Showing posts with label wireless. Show all posts
Showing posts with label wireless. Show all posts

Wednesday, November 3, 2010

Completed OWSP challenge …………………and passed!

A few months ago I blogged about taking the Offensive-Security Wifu class, which can be found here. I finally completed the second part of the class and signed up for the challenge to get the Offensive Security Wireless Professional (OWSP).

The second part of the class, which had several videos with it, was focused on gathering information and using that information to attack wireless networks. The class focused on the different applications that make up the aircrack-ng suite of tools. After learning what you used the various tools for the put it all together to show how to crack WEP-OPN, WEP-SKA and WPA-PSK. They also discussed different ways to attack wireless networks that have no associated clients or very little network activity.

After completing the class I studied the lab material and ran through every attack scenario a few times to make sure I was able to successfully perform each type of attack. Once I was comfortable with all of the attack types I registered to take the OWSP challenge.

The OWSP exam is different than other certifications exams in which they ask you a question and you typically choice a multiple choice answer. For the OWSP I had to connect to a system on the Internet and perform a series of attacks to gain access to wireless networks within 4 hours. Once you complete the objectives you write up how you performed the attacks and they send you the answers back with-in 72 hours.

I started my exam on time, but ran into 1 technical issue. I contact exam support and the issue was resolved immediately. After the issue was resolved I went about my exam and completed all my objectives in about an hour and half. I should have been done sooner but I made a mistake on one attack that added about 20 minutes to the length of the exam. After completing my objectives I had 24 hours to prepare my documentation and turn in for grading.

I completed the documentation a couple of hours after the exam and sent off to be graded. I receive a confirmation they received the documentation and went about my business, expecting to hear back in a couple of days. This morning I was pleasantly surprised to receive an email stating that I had successfully passed my challenge and was certified as an OWSP.

If you have any interested in wireless security this is a great course to start off with, especially if you factor in the cost of the course and certification. If you need to take a wireless security course and have limited funds, this is a great course to take and I will recommend it to anyone.

Monday, September 13, 2010

WEP cracked in under 10 seconds………….

In a previous post I discussed taking the Offensive-Security Wireless Attacks course. I went through the first technical section which focuses on using aircrack-ng (and associated tools) to detect and attack wireless networks in a lab. The lab I built for this class consists of an Alfa USB Wifi Card and a Linksys WRT-54G (Linux) that supports WEP, WPA and WPA2 encryption.

Most Information Security professionals with exposure to wireless security understand why WEP is insecure, why not to use it and the risk associated with using it. However there are people who still believe WEP is sufficient for security of a wireless network.

During one of the exercises cracking WEP keys, I came across something that I could not believe at first. I was able to capture packets for my lab SSID using airodump. Typically you want about 40000 IV’s to start cracking WEP, to get a decent opportunity at successfully cracking it.

On this exercise though I thought I would take a shot at 20000 IV’s. Well, I should have bought a lottery ticket because my WEP key was cracked in 8 seconds. Now this WEP key uses a “64” bit key and is quicker to crack, but the fact that it took me longer to enter in the commands to crack the key then it took to actually crack the key shows how insecure WEP is.

I saved the packet capturefor demonstration purposes when I hear people discuss WEP security/insecurity. Like the say a picture is worth a 1000 words!

Tuesday, August 24, 2010

Offensive- Security.com WiFu Training Class……………..

A couple of weeks ago I was looking at that the latest Backtrack release and decided to finally check out offensive-security.com. For those of you unfamiliar with offensive-security.com it is a training organization that uses Backtrack to teach penetration testing. It was founded by Mati Aharoni, creator of WHAX and a core developer of Backtrack.

Offensive-Security offers 3 training courses, Pentesting With Backtrack (PWB), Cracking the Perimeter (CTP), and Offensive-Security Wireless Attacks (WiFu). Upon successful completion of the course and hands on lab for that course you are awarded the OSCP(PWB Course), OSCE(CTP) or the OSWP(WiFu) certifications.

What makes these certifications challenging is they are not testing on your ability to memorize answers, they present you with a challenge and you must correctly complete the challenge in an allocated amount of time to be awarded the certification.

I did some online research and saw some really good reviews so I thought I would look into the cost of some classes. I was surprised by the cost ranging of the course, 350 USD for WiFu to 1500 USD for CTP with 60 days of lab access. Although I had done some wireless security work in the past I thought I would give the WiFu course a try.

I went through the registration process and received my course material in the allotted amount of time. The material included a PDF for the class, and some video tutorials. I would say the PDF (and the class) is broken up into two parts, the first is about wireless and wireless security, and the second is about attacking wireless.

I spent last week going over the first half of the class. Because I had not used my wireless skills in a long time this was a great refresher. This part of the class covered 802.11 standards, different wireless modes, different types of packets you will see on a wireless network, and how to choose hardware.

The hardware section was of great interest to me, because of the details it gave. In this section it covered different type of wireless adapters, chip sets, and antenna's details. This section gave some good details on how to choose wireless equipment for what you are testing.

The information in the first part of the class as been wonderful so far and I am looking forward to the "attacking" phase of the class. Once I get more into the attaching phase of the class I will post some more blogs about the class.
 
Site Meter