Wardriving without the driving
We would like to show you a couple of great methods to get clean working proxies, and or access points by wardriving, without driving anywhere. Again, proxy means to go through. So, we will be going through, a WiFi access point to get internet. When we mention proxy in our tutorials, we are speaking about ip or access point or proxy. For those of you that are very quick to understand things, lets refer to our first example we give you in the Proxy section, Every proxy server has an ip. But.. not every ip has a proxy server. So by wardriving, we are not using traditional proxies. We are directly jumping into a different ip. For our purposes, this is absolutely the cleanest un-abused Craigslist friendly ip you can grab. You can use them to post, flag, create new accounts.. How to modify the equipment listed below just a little is all you really need to understand to be able to acquire access to limitless IP’s in your own backyard. (your own 20 km backyard that is) Some of you will need to have it explained a little further.
Home made WiFi repeaters
The most darn cool, and economic way to grab nearly limitless access points without even leaving the office, or home as the case may be, is to use WiFi equipment to amplify the faint WiFi signals from your apartment office situated high above the city.
Our first example is achieved with an external usb network adapter housed in a home made parabolic apparatus with remote trim and pan functions. You just inch your modified star choice satellite dish across the city-scapes aiming at apartment blocks and neighborhoods miles away and jump into every unlocked network you find. For the advanced students, you can use a parallel port relay board 35$ and the cool timer software that comes with it to pan and tilt your
system all day long automatically as it jumps on and off the networks you programmed into it as it scans the skyline.
Once you have all the access points programmed in the first pass, it will just jump on and off the networks automatically changing your entire ip while the software flags your targets with the flag forever function. Here is a photo of a modified satellite dish for picking up WiFi at great distances. You use an external usb WiFi adapter and take it apart carefully. smear clear RTV silicone on the circuit board, a thin but decent layer. cover all of the metal parts, try not to add extra or it will reduce the life of the device due to heat build up. If you cant get it apart, just cover the seams with jbweld, or epoxy and put a dab of silicone on the light so no water can get in. This “quick” method will condensate inside the casing eventually and destroy your usb device by leaving droplets of water on the circuit board, and when it does, it might take your usb port with it if enough water builds up. Use an old computer, or a PCI card with extra usb ports for this system. If anything goes wrong, you don’t want to blow a port in your brand new laptop!
We buy old laptops for $60 – $200 and use them in this type of setup. Then you can use a booster usb extension cable, plug the unit in, silicone with RTV very very well the entire joint. Mount this in the tomato soup can as in the photo. The can in this photo is positioned wrong BTW, bolt the open mouth of the can to the edge of the mounting pole.(the lip, not the base). Cut a small square hole in the bottom of the base, and mount your usb WiFi card in the back of the can, 1 inch away from the back. Spray paint the whole thing flat gray so no one notices anything afoot. Tell your curious neighbors nothing! If you explain it to them, they will smile politely and say “oh that’s neat!” then go and call the police on you. (9 times out of 9)
This gives you 2 to 7 miles extra WiFi sniffing range! Or you can use the tomato juice can by its self as a simple wave guide (radio amplifier) with no dish. You can strap the can to a broom stick pointed outward, it’s not as effective & much trickier to aim. The dish gathers scattered signals and makes them useful. If you cannot do this, you can attach your waterproof network card to a broomstick or equivalent and mount it out your window. Now you have free WiFi internet, and you can jump through other access points like a ghost and reload your flagging powers endlessly. Remember, 4 flags per ad, then switch IP’s.
Professional WiFi rebroadcasting
There is a very big company you have probably heard very little about, but it is time you were introduced. They are called Ubiquity. The
device we are going to feature, although you may use any number of devices with the exact same software interface and the exact same configuration. The category we have decided to use for our purposes is called AirMax. The specific device is the small parabolic (89$ USD) called NanoBridge M5 2.4 GHz.. the frequency is very important, buy any of these AirMax devices you like, but they must be the 2.4 GHz model, or you will only be able to see other AirMax equipment, and not the common 2.4 GHz access points you are actually hunting for.
This is water resistant equipment, and does not require any silicone or jb-weld. You will likely want to get the out-door POE (power over ethernet) cable for your use. You can run nearly unlimited length of it, as compared to only 10 to 15 feet of usb extension in the previous system. This gives you a distinct mounting advantage over the usb cable setups. Your AirMax unit will run on 24 or 48 volts, and will come supplied with the POE power adapter. You will not need to put power up on the roof to make his work, the power goes through the ethernet cable alone. If you want to support the cool Ubiquity folks, you might also want to buy their tough switch, especially if you’re going to power multiple units at once, and you don’t want to have a bunch of POE adapters taking up power-bar spaces, and extra patch ethernet cables etc.. The Tough Switch lets you configure it’s POE output with it’s internal software you set up to configure it. But.. for our purpose in this article, it’s entirely unnecessary.
Once you configure your AirMax device correctly, you will be able to scan up to 20 km @ 150 Mbps for usable signals (in the line of sight) with the parabolic dish included with it. You should begin your device setup on your laptop. Once you have the NanoBridge configured correctly, and you can jump onto a network and access the internet, you simply plug the ethernet cable from the NanoBridge into the port on your WiFi router (or Tough Switch) that is reserved for the cable modem input. You can use any WiFi router for this purpose, and not even change any settings if it’s already been previously set up. You just log into your own network as usual. We use this type of home router since the tough switch does not come with a WiFi option just yet, it’s ethernet cable only.
After you have completed these steps, you can then log into the AirMax wirelessly on your laptop, and go up on your roof and aim it until it grabs the signals you’re looking at. There is the decibel measurement graph to tell you if you’re getting warmer or colder. We like to use a home satellite remote trim and pan mount for our dish, so we don’t need to go up top to reposition the dish when we are scanning and jumping in and out of access points. You may even want to splurge on an extra dish and have them aim back to back so you have 2 fresh networks piped down to your home / office. In order to get the biggest bang for our buck, we also decided to upgrade our parabolic dish itself. It’s very easy to do, and this hack will increase your range proportionately.
To change your dish, just find an old satellite dish of the size (larger is the idea) you would like to mount. Remove all your hardware from the original AirMax mounting bracket, and strip the larger dish down to a dish only, remove it’s mount, and it’s arm. Drill a hole the appropriate size dead center. Be careful not to dent the dish as you push down on it. Use a metal hole-saw or equivalent to make your 1.5 inch hole in the center. Once this is done, take your AirMax mounting bracket, and hold it against the new dish back side, and drill the 4 mounting holes into the new dish so you can bolt it on. Once the AirMax mounting bracket is bolted on to the new dish, take your antenna, plug it back in, and reinsert it into your mount. Make sure, that the original position is still correct, do not mount the antenna sideways or upside down, or it will get water into it and fail. You could use a little rtv silicone once everything is set up and complete if you like, but we have found it unnecessary.
If all went as planned, you can remount your AirMax unit and double check it’s operation up top with your laptop by logging into it’s interface after you reassemble it. If it was online when you took it apart, it will reboot, and log back in by itself. To further enhance our mount, we inserted a 32 millimeter galvanized pole right inside of a standard star-choice short grey pole, and mounted our modified AirMax device well above our neighbors roof / tree-line. The entire modification expense was 5$ for the pole, and 45 minutes start to finish. An old large discarded satellite dish was already abandoned up on the roof. We increased our already phenomenal range by a further 30 – 50% and got our decibels very high and very fast. We are grabbing any signals we feel like all around us at a great distance for free, and distributing it to our entire home network by way of our home WiFi router.
A word to the wise, you might want to install a lightning rod at the opposite corner of your area that is at least as tall as your AirMax on it’s pole.
Unlike the standard usb devices you are used to, these Ubiquity devices are what is known as full duplex. They can send and receive at 150 Mbps. Some people are actually setting up a hotspot server with these things that has a credit card or PayPal authorization portal, and reselling internet signal (WISP) to anyone who will log into the open WiFi and try to use it. There are many absolutly free programs for this online, as well as other services you can just become a member of in minutes, and they send you a % of the profits, and handle all the billing and commissions for you. This equipment was designed to
function very well in commercial applications such as this, and if you have a keen eye, you might notice it on those towers around town. You can even grab the WiFi from somewhere, and beam the signal 20 km to your neighbors or your office even in some cases. There are endless ways you can generate a network in your area for miles, and perhaps even offset your cable / internet bills by reselling WiFi to your neighbors and friends. The term for a business who sells WiFi is WISP (wireless internet service provider). You probably should not resell your neighbors WiFi though. If the poor guy can’t even get YouTube to work for him because you have more of his bandwidth than he does, he will eventually be forced to switch providers and lock you out for good. Be quiet like a mouse, and you will enjoy your arrangements for much longer.
Ubiquity is one of WiFi’s best kept secrets, if you don’t ask, no one will tell you. But if you’re in the know, all of a sudden you see it everywhere. This is precisely what we use to manage our wireless network needs, far and wide, and in more ways than one. The potential for such economic and available gear is enormous. If you are the least bit interested in how to tap into and control some of the airwaves around you, we suggest you google forums talking about the NanoBridge M5 2.4 GHz, and watch all the Ubiquiti YouTube videos you can find on the subject, and see exactly how others are doing some of what we mentioned for as little as $79.00.
Cracking Passwords
For those of you who are not interested in Linux Wifi password crackers.. there is a tool made by Tamo Soft called CommView. It is a windows packet scanner. It works in Windows 7 and 8.1. Dont use it in XP.. its iffy, we didn’t get a good result. It only works with the specified USB WiFi adapters, which you can find a list of on their website. We use the TP-LINK TL-WDN3200 usb adapter, (install the driver, but not the utility before you run CommView) and it works great. You can find this adapter in many computer stores. Get one for home and one for the office.. because you can set them up to scan everything in their reach, and have all of the passwords by the morning. Commview WiFi can get a little pricey. If you have the cash its worth it though. If you don’t have the cash, then you might need to figure out a different plan. And if you needed a little help with this plan, there is always YouTube. If you have more than 10 access points to scan at once, you will make sure you select worldwide license, not the home license.
Before you buy anything, if you’re wondering how it actually works, if its overly complex.. there is a good YouTube tutorials on the process here. Hes using an older version, but it’s still the same idea. It is a 2 stage process. Collect the IV’s.. (special packets with encrypted passwords in them) by collecting all the packets from a specific WiFi channel. You might collect 200 thousand packets and only 5800 are IV’s. Then the second stage is to download a free windows utility called Aircrack ng. This program loads the CommView packet log, and discards all the junk packets, and analyzes the IV’s to see what is in common among them. If you have enough IV’s collected, it will output your password. Just enter the numbers without the colons, and your done.
Some of you will build in one of these special adapters into a dish, and see far and wide, and crack them all open. You might get access to as many as 40 access points if your in a high rise depending on where your from. In the world of online advertising.. access to this many clean IP’s makes you very powerful indeed. Well worth the move into an “Office/Apartment” on the 18th floor of some development for business purposes alone. Some of you will take these adapters and 2 laptops in the car at the same time.. with the adapters taped to the windows for good line of sight.. and crack twice as many twice as fast. Sit outside a high rise, and crack them all open. The next time you visit.. you will already have all your AP’s programmed in, and your job is much faster.. If you cracked 4 of these high rises open.. and got 10 AP’s from each, there is not so much work involved to pop all the accounts that are offending you the next time you roll in. You can probably clear an entire section in 2 hours or less. (NOT RECOMMENDED!!)
Here are some tools to get you started.. well, these are for the more advanced wardrivers among you.
| Name:aerosol | Download:aerosol-0.65.zip |
| Operating System: Windows | HomePage:http://www.stolenshoes.net/sniph/aerosol.html |
| Aerosol is easy to use wardriving software for PRISM2 Chipset, ATMEL USB and WaveLAN Wireless cards on Windows. Its lightweight, written in C, free, and uh, just works! |
|
| Name:Aircrack-ng | Download:aircrack-ng-0.7.tar.gz |
| Operating System: Windows, Linux | HomePage:http://aircrack-ng.org/doku.php |
| 802.11 sniffer and WEP key cracker for Windows and Linux. |
|
| Name:airfart | Download:airfart-v0.2.1.tar.gz |
| Operating System: Linux | HomePage:http://airfart.sourceforge.net/ |
| AirFart is a wireless tool created to detect wireless devices, calculate their signal strengths, and present them to the user in an easy-to-understand fashion. It is written in C/C++ with a GTK front end. Airfart supports all wireless network cards supported by the linux-wlan-ng Prism2 driver that provide hardware signal strength information in the “raw signal” format (ssi_type 3). Airfart implements a modular n-tier architecture with the data collection at the bottom tier and a graphical user interface at the top. |
|
| Name:airjack | Download:airjack-v0.6.6b-alpha.tar.bz2 |
| Operating System: Linux | HomePage:http://sourceforge.net/projects/airjack/ |
| AirJack is a device driver (or suit of device drivers) for 802.11(a/b/g) raw frame injection and reception. |
|
| Name:airsnarf | Download:airsnarf-0.2.tar.gz |
| Operating System: Linux | HomePage:http://airsnarf.shmoo.com/ |
| Airsnarf is a simple rogue wireless access point setup utility designed to demonstrate how a rogue AP can steal usernames and passwords from public wireless hotspots. Airsnarf was developed and released to demonstrate an inherent vulnerability of public 802.11b hotspots–snarfing usernames and passwords by confusing users with DNS and HTTP redirects from a competing AP. |
|
| Name:airtraf | Download:airtraf-1.1.tar.gz |
| Operating System: Linux | HomePage:http://airtraf.sourceforge.net/ |
| AirTraf is a 100% passive packet sniffing tool for the wireless 802.11b networks. It captures and tracks all wireless activity in the coverage area, decodes packets, and maintains acquired information associated by access points, as well as detected individual wireless nodes. It dynamically detects any access points in the area, finds association between wireless clients and access points, and builds information table for each packet that is transmitted via the air. AirTraf is able to maintain packet count, byte information, related bandwidth, as well as signal strength of nodes. |
|
| Name:AP Hopper | Download:aphopper-0.3.tar.gz |
| Operating System: Linux | HomePage:http://aphopper.sourceforge.net/ |
| AP Hopper is a program that automatically hops between access points of different wireless networks. It checks for DHCP and Internet Access on all the networks found. It logs successful and unsuccessful attempts. |
|
| Name:AP Hunter | Download:aphunter.tgz |
| Operating System: Linux | HomePage:http://www.math.ucla.edu/~jimc/mathnet_d/download.html |
| Access Point Hunter. It can find and automatically connect to whatever wireless network is within range. It can be used for site surveys, writing the results in a file. |
|
| Name:AP Radar | Download:apradar-0.52.tar.gz |
| Operating System: Linux | HomePage:http://apradar.sourceforge.net/ |
| AP Radar is a Linux/GTK+ based graphical netstumbler and wireless profile manager. This project makes use of the version 14 wireless extensions in linux 2.4.20 and 2.6 to provide access point scanning capabilities for most models of wireless cards. It is meant to replace the manual process of running iwconfig and dhclient. It makes reconfiguring for different APs quick and easy. |
|
| Name:asleap | Download:asleap-1.4.tgz |
| Operating System: Windows | HomePage:http://asleap.sourceforge.net |
| This tool is released as a proof-of-concept to demonstrate weaknesses in the LEAP and PPTP protocols. |
|
| Name:bsd-airtools | Download:bsd-airtools-v0.2.tgz |
| Operating System: NetBSD, OpenBSD, FreeBSD |
HomePage:http://www.dachb0den.com/projects/bsd-airtools.html |
| bsd-airtools is a package that provides a complete toolset for wireless 802.11b auditing. Namely, it currently contains a bsd-based wep cracking application, called dweputils (as well as kernel patches for NetBSD, OpenBSD, and FreeBSD). It also contains a curses based ap detection application similar to netstumbler (dstumbler) that can be used to detect wireless access points and connected nodes, view signal to noise graphs, and interactively scroll through scanned ap’s and view statistics for each. It also includes a couple other tools to provide a complete toolset for making use of all 14 of the prism2 debug modes as well as do basic analysis of the hardware-based link-layer protocols provided by prism2’s monitor debug mode. |
|
| Name:Classic Stumbler | Download:ClassicStumbler.img.sit.hqx |
| Operating System: MacOS | HomePage:http://www.alksoft.com/classicstumbler.html |
| ClassicStumbler scans for and displays information about all the wireless access points in range. It will display your signal strength, noise strength, signal to noise ratio, what channel your access point is on, if other access points are interfering with yours, and whether or not those access points are providing encrypted, unencrypted, computer-to-computer, or infrastructure type networks. |
|
| Name:CoWF/Warglue | Download:cowf-warglue-suite-1.0-full.tar.gz |
| Operating System: Windows | HomePage:http://sourceforge.net/projects/warglue |
| This is a multiplatform general utility suite for use with existing network stumbling software, such as Kismet or NetStumbler. The program will convert between multiple output logs, including the popular wi-scan format, between platforms. |
|
| Name:FakeAP | Download:fakeap-0[1].3.2.tar.gz |
| Operating System: Linux, BSD* | HomePage:http://www.blackalchemy.to/project/fakeap/ |
| Black Alchemy’s Fake AP generates thousands of counterfeit 802.11b access points. Hide in plain sight amongst Fake AP’s cacophony of beacon frames. As part of a honeypot or as an instrument of your site security plan, Fake AP confuses Wardrivers, NetStumblers, Script Kiddies, and other undesirables.* See HomePage for more information |
|
| Name:gpsd | Download:gpsd-2.34.tar.gz |
| Operating System: Linux, BSD | HomePage:http://gpsd.berlios.de/ |
| gpsd is a service daemon that monitors a GPS attached to a host computer through a serial or USB port, making its data on the location/course/velocity of the sensor available to be queried on TCP port 2947 of the host computer. With gpsd, multiple GPS client applications (such as navigational and wardriving software) can share access to a GPS without contention or loss of data. Also, gpsd responds to queries with a format that is substantially easier to parse than the NMEA 0183 emitted by most GPSes. The gpsd distribution includes a linkable C service library and a Python module that developers of gpsd-aware applications can use to encapsulate all communication with gpsd. |
|
| Name:iStumbler | Download: istumbler-98.tgz |
| Operating System: MacOS | HomePage:http://www.istumbler.net/ |
| iStumbler is a free, open source tool for finding AirPort networks, Bluetooth devices Bonjour services, and now GPS locations with your Mac. |
|
| Name:Kismet | Download:kismet-2007-01-R1b.tar.gz |
| Operating System: Linux, BSDs, MacOS, Windows |
HomePage:http://www.kismetwireless.net/ |
| Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system. Kismet will work with any wireless card which supports raw monitoring (rfmon) mode, and can sniff 802.11b, 802.11a, and 802.11g traffic.Kismet identifies networks by passively collecting packets and detecting standard named networks, detecting (and given time, decloaking) hidden networks, and infering the presence of nonbeaconing networks via data traffic. |
|
| Name:Radiate | Download:libradiate-beta-0.02.tar.gz |
| Operating System: Linux | HomePage:http://www.packetfactory.net/projects/libradiate/ |
| Radiate is a small C library designed read, build and write 802.11 frames. |
|
| Name:MacStumbler | Download:MacStumbler-075b.tgz |
| Operating System: MacOS | HomePage:http://www.macstumbler.com/ |
| MacStumbler is a utility to display information about nearby 802.11b and 802.11g wireless access points. It is mainly designed to be a tool to help find access points while traveling, or to diagnose wireless network problems. Additionally, MacStumbler can be used for “wardriving”, which involves co-ordinating with a GPS unit while traveling around to help produce a map of all access points in a given area. |
|
| Name:MiniStumbler | Download:ministumblerinstaller_0_4_0.exe |
| Operating System: Windows CE | HomePage:http://www.netstumbler.com/ |
| MiniStumbler is a tool for Windows CE that allows you to detect Wireless Local Area Networks (WLANs) using 802.11b, 802.11a and 802.11g. |
|
| Name:Mognet | Download:Mognet-1.16.tar.gz |
| Operating System: Linux | HomePage:http://www.node99.org/projects/mognet/ |
| Mognet is a simple, lightweight 802.11b sniffer written in Java and available under the GPL. It features real time capture output, support for all 802.11b generic and frame-specific headers, text mode capture for GUI-less devices, and loading/saving capture sessions in libpcap format. |
|
| Name:NetStumbler | Download:netstumblerinstaller_0_4_0.exe |
| Operating System: Windows | HomePage:http://www.netstumbler.com/ |
| NetStumbler is a tool for Windows that allows you to detect Wireless Local Area Networks (WLANs) using 802.11b, 802.11a and 802.11g. |
|
| Name:ssidsniff | Download:ssidsniff-0.42.tar.gz |
| Operating System: Linux | HomePage:http://www.bastard.net/~kos/wifi/ |
| A curses based tool that allows identification, classification and data capturing of wireless networks. The interface is inspired from the unix top(1) utility. |
|
| Name:wavemon | Download:wavemon-current.tar.gz |
| Operating System: Linux | HomePage:http://www.janmorgenstern.de/projects-software.html |
| wavemon is a ncurses-based monitoring application for wireless network devices. |
|
| Name:Wellenreiter | Download:Wellenreiter-v1.9.tar.gz |
| Operating System: Linux | HomePage:http://wellenreiter.sourceforge.net/ |
| Wellenreiter is a wireless network discovery and auditing tool. Prism2, Lucent, and Cisco based cards are supported. It is the easiest to use Linux scanning tool. No card configuration has to be done anymore. The whole look and feel is pretty self-explaining. It can discover networks (BSS/IBSS), and detects ESSID broadcasting or non-broadcasting networks and their WEP capabilities and the manufacturer automatically. DHCP and ARP traffic are decoded and displayed to give you further information about the networks. An ethereal/tcpdump-compatible dumpfile and an Application savefile will be automaticly created. Using a supported GPS device and the gpsd you can track the location of the discovered networks |
|
| Name:WepAttack | Download:WepAttack-0.1.3.tar.gz |
| Operating System: Linux | HomePage:http://wepattack.sourceforge.net/ |
| WepAttack is a WLAN open source Linux tool for breaking 802.11 WEP keys. This tool is based on an active dictionary attack that tests millions of words to find the right key. Only one packet is required to start an attack. |
|
| Name:WepLab | Download:weplab-0.1.5_win32.zip, weplab-0.1.5.tar.gz |
| Operating System: Linux, BSD, MacOS, Windows |
HomePage:http://weplab.sourceforge.net/ |
| WepLab is a tool designed to teach how WEP works, what different vulnerabilities it has, and how they can be used in practice to break a WEP protected wireless network. So far, WepLab more than a Wep Key Cracker, is a Wep Security Analyzer designed from an educational point of view. |
|
| Name:WEPWedgie | Download:wepwedgie-alpha-0.1.0.tar.gz |
| Operating System: Linux | HomePage:http://sourceforge.net/projects/wepwedgie/ |
| WEPWedgie is a toolkit for determining 802.11 WEP keystreams and injecting traffic with known keystreams. The toolkit also includes logic for firewall rule mapping, pingscanning, and portscanning via the injection channel and a cellular modem |
|
| Name:WiFiFoFum | Download:WiFiFoFumInstaller.msi |
| Operating System: Windows CE | HomePage:http://www.aspecto-software.com/WiFiFoFum/ |
| 802.11 scanner for PDA’s that run PocketPC. | |
| Name:WiFiScanner | Download:WifiScanner-1.0.2a.tar.gz |
| Operating System: Linux | HomePage:http://wifiscanner.sourceforge.net/ |
| WifiScanner is a tool that has been designed to discover wireless node (i.e access point and wireless clients). |
|
| Name:WiStumbler | Download:wistumbler-current.tar.gz |
| Operating System: NetBSD | HomePage:http://www.gongon.com/persons/iseki/wistumbler/ |
| Network stumbler for WaveLAN/IEEE wireless networking | |
| Name:wscan | Download:wscan1.00.tar.gz |
| Operating System: Linux, FreeBSD | HomePage:http://www.cs.pdx.edu/research/SMN/ |
| wscan is a X-11/visual 802.11 wireless signal-strength display tool. | |
