1
1

00:00:00,730  -->  00:00:02,170
<v ->Wireless attacks.</v>
2

2

00:00:02,170  -->  00:00:03,760
In this lesson, we're going to discuss
3

3

00:00:03,760  -->  00:00:05,550
the different types of wireless attacks
4

4

00:00:05,550  -->  00:00:07,000
that you need to be aware of.
5

5

00:00:07,000  -->  00:00:09,620
This includes rogue access points, evil twins,
6

6

00:00:09,620  -->  00:00:11,810
deauthentication attacks, password attacks,
7

7

00:00:11,810  -->  00:00:13,350
and wireless interception.
8

8

00:00:13,350  -->  00:00:16,220
A rogue access point is any wireless access point
9

9

00:00:16,220  -->  00:00:18,130
that's been installed on a secure network
10

10

00:00:18,130  -->  00:00:19,770
without explicit authorization
11

11

00:00:19,770  -->  00:00:21,640
from a local network administrator.
12

12

00:00:21,640  -->  00:00:23,860
These are often added by a malicious attacker
13

13

00:00:23,860  -->  00:00:26,010
or simply by one of your end users
14

14

00:00:26,010  -->  00:00:27,370
who didn't know any better.
15

15

00:00:27,370  -->  00:00:30,170
For example, if your office only has a wired network,
16

16

00:00:30,170  -->  00:00:32,260
but somebody wanted to add wireless capability
17

17

00:00:32,260  -->  00:00:34,170
so they could use their iPad in the office,
18

18

00:00:34,170  -->  00:00:37,240
they may go out to the store and buy a wireless access point
19

19

00:00:37,240  -->  00:00:39,770
and then connect it to the wall jack in their office.
20

20

00:00:39,770  -->  00:00:41,470
Now, this may seem harmless enough,
21

21

00:00:41,470  -->  00:00:44,470
but if that wireless access point isn't properly secured
22

22

00:00:44,470  -->  00:00:46,240
with a strong password and encryption,
23

23

00:00:46,240  -->  00:00:48,580
an attacker can also connect to that access point
24

24

00:00:48,580  -->  00:00:49,870
from outside the building
25

25

00:00:49,870  -->  00:00:51,470
and now they're going to be fully connected
26

26

00:00:51,470  -->  00:00:53,100
to your network, too.
27

27

00:00:53,100  -->  00:00:54,830
Another risk with these types of devices
28

28

00:00:54,830  -->  00:00:56,400
is that many wireless access points
29

29

00:00:56,400  -->  00:00:57,870
sold at the electronic stores
30

30

00:00:57,870  -->  00:00:59,690
aren't really wireless access points,
31

31

00:00:59,690  -->  00:01:02,900
but instead they're wireless routers or wireless gateways.
32

32

00:01:02,900  -->  00:01:06,730
This means that device has a router and a DHCP server in it
33

33

00:01:06,730  -->  00:01:08,440
and it's usually enabled by default.
34

34

00:01:08,440  -->  00:01:10,340
So when they connect this device,
35

35

00:01:10,340  -->  00:01:12,240
they thought it only had an access point,
36

36

00:01:12,240  -->  00:01:15,480
but it also has a rogue DHCP server, too.
37

37

00:01:15,480  -->  00:01:18,310
Devices like these are added to the network all the time,
38

38

00:01:18,310  -->  00:01:20,060
without knowledge of the IT department
39

39

00:01:20,060  -->  00:01:21,560
and its system administrators.
40

40

00:01:21,560  -->  00:01:23,410
This can lead to many insecure devices
41

41

00:01:23,410  -->  00:01:25,090
being all over your network.
42

42

00:01:25,090  -->  00:01:27,270
These devices, when we take them all together,
43

43

00:01:27,270  -->  00:01:29,390
are known as shadow IT.
44

44

00:01:29,390  -->  00:01:32,400
Shadow IT is the use of information technology systems,
45

45

00:01:32,400  -->  00:01:35,220
devices, software, applications, or services
46

46

00:01:35,220  -->  00:01:38,090
without the explicit approval of the IT department.
47

47

00:01:38,090  -->  00:01:40,950
Shadow IT is a major risk to any organization,
48

48

00:01:40,950  -->  00:01:42,300
because if the IT department
49

49

00:01:42,300  -->  00:01:43,800
doesn't know about these devices,
50

50

00:01:43,800  -->  00:01:45,240
how are they supposed to configure them
51

51

00:01:45,240  -->  00:01:47,290
and secure them from attacks?
52

52

00:01:47,290  -->  00:01:48,123
That's the idea,
53

53

00:01:48,123  -->  00:01:49,880
we need to make sure we understand what's out there
54

54

00:01:49,880  -->  00:01:51,700
so we can then better protect it.
55

55

00:01:51,700  -->  00:01:53,470
Speaking of rogue wireless access points
56

56

00:01:53,470  -->  00:01:54,720
being added to your network,
57

57

00:01:54,720  -->  00:01:56,470
we also have the threat of evil twins
58

58

00:01:56,470  -->  00:01:57,990
in and around our network.
59

59

00:01:57,990  -->  00:01:59,480
Now, in an evil twin attack,
60

60

00:01:59,480  -->  00:02:01,750
an attacker will set up a wireless access point
61

61

00:02:01,750  -->  00:02:04,250
that uses the same name as your own network.
62

62

00:02:04,250  -->  00:02:06,140
For example, if you're sitting in Starbucks
63

63

00:02:06,140  -->  00:02:08,270
having some coffee and you go to wifi,
64

64

00:02:08,270  -->  00:02:10,480
you might see the Starbucks free wifi.
65

65

00:02:10,480  -->  00:02:12,050
Now, an attacker can also be sitting there
66

66

00:02:12,050  -->  00:02:13,620
with their own wireless access point
67

67

00:02:13,620  -->  00:02:16,680
and having it broadcast out the name Starbucks Free Wi-Fi
68

68

00:02:16,680  -->  00:02:17,860
with a stronger signal.
69

69

00:02:17,860  -->  00:02:19,280
And they're hoping you connect to them
70

70

00:02:19,280  -->  00:02:20,840
instead of to Starbucks.
71

71

00:02:20,840  -->  00:02:22,530
Now, if you do connect to them,
72

72

00:02:22,530  -->  00:02:25,170
their evil twin will still give you access to the internet,
73

73

00:02:25,170  -->  00:02:27,360
but it also puts the attacker in a position
74

74

00:02:27,360  -->  00:02:29,130
to see and record everything you're doing
75

75

00:02:29,130  -->  00:02:30,680
over that wireless connection,
76

76

00:02:30,680  -->  00:02:32,100
because you're really connected to them
77

77

00:02:32,100  -->  00:02:33,670
and not to Starbucks.
78

78

00:02:33,670  -->  00:02:35,100
This is an evil twin.
79

79

00:02:35,100  -->  00:02:37,350
And an evil twin is an easy way for an attacker
80

80

00:02:37,350  -->  00:02:40,140
to conduct an on path or men in the middle attack.
81

81

00:02:40,140  -->  00:02:43,050
The next attack we have is known as a deauthentication,
82

82

00:02:43,050  -->  00:02:44,420
or deauth attack.
83

83

00:02:44,420  -->  00:02:46,410
Now a deauthentication attack is a type of
84

84

00:02:46,410  -->  00:02:47,730
denial of service attack
85

85

00:02:47,730  -->  00:02:49,420
that attempts to interrupt communication
86

86

00:02:49,420  -->  00:02:50,870
between an end user's client
87

87

00:02:50,870  -->  00:02:52,710
and the wireless access point.
88

88

00:02:52,710  -->  00:02:54,770
A deauthentication attack is commonly used
89

89

00:02:54,770  -->  00:02:56,140
in wireless hacking attacks
90

90

00:02:56,140  -->  00:02:58,150
to kick a person off of the network.
91

91

00:02:58,150  -->  00:02:59,280
To perform this attack,
92

92

00:02:59,280  -->  00:03:01,400
the attacker sends a deauthentication frame
93

93

00:03:01,400  -->  00:03:02,860
to the wireless access point
94

94

00:03:02,860  -->  00:03:05,240
using the spoofed IP address of their victim,
95

95

00:03:05,240  -->  00:03:07,330
which is one of your network clients.
96

96

00:03:07,330  -->  00:03:08,660
Then when this happens,
97

97

00:03:08,660  -->  00:03:10,170
the client will attempt to reconnect
98

98

00:03:10,170  -->  00:03:13,200
and reestablish a connection to the wireless access point
99

99

00:03:13,200  -->  00:03:16,290
by conducting a new session establishment and handshake.
100

100

00:03:16,290  -->  00:03:17,270
As they do this,
101

101

00:03:17,270  -->  00:03:19,210
the attacker can then capture that handshake
102

102

00:03:19,210  -->  00:03:20,500
and attempt to crack or break
103

103

00:03:20,500  -->  00:03:21,910
the wireless network's password
104

104

00:03:21,910  -->  00:03:23,590
from that encrypted handshake.
105

105

00:03:23,590  -->  00:03:25,740
Again, this is something you want to be careful of
106

106

00:03:25,740  -->  00:03:27,950
and make sure that if you're using a wireless network,
107

107

00:03:27,950  -->  00:03:29,620
you're aware of these types of techniques
108

108

00:03:29,620  -->  00:03:31,700
because they are extremely common.
109

109

00:03:31,700  -->  00:03:33,260
Speaking of password attacks,
110

110

00:03:33,260  -->  00:03:35,230
let's talk a little bit more about an attacker
111

111

00:03:35,230  -->  00:03:37,230
and how they can crack a password.
112

112

00:03:37,230  -->  00:03:39,790
There are really two methods of cracking a password.
113

113

00:03:39,790  -->  00:03:42,480
You have a dictionary attack and a brute force attack.
114

114

00:03:42,480  -->  00:03:44,730
Now a dictionary attack occurs when an attacker tries to
115

115

00:03:44,730  -->  00:03:46,650
guess the password by attempting to check
116

116

00:03:46,650  -->  00:03:49,830
every single word or phrase contained within a word list,
117

117

00:03:49,830  -->  00:03:51,450
which we call a dictionary.
118

118

00:03:51,450  -->  00:03:52,750
Now, an attacker's dictionary
119

119

00:03:52,750  -->  00:03:54,710
isn't like the dictionary you used in high school.
120

120

00:03:54,710  -->  00:03:56,670
It doesn't just contain real words.
121

121

00:03:56,670  -->  00:03:57,810
Many attacker's dictionaries
122

122

00:03:57,810  -->  00:03:59,560
contain things like the word password,
123

123

00:03:59,560  -->  00:04:01,130
but the A becomes an @ symbol
124

124

00:04:01,130  -->  00:04:02,940
and the S becomes a dollar sign.
125

125

00:04:02,940  -->  00:04:04,760
When an attacker attempts to crack your password
126

126

00:04:04,760  -->  00:04:08,000
using this list, we consider it a dictionary attack.
127

127

00:04:08,000  -->  00:04:09,780
The best defense against a dictionary attack
128

128

00:04:09,780  -->  00:04:12,350
is to not use anything that looks like a regular word.
129

129

00:04:12,350  -->  00:04:14,840
Even if you've already substituted out symbols for letters
130

130

00:04:14,840  -->  00:04:16,290
or numbers for letters.
131

131

00:04:16,290  -->  00:04:17,123
On the other hand,
132

132

00:04:17,123  -->  00:04:19,010
if a dictionary attack isn't successful,
133

133

00:04:19,010  -->  00:04:21,580
the attacker can try to do a brute force attack.
134

134

00:04:21,580  -->  00:04:23,130
Now, with a brute force attack,
135

135

00:04:23,130  -->  00:04:25,090
they're going to try every possible combination
136

136

00:04:25,090  -->  00:04:26,810
until they figure out your password.
137

137

00:04:26,810  -->  00:04:27,643
For example,
138

138

00:04:27,643  -->  00:04:30,290
if your password was something like a four digit pin number,
139

139

00:04:30,290  -->  00:04:33,060
the attacker could start out at zero, zero, zero, zero.
140

140

00:04:33,060  -->  00:04:35,440
Then they try zero, zero, zero, one.
141

141

00:04:35,440  -->  00:04:38,070
Then zero, zero, zero, two, and so on.
142

142

00:04:38,070  -->  00:04:40,550
And eventually they'll get to your four digit code
143

143

00:04:40,550  -->  00:04:43,290
of five, two, four, six, or whatever it was.
144

144

00:04:43,290  -->  00:04:44,710
The thing about a brute force attack
145

145

00:04:44,710  -->  00:04:47,510
is they will always be successful, eventually.
146

146

00:04:47,510  -->  00:04:49,150
It's just a matter of time.
147

147

00:04:49,150  -->  00:04:51,790
Now, the key is to preventing a brute force attack.
148

148

00:04:51,790  -->  00:04:54,100
The longer and more complicated your password is,
149

149

00:04:54,100  -->  00:04:55,560
the longer it's going to take for an attacker
150

150

00:04:55,560  -->  00:04:57,460
to guess it using brute force.
151

151

00:04:57,460  -->  00:05:00,220
Now, in addition to a dictionary and a brute force attack,
152

152

00:05:00,220  -->  00:05:02,400
we have something known as a hybrid attack
153

153

00:05:02,400  -->  00:05:04,970
where we can basically get a few key words about our victim,
154

154

00:05:04,970  -->  00:05:07,490
and we enter those to create a small word list.
155

155

00:05:07,490  -->  00:05:10,370
Then we use those as part of our brute force attack.
156

156

00:05:10,370  -->  00:05:12,870
It's essentially seeding the brute force of it.
157

157

00:05:12,870  -->  00:05:14,850
Now this helps focus the brute force attack
158

158

00:05:14,850  -->  00:05:16,400
better than just starting out with the letter A
159

159

00:05:16,400  -->  00:05:18,070
and moving upwards from there.
160

160

00:05:18,070  -->  00:05:19,620
This gives you some way to actually
161

161

00:05:19,620  -->  00:05:21,510
cut down the time of brute force attack.
162

162

00:05:21,510  -->  00:05:23,270
But again, you have to know some information
163

163

00:05:23,270  -->  00:05:25,070
about your target system.
164

164

00:05:25,070  -->  00:05:26,920
Next, we need to discuss the concept
165

165

00:05:26,920  -->  00:05:28,450
of wireless interception.
166

166

00:05:28,450  -->  00:05:30,130
Now, wireless interception is an attack
167

167

00:05:30,130  -->  00:05:32,180
that involves capturing wireless data packets
168

168

00:05:32,180  -->  00:05:33,940
as they go across the airwaves.
169

169

00:05:33,940  -->  00:05:36,200
Since wireless networks operate much like a hub,
170

170

00:05:36,200  -->  00:05:37,900
the data is simply floating through the air
171

171

00:05:37,900  -->  00:05:39,480
for any attacker to grab.
172

172

00:05:39,480  -->  00:05:40,580
To protect this data.
173

173

00:05:40,580  -->  00:05:43,270
most wireless networks use wireless encryption technologies
174

174

00:05:43,270  -->  00:05:45,880
like AES in the WPA2 standard.
175

175

00:05:45,880  -->  00:05:47,860
But even though these packets are encrypted,
176

176

00:05:47,860  -->  00:05:49,910
they can still be intercepted and recorded
177

177

00:05:49,910  -->  00:05:51,500
using a packet capture.
178

178

00:05:51,500  -->  00:05:54,500
Then the attacker can attempt to crack the password offline
179

179

00:05:54,500  -->  00:05:55,640
when they have more time
180

180

00:05:55,640  -->  00:05:58,840
using a dictionary, brute force or hybrid technique.
181

181

00:05:58,840  -->  00:06:01,570
In addition to wireless interception of wifi networks,
182

182

00:06:01,570  -->  00:06:03,320
wireless interception can also focus
183

183

00:06:03,320  -->  00:06:05,290
on Bluetooth or cellular signals.
184

184

00:06:05,290  -->  00:06:07,150
It just becomes a matter of changing the type of
185

185

00:06:07,150  -->  00:06:08,630
antenna and radio that you're using
186

186

00:06:08,630  -->  00:06:10,600
to conduct that packet capture.
187

187

00:06:10,600  -->  00:06:12,500
For example, a Stingray device,
188

188

00:06:12,500  -->  00:06:14,790
also known as an IMSI catcher,
189

189

00:06:14,790  -->  00:06:16,750
can be used to act like a cellular tower
190

190

00:06:16,750  -->  00:06:19,080
and send out signals and get specific devices
191

191

00:06:19,080  -->  00:06:20,300
to connect to it.
192

192

00:06:20,300  -->  00:06:22,830
The Stingray can then identify what cellular devices
193

193

00:06:22,830  -->  00:06:25,370
are being used in an area by clicking location data
194

194

00:06:25,370  -->  00:06:26,770
and other identifying information
195

195

00:06:26,770  -->  00:06:28,780
about those cellular devices.
196

196

00:06:28,780  -->  00:06:30,400
When the cellular devices connect to it,
197

197

00:06:30,400  -->  00:06:31,890
the stingray can then capture any data
198

198

00:06:31,890  -->  00:06:32,920
that's sent through it,
199

199

00:06:32,920  -->  00:06:34,420
essentially performing an on path,
200

200

00:06:34,420  -->  00:06:35,700
or man in the middle attack,
201

201

00:06:35,700  -->  00:06:37,910
against any cellular device in range.
202

202

00:06:37,910  -->  00:06:39,630
These stingray devices were originally developed
203

203

00:06:39,630  -->  00:06:42,480
by the US government for use in criminal investigations,
204

204

00:06:42,480  -->  00:06:44,800
but some attackers have them, as well.
205

205

00:06:44,800  -->  00:06:45,930
Now, your wired networks
206

206

00:06:45,930  -->  00:06:48,370
can also be subject to wireless interception, too,
207

207

00:06:48,370  -->  00:06:49,800
using specialized techniques
208

208

00:06:49,800  -->  00:06:51,390
that are going to be way beyond the abilities
209

209

00:06:51,390  -->  00:06:52,970
of a standard network technician.
210

210

00:06:52,970  -->  00:06:53,950
But I want to discuss this
211

211

00:06:53,950  -->  00:06:55,760
just so you understand the concept.
212

212

00:06:55,760  -->  00:06:58,230
If your wired network is using copper wires,
213

213

00:06:58,230  -->  00:07:00,280
like an unshielded twisted pair cable,
214

214

00:07:00,280  -->  00:07:03,110
those cables actually admit electromagnetic waves
215

215

00:07:03,110  -->  00:07:05,120
as the data travels down the cable.
216

216

00:07:05,120  -->  00:07:07,830
Now a highly skilled analyst with specialized equipment
217

217

00:07:07,830  -->  00:07:09,880
could collect those electromagnetic waves
218

218

00:07:09,880  -->  00:07:11,810
and convert them back into ones and zeros
219

219

00:07:11,810  -->  00:07:13,500
that are being sent down the copper cable
220

220

00:07:13,500  -->  00:07:15,050
as an electrical impulse.
221

221

00:07:15,050  -->  00:07:16,260
To capture these signals,
222

222

00:07:16,260  -->  00:07:17,700
the attacker would have to be fairly close
223

223

00:07:17,700  -->  00:07:18,900
to the copper cable, though,
224

224

00:07:18,900  -->  00:07:21,090
usually within about 10 to 12 inches.
225

225

00:07:21,090  -->  00:07:24,700
But it is still technically a type of wireless interception.
226

226

00:07:24,700  -->  00:07:25,980
All right, as I said,
227

227

00:07:25,980  -->  00:07:28,280
this whole area is a very technical area,
228

228

00:07:28,280  -->  00:07:30,330
but it's just one of many different types
229

229

00:07:30,330  -->  00:07:31,450
of specialized attacks
230

230

00:07:31,450  -->  00:07:33,370
that I wanted to make sure you understood existed.
231

231

00:07:33,370  -->  00:07:35,010
And so if anybody ever asked you about it,
232

232

00:07:35,010  -->  00:07:36,260
you could be aware of it.
