1
00:00:06,450 --> 00:00:08,160
- In this lesson, 8.6,

2
00:00:08,160 --> 00:00:10,803
we're gonna focus in on wireless attacks.

3
00:00:11,790 --> 00:00:13,950
Now, the objective of a wireless attack

4
00:00:13,950 --> 00:00:15,450
is gonna be the disruption,

5
00:00:15,450 --> 00:00:17,970
the manipulation, or the compromise

6
00:00:17,970 --> 00:00:21,347
of wireless transmission
or wireless devices.

7
00:00:21,347 --> 00:00:22,770
Now, there are a variety

8
00:00:22,770 --> 00:00:25,410
of wireless transmission
architectures out there

9
00:00:25,410 --> 00:00:30,410
including 802.15 WPAN, which
you and I know as Bluetooth,

10
00:00:30,780 --> 00:00:35,780
802.11 WAN, cellular,
RFID, radio frequency ID

11
00:00:36,030 --> 00:00:38,793
and NFC, Near Field Communication.

12
00:00:40,410 --> 00:00:42,495
So let's look at four
wireless attack categories.

13
00:00:42,495 --> 00:00:43,987
And if you're looking at this thinking,

14
00:00:43,987 --> 00:00:45,810
"Wow, I've already seen this,"

15
00:00:45,810 --> 00:00:46,740
it's because we've talked

16
00:00:46,740 --> 00:00:48,690
about these type of attacks already

17
00:00:48,690 --> 00:00:50,130
but this time, we're thinking about them

18
00:00:50,130 --> 00:00:52,440
in terms of a wireless attack.

19
00:00:52,440 --> 00:00:56,970
So access, spoofing, sniffing,
and denial of service.

20
00:00:56,970 --> 00:00:59,896
A wireless access attack is
an authentication exploit.

21
00:00:59,896 --> 00:01:02,916
It enables unauthorized
or unsolicited access

22
00:01:02,916 --> 00:01:05,973
to an end user wireless device.

23
00:01:07,020 --> 00:01:09,990
Spoofing is impersonating
a wireless device

24
00:01:09,990 --> 00:01:11,940
and that enables the attacker to act

25
00:01:11,940 --> 00:01:16,890
as the trusted source and
redirect or manipulate actions.

26
00:01:16,890 --> 00:01:19,980
Sniffing is capturing
wireless data packets

27
00:01:19,980 --> 00:01:23,640
and that enables the attacker
to eavesdrop, manipulate,

28
00:01:23,640 --> 00:01:26,460
and/or reuse data packets.

29
00:01:26,460 --> 00:01:29,190
And denial of service, as
we've talked about before,

30
00:01:29,190 --> 00:01:31,380
is overwhelming system resources

31
00:01:31,380 --> 00:01:34,680
which enables the attacker
to make services unavailable

32
00:01:34,680 --> 00:01:36,390
for their intended use.

33
00:01:36,390 --> 00:01:40,500
So access, spoofing, sniffing,
and denial of service.

34
00:01:40,500 --> 00:01:43,223
Now let's dive a little bit
deeper into each one of them.

35
00:01:44,400 --> 00:01:47,490
In an access attack, it's
really an authentication exploit

36
00:01:47,490 --> 00:01:51,360
and the goal of the attacker,
is to have unauthorized

37
00:01:51,360 --> 00:01:55,590
or unsolicited access to a
wireless endpoint device.

38
00:01:55,590 --> 00:01:58,500
Now, there are three types of
attacks I want you to know.

39
00:01:58,500 --> 00:02:03,060
Bluejacking, bluesnarfing, and NFC bump.

40
00:02:03,060 --> 00:02:05,220
The first two bluejacking
and bluesnarfing,

41
00:02:05,220 --> 00:02:07,230
are really Bluetooth attacks.

42
00:02:07,230 --> 00:02:09,840
Bluejacking is all about
Bluetooth discovery.

43
00:02:09,840 --> 00:02:12,840
It enables the attacker
to send an unsolicited

44
00:02:12,840 --> 00:02:15,900
or unwanted message to a Bluetooth device.

45
00:02:15,900 --> 00:02:17,793
Very useful in social engineering.

46
00:02:18,660 --> 00:02:21,450
Bluesnarfing, is about
Bluetooth authentication

47
00:02:21,450 --> 00:02:23,580
and that's discovering or connecting

48
00:02:23,580 --> 00:02:26,160
to a Bluetooth device that either has weak

49
00:02:26,160 --> 00:02:29,850
or non-existent
authentication requirements.

50
00:02:29,850 --> 00:02:34,320
And the third is NFC or Near
Field Communication bump.

51
00:02:34,320 --> 00:02:35,353
Now what's NFC?

52
00:02:35,353 --> 00:02:37,350
A Near Field Communication
is when you need

53
00:02:37,350 --> 00:02:40,350
to be in very close proximity
to make the connection.

54
00:02:40,350 --> 00:02:42,780
You're probably most familiar
with it if you use your credit

55
00:02:42,780 --> 00:02:46,710
or debit card for tap and go
at a point of sale terminal.

56
00:02:46,710 --> 00:02:48,330
Near Field communication bump

57
00:02:48,330 --> 00:02:51,420
enables an NFC enabled attacker to connect

58
00:02:51,420 --> 00:02:55,293
to an NFC device by being
in close enough range.

59
00:02:57,240 --> 00:02:59,430
Next is spoofing, and we
talked about spoofing.

60
00:02:59,430 --> 00:03:00,360
We talked about spoofing

61
00:03:00,360 --> 00:03:03,030
in fairly general terms
about impersonation.

62
00:03:03,030 --> 00:03:04,080
In this case, we're talking

63
00:03:04,080 --> 00:03:07,320
about impersonating a
wireless device, a connection,

64
00:03:07,320 --> 00:03:09,300
or even a chip.

65
00:03:09,300 --> 00:03:11,940
Now the outcome is it
enables the attacker to act

66
00:03:11,940 --> 00:03:16,233
as a trusted source and
redirect or manipulate actions.

67
00:03:17,460 --> 00:03:19,830
Now, there are two attacks I
want you to be familiar with.

68
00:03:19,830 --> 00:03:22,950
Evil Twin and RFID cloning.

69
00:03:22,950 --> 00:03:27,030
Now, Evil Twin is when an access point

70
00:03:27,030 --> 00:03:30,330
a rogue access point with the same SSID

71
00:03:30,330 --> 00:03:33,284
as the access point that
is legitimate is enabled.

72
00:03:33,284 --> 00:03:36,420
So that enables the
attacker to trick a user

73
00:03:36,420 --> 00:03:39,510
into connecting to an
attacker controlled network.

74
00:03:39,510 --> 00:03:42,510
Now, it also may
impersonate a captive portal

75
00:03:42,510 --> 00:03:46,710
to capture credentials and/or
any payment information.

76
00:03:46,710 --> 00:03:49,950
So Evil Twin refers to,
right, it's the evil

77
00:03:49,950 --> 00:03:52,757
the bad twin of what's a
legitimate access point.

78
00:03:52,757 --> 00:03:55,650
But that access point has the same SSID,

79
00:03:55,650 --> 00:03:57,450
so users will connect to it.

80
00:03:57,450 --> 00:04:01,050
And then we have RFID cloning,
which is really replicating

81
00:04:01,050 --> 00:04:04,290
an RFID chip, a Radio Frequency ID chip.

82
00:04:04,290 --> 00:04:07,470
And that enables the
attacker to access a system,

83
00:04:07,470 --> 00:04:10,223
engage in credit card
fraud, remove inventory,

84
00:04:10,223 --> 00:04:14,343
or whatever else that RFID
card is being used for.

85
00:04:16,410 --> 00:04:18,180
Next is sniffing.

86
00:04:18,180 --> 00:04:19,380
In a sniffing attack,

87
00:04:19,380 --> 00:04:22,950
what's happening is wireless
data packets are being captured

88
00:04:22,950 --> 00:04:24,750
and the outcome potentially

89
00:04:24,750 --> 00:04:26,640
is that the attacker can eavesdrop,

90
00:04:26,640 --> 00:04:30,240
manipulate, and/or reuse
those data packets.

91
00:04:30,240 --> 00:04:32,280
There are three attacks you wanna know.

92
00:04:32,280 --> 00:04:35,280
A replay attack, an IV attack,

93
00:04:35,280 --> 00:04:38,190
and an RFID eavesdropping attack.

94
00:04:38,190 --> 00:04:42,150
Now, in a replay attack,
the attacker is capturing

95
00:04:42,150 --> 00:04:44,640
and reusing these data packets.

96
00:04:44,640 --> 00:04:45,690
So they might be doing it

97
00:04:45,690 --> 00:04:48,480
because they wanna reuse
the authentication data

98
00:04:48,480 --> 00:04:51,600
and credentials, or they
might be replaying a packet

99
00:04:51,600 --> 00:04:55,230
over and over again to
cause a denial of service.

100
00:04:55,230 --> 00:04:59,160
An IV attack is capturing the
weak initialization vector

101
00:04:59,160 --> 00:05:00,480
known as an IV.

102
00:05:00,480 --> 00:05:02,700
And knowledge of the IV can be used

103
00:05:02,700 --> 00:05:04,800
to decrypt encrypted packets.

104
00:05:04,800 --> 00:05:07,006
And that RFID eavesdropping

105
00:05:07,006 --> 00:05:10,920
which is intercepting
communications between an RFID tag

106
00:05:10,920 --> 00:05:12,330
and a reader can be used

107
00:05:12,330 --> 00:05:16,263
for interception, manipulation,
and reuse of data.

108
00:05:18,960 --> 00:05:21,930
And lastly, we get to a
denial of service attack.

109
00:05:21,930 --> 00:05:23,940
We know that a denial of service attack

110
00:05:23,940 --> 00:05:26,370
is overwhelming system resources

111
00:05:26,370 --> 00:05:29,670
and the ultimate goal is to
make those resources unavailable

112
00:05:29,670 --> 00:05:31,353
for their intended use.

113
00:05:32,520 --> 00:05:34,710
So in the wireless environment,
there are two attacks

114
00:05:34,710 --> 00:05:38,100
you wanna know, jamming
and disassociation.

115
00:05:38,100 --> 00:05:39,810
Jamming is overwhelming

116
00:05:39,810 --> 00:05:42,840
the wireless frequency
with illegitimate traffic,

117
00:05:42,840 --> 00:05:44,220
traffic that shouldn't be there.

118
00:05:44,220 --> 00:05:46,636
And the frequency then becomes unavailable

119
00:05:46,636 --> 00:05:48,543
for legitimate traffic.

120
00:05:49,440 --> 00:05:53,940
Disassociation is spoofing
a disassociate message

121
00:05:53,940 --> 00:05:56,490
which forces a device to disassociate

122
00:05:56,490 --> 00:05:59,010
and then attempts to reassociate.

123
00:05:59,010 --> 00:06:01,477
Disassociation message is
when an access point says,

124
00:06:01,477 --> 00:06:03,240
"No, I need to knock you off."

125
00:06:03,240 --> 00:06:05,610
Basically, "I need you not
to be associated with me."

126
00:06:05,610 --> 00:06:07,267
Then of course the your system will say,

127
00:06:07,267 --> 00:06:10,530
"Okay but I wanna try again
and we'll try to associate."

128
00:06:10,530 --> 00:06:14,340
So the device is continually
knocked offline, right?

129
00:06:14,340 --> 00:06:16,110
Tries to, you know, get up there,

130
00:06:16,110 --> 00:06:19,260
it's knocked offline, tries
to connect, knocked offline.

131
00:06:19,260 --> 00:06:21,510
It's also known as a
deauthentication attack.

132
00:06:21,510 --> 00:06:24,990
And very often it's used as
a precursor to an evil twin.

133
00:06:24,990 --> 00:06:27,390
And so you get knocked off,

134
00:06:27,390 --> 00:06:29,280
you get a packet that
knocks you off, right?

135
00:06:29,280 --> 00:06:33,000
Your legitimate access point
and then the evil twin comes up

136
00:06:33,000 --> 00:06:36,153
and aha, that's the one
that you reassociate with.

137
00:06:38,490 --> 00:06:40,170
That was a lot of information.

138
00:06:40,170 --> 00:06:42,390
And now we're gonna do a
three-second challenge.

139
00:06:42,390 --> 00:06:43,440
Are you ready?

140
00:06:43,440 --> 00:06:45,480
Five challenge questions,
three seconds each.

141
00:06:45,480 --> 00:06:47,010
Let's do it.

142
00:06:47,010 --> 00:06:49,350
An unauthorized Bluetooth connections.

143
00:06:49,350 --> 00:06:50,790
What kind of attack is that?

144
00:06:50,790 --> 00:06:52,503
One, two, three.

145
00:06:53,340 --> 00:06:54,790
That's gonna be bluesnarfing.

146
00:06:56,190 --> 00:07:00,300
Forced deauthentication kind of attack.

147
00:07:00,300 --> 00:07:02,460
One, two, three.

148
00:07:02,460 --> 00:07:04,113
That's disassociation.

149
00:07:06,750 --> 00:07:09,510
Unauthorized access to an NFC device

150
00:07:09,510 --> 00:07:11,580
or transmission, number three.

151
00:07:11,580 --> 00:07:12,900
One, two, three.

152
00:07:12,900 --> 00:07:17,283
That is a an FC bump or bumping.

153
00:07:18,810 --> 00:07:22,620
Number four, overwhelming frequencies.

154
00:07:22,620 --> 00:07:24,210
One, two, three.

155
00:07:24,210 --> 00:07:25,473
What's happening there?

156
00:07:26,370 --> 00:07:28,320
That's jamming.

157
00:07:28,320 --> 00:07:31,290
And lastly, a rogue wireless access point

158
00:07:31,290 --> 00:07:33,390
that has the same SSID

159
00:07:33,390 --> 00:07:36,000
as a legitimate wireless access point.

160
00:07:36,000 --> 00:07:37,620
What is that called?

161
00:07:37,620 --> 00:07:39,213
Initials, ET.

162
00:07:40,380 --> 00:07:42,183
That's gonna be an evil twin.

163
00:07:43,320 --> 00:07:44,670
All right, let's do a security-in-action

164
00:07:44,670 --> 00:07:45,900
and put that knowledge to use.

165
00:07:45,900 --> 00:07:47,643
This is about wireless disruption.

166
00:07:48,570 --> 00:07:49,680
You generally connect

167
00:07:49,680 --> 00:07:51,870
to the corporate LAN wirelessly.

168
00:07:51,870 --> 00:07:54,510
Midday today, you were
disconnected and you were presented

169
00:07:54,510 --> 00:07:56,670
with a screen you've never seen before

170
00:07:56,670 --> 00:07:59,490
asking you to enter your
network credentials.

171
00:07:59,490 --> 00:08:01,680
You were then successfully reconnected

172
00:08:01,680 --> 00:08:05,340
to the wireless local area
network or the wireless LAN.

173
00:08:05,340 --> 00:08:06,900
All seems fine now.

174
00:08:06,900 --> 00:08:09,150
Any further action necessary?

175
00:08:09,150 --> 00:08:10,320
So this weird little thing.

176
00:08:10,320 --> 00:08:11,250
You got knocked off,

177
00:08:11,250 --> 00:08:12,660
you got the screen saying you gotta put in

178
00:08:12,660 --> 00:08:13,800
your network credentials.

179
00:08:13,800 --> 00:08:17,490
You did, you got connected,
everything's been working fine.

180
00:08:17,490 --> 00:08:19,830
Hmm, any further action necessary

181
00:08:19,830 --> 00:08:22,137
or can we just ignore the situation?

182
00:08:22,137 --> 00:08:23,910
Well, I want you to put me on pause

183
00:08:23,910 --> 00:08:25,380
and think about what you might do.

184
00:08:25,380 --> 00:08:26,430
What's your action?

185
00:08:26,430 --> 00:08:28,973
Then come on back and we'll
talk about it together.

186
00:08:30,420 --> 00:08:33,870
Well, yes, this really should
be investigated, right?

187
00:08:33,870 --> 00:08:35,250
It's a weird situation.

188
00:08:35,250 --> 00:08:36,420
You got disconnected.

189
00:08:36,420 --> 00:08:38,100
Okay, well maybe that happens

190
00:08:38,100 --> 00:08:40,500
but then you got the screen
you've never seen before

191
00:08:40,500 --> 00:08:43,020
asking you to put your credentials?

192
00:08:43,020 --> 00:08:44,730
And we definitely wanna look into it.

193
00:08:44,730 --> 00:08:46,860
And it's very symptomatic

194
00:08:46,860 --> 00:08:50,670
of an evil twin attack
where you get disconnected,

195
00:08:50,670 --> 00:08:52,680
maybe you get asked
for credentials or not,

196
00:08:52,680 --> 00:08:54,720
and then you automatically get reconnected

197
00:08:54,720 --> 00:08:56,253
and everything seems fine.

198
00:08:57,600 --> 00:09:00,060
So we had disassociation.

199
00:09:00,060 --> 00:09:04,050
This probably is connection
to a rogue access point.

200
00:09:04,050 --> 00:09:05,970
And then the other thing that happened

201
00:09:05,970 --> 00:09:08,970
is when they were asking for
your credentials, it's use

202
00:09:08,970 --> 00:09:13,143
of a fraudulent captive portal
to capture those credentials.

203
00:09:14,490 --> 00:09:16,740
And then we have reassociation, right?

204
00:09:16,740 --> 00:09:19,020
So you got disassociated, associated.

205
00:09:19,020 --> 00:09:21,390
You got connected to a rogue access point,

206
00:09:21,390 --> 00:09:23,280
you were then asked your credentials

207
00:09:23,280 --> 00:09:25,050
and then you were reassociated.

208
00:09:25,050 --> 00:09:27,360
Again, all of those things are symptomatic

209
00:09:27,360 --> 00:09:29,883
of an evil twin type of attack.

210
00:09:31,230 --> 00:09:33,240
So users should always be instructed

211
00:09:33,240 --> 00:09:35,670
to report any unusual activity.

212
00:09:35,670 --> 00:09:38,880
Especially, really especially
when related to credentials.

213
00:09:38,880 --> 00:09:41,910
And as help desk folks, we
need to be in the position

214
00:09:41,910 --> 00:09:43,200
of not just being dismissive.

215
00:09:43,200 --> 00:09:44,910
We shouldn't say, "Well,
is everything okay now?"

216
00:09:44,910 --> 00:09:45,743
And they say, "Yeah."

217
00:09:45,743 --> 00:09:47,220
And you're like, "Okay, well then,

218
00:09:47,220 --> 00:09:48,630
you know, just go ahead and do your work.

219
00:09:48,630 --> 00:09:49,860
Don't worry about it."

220
00:09:49,860 --> 00:09:53,040
Whenever we see anything
unusual happening,

221
00:09:53,040 --> 00:09:55,890
it always warrants an investigation.

222
00:09:55,890 --> 00:09:58,390
And doing that, my friends,
is security-in-action.

223
00:09:59,400 --> 00:10:00,450
There's your word cloud.

224
00:10:00,450 --> 00:10:02,040
Quite a few things there.

225
00:10:02,040 --> 00:10:03,840
Make sure you understand
all these attacks.

226
00:10:03,840 --> 00:10:04,673
You can speak to them,

227
00:10:04,673 --> 00:10:06,897
you can describe them,
you're confident in them.

228
00:10:06,897 --> 00:10:09,780
If you're not, go back and
look through the lesson again

229
00:10:09,780 --> 00:10:12,420
and when you are, head on
over to our next lesson.

230
00:10:12,420 --> 00:10:13,920
I'll be waiting for you there.
