Wardriving without the driving

We would like to show you a couple of great methods to get clean working proxies, and or access points by wardriving, without driving anywhere. Again, proxy means to go through. So, we will be going through, a WiFi access point to get internet. When we mention proxy in our tutorials, we are speaking about ip or access point or proxy. For those of you that are very quick to understand things, lets refer to our first example we give you in the Proxy section, Every proxy server has an ip. But.. not every ip has a proxy server. So by wardriving, we are not using traditional proxies. We are directly jumping into a different ip. For our purposes, this is absolutely the cleanest un-abused Craigslist friendly ip you can grab. You can use them to post, flag, create new accounts.. How to modify the equipment listed below just a little is all you really need to understand to be able to acquire access to limitless IP’s in your own backyard. (your own 20 km backyard that is) Some of you will need to have it explained a little further.

Home made WiFi repeaters

The most darn cool, and economic way to grab nearly limitless access points without even leaving the office, or home as the case may be, is to use WiFi equipment to amplify the faint WiFi signals from your apartment office situated high above the city.

Our first example is achieved with an external usb network adapter housed in a home made parabolic apparatus with remote trim and pan functions. You just inch your modified star choice satellite dish across the city-scapes aiming at apartment blocks and neighborhoods miles away and jump into every unlocked network you find. For the advanced students, you can use a parallel port relay board 35$ and the cool timer software that comes with it to pan and tilt your Craigslist flaggerssystem all day long automatically as it jumps on and off the networks you programmed into it as it scans the skyline.

Once you have all the access points programmed in the first pass, it will just jump on and off the networks automatically changing your entire ip while the software flags your targets with the flag forever function. Here is a photo of a modified satellite dish for picking up WiFi at great distances. You use an external usb WiFi adapter and take it apart carefully. smear clear RTV silicone on the circuit board, a thin but decent layer. cover all of the metal parts, try not to add extra or it will reduce the life of the device due to heat build up. If you cant get it apart, just cover the seams with jbweld, or epoxy and put a dab of silicone on the light so no water can get in. This “quick” method will condensate inside the casing eventually and destroy your usb device by leaving droplets of water on the circuit board, and when it does, it might take your usb port with it if enough water builds up. Use an old computer, or a PCI card with extra usb ports for this system. If anything goes wrong, you don’t want to blow a port in your brand new laptop!

We buy old laptops for $60 – $200 and use them in this type of setup. Then you can use a booster usb extension cable, plug the unit in, silicone with RTV very very well the entire joint. Mount this in the tomato soup can as in the photo. The can in this photo is positioned wrong BTW, bolt the open mouth of the can to the edge of the mounting pole.(the lip, not the base). Cut a small square hole in the bottom of the base, and mount your usb WiFi card in the back of the can, 1 inch away from the back. Spray paint the whole thing flat gray so no one notices anything afoot. Tell your curious neighbors nothing! If you explain it to them, they will smile politely and say “oh that’s neat!” then go and call the police on you. (9 times out of 9)

This gives you 2 to 7 miles extra WiFi sniffing range! Or you can use the tomato juice can by its self as a simple wave guide (radio amplifier) with no dish. You can strap the can to a broom stick pointed outward, it’s not as effective & much trickier to aim. The dish gathers scattered signals and makes them useful. If you cannot do this, you can attach your waterproof network card to a broomstick or equivalent and mount it out your window. Now you have free WiFi internet, and you can jump through other access points like a ghost and reload your flagging powers endlessly. Remember, 4 flags per ad, then switch IP’s.

Professional WiFi rebroadcasting

There is a very big company you have probably heard very little about, but it is time you were introduced. They are called Ubiquity. The Craigslist flaggersdevice we are going to feature, although you may use any number of devices with the exact same software interface and the exact same configuration. The category we have decided to use for our purposes is called AirMax. The specific device is the small parabolic (89$ USD) called NanoBridge M5 2.4 GHz.. the frequency is very important, buy any of these AirMax devices you like, but they must be the 2.4 GHz model, or you will only be able to see other AirMax equipment, and not the common 2.4 GHz access points you are actually hunting for.

This is water resistant equipment, and does not require any silicone or jb-weld. You will likely want to get the out-door POE (power over ethernet) cable for your use. You can run nearly unlimited length of it, as compared to only 10 to 15 feet of usb extension in the previous system. This gives you a distinct mounting advantage over the usb cable setups. Your AirMax unit will run on 24 or 48 volts, and will come supplied with the POE power adapter. You will not need to put power up on the roof to make his work, the power goes through the ethernet cable alone. If you want to support the cool Ubiquity folks, you might also want to buy their tough switch, especially if you’re going to power multiple units at once, and you don’t want to have a bunch of POE adapters taking up power-bar spaces, and extra patch ethernet cables etc.. The Tough Switch lets you configure it’s POE output with it’s internal software you set up to configure it. But.. for our purpose in this article, it’s entirely unnecessary.

Once you configure your AirMax device correctly, you will be able to scan up to 20 km @ 150 Mbps for usable signals (in the line of sight) with the parabolic dish included with it. You should begin your device setup on your laptop. Once you have the NanoBridge configured correctly, and you can jump onto a network and access the internet, you simply plug the ethernet cable from the NanoBridge into the port on your WiFi router (or Tough Switch) that is reserved for the cable modem input. You can use any WiFi router for this purpose, and not even change any settings if it’s already been previously set up. You just log into your own network as usual. We use this type of home router since the tough switch does not come with a WiFi option just yet, it’s ethernet cable only.

Craigslist flaggersAfter you have completed these steps, you can then log into the AirMax wirelessly on your laptop, and go up on your roof and aim it until it grabs the signals you’re looking at. There is the decibel measurement graph to tell you if you’re getting warmer or colder. We like to use a home satellite remote trim and pan mount for our dish, so we don’t need to go up top to reposition the dish when we are scanning and jumping in and out of access points. You may even want to splurge on an extra dish and have them aim back to back so you have 2 fresh networks piped down to your home / office. In order to get the biggest bang for our buck, we also decided to upgrade our parabolic dish itself. It’s very easy to do, and this hack will increase your range proportionately.

To change your dish, just find an old satellite dish of the size (larger is the idea) you would like to mount. Remove all your hardware from the original AirMax mounting bracket, and strip the larger dish down to a dish only, remove it’s mount, and it’s arm. Drill a hole the appropriate size dead center. Be careful not to dent the dish as you push down on it. Use a metal hole-saw or equivalent to make your 1.5 inch hole in the center. Once this is done, take your AirMax mounting bracket, and hold it against the new dish back side, and drill the 4 mounting holes into the new dish so you can bolt it on. Once the AirMax mounting bracket is bolted on to the new dish, take your antenna, plug it back in, and reinsert it into your mount. Make sure, that the original position is still correct, do not mount the antenna sideways or upside down, or it will get water into it and fail. You could use a little rtv silicone once everything is set up and complete if you like, but we have found it unnecessary.

If all went as planned, you can remount your AirMax unit and double check it’s operation up top with your laptop by logging into it’s interface after you reassemble it. If it was online when you took it apart, it will reboot, and log back in by itself. To further enhance our mount, we inserted a 32 millimeter galvanized pole right inside of a standard star-choice short grey pole, and mounted our modified AirMax device well above our neighbors roof / tree-line. The entire modification expense was 5$ for the pole, and 45 minutes start to finish. An old large discarded satellite dish was already abandoned up on the roof. We increased our already phenomenal range by a further 30 – 50% and got our decibels very high and very fast. We are grabbing any signals we feel like all around us at a great distance for free, and distributing it to our entire home network by way of our home WiFi router.

A word to the wise, you might want to install a lightning rod at the opposite corner of your area that is at least as tall as your AirMax on it’s pole.

Unlike the standard usb devices you are used to, these Ubiquity devices are what is known as full duplex. They can send and receive at 150 Mbps. Some people are actually setting up a hotspot server with these things that has a credit card or PayPal authorization portal, and reselling internet signal (WISP) to anyone who will log into the open WiFi and try to use it. There are many absolutly free programs for this online, as well as other services you can just become a member of in minutes, and they send you a % of the profits, and handle all the billing and commissions for you. This equipment was designed to Craigslist flaggersfunction very well in commercial applications such as this, and if you have a keen eye, you might notice it on those towers around town. You can even grab the WiFi from somewhere, and beam the signal 20 km to your neighbors or your office even in some cases. There are endless ways you can generate a network in your area for miles, and perhaps even offset your cable / internet bills by reselling WiFi to your neighbors and friends. The term for a business who sells WiFi is WISP (wireless internet service provider). You probably should not resell your neighbors WiFi though. If the poor guy can’t even get YouTube to work for him because you have more of his bandwidth than he does, he will eventually be forced to switch providers and lock you out for good. Be quiet like a mouse, and you will enjoy your arrangements for much longer.

Ubiquity is one of WiFi’s best kept secrets, if you don’t ask, no one will tell you. But if you’re in the know, all of a sudden you see it everywhere. This is precisely what we use to manage our wireless network needs, far and wide, and in more ways than one. The potential for such economic and available gear is enormous. If you are the least bit interested in how to tap into and control some of the airwaves around you, we suggest you google forums talking about the NanoBridge M5 2.4 GHz, and watch all the Ubiquiti YouTube videos you can find on the subject, and see exactly how others are doing some of what we mentioned for as little as $79.00.

Cracking Passwords

For those of you who are not interested in Linux Wifi password crackers.. there is a tool made by Tamo Soft called CommView. It is a windows packet scanner. It works in Windows 7 and 8.1. Dont use it in XP.. its iffy, we didn’t get a good result. It only works with the specified USB WiFi adapters, which you can find a list of on their website. We use the TP-LINK TL-WDN3200 usb adapter, (install the driver, but not the utility before you run CommView) and it works great. You can find this adapter in many computer stores. Get one for home and one for the office.. because you can set them up to scan everything in their reach, and have all of the passwords by the morning. Commview WiFi can get a little pricey. If you have the cash its worth it though. If you don’t have the cash, then you might need to figure out a different plan. And if you needed a little help with this plan, there is always YouTube. If you have more than 10 access points to scan at once, you will make sure you select worldwide license, not the home license.

Before you buy anything, if you’re wondering how it actually works, if its overly complex.. there is a good YouTube tutorials on the process here. Hes using an older version, but it’s still the same idea. It is a 2 stage process. Collect the IV’s.. (special packets with encrypted passwords in them) by collecting all the packets from a specific WiFi channel. You might collect 200 thousand packets and only 5800 are IV’s. Then the second stage is to download a free windows utility called Aircrack ng. This program loads the CommView packet log, and discards all the junk packets, and analyzes the IV’s to see what is in common among them. If you have enough IV’s collected, it will output your password. Just enter the numbers without the colons, and your done.

Some of you will build in one of these special adapters into a dish, and see far and wide, and crack them all open. You might get access to as many as 40 access points if your in a high rise depending on where your from. In the world of online advertising.. access to this many clean IP’s makes you very powerful indeed. Well worth the move into an “Office/Apartment” on the 18th floor of some development for business purposes alone. Some of you will take these adapters and 2 laptops in the car at the same time.. with the adapters taped to the windows for good line of sight.. and crack twice as many twice as fast. Sit outside a high rise, and crack them all open. The next time you visit.. you will already have all your AP’s programmed in, and your job is much faster.. If you cracked 4 of these high rises open.. and got 10 AP’s from each, there is not so much work involved to pop all the accounts that are offending you the next time you roll in. You can probably clear an entire section in 2 hours or less. (NOT RECOMMENDED!!)

Here are some tools to get you started.. well, these are for the more advanced wardrivers among you.

Name:aerosol Download:aerosol-0.65.zip
Operating System: Windows HomePage:http://www.stolenshoes.net/sniph/aerosol.html
Aerosol is easy to use wardriving software for PRISM2 Chipset, ATMEL USB and WaveLAN
Wireless cards on Windows. Its lightweight, written in C, free, and uh, just works!

 

Name:Aircrack-ng Download:aircrack-ng-0.7.tar.gz
Operating System: Windows, Linux HomePage:http://aircrack-ng.org/doku.php
802.11 sniffer and WEP key cracker for Windows and
Linux.

 

Name:airfart Download:airfart-v0.2.1.tar.gz
Operating System: Linux HomePage:http://airfart.sourceforge.net/
AirFart is a wireless tool created to detect wireless
devices, calculate their signal strengths, and present them to the user
in an easy-to-understand fashion. It is written in C/C++ with a GTK front
end. Airfart supports all wireless network cards supported by the linux-wlan-ng
Prism2 driver that provide hardware signal strength information in the
“raw signal” format (ssi_type 3). Airfart implements a modular
n-tier architecture with the data collection at the bottom tier and a
graphical user interface at the top.

 

Name:airjack Download:airjack-v0.6.6b-alpha.tar.bz2
Operating System: Linux HomePage:http://sourceforge.net/projects/airjack/
AirJack is a device driver (or suit of device drivers)
for 802.11(a/b/g) raw frame injection and reception.

 

Name:airsnarf Download:airsnarf-0.2.tar.gz
Operating System: Linux HomePage:http://airsnarf.shmoo.com/
Airsnarf is a simple rogue wireless access point setup
utility designed to demonstrate how a rogue AP can steal usernames and
passwords from public wireless hotspots. Airsnarf was developed and released
to demonstrate an inherent vulnerability of public 802.11b hotspots–snarfing
usernames and passwords by confusing users with DNS and HTTP redirects
from a competing AP.

 

Name:airtraf Download:airtraf-1.1.tar.gz
Operating System: Linux HomePage:http://airtraf.sourceforge.net/
AirTraf is a 100% passive packet sniffing tool for
the wireless 802.11b networks. It captures and tracks all wireless activity
in the coverage area, decodes packets, and maintains acquired information
associated by access points, as well as detected individual wireless nodes.
It dynamically detects any access points in the area, finds association
between wireless clients and access points, and builds information table
for each packet that is transmitted via the air. AirTraf is able to maintain
packet count, byte information, related bandwidth, as well as signal strength
of nodes.
Name:AP Hopper Download:aphopper-0.3.tar.gz
Operating System: Linux HomePage:http://aphopper.sourceforge.net/
AP Hopper is a program that automatically hops between
access points of different wireless networks. It checks for DHCP and Internet
Access on all the networks found. It logs successful and unsuccessful
attempts.

 

Name:AP Hunter Download:aphunter.tgz
Operating System: Linux HomePage:http://www.math.ucla.edu/~jimc/mathnet_d/download.html
Access Point Hunter. It can find and automatically
connect to whatever wireless network is within range. It can be used for
site surveys, writing the results in a file.

 

Name:AP Radar Download:apradar-0.52.tar.gz
Operating System: Linux HomePage:http://apradar.sourceforge.net/
AP Radar is a Linux/GTK+ based graphical netstumbler
and wireless profile manager. This project makes use of the version 14
wireless extensions in linux 2.4.20 and 2.6 to provide access point scanning
capabilities for most models of wireless cards. It is meant to replace
the manual process of running iwconfig and dhclient. It makes reconfiguring
for different APs quick and easy.

 

Name:asleap Download:asleap-1.4.tgz
Operating System: Windows HomePage:http://asleap.sourceforge.net
This tool is released as a proof-of-concept to demonstrate
weaknesses in the LEAP and PPTP protocols.

 

Name:bsd-airtools Download:bsd-airtools-v0.2.tgz
Operating System: NetBSD,
OpenBSD, FreeBSD
HomePage:http://www.dachb0den.com/projects/bsd-airtools.html
bsd-airtools is a package that provides a complete
toolset for wireless 802.11b auditing. Namely, it currently contains a
bsd-based wep cracking application, called dweputils (as well as kernel
patches for NetBSD, OpenBSD, and FreeBSD). It also contains a curses based
ap detection application similar to netstumbler (dstumbler) that can be
used to detect wireless access points and connected nodes, view signal
to noise graphs, and interactively scroll through scanned ap’s and view
statistics for each. It also includes a couple other tools to provide
a complete toolset for making use of all 14 of the prism2 debug modes
as well as do basic analysis of the hardware-based link-layer protocols
provided by prism2’s monitor debug mode.

 

Name:Classic Stumbler Download:ClassicStumbler.img.sit.hqx
Operating System: MacOS HomePage:http://www.alksoft.com/classicstumbler.html
ClassicStumbler scans for and displays information
about all the wireless access points in range. It will display your signal
strength, noise strength, signal to noise ratio, what channel your access
point is on, if other access points are interfering with yours, and whether
or not those access points are providing encrypted, unencrypted, computer-to-computer,
or infrastructure type networks.
Name:CoWF/Warglue Download:cowf-warglue-suite-1.0-full.tar.gz
Operating System: Windows HomePage:http://sourceforge.net/projects/warglue
This is a multiplatform general utility suite for
use with existing network stumbling software, such as Kismet or NetStumbler.
The program will convert between multiple output logs, including the popular
wi-scan format, between platforms.

 

Name:FakeAP Download:fakeap-0[1].3.2.tar.gz
Operating System: Linux, BSD* HomePage:http://www.blackalchemy.to/project/fakeap/
Black Alchemy’s Fake AP generates thousands of
counterfeit 802.11b access points. Hide in plain sight amongst Fake
AP’s cacophony of beacon frames. As part of a honeypot or as an instrument
of your site security plan, Fake AP confuses Wardrivers, NetStumblers,
Script Kiddies, and other undesirables.* See HomePage for more information

 

Name:gpsd Download:gpsd-2.34.tar.gz
Operating System: Linux, BSD HomePage:http://gpsd.berlios.de/
gpsd is a service daemon that monitors a GPS attached
to a host computer through a serial or USB port, making its data on the
location/course/velocity of the sensor available to be queried on TCP
port 2947 of the host computer. With gpsd, multiple GPS client applications
(such as navigational and wardriving software) can share access to a GPS
without contention or loss of data. Also, gpsd responds to queries with
a format that is substantially easier to parse than the NMEA 0183 emitted
by most GPSes. The gpsd distribution includes a linkable C service library
and a Python module that developers of gpsd-aware applications can use
to encapsulate all communication with gpsd.

 

Name:iStumbler Download:
istumbler-98.tgz
Operating System: MacOS HomePage:http://www.istumbler.net/
iStumbler is a free, open source tool for finding
AirPort networks, Bluetooth devices Bonjour services, and now GPS locations
with your Mac.

 

Name:Kismet Download:kismet-2007-01-R1b.tar.gz
Operating System: Linux,
BSDs, MacOS, Windows
HomePage:http://www.kismetwireless.net/
Kismet is an 802.11 layer2 wireless network detector,
sniffer, and intrusion detection system. Kismet will work with any wireless
card which supports raw monitoring (rfmon) mode, and can sniff 802.11b,
802.11a, and 802.11g traffic.Kismet identifies networks by passively collecting packets and detecting
standard named networks, detecting (and given time, decloaking) hidden
networks, and infering the presence of nonbeaconing networks via data
traffic.

 

Name:Radiate Download:libradiate-beta-0.02.tar.gz
Operating System: Linux HomePage:http://www.packetfactory.net/projects/libradiate/
Radiate is a small C library designed read, build
and write 802.11 frames.

 

Name:MacStumbler Download:MacStumbler-075b.tgz
Operating System: MacOS HomePage:http://www.macstumbler.com/
MacStumbler is a utility to display information about
nearby 802.11b and 802.11g wireless access points. It is mainly designed
to be a tool to help find access points while traveling, or to diagnose
wireless network problems. Additionally, MacStumbler can be used for “wardriving”,
which involves co-ordinating with a GPS unit while traveling around to
help produce a map of all access points in a given area.

 

Name:MiniStumbler Download:ministumblerinstaller_0_4_0.exe
Operating System: Windows CE HomePage:http://www.netstumbler.com/
MiniStumbler is a tool for Windows CE that allows
you to detect
Wireless Local Area Networks (WLANs) using 802.11b, 802.11a and 802.11g.

 

Name:Mognet Download:Mognet-1.16.tar.gz
Operating System: Linux HomePage:http://www.node99.org/projects/mognet/
Mognet is a simple, lightweight 802.11b sniffer written
in Java and available under the GPL. It features real time capture output,
support for all 802.11b generic and frame-specific headers, text mode
capture for GUI-less devices, and loading/saving capture sessions in libpcap
format.

 

Name:NetStumbler Download:netstumblerinstaller_0_4_0.exe
Operating System: Windows HomePage:http://www.netstumbler.com/
NetStumbler is a tool for Windows that allows you
to detect Wireless Local Area Networks (WLANs) using 802.11b, 802.11a and 802.11g.

 

Name:ssidsniff Download:ssidsniff-0.42.tar.gz
Operating System: Linux HomePage:http://www.bastard.net/~kos/wifi/
A curses based tool that allows identification, classification
and data capturing of wireless networks. The interface is inspired from
the unix top(1) utility.

 

Name:wavemon Download:wavemon-current.tar.gz
Operating System: Linux HomePage:http://www.janmorgenstern.de/projects-software.html
wavemon is a ncurses-based monitoring application
for wireless network devices.

 

Name:Wellenreiter Download:Wellenreiter-v1.9.tar.gz
Operating System: Linux HomePage:http://wellenreiter.sourceforge.net/
Wellenreiter is a wireless network discovery and auditing
tool. Prism2, Lucent, and Cisco based cards are supported. It is the easiest
to use Linux scanning tool. No card configuration has to be done anymore.
The whole look and feel is pretty self-explaining. It can discover networks
(BSS/IBSS), and detects ESSID broadcasting or non-broadcasting networks
and their WEP capabilities and the manufacturer automatically. DHCP and
ARP traffic are decoded and displayed to give you further information
about the networks. An ethereal/tcpdump-compatible dumpfile and an Application
savefile will be automaticly created. Using a supported GPS device and
the gpsd you can track the location of the discovered networks

 

Name:WepAttack Download:WepAttack-0.1.3.tar.gz
Operating System: Linux HomePage:http://wepattack.sourceforge.net/
WepAttack is a WLAN open source Linux tool for breaking
802.11 WEP keys. This tool is based on an active dictionary attack that
tests millions of words to find the right key. Only one packet is required
to start an attack.

 

Name:WepLab Download:weplab-0.1.5_win32.zip,
weplab-0.1.5.tar.gz
Operating System: Linux,
BSD, MacOS, Windows
HomePage:http://weplab.sourceforge.net/
WepLab is a tool designed to teach how WEP works,
what different vulnerabilities it has, and how they can be used in practice
to break a WEP protected wireless network. So far, WepLab more than a
Wep Key Cracker, is a Wep Security Analyzer designed from an educational
point of view.

 

Name:WEPWedgie Download:wepwedgie-alpha-0.1.0.tar.gz
Operating System: Linux HomePage:http://sourceforge.net/projects/wepwedgie/
WEPWedgie is a toolkit for determining 802.11 WEP
keystreams and injecting traffic with known keystreams. The toolkit also
includes logic for firewall rule mapping, pingscanning, and portscanning
via the injection channel and a cellular modem

 

Name:WiFiFoFum Download:WiFiFoFumInstaller.msi
Operating System: Windows CE HomePage:http://www.aspecto-software.com/WiFiFoFum/
802.11 scanner for PDA’s that run PocketPC.

 

Name:WiFiScanner Download:WifiScanner-1.0.2a.tar.gz
Operating System: Linux HomePage:http://wifiscanner.sourceforge.net/
WifiScanner is a tool that has been designed to discover
wireless node (i.e access point and wireless clients).

 

Name:WiStumbler Download:wistumbler-current.tar.gz
Operating System: NetBSD HomePage:http://www.gongon.com/persons/iseki/wistumbler/
Network stumbler for WaveLAN/IEEE wireless networking

 

Name:wscan Download:wscan1.00.tar.gz
Operating System: Linux, FreeBSD HomePage:http://www.cs.pdx.edu/research/SMN/
wscan is a X-11/visual 802.11 wireless signal-strength display tool.