloak: 00:00:11:11:22:22 ]
ãšãã¢ã¯ã»ã¹ãã€ã³ãã®BSSIDãå«ããã©ãŒã ã®ã¡ãã»ãŒãžã衚瀺ãããŸãã
ã¯ã©ã€ã¢ã³ãã®åæã¯ããã¹ãŠã®ã¯ã€ã€ã¬ã¹èŠæ Œã§æäŸãããaireplay-ngã䜿çšããŠè¡ãããŸãïŒç§ãã¡ããã§ã«ç¥ã£ãŠãã3ã€ã®ãŠãŒãã£ãªãã£ã¯ãã¹ãŠãAircrack-ngãããžã§ã¯ãã®äžéšã§ãããã»ããå ã®èãçŽ æãæäœããããã®ããããçš®é¡ã®ããŒã«ãå«ãŸããŠããŸãïŒïŒ
aireplay-ng wlan0 --deauth 5 -a AP_BSSID -c CLIENT_BSSID
èŠåïŒãã®ã³ãã³ãã¯äŸå€ã§ãããairmon-ngã䜿çšããŠäœæãããmon0ã§ã¯ãªããå®éã®ã¯ã€ã€ã¬ã¹ã¢ããã¿ãŒã®èå¥åãåãå ¥ããŸããèµ·åæã«ãã³ããããããŠããªããã£ãã«ã«é¢ãããšã©ãŒã衚瀺ãããããå³äžé ã«airodump-ngã衚瀺ããããããå Žåãäžéšã®ããã°ã©ã ãŸãã¯ãµãŒãã¹ãã¢ããã¿ãŒã匷å¶çã«ãã£ãã«ãããã£ãã«ã«ãžã£ã³ããããŸãïŒåãairodump-ngã§ããå¯èœæ§ããããŸãïŒãåé ã§èª¬æããããã«ããã«ãã
[ fixed channel -1 ]
airmon-ng check kill
äžèšã®ã³ãã³ãã¯ãã¢ã¯ã»ã¹ãã€ã³ããå€ãããŒãç¡å¹ã§ããããšãã¯ã©ã€ã¢ã³ãã«éç¥ããç¶æ³ãã·ãã¥ã¬ãŒãããŸãïŒãã³ãã·ã§ã€ã¯ãç¹°ãè¿ããŠãã€ãŸããã¹ã¯ãŒããšãããã¯ãŒã¯åãå床転éããããšã§æŽæ°ããå¿ èŠããããŸãïŒãã¡ãã»ãŒãžã¯ãããããã¢ã¯ã»ã¹ãã€ã³ãããã¯ã©ã€ã¢ã³ãã®ã¢ãã¬ã¹ã«éä¿¡ããããããã¯ãŒã¯ããåæããŠã»ãã·ã§ã³ããŒã¿ãæŽæ°ããå¿ èŠããããŸãããã®ã¿ã€ãã®ãã±ããã¯æå·åãããŠããªãïŒã€ãŸããèªèšŒã®åã§ãã³ãã³ããå®è¡ã§ããïŒãããéä¿¡è ã®ãã¢ã€ãã³ãã£ãã£ãã確ç«ã§ããªããšããåçŽãªçç±ã§å¯Ÿæããããšã¯ã§ããŸããããã±ããå ã®MACã¢ãã¬ã¹ã¯åœé ããã-aããã³-cã®åŸã«æž¡ããå€ãé »ç¹ã«çºçããåæ¢ã®ã¿ãç£èŠããããã€ãã®å¯Ÿçãè¬ããããšãã§ããŸãã--deauthã®
åŸåŸåŸ©ã§éä¿¡ãããèªèšŒè§£é€ãã±ããã®æ°ããããŸããéåžžã¯3ã5ã§ååã§ããã30以äžãæå®ã§ããŸããç°¡æœã«
--deauth
ããããã«ã
-0
ïŒãŒãïŒã«çœ®ãæããããšãã§ããŸãã
ãã®ããã2çªç®ã®ããŒãã«airodump-ngã«æ¬¡ã®è¡ããããšããŸãããã
BSSID STATION PWR Rate Lost Frames Probe 4F:B1:A4:05:5C:21 5B:23:15:00:C8:57 -54 0 - 1 0 1266 homenet, XCom
æåã®åã¯-aïŒåºå°å±MACïŒã®å€ã§ã2çªç®ã®åã¯-cïŒã¯ã©ã€ã¢ã³ãMACïŒã®å€ã§ããairodump-ngãåèµ·åãããã£ãã«5ïŒããã¯æ»æãããã¹ããŒã·ã§ã³ã®ãã£ãã«ã§ãïŒã§ä¿®æ£ãã次ã®ã¿ãŒããã«ãŠã£ã³ããŠã§ã¯ã©ã€ã¢ã³ããåæããŸãã
airodump-ng -c5 mon0 aireplay mon0 -0 5 -a 4F:B1:A4:05:5C:21 -c 5B:23:15:00:C8:57
ä¿¡å·ãååã«åŒ·ãå Žåããã±ããã®æ°ã¯å€ããã¯ã©ã€ã¢ã³ã/ã¢ã¯ã»ã¹ãã€ã³ãã¯ç§ãã¡ãèãã-ãããã¯äºãã«åæããæ¥ç¶ããããšãã«åã³ãããã¯ãŒã¯ã«é¢ããæ å ±ãéä¿¡ããairodump-ngã¯ããããšã©ã€ã³ã衚瀺ããŸã
[ Decloak ]
ã
ã芧ã®ãšãããé衚瀺ããŒã³ã³ã䜿çšãããã®ããªãã¯ã¯ã誰ãã1æ¥ã«2ã3åæ¥ç¶ããããŒã ãããã¯ãŒã¯ã«äœ¿çšã§ããŸãããããã§ãåžžã«ã§ã¯ãããŸãã-ããããæåéã1ã€ã®ã³ãã³ããšããã«å¯Ÿããä¿è·ã«ãã£ãŠæããã«ãªãã®ã§ãäŒæ¥ãããã¯ãŒã¯ã«ã¯ééããªãæ©èœããŸããããç§ã®æèŠã§ã¯ããã©ã€ããŒããããã¯ãŒã¯ã®å Žåã§ããããã¯å©ç¹ãããäžäŸ¿ã§ããå¯èœæ§ãé«ããªããŸããååãæåã§å ¥åããå¿ èŠããããããŒã¹ã¹ããŒã·ã§ã³ãã¢ã¯ãã£ããã©ããã¯äžæã§ãã
ãŸãã-cïŒã¯ã©ã€ã¢ã³ãMACïŒã¯çç¥ã§ããŸããã¢ã¯ã»ã¹ãã€ã³ãã«ä»£ãã£ãŠãããŒããã£ã¹ããã±ãããéä¿¡ããããã¹ãŠã®ã¯ã©ã€ã¢ã³ããåæãããŸãããã ããããã¯ä»æ¥ã»ãšãã©æ©èœããŸãã-ãã©ã€ããŒã¯ãã®ãããªãã±ãããç¡èŠããŸããåé¡ãã¯ãªãŒã³ã§ãªããšæ£ããä¿¡ããŠããããã§ã-ã¢ã¯ã»ã¹ãã€ã³ãã¯åžžã«èª°ã«æ¥ç¶ãããŠããããèªèããç¹å®ã®ã¯ã©ã€ã¢ã³ãã«åããŠãã±ãããéä¿¡ããŸãã
MACãã£ã«ã¿ãªã³ã°-ãšãŠãç°¡å
ãããã¯ãŒã¯ãäœæããåŸã®æåã®ããšã¯ãã¯ã©ã€ã¢ã³ãã®ãªã¹ããç¹å®ã®MACã¢ãã¬ã¹ã®ã»ããã«å¶éããããšã§ããããã¹ã¯ãŒãã¯äžè¬ã«åœ¹ã«ç«ããªããšããæšå¥šäºé ãããè³ã«ããŸãããã ãããã®å¶éã¯ãç§å¯ã®ãããã¯ãŒã¯ãçºèŠãããã®ãšåããããç°¡åã§ãã
å®éãåã¯ã©ã€ã¢ã³ãã¯ããããã¯ãŒã¯ã«æ¥ç¶ãããŠãããã©ããã«é¢ä¿ãªãããã±ãããéä¿¡ãããšãã«MACã¢ãã¬ã¹ãæããã«ããŸããairodump-ngããŒãã«ã§ã¯ããããã®ã¢ãã¬ã¹ã¯STATIONåã«è¡šç€ºãããŸãããããã£ãŠãäœããã®çç±ã§ããã«å°éã§ããªããããã¯ãŒã¯ãèŠããšããã«ïŒLinuxã¯éåžž
Unspecified failure
æ¥ç¶æ®µéã§ããã«ã€ããŠå ±åããWindowsã¯é·ãéèããŠããäžæãªãšã©ãŒãå ±åããŸãïŒã次ã«ãã®ãããã¯ãŒã¯ã«æ¥ç¶ããŠããã¯ã©ã€ã¢ã³ãããªã¹ãã«è¡šç€ºããŸã- MACã¢ãã¬ã¹ãååŸããŠãèªåã®MACã¢ãã¬ã¹ãå€æŽã§ããŸããçµæã¯ç°ãªãå ŽåããããŸãã
Linuxã§ã¯ãã¢ããã¿ãŒã®MACã次ã®ããã«å€æŽã§ããŸãïŒæç·ãããã¯ãŒã¯ãšç¡ç·ãããã¯ãŒã¯ã®äž¡æ¹ã§æ©èœããŸãïŒã
ifconfig wlan0 down ifconfig wlan0 hw ether 00:11:22:AA:AA:AA ifconfig wlan0 up
æåã«ããã¹ãŠã®mon- interface ãç¡å¹ã«ããå¿ èŠããããŸããç²åŸãã眮æãåå ãšããããšãã§ãããã©ããã確èªããŠãã ãã
ifconfig wlan0
ã©ã€ã³ã«- HWADDR MACãè¶ ããã¹ãã§ãã
ããã«ã* nixã«ã¯macchangerããããŸããããã䜿çšãããšãã©ã³ãã ãªMACãèªåã§èšå®ã§ããŸããinit.dã«å ¥ãããšãããŒãããšã«MACãç°ãªããããæµã¯å®å šã«å°æããŸãïŒifconfigãªã©ã®æç·ããã³ç¡ç·ã¢ããã¿ãŒã§æ©èœããŸãïŒã
# MAC: macchanger -r wlan0 # MAC: macchanger -m 11:22:33:AA:BB:CC wlan0 # MAC: macchanger -s wlan0
Windowsã§ã¯ãã¬ãžã¹ããªãæäœããå¿ èŠããããŸããããã®ãããã¯ã«ã€ããŠã¯Googleã«çžè«ããããšããå§ãããŸããïŒalexeywolfã«ä»£è¡šãããèªè ã¯ããããèªåçã«è¡ãTMACããŒã«ãææ¡ããŠããŸããïŒ
ãã£ãš
ç§ãã¡ã¯ãã¹ãŠãæ£ããè¡ããã¢ã¯ã»ã¹ãã€ã³ãã¯ããã®63æ¡ã®ãã¹ã¯ãŒãã§äŸµå ¥äžå¯èœãªWPA2-PSK-CCMPã䜿çšã
/dev/urandom
ãŸããããã§ååã§ããïŒWPSã«ãŒã¿ãŒãããå Žåãç¹ã«å€ãã«ãŒã¿ãŒã®å Žåã¯ããã§ã¯ãããŸããã
äžã®å³ã¯ãPINã³ãŒãã䜿çšããŠã¯ã©ã€ã¢ã³ããã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããããã»ã¹ã瀺ããŠããŸãã PIN-8æ¡ãéåžžãã«ãŒã¿ãŒèªäœã«è²Œãä»ããããŸãã WPSããµããŒãããã¯ã©ã€ã¢ã³ãã¯ãéåžžã®WEP / WPAãã¹ã¯ãŒããŸãã¯PINã䜿çšããŠãããã¯ãŒã¯ã«æ¥ç¶ã§ããŸããæåŸã®ã¯ã©ã€ã¢ã³ããå ¥åãããšããããã¯ãŒã¯ãã¹ã¯ãŒããçŽç²ãªåœ¢åŒã§åä¿¡ãããŸãã
æšæºã«ãããšãPINã®æåŸã®æ¡ã¯ãã§ãã¯ãµã ã§ããã€ãŸããæ®ãã®æ¡ã«åºã¥ããŠèšç®ã§ããŸãããããã£ãŠãå¯èœãªãã¹ãŠã®çµã¿åãããæŽçããå Žåã10 7åã®è©Šè¡ãå¿ èŠã«ãªããŸãïŒããŒã¹-å¯èœãªæåæ°ïŒ0-9-10ïŒãç¯å²-ã¹ããªã³ã°ã®é·ãïŒ-1,000äžïŒçŽ116æ¥ïŒã 1ç§éã«1ã€ã®ã³ãŒããè©ŠããŠã¿ããšãéåžžãé床ã¯æ°åäœããªããããéžæã«ã¯1幎以äžããããŸãã
ãã ããæšæºã«èª€ãããããŸããæ¿èªããã»ã¹ã¯ããã€ãã®æ®µéã§è¡ãããŸããåŒç€Ÿããéä¿¡ãããPINãæ£ããå Žåãã¢ã¯ã»ã¹ãã€ã³ãã¯æåãå ±åããŸãã PINã®æåã®4æ¡ãæ£ãããã4ã7ã®æ°åãæ£ãããªãå Žåãã¢ã¯ã»ã¹ãã€ã³ãã¯M6ãã±ãããéä¿¡ããåŸã«éç¥ããŸããæåã®4æ¡ã§ãšã©ãŒãçºçããå Žåã¯ãM4ããã±ãŒãžã®åŸã§-ãèŠã€ããŸãããã®åé¡ã¯2011幎æ«ã«çºèŠãããããã§èª¬æãããŠããŸããç±ãè¿œæ±ã§ããã®ç 究ã®èè ã¯reaver-wpsãäœæãããããGoogle Codeã§å ¬éãããŸããããŸããå ã®è匱æ§ã®èª¬æææžãèŠã€ããããšãã§ããŸãã
ãããã£ãŠãPINã99741624ã§ãããšããŸãããã PINã䜿çšããŠæ¥ç¶ããããšããŠããŸã9974 0000- M6ãã±ããã®éä¿¡åŸã«èš±å¯æåŠãåãåããŸãïŒã³ãŒãã®ååãæ£ããããïŒã 0000 1624ã§æ¥ç¶ãããšãM4ã®åŸã«é害ãçºçããŸãã
ã芧ã®ããã«ãäž»ãªåé¡ã¯ã2çªç®ã«ãšã©ãŒãå«ãŸããŠããŠããã³ãŒãã®1ã€ã®éšåã®æ£ç¢ºæ§ã«ã€ããŠåŠç¿ã§ããããšã§ããããã¯äœãäžããŸããïŒä»ã§ã¯ã1000äžã®çµã¿åããã®ä»£ããã«ã10 4 + 10 3 = 11 000 ã ããè©Šãå¿ èŠããããŸããããã¯ã1é±éã ãã§ãªãã15æéã§è¡ãã®ãçŸå®çã§ãã
泚ïŒæåŸã®ãã§ãã¯ãµã ã¯ãã§ãã¯ãµã ã§ãããèªåã§èšç®ãããããéžæã®æ°å€ã¯8ã§ã¯ãªã7ã«ãªããŸãããããã£ãŠãéžæããå¿ èŠã¯ãããŸããã以äžã®äŸã§ã¯ãããã¯ïŒã§ãã
ããäžåºŠèŠãŠã¿ãŸãããã0000000ïŒããæ€çŽ¢ãéå§ããŸããM4ã®åŸã®å€±æïŒæåã®4æ¡ã®ãšã©ãŒïŒã0001000ïŒã«å€æŽããŸããM4ã®åŸã®å€±æã0002000ïŒãM4ã9974 000ïŒã«å°éããŸããããïŒM6ã®åŸã®å€±æãæåã®4æ¡ãæšæž¬ãããŸãã
次-ãŸã£ããåããã³ãŒããååã«ãªã£ããã2çªç®ã®ã³ãŒããåŸã ã«å¢ãããŸãã9974 001ïŒã倱æ 9974002ïŒã倱æ <...> 99741624ãåãå ¥ãããã
ããã¯ã
ãªãŒããŒ
ãããŠãã¢ã¯ã»ã¹ãã€ã³ãããã®è·åãã©ãã ãå¿ å®ã«æãããŠãããã確èªããŸããWPSãåããã«ãŒã¿ãŒããªãå Žå- ãã®æ»æãè åšã«ãªããªãããã«
WPSã®è匱æ§ãæªçšããããã«ãKaliã«ã¯ããã€ãã®ãŠãŒãã£ãªãã£ããããŸãããç§ã®æèŠã§ã¯ãæãæçœã§æè»ãªã®ã¯åãç¥å¥ªè ã§ããåŒã³åºãæ§æïŒ
reaver -i mon0 -c 5 -b AP_BSSID -va
ããã«ã以äžã瀺ãããšãã§ããŸãã
- -m OUR_MAC-ã¢ããã¿ãŒã®MACã¢ãã¬ã¹ãå€æŽããå ŽåïŒäžèšã®MACãã£ã«ã¿ãªã³ã°ãåç §ïŒããã®ãã©ã¡ãŒã¿ãŒãæ°ããïŒéå·¥å ŽïŒMACã§æå®ããŸãã
- -e ESSID â reaver , BSSID; â ESSID , .
- -p PIN â 8- WPS, ( - ). â .
- -vv â / , M4 M6 . .
reaverã¯ãã¢ã¯ã»ã¹ãã€ã³ãããããã®ãããããåãå ¥ããããšãæ€åºãããŸã§ã11,000ãè¶ ããçµã¿åãããç¹°ãè¿ããŸããæ€çŽ¢é床ã¯ãä¿¡å·åŒ·åºŠ/åºå°å±ãŸã§ã®è·é¢ã«å€§ããäŸåãã1ç§ããã3ãã30ã®ç¯å²ã§ããéåžžã1ã€ã®ãããã¯ãŒã¯ã§ã¯æ倧10ã15æéããããŸããReaverã
äžæããã«ã¯Ctrl + Cã䜿çšããŸãããã®ãããã¯ãŒã¯ã®çŸåšã®é²è¡ç¶æ³ãä¿åããåèµ·åãããšäžæ¢ãããPINã§éå§ãããŸããã©ã€ãã¢ãŒãïŒèªã¿åãå°çšïŒã§äœæ¥ããŠããå Žåã¯ãã»ãã·ã§ã³ããŒã¿ãæ°žç¶çãªã¡ãã£ã¢ã«æžãæããŠããã次åã®èµ·åæã«ãã®ã¡ãã£ã¢ã«æžãæ»ãããšãã§ããŸãããã®ãã©ã«ãã«ã¯ããã¥ãŒåãšå éšã§æ€çŽ¢ããããã¹ãŠã®çªå·ã®ãªã¹ããå«ãããã¹ããã¡ã€ã«ãå«ãŸããŠããŸãïŒæåã®è¡ã¯ãåèµ·åæã«æ€çŽ¢ãéå§ããPINè¡çªå·ã§ãïŒã
/etc/reaver/
AP_MAC.wpc
2幎åã圌ãã¯Habréã§ã®WPS ã«ã€ããŠã ãã§ãªããæžããã®ã§ãããå€ãã®æ å ±ãèŠã€ããã®ã¯ç°¡åã§ãã
ïŒmailbrush ã¯ãŸããã«ãªã«ãããåæ§ã®ã¿ã¹ã¯ãå®è¡ããbullyã«æ³šæãæãããšãå§ããŸãããïŒ
ã©ããã
çŸåšã®ãšãããå¯äžã®ãªãã·ã§ã³ã¯WPSãç¡å¹ã«ããããšã§ããããªããŸãã¯ããªãã®å人ããããã¯ãŒã¯ããã»ããã¢ãããããã®ãå°é£ãªå ŽåïŒããã¯ä¿¡ããããããšã§ãïŒ-æ°ããããã€ã¹ãæ¥ç¶ãããšãã«ã®ã¿WPSããªã³ã«ããŠãã ããã確ãã«ãäžè¬çã«ãã¹ãŠã®ã«ãŒã¿ãŒ/ãã¡ãŒã ãŠã§ã¢ããã®æ©äŒãäžããããã§ã¯ãããŸããããç§ããã®ããã«èŠããªãã£ãããç§ã¯å¥ã®ãã®ã«è¡ã£ãŠããã ããã
ãããããã¹ãŠãããã»ã©æªãããã§ã¯ãããŸãããæ°ãããã¡ãŒã ãŠã§ã¢ã¯ãã¬ãŒãå¶éã䜿çšããéžæã®å¯èœæ§ãå¶éããŸã-èš±å¯ã®è©Šè¡ãæ°å倱æãããšãWPSã¯èªåçã«ç¡å¹ã«ãªããŸããäžéšã®ã¢ãã«ã§ã¯ãçãæéå ã«å€±æããå ¥åãè¡ãããå Žåã§ããã·ã£ããããŠã³æéãããã«é·ããªããŸãããã ããç¹å®ã®ã±ãŒã¹ã§åŸ¹åºçãªãã§ãã¯ãè¡ã£ãåŸã«ã®ã¿ããã«é Œãããšãã§ããŸã-ã·ã£ããããŠã³æéãçããååã«é·ããªããªãããšãå€æããå¯èœæ§ããããŸã-11,000ã®çµã¿åããã¯éåžžã«å°ããã1åã«1åã®è©Šè¡ã§ãç¯å²å šäœã䜿çšããæ倧8æ¥éãåæã«ãPINã¯ãããã¯ãŒã¯ãã¹ã¯ãŒããšã¯å¥ã«å€æŽããããããPINã®æ€çŽ¢ãè€éã«ããããšãªããPINãäœåºŠã§ãæŽæ°ã§ããŸãã
ãšããã§ãWebã§ã¯ãã«ãŒã¿ãŒã匷å¶çã«åèµ·åãããšã¯ã¹ããã€ãã䜿çšããŠãããã¯ãæééãã«ãã€ãã¹ããå®éšãèŠã€ããããšãã§ããŸã-ãã¡ãããWPSã¿ã€ã ã¢ãŠãã¯ãªã»ãããããéžæãåã³ç¶ããããšãã§ããŸãããããã£ãŠããWPSã«å¯Ÿããä¿è·ãã«é Œãã¹ãã§ã¯ãããŸããã
ãããã¯ãŒã¯åæ
æåŸã«ãç¥å¥ªè ã«ä»£ãããã®
Waiting for beacon...
- airodump-ng WPS , , ( )
- wash -i mon0 WPS-enabled , , Ctrl+C . , , WPS, (. rate limiting )
- iwlist wlan0 scan , WPS
- wifite â ; , , . : WPS
ãŸããéåžžã«å€ãã®äººã«æãããéåœïŒMacintoshçšãšã¢ããã°- KisMACïŒããç§ã®æèŠã§ã¯ãããã¯ããŸãã«ã空æ³ã§ããã©ã¡ãã«ãGPSãçµ±åãããŠãããåºããšãªã¢ã§ãããã¯ãŒã¯ãæ¢çŽ¢ããïŒã¯ãŒãã©ã€ãã³ã°ïŒå Žåã«åœ¹ç«ã¡ãŸãã
ããã¯ãã¹ãŠãäŸµå ¥ã®äžæ£è¡çºæ¹æ³ã§ãã 3çªç®ã®éšåã¯ããããã¯ãŒã¯ã«æ¥ç¶ãããšãã«ã¯ã©ã€ã¢ã³ããã³ãã·ã§ã€ã¯ãååããCPUãšGPUã䜿çšããŠWPAã®ãã¹ã¯ãŒããéžæããããšã§ãïŒ2ïŒãèšäºã®æ ¡æ£ã«é¢ããæçãªã³ã¡ã³ãã«ã€ããŠã¯ãåå¿chem_uaã«
æè¬ããŸããã°ã©ãã¯gliffy.comã§äœæãããŸããããã€ãã®ããã«ãã±ãŒã¹ã«ã€ããŠã®ã³ã¡ã³ãã¯å€§æè¿ã§ããå 容ïŒ1ïŒææ2ïŒ
ã«ãŒãªãŒ SSIDãé衚瀺ã«ããŸããMACãã£ã«ã¿ãªã³ã°ãWPS
3ïŒ WPAãOpenCL / CUDAããããã³ã°çµ±èš