CarahCast: Podcasts on Technology in the Public Sector

Bastille Presents: The Wireless Threat Series Podcast, Wi-Fi Attacks

Episode Summary

Federal agencies and businesses face growing exposure to wireless threats as modern devices introduce new cybersecurity attack vectors that traditional security tools cannot detect or control. To mitigate consumer and enterprise risks associated with IoT devices in no-phone zones, Bastille Networks’ wireless intrusion detection system identifies and quarantines unauthorized emitters and behavioral abnormalities before data breaches can occur. Explore real-world examples of how Bastille’s IoT security solution proactively defends mission-critical environments from covert emissions, unapproved device behavior and Wi-Fi deauthentication attacks.

Episode Transcription

Anthony Jimenez

Welcome back to Carahcast, the podcast from Carahsoft, the trusted government IT solutions provider. Subscribe to get the latest technology updates in the public sector. I'm Anthony Jimenez, your host from the Carahsoft production team.

 

On behalf of Bastille, we would like to welcome you to today's podcast. We'll be joined by Bluetooth experts from the Defenders Initiative and Bastille as we understand how Wi-Fi security evolved from WP's early weaknesses to our modern WPA3 standards. Learn why password hygiene, network segmentation, and regular patching are still the best ways to defend against threats to Wi-Fi environments.

 

Adrian Sanabria

Welcome to the Wireless Threat Podcast Series, sponsored by Bastille Networks. I'm Adrian Sanabria, and joining me is John Bundy, as always. I'm excited to cover stuff here.

 

I typically learn stuff as we go through these, and I love the nostalgia of going through old attacks and old vulnerabilities and just filling in the gaps in my knowledge. In this podcast series, we explore a new class of device or threat in each episode. We did a series on Bluetooth, now we're doing a series on Wi-Fi, and as we go through these, we help you understand the threat, walk through some real-life scenarios, and even do the occasional live demo.

 

And ultimately, the goal is to answer the question, should you be worried about this? If you have any devices, threats, or attacks you want us to dissect in this podcast, please let us know in the comments. And this week, we're discussing Wi-Fi attacks.

 

Last week, we covered the basics of Wi-Fi, so we're not going to be covering the basics here as much. We will be covering some of the basics of how authentication works with Wi-Fi, but you should go back and listen to the previous one if you want to beef up on your knowledge of how Wi-Fi works, the history of Wi-Fi, stuff like that. But let's get started, John.

 

I think my first memory of, and I did have an 802.11 card. Not A, not B, just 802.11. It was a CableTron device was the brand of it.

 

Jon Bundy

Do you remember what access point you had?

 

Adrian Sanabria

Also CableTron.

 

 

Jon Bundy

Yeah. Because we did talk about the interoperability issues back then.

 

Adrian Sanabria

CableTron, PCMCIA talking to CableTron access point. Yep.

 

Jon Bundy

Wow. Sticking that slot, sticking out of the side of the laptop with that little bubble for the internet.

 

Adrian Sanabria

Yeah. So early days Wi-Fi, we talked about what the demand for it was. One of the big demands was retail.

 

So the Retail Alliance, or I forget the name of the organization, Wi-Fi Alliance.

 

Jon Bundy

NCR was one of the companies that was involved in the National Cash Register, I think.

 

Adrian Sanabria

Not only one of the first Wi-Fi attacks, but one of the first breaches that led to US government and others in the industry saying, Hey, maybe we should have some breach transparency. Maybe you should be required to notify people of breaches. And back then attackers were focused on stealing payment data, stealing credit card numbers, selling those credit card numbers or pulling as much cash as they could off them and laundering that money somehow.

 

And that put wireless security in the headlines in a big way.

 

Jon Bundy

Good old WEP. So that was the first security standard back in the first releases. Yeah.

 

WEP. So we don't use WEP anymore. We don't talk about WEP, right?

 

Adrian Sanabria

It was, I remember originally it took about 10 minutes. My early pen testing days back when WEP became known as incredibly flawed and easy to crack. And then I remember, I think the tool was Aircrack.

 

Somebody found a better way of doing it and got it down to like under 60 seconds. So it was, if you had the tool to do it, and if you had a laptop and you had the right network card, I think you needed a card you could put in promiscuous mode so you could collect those IVs. It was trivial with a laptop and maybe a hundred dollar card and the right piece of open source software.

 

You could hack any, pretty much any wireless network because there was nothing to upgrade to. Nothing to really patch. Like we had to replace the whole security part of the protocol.

 

Jon Bundy

Yeah. That's what we talked about last episode is WEP came around, you know, around 2000, 1999, 2001, it was just wrecked. Wi-Fi Alliance came into being, they said, Hey, we've got to address this.

 

Came out with WPA next, which came out in around 2002, 2003. From the last episode, do you remember there's authentication requests and responses, and then there's association requests and response. And we talked about how usually we use open system authentication for those first messages now.

 

But for WEP, they actually put the challenge and response right there. So right up front, you're just like, Hey, prove that you have the key. Both prove that they have the key and then they're like, all right, let's use that key and we'll encrypt stuff.

 

And they used what you mentioned in IV, an initialization vector. There's only like 16.7 million unique initialization vectors you use with that same key. Now that sounds like a lot to you and me, maybe, but for the computers, as you go through traffic, they start to get reused.

 

And when you reuse the same key for encryption, that's bad. That's how you start to leak and decrypt things. So that's what happened is you just got these initializations being reused and you can crack it.

 

And so what attackers did is they started going, well, what if I inject traffic and cause new initialization vectors to use faster and I can just speed this right up. That's what they did. Seconds later, you know, it's like gone in 60 seconds, they would have enough material to crack that.

 

And it's a short key. And they're like, once you have the key, you're in, you can decrypt everything. You can send messages and you can join that network and do whatever you want.

 

That's what happened in some of those first exploits, which I think you brought up a couple of good ones.

 

Adrian Sanabria

Yeah. So you classify this as brute force, maybe?

 

Jon Bundy

Yeah. At the end of the day, what they're trying to do is just brute force that key by having enough encrypted material with reused initialization vectors, where they can just start to figure out bits and pieces of it. There's two or three different methods that were used and they just refined it, got better.

 

But again, it's kind of like ancient history.

 

 

 

Adrian Sanabria

Yeah. We should mention the historical significance of WEP and there was a rash of attacks where Albert Gonzalez and his accomplices would just drive up U.S. Route 1 from Miami and just hack every retail company that they found along the way. So TJX is the one that everybody remembers him and some of his accomplices for hitting BJ's Wholesale Club, DSW, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, in addition to TJX, which had HomeGoods and TJ Maxx and a couple of brands of different stores there.

 

But millions and millions of stolen credit card numbers went through their fingers before they were... I think it took a couple of years for them to pick them up and put them in jail.

 

Jon Bundy

Yeah. And I think what's important about this is, you mentioned it, they were doing this for years. That was after these exploits were known.

 

So we knew in 2001, but this was happening, what, in 2005? Yeah. And it continued for a couple of years.

 

Yeah. WPA had come out. I think WPA2 had come out.

 

And so that's just kind of negligence at that point. Always patch your stuff.

 

Adrian Sanabria

Yeah. I mean, early days, I think the only breaches that ever hit headlines were website defacements before then. We didn't really see large scale corporate breaches, data breaches, attacks that were financially motivated, that we could really call, like, this is cybercrime moving into the digital age.

 

This was the very beginning of that. So I don't think there were any big lessons that I can recall from before this incident that would have really telegraphed to retail companies that, hey, you got to upgrade your stuff. You got to stay on top of broken encryption, broken security controls, and fix it in a timely manner.

 

I think this was that big lesson for so many companies. Yeah. And in fact, should have been the wake up call for Target in investigating the Target breach.

 

It was found that they were well aware of the risks to their POS devices before that attack began. And the investigation even told us, like, seven people had gone to this website describing these POS attacks, and they didn't do anything about it, like six or seven months before the attack occurred. And they could have segmented, they could have configured it in a more secure way.

 

I think there were a number of failed lessons learned there. So we continue to see a failure to act and to update systems and to address these threats even a decade later. Yeah, moving on.

 

So you said WPA we had as early as 2003, and I don't think WPA1 stuck around real long, did it? We got WPA2 pretty quickly, because there are also issues, right?

 

Jon Bundy

Yeah, there's a draft spec, the 802.11i spec, I believe, that the Wi-Fi Alliance used to come up with WPA, and they had to compromise it a little bit because they wanted to rush it out and make it work on the hardware that was already out there that supported WEP. So they made some decisions and they used a special message integrity check, a MIC, that was known to be weak. It had the limited size of the cryptographic material due to the hardware.

 

And there's some cool things about this is if the access point detected two bad MICs, message integrity checks, again, within a minute, it would shut down for a minute. And so what do you do the first thing you see that? You send some bad MICs to it, some data with bad MICs, and the AP shuts down and you have an immediate denial of service.

 

So then after that, researchers decided they found that they could do some other attacks where they modify bytes at a time, this chop attack, and they can recover the key stream and all this and that. And I think we should compare and contrast a little bit WEP to going to WPA and above. So we saw WEP here in the picture, what it looks like.

 

Let's go and look at what the future held, which is what we have now. And there's three security modes now. So before there was WEP and Open, now there's Open, Personal, and Enterprise Network.

 

So when I say Enterprise Network, I don't mean the network at the corporation. I mean, it's a certain flavor secured. And Personal, the same thing.

 

So Personal means there's a pre-shared key, everybody has the same key. Enterprise means every user probably has a unique method to authenticate and get a unique key. So it's a little more robust in that way, you can add and remove users.

 

And Open means you don't need any passwords or keys, you can just connect. So all of these networks currently, all these three different security modes, from WPA to WPA2 to WPA3, all use kind of the same format. Now there's this diagram, and again, to compare and contrast the difference between WEP here, we have this authentication request response, association request response, and you go, you've got a key, you both know the key.

 

This one, they're included the discovery part, and then you find your network, and then you do the open system authentication that says, I want to talk, and then you do an association. And then there's some things that can happen there, like in the open encrypted network, you can do a little key exchange and get your PMK, your pre-shared master key. If you're doing an enterprise network, you do 802.1X authentication, and end with that PMK, the pre-shared master key. And if it's a personal network, you have already derived the pre-shared master key. So these kind of creamy, tan-ish blocks are just different ways to get a pre-shared master key, which is the entry point, the purple, the four-way handshake, which is what drives all your keys. Every network uses this today, if they're using encryption, that's where you get your pairwise training key, I believe it's called, the group temporal key.

 

But you have a key that's between you, the client, and the AP, when you're talking to each other, and then you have a group key for when the access point needs to send a message to everybody, but have it encrypted.

 

Adrian Sanabria

And I should mention, if you're listening to this and not watching the video version, we do have a diagram up on the screen, so you can see how the authentication process works here for personal and enterprise, for WPA. Something else, John, before we jump into some of the next stage of attacks that we saw, I should mention, when some of these different protocols were broken, we did see people start to try to implement some mitigations that were not based on improving the actual Wi-Fi encryption or authentication. I remember starting to see people hide the SSIDs, which was trivial to find, because to be able to talk to these wireless access points, you still needed to talk over the air so you can see the packets.

 

So, for any hacker with a wireless hacking tool, you could easily see, it would just call it hidden, so it was kind of trivial to see. And then, trying to create a MAC access control list, right? Like, only these MAC addresses of my computers at my business are allowed to access the wireless network, which was, again, pretty easy to take advantage of, because you could still see it, the MAC addresses flying around.

 

You could capture the packets, and you could say, I'm going to steal this computer's MAC address. And now you were that computer, because MAC addresses, pretty much every operating system back then, you could just customize your MAC address and now be that authorized computer. It would cause some issues for data delivery, but if you were clever about it, you could choose something that would come online and go offline, you know, so you could borrow its MAC address when it wasn't present.

 

If it was a laptop and somebody wasn't there that day or something like that, if you were patient, you could do it pretty smoothly.

 

Jon Bundy

Yeah, and both of those are kind of trivial, like you said, to bypass. The hidden SSID, I think, if anyone's ever read about it, you almost always see something that says, don't bother using this. It's security by obfuscation, and it's barely obscured as it is.

 

If we go back to that picture, you can kind of see why. So, access points send out beacons to be discovered about 10 per second. If it's a hidden SSID, they just don't include their name, but they're still beaconing, so you know it's there.

 

And then when there's a probe request, there can be two types. There can be a broadcast probe request, which just says, hey, anybody out there, any networks out there, please respond, and then all of them should respond. But hidden networks go, not so fast, I'm hidden, I won't respond.

 

But then there's a directed probe response where you go, I know exactly what network I want to talk to, and I only want this network to respond if you're out there, and you ask for that network by name. Which is the hidden SSID in here.

 

Adrian Sanabria

And I can see that.

 

Jon Bundy

Everybody can see that. So, you have to do that in order to find it to connect. So, at some point, if a client connects to that hidden SSID and somebody is sniffing the wireless traffic, they'll just see it.

 

And then, like you said, you can steal MAC addresses all day, and if there's an allow list by MAC address, you just say, well, I'll just use this MAC address. If the client's gone, you're free to go. If the client's there, well, then you're both kind of competing for the traffic.

 

You might have to do other things, but it's no defense. Hidden access points, hidden SSIDs, not great. So, where do we get to?

 

We talked about WPA and how that has some flaws with the NIC and there's some attacks. Then they came out with WPA2, right? In 2004, when that draft 802.11i specification was completed, and we moved on to something better, which has serviced well until just a few years ago when we moved to WPA3. What are some other attacks that happened in this time frame? One of my favorite ones was Karma and Mana attacks. These allow an attacker to entice you to join the attacker's evil twin.

 

So, what's an evil twin? It's just an access point that looks like somebody else's twin. It looks like a good access point, but it's evil because the attacker's controlling it.

 

They want to do things to you. So far, we've talked about attacking the encryption and breaking in that way. This is a different approach.

 

Instead of attacking the encryption, which has gotten better now in WPA2, why don't we just get clients to connect to us? This started back in 2004 with something called Karma. We saw how, in discovery, there's these directed pull requests where a client says, hey, network, are you there?

 

Network A, we'll call it. So, Karma just said, hey, what if I just say I'm Network A, will that work? So, the attacker says, yeah, I'm Network A.

 

What do you know? It worked. The client, back in those days, everybody was so trusting.

 

It was an open network. Well, I'm looking for you. So, clearly, I want to connect to you.

 

So, let's just connect. The attacker's like, cool. Come on in.

 

There you go. Now, you just enticed a client that was looking for maybe a network that's not even in the area because you heard that client was looking for that network. You just said you're that network, and the client connected to that network.

 

It was called the preferred network list. You might have heard that. But your devices build up a list of SSIDs that they would like to connect to you.

 

That's called their preferred network list. Back in the day, when things were safer or they didn't know about the dangers, they would just shout out, hey, Network A, are you there? Network B, are you there?

 

Network C, are you there? Because I'd like to connect to anybody there. And they would just go through their network list.

 

And all you had to do is listen. You're like, hey, that device wants to connect to this network. I'll just say I'm that network.

 

Boom, Karma. And then they connected. Away you go.

 

Adrian Sanabria

It's super easy with a tool like Kismet or something like that to just sit and collect what everybody's trying to connect to. I don't recall Wi-Fi being front and center in any other big breaches. I think WEP kind of made everybody overprotective at that point.

 

And attackers kind of went a different route from then on. The most likely place you were to see Wi-Fi attacks were at security conferences. If you went to DEF CON or something like that.

 

Jon Bundy

But this led then to an interesting kind of arms race between the vendors and the attackers. After Karma, vendors said, you know, maybe we shouldn't just trust anybody that says they're the network that they say they are. Maybe we should look for proof that the network actually existed via a beacon or a broadcast response.

 

If I send out a broadcast response and I don't see network A answer, but then I look for network A and it answers, that's suspicious. So they started doing that. And then in 2014, MANA came out and they said, well, eventually you're going to look for that network and connect to it.

 

And I'm just going to build up a list of all the networks that you like to connect to per client. And then when that client does a broadcast probe request, I know all of the networks that it's been looking for at some point. I'll just answer back with all of them.

 

So now I target each client with a personalized response to prove that the network already exists. Look, here's a broadcast response. I'm here.

 

And maybe I'll throw out some beacons too. This network's been here. It's always been here.

 

And then the client would do its normal directed probe request and it carried on just like that. So MANA just expanded it by tracking clients, looking for what they were looking for and responding back with a little more supporting evidence. Then vendors said, well, I don't like that they're building this preferred network list of what I like to look for.

 

So I'm going to randomize my MAC requests when I start asking for directed probes. So that you can't tell which device is looking for which network. And that way you can't target me with this.

 

Then they came up with Loudman and they said, you know what? I'll just beacon out everything I hear. If I see anybody looking for anything, I'll just beacon it out.

 

If I see an IoT device looking for a network, I figure, hey, maybe you're also looking for that network because you guys might have similar profiles and you like the same networks. So that IoT device isn't being very protective of its preferred network list. It's labbing.

 

I'll just use them all and I'll beacon them all. I'll do probe responses for all of them. And then anytime anybody asks for it, I'll just beacon everybody.

 

It's called Loudman. Very easy to detect. So now what happened?

 

WIDS was like, hey, that one MAC address sure is sending out a lot of different beacons for different networks and different probe responses. That's weird. And so that's the counter.

 

It's a red flag. I guess it's a red flag.

 

Adrian Sanabria

Yeah.

 

Jon Bundy

Finally, the culmination of this was attackers said, well, what if I just send out known beacons? There's a bunch of networks across the globe that have the same names, like your AT&T has got open Wi-Fi here in the airport to Starbucks. What if I just send those out and see if anybody is game?

 

Or if I do some recon and I know where you are and what you like to connect to, or if I know you like to connect to this corporate network and I know you're somewhere else, what if I just put that corporate network up and see if I can get you to connect? Because it is on your preferred network list and you might just automatically connect. So these are all just ways to get users to connect to the Eagle Twin and then you can do things.

 

Adrian Sanabria

Yeah. You saw that less and less 2015 and on, but still more than a decade after everybody knew it was no longer safe to use. You still saw a good amount of it out there.

 

Jon Bundy

So a few years after the last WPA attacks, there's some WPA2 attacks. In particular on the pre-shared key, the personal network. So there's some PSK cracking going on.

 

Why does that happen? Well, you have to understand the four-way handshake a little bit, which is in the picture. And so what we did is we blew up the four-way handshake.

 

There's four messages in it. That's why it's a four-way handshake. All they're trying to do is prove that they both know that PMK, the pre-shared master key.

 

So we said, you have to start the process with the pre-shared master key. In the case of personal networks for WPA and WPA2, that pre-shared master key was computed from the passphrase and the name of the SSID. Because both the client and the access point know that, they both can calculate the PMK uniquely, individually, without sharing it over the air, just by knowing the password and the name of the SSID.

 

So that's what they do. Now they both have this PMK. They have to prove that they do, which proves that they both know the password.

 

And so all they do is they send some challenges with some random numbers and use that PMK to come up with answers. And once they're both satisfied, the access point says, cool. And it gives you that group temporal key and the pairwise transient key back to the client so that they can start encryption.

 

And that's how it works. So what's so bad about that? What's bad about it is you can see all of these messages.

 

You can see the two random numbers called anons and snons for the authenticator and supplicant. Those are just numbers used once is what non stands for. It's a cryptographic principle.

 

It's a random number, two different random numbers. And they use that along with the shared master key to come up with some, run it through some algorithms and come up with these keys. The thing is you can also guess a password, hash it with the SSID, run it through the same algorithms and see if you get the same result that was passed by.

 

If you guess, yeah, you have just guessed the password. And well, who's going to guess it? Well, we can guess with computers, lots of things really quickly.

 

And humans are not awesome at making passwords. So very often if there's a password involved, the password, one, two, three, four, five, six, there's lists of passwords that have been leaked. And so you would just start by testing those.

 

Adrian Sanabria

One of the most common. Yeah. And in fact, rainbow tables were a thing.

 

The idea that I'm, you know, for very common things that I know I'm going to encounter, like if I want to hit Starbucks or something like that, very common SSIDs, I can pre-compute all the possible passwords within a given character set and range. And now I'm not cracking passwords. I'm doing a database lookup.

 

Jon Bundy

Those exist online still. And so someone said, well, what if we just calculate a bunch of dictionary words using Linksys as the salt? And then all you have to do is, like you said, just look it up.

 

They used to sell disks full of these, like eight terabytes of these hashes already pre-computed. So you don't have to run the algorithm for the four-way handshake. You just look up and see if that hash is there that was the PMK.

 

Adrian Sanabria

So different variations of that. Or like you said, you could go to a hacking conference and somebody be selling them on hard drives or, you know, burn DVDs and stuff like that.

 

Jon Bundy

Yeah. So that made it a lot faster just to do the lookup instead of having to calculate and see if there's matches.

 

Adrian Sanabria

And John, a question here. I know at some point in the spec, they said, okay, you can't use the SSID as part of the password or as part of the shared key, right? I'm not sure exactly when that happened, but I suspect it came out of the ease of brute forcing here.

 

Jon Bundy

Probably. Yeah. I don't remember that either.

 

I haven't tried ever to do that. I don't know if it was ever allowed.

 

Adrian Sanabria

Yes. This point that I have tested on, it will not let you use the SSID in the name of the key in WPA2 personal.

 

Jon Bundy

Well, good for that. At least that's one small step forward.

 

Adrian Sanabria

Also, at the same time they did that, they made the minimum characters 12.

 

Jon Bundy

It's 8 to 63 is the limit. But is this vulnerable? Well, yeah, if you use something in a dictionary and someone sniffs this, it's easy to crack.

 

The takeaway here is don't use a simple password on your PSP networks. Make it a little more complex, just like they always advise you. You don't have the capital letters, the symbols, the numbers, but don't use a dictionary word.

 

Adrian Sanabria

So you want to talk a little bit about WPS pin? Yeah.

 

 

 

Jon Bundy

So at some point, the Wi-Fi Alliance said, you know, entering passwords is kind of a drag. What if we made it easier? We see where this is going.

 

In 2011, it was discovered. So first, the Wi-Fi Alliance said, let's make it easier. And they came up with Wi-Fi Protected Setup, WPS.

 

And that was simply a way to not use a password. You can go to your new device, hit a button, go to your access point, hit a button, and they would kind of see each other. And you'd say, yeah, that's the one.

 

No password involved. Or maybe you'd have to enter a pin that was on your access point. So you could have a pin or they could do out of band, which nobody ever uses.

 

Well, WPS had pins and it's cool, right? It's eight digits. You could look it up.

 

It's on the access point. And so all you have to do is just kind of know that number. It's only eight instead of maybe your long, fancy password that's hard to type in.

 

Adrian Sanabria

Eventually, we saw other stuff like QR code. Like maybe I don't want them to know the password, but I want them to be able to connect to it. Which, I mean, they can still go in their device and show the password.

 

So you could use NFC, has a record type specifically for setting up Wi-Fi, as well as QR codes. You can, most operating systems support that where you can just scan a QR code and join it.

 

Jon Bundy

This WPS pin boot forcing was really neat because at first glance, you're like, hey, they're using an eight digit pin. That's awesome. That's a lot of digits.

 

Should be a hundred million combinations. A hundred million. Okay.

 

That would take a long time to guess. But for whatever reason, the spec said, here's what we're going to do. We're just going to check the first four digits as a group.

 

We'll do an eight-way handshake. First, we're going to check the first four and we'll let you know if it's okay before we continue. So four digits only has 10K to check.

 

So this, they very nicely said, okay, once you get the first four, right, you'll know and we'll continue to the last four. So you figured 10,000 more, right? No.

 

The last digit is now a checksum. So now you only have four digits to check. A thousand more to go.

 

So they took a possible address space of a hundred million different unique pins and turned it into something where you only have to check a maximum of 11,000. And did they rate limit those checks always? No.

 

So you could usually rip through this with tools like Bully and Reaver and not only that. Then there was another one where there was a flawed random number implementation that was known on some of these generations. And so you could use that to your advantage.

 

That went away eventually. I think it's been replaced with something like Wi-Fi direct setup or protect. WFA came up with a new technique to kind of simulate the same convenience.

 

Wi-Fi Easy Connect, in fact, is what the replacement is called. That came out in 2018. I don't know if there's any exploits against that yet.

 

The problem with these speculators, there's always something weird that you just don't consider that this one just seems bad even without an expert. That was WPS. So that was a fun one because I found it.

 

I tried it. And a few minutes later, you've got the pin. You're on the network.

 

Adrian Sanabria

Yeah. Yeah. So what else do we have left here now?

 

Jon Bundy

So the big one in 2017, Crack. Key reinstallation attack. This was an attack on that state machine.

 

Message three. So the four-way handshake. That's where the group temporal key gets installed.

 

And the client installs the transient key that it's derived. But it turns out, per the spec, you could just keep resending that message three. And every time the client gets it, it reinstalls the key.

 

But it also resets counters, replay counters, which are supposed to be used one time. Oh, no. So if you can send this message after the client sent some traffic and you've collected it, then you just send message three again.

 

And the client goes, oh, better reinstall that key and reset my counters back to where they were. And then it starts sending traffic again with the same counters. Now you can do replay attacks.

 

I believe you could do injections. You could forge some packets, depending on which mode of encryption was used. It was pretty tricky, a little academic.

 

Definitely an attack. It's just one of those things overlooked in the spec where nobody said, hey, what happens if message three is sent later? And the default was, well, when you get message three, you reinstall the key.

 

You install the key and set the counters. So the clients all did that.

 

Adrian Sanabria

It was patched. It sounds like most of the major attacks that we're talking about are things that were possible across all devices, all implementations. So most of the really critical bugs here were in the spec itself or the protocol itself, right?

 

Jon Bundy

Yeah. In crack, for example, Android would handle that message three differently, and they might reinstall all zero key, which is not great. It really made it easy.

 

So that was kind of, depending on the stack, things behave differently. Tell me about OPCW. Yeah.

 

Wow. Organization for the Prohibition of Chemical Weapons. Hack attack by the GRU.

 

So in 2018, this group of Russian spies, there was an investigation on a poisoning in the UK, and Russia wanted to disrupt these meetings. So they sent their best and brightest over to the Netherlands, I believe, to try to do some Wi-Fi attacks, and they were tracked and caught. This is one example of someone trying to do some Wi-Fi hacks.

 

Just all the stuff they had in their truck, their car, they had patch antennas, they had 4G. So it's just like a drive-by attack. They're just parked outside, trying to get within Wi-Fi range, and either steal credentials, try to get on the network so that they could disrupt the investigation.

 

It's interesting, mostly because it's one of the few ones where they have this full investigation released. The whole thing is just totally uncovered. Another one that we've heard about but never really learned more was a drone attack on a FinTech.

 

They flew in a Wi-Fi pineapple. It's like, we talked about evil twins earlier. This is a hardware device.

 

It's an access point that is meant to just act as evil twins, and it implements all of those karma and mana attacks to try to get people to connect and become a machine in the middle to get those clients' information. Collected data, and eventually they were able to relay through that, probably through a cellular modem to another Raspberry Pi or some small computer, once they had some credentials, and connect to the network and attack it that way. That was one.

 

Adrian Sanabria

Another thing I want to mention that I should have mentioned earlier, but I just now remembered this. In the early days of network security or wireless security tooling, I think it was Cisco that did this. Don't come at me if I'm wrong on this, but they installed a wireless defense system at a business across the street from Wall Street in New York City.

 

It basically just deauthed anything that wasn't intended for its networks or its trusted clients. When they deployed it, it effectively functioned as a wireless jammer, and it took down all the wireless networks across the street at Wall Street. Caused a big kerfuffle.

 

FCC got involved and said, yeah, you're not allowed to do that. That is now illegal. They changed the rules to where- Keep it to your own network.

 

Yeah. Yeah.

 

Jon Bundy

We talked about the deauth attacks last time.

 

Adrian Sanabria

Yeah, we were talking about mitigations. We can't protect the authentication piece. What else can we do to keep people away from our networks?

 

I think that was one of the things we saw tried early on that was just so disruptive.

 

Jon Bundy

So another attack, let's hop back to attacks. The PMK ID attack. PMK, pre-shared master key ID.

 

So it's a hash of your PMK ID. And so at some point in the spec in 2004, they said, hey, what if we just kind of use this hash of the pre-shared master key as an index? And that way we can check when a device is roaming, if you guys have the same index, you can prove it, then we already know the PMK, they have it.

 

You don't have to go through this expensive PMK derivation process that's used on the enterprise network. With personal networks, the PMK comes from a password and an SSID. It's pretty quick to calculate.

 

It doesn't take much time. But for enterprise networks, it can take up to like a half a second to go through all of that authentication back and forth. And if you're on a call and you're roaming, do you want a half second of delay?

 

They said, well, what if we could prove that this client has a PMK already? And if we share that information over with the other AP, but we don't want to put the PMK over the air because that's secret stuff. But we make a hash of it on the ID and go, hey, do you have this ID?

 

Yeah, I've got that ID. OK, I'm trusting you. If you do, we're going to use that PMK and then we're going to go through the four-way handshake real quick, come up with some new keys, and we'll talk.

 

And it won't take so long because you don't have to go back to the RADIUS server and go through all that authentication to get a new PMK. That's what a PMK ID is. The beauty of this was in the spec, they said, well, you should share it in the first message.

 

You don't need this if you're not roaming. Consumer routers just started putting it out in the first message. No roaming involved.

 

They just said, here's a PMK ID. After 14 years, someone said, hey, that's not a crypto material. It's a hash of a secret, which means we can guess what the secret was for pre-shared network.

 

Remember, go back, guess the password. We know the SSID. Yes, derive the PMK.

 

Now there's another algorithm that derives the PMK ID from that. You do that, and if you get the right PMK ID, you just guess the password. So you don't even have to wait for clients.

 

The thing with the four-way handshake was you needed clients to go through it, and you needed to collect some information. You go, oh, I've got all the information. Now, in the very first message, the access point says, here's the PMK ID that we're using.

 

If you can guess what got here, you just guess the password. And it's all because the product just said, do it.

 

Adrian Sanabria

There's a long history of people even using hard-coded keys and passwords from specs that were given as examples, but they just literally put it in there. And yeah, somebody just wasn't thinking or didn't understand the spec when they did this because no consumer router I've ever seen, at least standalone routers, supports roaming because there's nowhere to roam to.

 

Jon Bundy

Where are you going to roam? Now, again, before that, the PMK was used also for caching. So if you came and you reconnected back to the same router, we don't have to derive the PMK.

 

Again, for a personal network, deriving the PMK is instant. It's really to avoid the expense of doing enterprise authentication again. And so if you had an enterprise access point that could cache the PMK ID, and then when somebody joins, the way it's supposed to work is the client says, I've already got a PMK.

 

It's valid because we generated it earlier. You might not remember, but here's the ID of it. See if you've got that ID.

 

And if the access point says, yeah, I do, then they can skip that authentication, the expensive authentication, the 802.1 authenticate, right to using the PMK. That's where you save time. But the way it was implemented is the vendor said it goes in the first message.

 

It goes in this robust, secure networking information elements. It's easy to calculate. No problems.

 

Got it. And they put it there for 14 years. So I have an access point that does it.

 

I verified it was there. I was like, holy smokes. There it is.

 

Adrian Sanabria

We should cover one more thing here. I know DragonBlood is kind of theoretical.

 

Jon Bundy

So DragonBlood, it was, again, where the researchers looked at the WPA spec that's out there in the open. They said, hey, there's a vulnerability. They published it anyways.

 

And then the research demonstrated these side channel attacks that are very academical. But I think they're getting patched. AirSnitch, there's a new one here that kind of bypasses Wi-Fi client isolation.

 

This is from last year. When you're connected to an access point, you can't just send traffic over to your other partners that are on that same access point. You're isolated.

 

Adrian Sanabria

And this is a big deal because this is what made using public Wi-Fi networks and coffee shop networks. What made them relatively safe is they almost always have client isolation enabled, which means you can't see your neighbor's traffic. You can't see their machine.

 

You can't scan it. You can't touch it. You can't do anything to it.

 

So if client isolation is broken, it's kind of a big deal because now we have to change our advice that we get.

 

Jon Bundy

You have to change your security posture again. And so what happened? They tested a few devices.

 

Each of them had certain violations. So it goes back to did the vendors implement things right? Each one did things a little differently.

 

And sometimes you can broadcast like a group message. Remember we said the access point can send a group message using that GTK? What if a client sends it?

 

Some access points are cool. And clients are like, cool. And you're like, whoa, you shouldn't be able to do that.

 

So that's AirSnitch. I think if you were going to talk about one, it would probably be nearest neighbor.

 

Adrian Sanabria

Whoever did the attribution said it was Russia that did this. Yeah, but so this was discovered during an investigation where they're having trouble figuring out where the attackers got in. And what happened was the attackers had working passwords.

 

Somehow they knew the passwords worked. But everywhere they tried to use these passwords, where they tried cred stuffing, logging into their OWA, their email, whatever login interfaces, VPN that they had exposed to the public internet, they couldn't get it. They couldn't get past the second factor, the MFA.

 

So somebody in this hacking group had the bright idea that, hey, I bet their Wi-Fi authentication, which is probably hooked to single sign-on, is probably connected to the corporate usernames and passwords. I bet it doesn't have MFA. And they're like, well, what are you going to do if you're in St. Petersburg and your target is in Washington, DC, right?

 

You're a little out of range of that wireless network.

 

Jon Bundy

Yeah, they make good antennas, but not that good.

 

 

 

Adrian Sanabria

Yeah. Curvature of the earth becomes an issue at that distance. Yeah.

 

So what they did is they're like, hey, what if we borrowed somebody else's Wi-Fi clients? So they basically tried to hack the neighbors. You know, go to Google Maps.

 

What are the names of these businesses that are within wireless range of our target? And they hacked not one, but two of them. Two of these neighbors, and that's why we call it the nearest neighbor attack.

 

Basically, they just had to find a device that was plugged in via Ethernet. So the Wi-Fi adapter was free. So think a laptop in a docking station that has Ethernet or something like that, or maybe even a desktop that has both Wi-Fi and Ethernet.

 

And it worked. They were able to use the wireless client on a PC on another business's computer that's just right across the street, line of sight through the window to the access point of their target. No MFA needed, got in through the wireless network, and we're hacking this company.

 

And it took them a long time to find it, the company investigating this attack, because the wireless network, there was no logging enabled on it. The logging didn't go into the SIM. They said, what are these IP addresses?

 

Oh, those are IP addresses from the Wi-Fi clients. And they had to turn on logging. They had to let the hacking activity continue so they could figure out what was going on and eventually determined, oh, OK, yeah, for all the way from Russia, these attackers hacked your neighbors and got into your wireless network that way with stolen credentials.

 

This is not a Wi-Fi hack per se, but it is a threat vector that we now have to consider because it's happened once in a high-profile case. Again, worth bringing up because we do have to consider attacks that our penetration testers can't do because it's unethical. So there's a category of attacks they can demonstrate, and they say, yeah, you're vulnerable to this, and the ones that they can't because it's not ethical to hack the businesses around the company.

 

Jon Bundy

But what's interesting to me was this is obviously a very targeted attack because it continued after the first one was discovered. They did it again, and they got in again, which is the crazy part. It was just three or four years ago.

 

Adrian Sanabria

Any thoughts on connecting to public Wi-Fi? Yeah, I kind of... Should we tell our employees not to do it?

 

Jon Bundy

I put it personally in two different pockets. One is the Wi-Fi itself safe. Well, it's usually open.

 

You're kind of client isolated. People can sniff it. But like you said, usually TLS.

 

But then there's the second part is the back end. You should treat it as a hostile network. You don't know what's happening to that traffic.

 

That's still encrypted, but you don't know where it goes. So is it really bad? No.

 

If you have a super sensitive device, would you put it on there? What's next? You can always throw a VPN in on top of that, too.

 

But there are these concepts of harvest. And I'm not saying Starbucks is doing this, but harvest now, decrypt later, right? When quantum comes about.

 

Adrian Sanabria

And the number of security controls that would have to be perfected for anybody to go to those links to want to save petabytes of traffic and decrypt one RSA key at a time with a quantum computer. That is not the easiest way to get what you're after. That is literally the hardest imaginable way of doing it.

 

There are a thousand other things you should be securing and worrying about before you get to that.

 

 

Jon Bundy

Yes. So again, like I said, if it's a super sensitive device, maybe don't do it. But in general, is anything bad going to happen?

 

Probably not.

 

Adrian Sanabria

Cracking Wi-Fi passwords is next here, which I think we covered pretty well. But it's worth calling out the main difference between personal and enterprise here.

 

Jon Bundy

So WEP is a 60-second crack. You can recover the original passphrase or password. WPA and WPA2 are susceptible personal.

 

There's three security modes. There's open. There's personal networks, which use a pre-shared key.

 

And then there's enterprise security modes, which use some sort of 802.1X authentication. Usually a certificate that would get installed in your laptop. But for the personal ones, because that passphrase is part of the PMK generation process, it goes through that four-way handshake.

 

It can be collected, and you can try to crack that. WPA2 can be attacked with a dictionary attack pretty quickly. So if you use a dictionary word, it's not that hard to recover.

 

If you use a good, strong password that's not in a dictionary, then you could brute force it, but it would take a very long time to ever recover it. And the reason why the enterprise networks are so much more secure is because they do make this random PMK. It's 32 bytes of just random.

 

You could try to brute force and get it, but it would take a super long time to get. WPA3, a little bit different. These elliptical curve that we held in public.

 

Key exchange up front to come up with the PMK. It's a little more secure that way. And the enhanced open also uses encryption.

 

And that one's got the same key exchange. The biggest concern I guess I would say is WPA, which hopefully you're not using in WPA2 networks. If you're using transition networks, which means you're using WPA2 and WPA3, you're really only using WPA2 because you can downgrade people to that.

 

And then you're only as good as your password. So I'd say the big concern for me is dictionary words being used in a pre-shared key network, a personal network, which again, hopefully businesses aren't using a lot of pre-shared key networks.

 

 

 

 

Adrian Sanabria

Yeah, hopefully not. Smaller ones almost certainly are. But yeah, once you get up to enterprise level, probably should not.

 

And then the last question, John, would you bring a burner? Would you bring only burner devices to DEF CON or would you bring your own devices?

 

Jon Bundy

Not only will I bring my own devices, I will bring my business devices.

 

Adrian Sanabria

I'm bringing my own devices, but with the caveat that I will change my behavior. When I'm at DEF CON, I might disable some radios. I might use a hotspot on my phone rather than connect to whatever Wi-Fi is around me.

 

It's not quite as wild west as it used to be, but there's more people than ever. And all it takes is a handful of people or one person to decide to try out some attacks in public to be a nuisance. But I think it's more nuisance type stuff that go on there rather than anybody really getting their stuff hacked or anything really damaging.

 

Jon Bundy

Worst I can think of is the BLE spam came out at DEF CON. But again, being on their secure network, be careful at the hotels. It's pretty easy to set up an evil twin there and maybe use a VPN.

 

But yeah, I'm going to bring my devices and use them. But what about other places like out of the US? I guess that depends on where you're going, what the country is like.

 

And you can treat it as hostile if you want. And it comes back to your personal risk. Should you take your business devices and connect to networks in China?

 

Sure, if you want to give up all your stuff, I guess.

 

Adrian Sanabria

I would expect that. You end up having to talk about like, do you even bring that device with you? It's hard to just talk about Wi-Fi.

 

Now we're talking about the security, the whole device and the data on it. That's a slippery slope we have to start talking about. Do you bring a burner?

 

How do you protect the data on that device? I mean, it's possible you go to a country like China that has some real hacking skills. Maybe they have some zero days you don't know about.

 

 

 

 

Jon Bundy

They could target your phone over cellular or Wi-Fi. So just take that into consideration, your risk profile, where you're going. I'm sure your company has guidance.

 

Adrian Sanabria

All right. So for me, setting up Wi-Fi securely and correctly, it's kind of like a 7 or 8 out of 10. I think both personally and on the enterprise side.

 

But we've seen a lot of attacks over the years that will absolutely take advantage of a misconfigured network. I think you're only saving grace here, as with all wireless attacks, is there is a proximity component of it, unless you use the nearest neighbor.

 

Jon Bundy

Send the drones. Right. I think you hit the nail on the head.

 

There are a lot of attacks. A lot of them are theoretical and academic. I'd say by far the biggest trouble you'll get into is misconfigured networks.

 

And by that, I mean a simple shared password that's on a yellow sticky. Open networks with improper network segmentation that isn't Wi-Fi anymore. Things like that.

 

I think those are probably the things you should be concerned about. Logging, like you said. Maybe you should log the Wi-Fi network because it's an important part of business nowadays.

 

I would say it's a risk and you should configure correctly. Keep your devices patched up. Make sure your network segmentation is the way you expect it to be.

 

I guess I wouldn't worry too much about a lot of the vulnerabilities. Be aware of them and just keep things patched.

 

Adrian Sanabria

Wi-Fi has almost 30 years of scar tissue and improvements to security. I think we can call it mature at this point. Upgrade your stuff every now and then.

 

Don't be cheap.

 

Jon Bundy

It's pretty good about WPA3 and where we're going. But having said that, let's check back in a few years and see what they say about it.

 

Adrian Sanabria

All right. With that, let's wrap the episode. Thank you so much, Jon, for joining me.

 

I learned a lot of very interesting attacks against Wi-Fi over the years. Next, we're going to do some demos. Thanks to Bastille for sponsoring this series.

 

You can check out bastille.net forward slash blog for more information on wireless threats. Don't forget to leave a comment with what you'd like to see us discuss next. See you next time.

 

All right. Bye.

 

Anthony Jimenez

Thanks for listening. Thank you to our guests, John Bundy and Adrian Sanabria. Don't forget to like, comment, and subscribe to Carahcast.

 

And be sure to listen to our other discussions. If you'd like more information on how Bastille can assist your organization, please visit www.carahsoft.com or email us at bastille at carahsoft.com. Have a great day.