[00:00.440 --> 00:06.420] So I'm Dragorn, I did Kismet and I'm in charge of the Wi-Fi network here at HOPE and etc. [00:07.520 --> 00:14.380] And I'm RenderMan and I spend a lot of time using the tools that he makes to do bad things to good people and all that fun stuff. [00:15.360 --> 00:15.880] I love you! [00:18.340 --> 00:19.060] Nice to be alive. [00:20.420 --> 00:24.500] All right, so we're going to start with a quick overview of 802.11 networks for the people who still aren't familiar with them. [00:24.880 --> 00:26.900] Talk about how APs are defended already. [00:26.900 --> 00:38.780] Basic vulnerabilities in 802.11 and then we'll turn little vulnerabilities into network spoofing, client hijacking, messing with layer 7 and arguably layer 8 when you break people. [00:41.160 --> 00:43.080] Directly from layer 2, which is really fun. [00:43.260 --> 00:45.600] Advanced misery that we can inflict on clients. [00:46.080 --> 00:50.340] And then time for Q&A and we'll probably sneak in a couple snarky comments about Google along the way. [00:50.460 --> 00:51.000] Oh, probably. [00:53.060 --> 00:53.540] Okay. [00:57.180 --> 01:03.300] So for those of you who probably should already be familiar, but 802.11 is on 2.4 and 5.8 gigahertz. [01:04.520 --> 01:08.100] A, B, G, N, you know, all sorts of letters of the alphabet there. [01:08.780 --> 01:10.280] They're actually up to double letters. [01:10.440 --> 01:12.900] So I believe the latest proposed spec is 802.11 AE. [01:14.800 --> 01:16.080] Wake me when they get to double D. [01:19.660 --> 01:20.860] I just came up with that. [01:22.420 --> 01:29.820] But basically every radio that's out there, like every network card, basically is the same radio that can receive signals from any network. [01:30.040 --> 01:32.240] So it's really, really easy to interact with this stuff. [01:33.480 --> 01:39.960] Unlike frequency hopping stuff, which is a lot more expensive and a little more obscure, generic Wi-Fi card. [01:40.080 --> 01:46.700] You can pick these things up for like 50 bucks for like a really decent one out of, you know, some of these Taiwanese chop shops. [01:47.220 --> 01:51.240] And you can plug this in and 50 bucks, you're doing all sorts of badass things. [01:51.240 --> 01:54.260] So for example, a Bluetooth isn't really any more secure. [01:54.500 --> 01:57.680] But the problem is that you can't buy a $5 Bluetooth adapter and sniff it. [01:59.120 --> 02:01.960] So you can, I mean, there's ways to attack Bluetooth. [02:02.660 --> 02:05.080] Mike Osman has given talks at other cons. [02:05.240 --> 02:10.660] Go look up some of them on ways for about 1,500 bucks you can sniff and attack Bluetooth very easily. [02:11.980 --> 02:16.480] But otherwise it's hopping all over the place and you can't keep up with it with consumer cards. [02:17.000 --> 02:19.560] But with wireless, 802.11 wireless, we can. [02:19.560 --> 02:22.540] So basically it's made up of three types of packets. [02:22.740 --> 02:30.160] You've got your management, defines, you know, the network name, what crypto level there is, and everything handles all the advertising, the administrative crap of connecting. [02:31.160 --> 02:35.460] Control, you know, as the connection's going on, just how, you know, power saving. [02:36.580 --> 02:38.020] Not a heck of a lot of interesting stuff there. [02:38.360 --> 02:41.700] Data, this is where Google's getting their crap kicked out of them. [02:42.360 --> 02:47.060] The actual data frames, the actual packets that are going, you know, the normal A to B stuff. [02:47.060 --> 02:50.600] Yeah, so remember, if you don't want to get sued, don't sniff the data packets. [02:52.100 --> 02:53.560] Or just don't admit to it. [02:54.960 --> 03:08.300] Yeah, so the 802.11 management frames, they define the network name, they define the crypto options, they define how often the network advertises itself, they control client access, so the client goes, you know, here's the management frame, I want to join. [03:08.440 --> 03:10.880] The AP goes, you're allowed in, or go screw yourself. [03:11.320 --> 03:13.000] They're not authenticated, they're not encrypted. [03:13.480 --> 03:14.200] That's a great idea. [03:14.700 --> 03:14.960] Yay! [03:15.700 --> 03:17.360] Yeah, we'll get to that on a later revision. [03:18.220 --> 03:24.380] They are working on an extension that encrypts, or it doesn't encrypt, but it authenticates some of the management packets. [03:24.680 --> 03:29.400] However, it still doesn't authenticate all of them, and you still need updated drivers for everything before that happens. [03:29.840 --> 03:32.040] And, yeah, I don't think that's going to happen too soon. [03:33.560 --> 03:37.380] The data frames, they contain data, kind of self-evident. [03:37.660 --> 03:42.320] It could be layer 2 encrypted, if there's WEP or WPA, it might not be. [03:42.620 --> 03:46.780] It could have data layer encryption, because it's a data frame, it's whatever people put over it. [03:46.880 --> 03:48.420] It could be Telnet, it could be SSH. [03:49.000 --> 03:50.220] We're just hoping for Telnet. [03:52.120 --> 03:57.800] So, Wi-Fi devices, they typically present to your computer as an 8023 Ethernet device, like it was a wired device. [03:58.620 --> 04:01.740] You can set promiscuous mode on them, but it doesn't really mean anything. [04:02.340 --> 04:04.160] What happens is kind of random. [04:04.760 --> 04:07.360] Some drivers kind of give you data packets, some don't. [04:07.780 --> 04:14.000] And if you're on, you're only going to get really data packets addressed to you, or definitely only data packets from your network. [04:14.500 --> 04:19.780] You're only going to get the data frames, you're not going to see management, you're not going to get the 802.11 headers, you're not going to get signal level headers. [04:19.980 --> 04:20.840] You're not going to get the good stuff. [04:21.060 --> 04:22.500] Yeah, it's pretty much useless. [04:22.620 --> 04:25.600] You can turn it on, it might, yeah, I wouldn't bother. [04:27.160 --> 04:29.260] So, what we do have is monitor mode. [04:29.400 --> 04:45.820] Monitor mode requires special support in the drivers, which most in Linux do, most in BSD do, few in Mac do, and there is only one driver in Windows with a public interface that we can use, which is the case AirPCAP, which means you have to go buy another card. [04:46.300 --> 04:47.020] So, don't use Windows. [04:47.360 --> 04:48.060] Easy solution. [04:48.560 --> 04:52.440] So, this, in monitor mode, it switches it to 802.11 for the data link type. [04:52.560 --> 04:57.440] So, it actually, instead of reporting Ethernet packets that used to be wireless, it now reports straight wireless packets. [04:57.580 --> 05:05.100] You get all the headers, you get some custom signal headers sometimes telling you what antenna it came in on, how strong it was, what encoding speed it arrived at. [05:05.400 --> 05:08.040] It requires support from drivers, it requires support from the firmware. [05:08.480 --> 05:16.820] Almost all firmware supports it except typically mobile devices have really small firmware that remove monitor mode, which sucks for people who want to sniff with cell phones. [05:17.980 --> 05:19.320] Why would you ever want to do that? [05:19.320 --> 05:21.660] Ah, you'd never want a subtle sniffer device. [05:22.860 --> 05:25.000] So, monitor mode shows all the packets seen by the radio. [05:25.120 --> 05:27.420] It's management packets, data packets, control panes, everything. [05:27.820 --> 05:29.120] Almost everything supports this. [05:29.880 --> 05:31.000] Well, I already covered that bit. [05:32.120 --> 05:39.200] So, we get all the packets, regardless of network, regardless of the encryption, regardless of if there's cloaking on the network, because cloaking doesn't work. [05:40.020 --> 05:44.000] There's, you can detect clients, so you can see who's talking on the network you're looking at. [05:44.380 --> 05:46.520] You can do IDS functions with it that way. [05:46.660 --> 05:47.720] You can do passive observation. [05:48.060 --> 05:51.760] You can collect data for offline attacks, like air crack. [05:52.040 --> 05:52.200] Yeah. [05:56.410 --> 06:02.890] So, basically, that packet format, you've got your header, which is completely unencrypted, so your to and your from addresses and everything. [06:03.750 --> 06:06.730] The length can vary based on the type of packet. [06:07.670 --> 06:10.190] Management frames are all header. [06:10.350 --> 06:12.030] There's no data portion to it. [06:12.770 --> 06:20.310] The whole thing with Google was that they were supposed to be just capturing that stuff, which had the relevant information they needed for their little geomapping thing. [06:21.810 --> 06:25.670] But they... something happened, and they were recording more than they should have. [06:26.090 --> 06:26.450] Yeah. [06:26.490 --> 06:31.290] So, the idea behind what Google was trying to do, was they were trying to go, I can see these 10 MAC addresses. [06:32.150 --> 06:34.570] And you call back to Google and say, I see these 10 MAC addresses. [06:34.710 --> 06:40.510] And Google goes, well, we've got from our Street View car that these 10 MAC addresses mean you're probably within this 400 foot radius. [06:40.790 --> 06:44.650] So, you don't have to turn on GPS, and you get better positioning than from the cell tower alone. [06:45.450 --> 06:53.410] What they instead did was went, hey, we're going to log all your data anyway, and then let the government subpoena it from us so that other people can look at it. [06:54.910 --> 06:55.630] Sad face. [06:59.610 --> 07:00.050] Yeah. [07:00.230 --> 07:02.070] Basically, the data frames can be unencrypted. [07:02.190 --> 07:04.230] They can be encrypted depending on the settings for the network. [07:06.670 --> 07:10.630] 802.3, normal wired network stuff has source and destination. [07:10.890 --> 07:12.050] So has 802.11. [07:12.350 --> 07:19.190] You can have multiple MAC fields depending on various factors, but source, client, you know, it's the usual stuff, back and forth. [07:20.250 --> 07:20.530] Yeah. [07:20.610 --> 07:24.350] So 802.11 pretty much just adds a third MAC address that says, and this is the AP I'm coming from. [07:24.770 --> 07:26.470] Otherwise, it looks more or less like Ethernet. [07:27.030 --> 07:30.710] That's a very interesting ability, which we will show you how to do terrible things with in a few. [07:33.070 --> 07:33.390] Roaming. [07:33.570 --> 07:37.210] Basically, with roaming, you've got multiple APs with the same SSID. [07:38.290 --> 07:50.070] Client figures that, oh, if I'm part of the same, you know, network, like, you know, everybody's familiar with the Linksys global network, you know, if I'm previously joined, you know, if I previously joined on here, this must be the same network. [07:50.230 --> 07:53.910] So I'll just, you know, go over to this other one and, you know, all is right with the world. [07:54.850 --> 07:55.690] Not always. [07:56.510 --> 07:58.670] But it basically roams to the strongest signal. [07:58.930 --> 08:00.110] This is relevant later. [08:01.910 --> 08:14.650] If it's a proper system that supports handoff, there's usually a backend controller or something common on the network that knows, okay, you're going from this AP over here in, you know, the west wing to this one over in the east. [08:15.110 --> 08:18.950] So the only differentiator between those access points is the MAC address. [08:23.490 --> 08:26.070] So finding an 802.11 network with a sniffer is trivial. [08:26.610 --> 08:27.450] Networks are really noisy. [08:27.570 --> 08:32.150] Ten times a second they go, I'm a network, come talk to me, I'm awesome, I'm a network, over and over and over again. [08:32.330 --> 08:37.790] Even weird networks that are, you know, someone set up a weird broken network that only talks data and doesn't beacon. [08:38.250 --> 08:41.410] As soon as someone joins the network, you're going to see them, you're going to see them talking to it, you're going to know it's there. [08:41.610 --> 08:44.770] There's no way to hide an 802.11 network and still have it be 802.11. [08:44.770 --> 08:46.870] It's a radio, it's got to disclose its presence. [08:47.110 --> 09:00.670] Yeah, and even if you manage to like rewrite the 802.11 low-level packet formats enough that common cards can't see them, you can still see an RF transmission with a spectrum analyzer and go, oh, there's a big spike and it's got the same little double hump that a 11G has in the radio profile. [09:00.990 --> 09:01.890] Someone's messing around. [09:03.290 --> 09:05.690] Clients also are constantly looking for a network to join. [09:06.230 --> 09:08.410] They'll tell us every network they'd like to join. [09:08.710 --> 09:17.930] If you have it, if it's saved in like the Windows preferences for preferred networks, if Windows can't find any other network it likes, it just starts going through that list, like, yeah, I'm looking for my home network, I'm looking for my company network. [09:18.490 --> 09:21.410] They can be really, really noisy when they're looking for a network that they can't find. [09:21.870 --> 09:26.110] Oh, and they can be really noisy about some of the weird-ass SSIDs that they are looking for. [09:26.510 --> 09:30.850] Like, I really wonder what people are connecting to or naming their home networks from some of the crap I see. [09:35.370 --> 09:40.910] So for sniffing, you pretty much just put the car in monitor mode, which requires, as we mentioned, the proper drivers and support. [09:41.310 --> 09:51.670] If you are a die-hard Windows or Mac person and don't have a card that works, Backtrack and Pen2 are two good live CDs that don't require you to format your hard drive, so drop one of them in and play with it. [09:54.250 --> 09:54.970] Wireshark, tcpdump. [09:55.090 --> 09:58.110] Yeah, you can play with Wireshark, and Kismet does all that for you. [10:01.550 --> 10:04.230] So right now, we've got a pretty good idea with 802.11 security. [10:04.490 --> 10:09.350] You'd think, you know, after eight or nine years, we'd stop having a talk every con about Wi-Fi security. [10:09.690 --> 10:11.330] But, you know, it keeps us employed. [10:11.810 --> 10:14.310] So we've got a pretty good idea about doing network security now. [10:14.570 --> 10:17.730] And, I mean, security professionals, you can build a secure Wi-Fi network. [10:17.910 --> 10:18.510] It's not that difficult. [10:18.510 --> 10:19.850] Not as professionals as in quotes. [10:21.110 --> 10:21.550] Yeah. [10:21.970 --> 10:25.110] But even random people are kind of cluing in. [10:25.490 --> 10:26.790] Encryption on home networks is up. [10:27.570 --> 10:30.890] You know, five years ago, we'd see maybe 10% encrypted with WEP. [10:31.270 --> 10:31.410] Yay. [10:32.110 --> 10:34.610] Now we're seeing, you know, 15% encrypted with WEP. [10:35.210 --> 10:39.410] And, you know, maybe 30 or 40% actually encrypted with WPAPSK. [10:39.650 --> 10:40.510] It's a step forward. [10:40.690 --> 10:42.150] People are kind of getting the clue. [10:42.750 --> 10:49.630] After a decade of news reports, people on Fox News with, you know, some guy in black and a pretty reporter going, we sniffed this person's Wi-Fi. [10:49.850 --> 10:51.630] Let's knock on their front door and talk to them. [10:52.430 --> 10:55.070] People are finally thinking, it's a good idea to encrypt this shit. [10:55.990 --> 11:02.570] Now, as a little side note, how many of you have gotten ISP provided, like, DSL routers or capabilities? [11:03.810 --> 11:04.410] Oh, yeah. [11:05.330 --> 11:05.770] Yeah. [11:06.650 --> 11:06.950] Yeah. [11:07.230 --> 11:07.370] Okay. [11:08.030 --> 11:10.390] So, yeah, the default Fios APs that went out. [11:11.050 --> 11:13.330] You've probably seen them near you if you live in an area with Fios. [11:13.450 --> 11:18.290] It's a whole bunch of network with the SSID is five characters, numbers and letters. [11:19.230 --> 11:19.370] Yes. [11:20.050 --> 11:25.570] Fun fact, that's all but two characters of the WEP key in base 26. [11:26.910 --> 11:35.210] So, you convert that number to base 26 and the other two bytes of the WEP key are the OUI bytes of the manufacturer. [11:36.290 --> 11:37.230] Who makes the router? [11:37.470 --> 11:38.010] Action Tech. [11:38.150 --> 11:39.890] How many MAC addresses do they have allocated to them? [11:40.050 --> 11:40.450] Six. [11:40.970 --> 11:47.770] So, we can just capture a data packet, guess the key, rotate through all six ones, and see if it matches. [11:48.010 --> 11:50.090] There's actually a plugin for Kismet that does it now automatically. [11:52.650 --> 11:59.010] I'd whistle innocently, but I'm afraid of doing feedback again. [11:59.290 --> 12:00.250] So, just imagine I did. [12:01.870 --> 12:13.290] But, yeah, like, I'm up in Canada, I'm in Alberta, and I see so many of these routers being sent out by ISPs and the Telecos saying, oh, here's your new secure free home router with WEP. [12:14.270 --> 12:14.750] Thanks. [12:16.830 --> 12:17.630] That's better? [12:19.030 --> 12:20.290] Well, for me, it is. [12:23.650 --> 12:24.050] Okay. [12:24.310 --> 12:26.090] So, Wi-Fi secure and proper deployments. [12:26.170 --> 12:27.350] What do we mean by proper deployment? [12:27.650 --> 12:28.430] WPA enterprise. [12:28.870 --> 12:31.410] You can do per user authentication, per user keying. [12:31.770 --> 12:38.490] If you're really hardcore, you can do per user certificates tied back to your certificate authority that validates them automatically as they do a sign in. [12:38.650 --> 12:41.770] And how many of you have actually tried rolling your own in this kind of system? [12:42.730 --> 12:43.510] Oh, come on. [12:43.570 --> 12:44.090] It's so easy. [12:44.250 --> 12:46.810] You only need five systems to start with. [12:47.850 --> 12:49.370] How many of you have gotten them to work? [12:52.480 --> 12:53.940] I see one guy in back. [12:54.700 --> 12:55.140] Two. [12:55.360 --> 12:56.280] I see two guys in back. [12:58.560 --> 13:00.340] No, I haven't gotten this crap to work. [13:03.020 --> 13:03.620] I'm sorry. [13:03.740 --> 13:05.400] Free radius kicked my ass. [13:06.320 --> 13:07.600] Free radius is awesome. [13:08.080 --> 13:09.920] Well, then you get to set it up for me. [13:12.500 --> 13:15.020] So, we've got a pretty good crypto system for Wi-Fi now. [13:15.580 --> 13:17.180] AES is not broken yet. [13:17.420 --> 13:21.280] I don't know of any working flaws against it, how it's used on Wi-Fi. [13:21.940 --> 13:22.900] TKIP is showing flaws. [13:23.660 --> 13:29.240] TKIP was made about... I think they wrote the spec about six years ago. [13:29.240 --> 13:36.480] And in the spec they said, we expect this to be valid for about five years before someone figures out a vulnerability in it. [13:36.820 --> 13:40.260] And about a year ago, someone started showing vulnerabilities in TKIP. [13:40.380 --> 13:44.340] And it was within a couple of months of when it was ratified. [13:44.780 --> 13:45.600] Good estimate. [13:46.520 --> 13:47.840] So, get off TKIP. [13:48.020 --> 13:48.720] Move to CCMP. [13:49.300 --> 13:51.040] Pretty much everything out there supports it. [13:51.340 --> 13:52.560] So, why not? [13:53.380 --> 13:58.660] There's a few handheld devices and phones and whatnot that don't support CCMP because they don't have the horsepower to do it. [13:59.400 --> 14:01.000] So, get rid of them. [14:02.880 --> 14:04.200] TKIP will eventually fall down. [14:04.340 --> 14:05.000] It's on its way. [14:05.980 --> 14:09.420] I haven't seen anyone have an out-of-the-box quick attack against it yet. [14:09.420 --> 14:11.560] But I think it's quickly going the way of WEP. [14:11.880 --> 14:14.400] And in the next year or so, we're probably going to see it be as vulnerable. [14:15.020 --> 14:17.260] So, WPA enterprise is secured, done correctly. [14:18.080 --> 14:21.880] Opportunities for failure exist if users don't validate certs. [14:22.220 --> 14:25.140] Or if you just let your users say okay, because they make great decisions all the time. [14:26.200 --> 14:27.460] That's why we trust them so much. [14:27.660 --> 14:32.000] Case in point, I gave the certificate for the hope network to the info desk guys. [14:32.140 --> 14:34.580] How many people validated that if you're using the WPA network? [14:36.420 --> 14:36.840] Yeah. [14:37.440 --> 14:44.500] So, theoretically, it's not that hard to bring up a WPA2 network that says it's your network with a certificate. [14:44.800 --> 14:47.140] And if your users can say, yeah, that's fine. [14:47.700 --> 14:48.400] I don't know what that means. [14:48.580 --> 14:50.280] And this actually works. [14:50.880 --> 14:52.960] It's proven very useful in a few tests. [14:53.340 --> 14:54.980] So, there are ways to do it. [14:55.140 --> 15:00.560] But if you have a... talking like a corporate sense where you can control the laptops, you can make a secure network. [15:02.140 --> 15:03.480] Also, defending the APs. [15:03.580 --> 15:04.820] We've been doing this for a long time now. [15:05.180 --> 15:07.260] The best defense is a strong network architecture. [15:07.640 --> 15:08.540] Yeah, you can DOS it. [15:08.780 --> 15:09.260] Big deal. [15:09.400 --> 15:09.740] It's a DOS. [15:10.340 --> 15:10.980] It's radio. [15:11.300 --> 15:12.360] It's made to be DOSed. [15:13.020 --> 15:15.380] You can monitor for conflicting and spoofed access points. [15:15.780 --> 15:19.180] You can know that a client connected to you, therefore it's a valid client. [15:19.360 --> 15:21.800] When it connects to an AP that you don't control, you go, well, that's not right. [15:21.920 --> 15:24.080] And kick it off with your own DOS attack. [15:25.760 --> 15:27.680] You can block inter-client traffic at the AP. [15:28.360 --> 15:35.140] Defending it on a strong network is easy, because you can go, well, all your crypto goes through me, because you have a per-user key, so I can control who you talk to. [15:35.920 --> 15:40.800] However, defending clients on an open AP is very hard to impossible, as we will discuss. [15:41.700 --> 15:42.600] So denial of service attacks. [15:42.700 --> 15:43.680] Management frames are unprotected. [15:43.800 --> 15:44.460] You can spoof the AP. [15:44.580 --> 15:45.500] You can kick everybody off. [15:46.880 --> 15:47.240] BFD. [15:47.380 --> 15:47.720] Who cares? [15:48.580 --> 15:49.860] You can do a pure channel denial. [15:50.040 --> 15:57.540] I mean, go download the specs from Lady Ada for building a wave bubble, and you can just stomp the entire spectrum into oblivion. [15:58.000 --> 15:59.560] The only real defense against this is crowbar. [15:59.640 --> 16:07.060] Find the person doing it, hit them with a crowbar until they stop doing it, and you'll stop the non-service attack, but that's really all that matters. [16:07.300 --> 16:08.840] Well, it's denial of attacker, weren't it? [16:08.960 --> 16:09.100] Yeah. [16:12.580 --> 16:15.560] Okay, basically, punching it into a living in the gut is absurdly easy. [16:16.200 --> 16:20.960] You know, like I said, any radio is capable of talking to these things and doing all this stuff. [16:22.280 --> 16:24.020] Management frames are totally unprotected. [16:24.560 --> 16:30.760] We can see who's talking to who, and you know, which clients are talking to the interesting corporate network versus ones at the coffee shop. [16:31.660 --> 16:33.640] Open networks are unauthenticatable. [16:33.900 --> 16:37.600] I have no idea if that coffee shop network is actually the coffee shop network. [16:37.980 --> 16:43.540] You know, of course, if some of my friends are around, I know it's probably not, but it's a shared media. [16:43.720 --> 16:45.080] Anything you send out, it's a radio. [16:45.260 --> 16:48.140] It's a big bubble of energy that gets sent out. [16:48.240 --> 16:49.260] It goes out in all directions. [16:49.820 --> 16:56.760] So if I'm anywhere in that, I can sniff the traffic that's going through there that, you know, will be on walls, parking lots, whatever. [16:58.780 --> 17:01.240] Avoiding hostile networks requires smart users. [17:02.640 --> 17:03.780] I haven't met one yet. [17:03.960 --> 17:04.100] Have you? [17:07.340 --> 17:09.360] Users typically make bad decisions. [17:09.770 --> 17:13.550] You know, if there is, like, the wrong option to choose, that's the one they choose. [17:14.570 --> 17:15.900] Would you like to be set on fire? [17:16.100 --> 17:16.310] Yes. [17:16.970 --> 17:16.990] Yes. [17:17.030 --> 17:17.330] Yes. [17:17.510 --> 17:17.790] Yes. [17:19.490 --> 17:21.750] The OS... OS's don't help. [17:22.620 --> 17:26.030] Windows, in particular, likes to just hop onto networks that it's seen before. [17:26.180 --> 17:29.640] It figures, oh, you know, I've been on Linksys before, I'll just hop onto Linksys. [17:30.210 --> 17:31.680] It's obviously the same network. [17:31.900 --> 17:32.290] Absolutely. [17:32.660 --> 17:32.770] Yeah. [17:33.990 --> 17:38.070] It's hard to tell what's real, assuming that the user even looks. [17:38.230 --> 17:39.420] They're just, you know, after free Internet. [17:39.660 --> 17:51.570] I mean, how many... I've seen a few cases today before that the network was up of guys standing next to the window at, you know, downstairs on the second floor, laptop up to the window, you know, trying to get onto something. [17:53.550 --> 17:54.250] Ah, good. [17:54.970 --> 17:56.990] You know, this is basically what you're doing. [17:57.840 --> 17:58.550] Free candy. [17:58.730 --> 17:59.200] Must be good. [17:59.330 --> 17:59.990] Let's go inside. [18:00.620 --> 18:01.180] You know, let's connect. [18:01.790 --> 18:02.920] We'll even give you a puppy. [18:06.760 --> 18:08.550] Actually, it's pretty close in color to the render man. [18:10.280 --> 18:13.030] So, for example, users really like free Wi-Fi. [18:13.250 --> 18:15.730] Who wouldn't want to join a network named free public Wi-Fi? [18:16.010 --> 18:16.710] Who's seen it? [18:18.460 --> 18:25.250] I actually was standing in registration yesterday, and some guy was standing in line, and I hear a comment of, oh, free public Wi-Fi. [18:25.380 --> 18:25.900] I wonder if that works. [18:28.580 --> 18:30.660] And I smiled to myself and walked away. [18:32.640 --> 18:37.380] So, sometime long ago, in the forgotten times, this network probably existed. [18:37.640 --> 18:40.460] There's probably some, you know, airport or something. [18:40.640 --> 18:40.900] I don't know. [18:41.070 --> 18:42.030] It's named free public Wi-Fi. [18:42.400 --> 18:43.230] So, fun fact. [18:43.440 --> 18:51.660] Windows, I think they finally fixed this in 7 and in SP3 on XP, but for a long time, when it couldn't find a network, it said, I can't find this network that you wanted me to connect to. [18:52.550 --> 18:53.940] Obviously, you want me to make an ad hoc. [18:55.550 --> 18:57.660] That's absolutely perfectly logical. [18:57.990 --> 18:59.030] What I didn't want it to do. [18:59.600 --> 19:02.680] So, now you have a network being advertised, called free public Wi-Fi. [19:02.880 --> 19:05.900] Maybe I had a little icon next to it that says it's an ad hoc, but who knows what that icon is. [19:06.050 --> 19:07.970] I actually don't even, because I don't use Windows. [19:08.660 --> 19:10.270] So, then someone else tries to join it. [19:12.780 --> 19:13.860] So, it doesn't go anywhere. [19:14.330 --> 19:17.050] So, then they now have a preferred network of free public Wi-Fi. [19:17.380 --> 19:22.470] So, it starts advertising as an ad hoc, and someone else goes, I like free public Wi-Fi, and tries to join it. [19:22.830 --> 19:23.490] And it doesn't go anywhere. [19:23.680 --> 19:24.940] But now they have a preferred network of an ad hoc. [19:25.230 --> 19:41.990] I've actually seen the same thing happen at a college campus with HP setup, where some kid brought an HP printer with Wi-Fi into the dorm, and you could almost watch the wave of it over the course of a day spread over a nine-floor dormitory of everybody's Windows machines kicking over to HP setup. [19:43.940 --> 19:45.900] So, I mean, it's a junk ad hoc network. [19:45.970 --> 19:46.660] It doesn't go anywhere. [19:46.750 --> 19:47.550] You can't do anything with it. [19:47.700 --> 19:54.940] Unless, of course, you brought up a network with the same name and handed out IP addresses, which would make us LAN local for the firewall domain to all the Windows machines that connected to it. [19:55.160 --> 19:56.470] But no one would ever do that. [19:56.790 --> 19:57.380] That's silly. [20:06.310 --> 20:07.630] Clients are really, really trusting. [20:07.910 --> 20:09.710] If you say you're the network, you must be, right? [20:09.830 --> 20:11.390] It's really hard to avoid this happening. [20:13.290 --> 20:15.130] I mean, even for us, it's really hard to tell. [20:15.230 --> 20:18.150] And if someone, if it's an open network and someone spoofs the MAC address, you can't tell. [20:19.590 --> 20:20.590] Remember before, roaming? [20:20.930 --> 20:21.790] How it works? [20:22.130 --> 20:29.090] You have multiple APs with the same name that have different MAC addresses, and it automatically jumps to the strongest signal? [20:30.110 --> 20:30.150] Hmm. [20:31.590 --> 20:31.850] Fun. [20:32.970 --> 20:34.830] So you get multiple APs, same SSID. [20:34.970 --> 20:39.370] Client assumes the SSID is one big common network, one big happy family. [20:39.670 --> 20:40.890] Roams to the strongest signal. [20:42.310 --> 20:43.230] What the hell? [20:44.630 --> 20:52.870] Oh, so if an attacker has a stronger radio than the AP, meaning I'm sitting right next to you, you know, at the... Or, you know, went and bought a 300mW Wi-Fi card. [20:53.510 --> 20:55.090] Nobody here has any of those. [20:55.570 --> 20:55.830] No. [20:57.370 --> 20:59.890] We won't discuss the laptops that are being held up in the front row. [21:02.210 --> 21:04.190] You may not be talking to who you think you're talking to. [21:04.770 --> 21:08.850] And as long as packets go through, you know, users won't notice. [21:09.490 --> 21:10.510] You're the man in the middle. [21:10.690 --> 21:12.430] You own everything on that connection. [21:12.690 --> 21:13.930] You win automatically. [21:15.730 --> 21:16.650] What the hell? [21:17.410 --> 21:17.750] Whatever. [21:18.950 --> 21:28.690] So now if you're a dual interface attacker, like, you know, you got USB and a PCMCIA or the onboard Wi-Fi, you got two interfaces. [21:29.130 --> 21:32.150] One connects to the legitimate network at the coffee shop or what have you. [21:32.530 --> 21:39.330] The other one is sitting there with a nice, you know, 300mW card, big antenna sticking on it. [21:40.330 --> 21:43.150] Advertising, free public local Wi-Fi or, you know, FarDux. [21:43.890 --> 21:53.190] And since you're sitting closer than the AP, because they always end up burying that thing somewhere in the ceiling and nobody ever knows where the hell it is, you've got a stronger signal. [21:53.290 --> 21:53.850] They roam to you. [21:54.010 --> 21:57.810] You now bridge the connection back and you've got all their traffic flowing through you. [21:57.990 --> 21:58.870] Oh, how kind. [22:02.190 --> 22:07.810] Sounds pretty boring to have to make a fake network for every single one of these, you know, potential coffee shops or anything. [22:08.370 --> 22:09.530] Let's just do all of them. [22:10.090 --> 22:12.690] So you've got Karma and AirBase are two wonderful tools for this. [22:12.870 --> 22:17.050] It basically says, yes, I am that network to any and all probe requests. [22:17.990 --> 22:20.450] This, you know, I'm lazy. [22:20.850 --> 22:21.590] This makes it easy. [22:21.610 --> 22:22.150] Are you free public Wi-Fi? [22:22.310 --> 22:23.170] Yeah, that's me. [22:23.490 --> 22:24.650] Are you, you know, Microsoft? [22:24.910 --> 22:25.610] Yeah, that's me. [22:25.990 --> 22:26.610] Why the hell not? [22:27.610 --> 22:29.850] So when you're the network, you're the Internet. [22:30.110 --> 22:30.950] I don't have to own the Internet. [22:31.130 --> 22:32.530] I have to own your Internet. [22:32.830 --> 22:34.210] Yeah, I'm your IMAP server. [22:34.430 --> 22:35.550] That's totally the IP of it. [22:36.030 --> 22:36.990] You're talking to the Internet. [22:37.110 --> 22:37.670] Yeah, give me your password. [22:37.770 --> 22:38.010] Log in. [22:38.110 --> 22:38.250] It's good. [22:38.530 --> 22:38.770] Log in. [22:39.050 --> 22:40.090] Want to update some software? [22:40.210 --> 22:40.710] Yeah, update. [22:40.890 --> 22:42.190] Yeah, you've got 10 updates. [22:42.330 --> 22:42.750] Imagine that. [22:43.130 --> 22:43.710] I don't know. [22:43.770 --> 22:44.810] They all came out at the same time. [22:45.230 --> 22:46.770] Here, download random binary. [22:47.590 --> 22:58.990] There's a program called Evil Grade, which is designed to take all of the vulnerable, all the network services in Windows and Mac that take updates that aren't signed digitally, like with SSL or SSL. [22:59.110 --> 23:02.750] They aren't encrypted or signed, and give you custom binaries. [23:02.850 --> 23:03.970] Yeah, run this as admin. [23:04.090 --> 23:04.370] Update it. [23:04.470 --> 23:04.990] Update Java. [23:05.130 --> 23:05.370] It's good. [23:05.450 --> 23:05.810] You need to. [23:07.010 --> 23:09.870] So, what happens when you mix this with Metasploit? [23:10.550 --> 23:23.630] You get Car Metasploit, Metasploit Airbase, basically, yeah, it's you connect to Airbase, it gives you an address, and then feeds you every single browser exploit known to man from Metasploit. [23:23.930 --> 23:25.610] Here, have a face full of exploits. [23:28.170 --> 23:31.510] All right, so most sites encrypt login, but they don't encrypt the session. [23:31.870 --> 23:36.290] Google was vulnerable, was guilty of this until very recently, or probably about a year ago. [23:36.410 --> 23:39.310] Anyway, so you, what's unencrypted now? [23:39.410 --> 23:41.670] Session cookies, your email data, etc. [23:42.310 --> 23:47.390] So the middler, SSL sniff, cookie monster, all hijack those cookies and log you in as whoever you captured. [23:49.330 --> 23:52.370] This is kind of boring though, because they're really obvious, people have done them. [23:52.810 --> 23:56.570] Might still get some users, but it'll be really obvious if anyone's looking for this, that something's going on. [23:56.970 --> 23:59.310] I figure points are awarded for style, or at least for stealth. [24:00.250 --> 24:02.950] So, wait a minute, didn't we say 802.11 is a shared media network? [24:03.050 --> 24:03.430] Yeah, we did. [24:03.750 --> 24:05.030] We found a great time machine. [24:06.310 --> 24:09.770] And it's not a hippie do-gooder time machine. [24:14.580 --> 24:17.540] But it's a time machine where we get to bring back awesome weapons from the future. [24:20.630 --> 24:23.610] Yeah, so the bad old days of the, you know, early 90s. [24:23.710 --> 24:30.490] Hair metal, grunge, ripped jeans, unswitched, shared media Ethernet, sniffing the entire segment, TCP session attacks, fun diversion. [24:30.750 --> 24:37.850] Render and I gave an early version of this talk in Poland, and we got to this slide and went, remember the early, the late 80s and early 90s, and all that, oh no, communism. [24:38.730 --> 24:39.950] Don't say that, don't say that. [24:41.150 --> 24:43.710] Skip this slide, shit, we just reminded them of communism. [24:47.270 --> 24:49.110] So, but I mean, it would never be that easy, right? [24:49.230 --> 24:51.250] I mean, people have gotten smarter since the 90s, right? [24:51.350 --> 24:57.190] You'd never take a system from a secured network to a completely insecure shared media network where anybody could do session hijacking, right? [25:03.840 --> 25:04.260] Oops. [25:04.260 --> 25:08.720] Airports, gyms, hotels, conferences, bookstores, you know. [25:09.440 --> 25:11.720] I mean, everybody's putting in Wi-Fi nowadays, you know, why shouldn't we? [25:13.880 --> 25:21.120] So remember, management frames have no protection, open networks have no client protection, nothing stops us from spoofing the AP and talking directly to the client. [25:21.580 --> 25:28.460] We don't even have to be, we don't have to bring up a full AP, we don't have to beacon, we just have to go, here's a data frame from this MAC address to you, accept it. [25:30.820 --> 25:34.040] So you can try to filter inter-client communication on the AP. [25:34.780 --> 25:40.720] Doesn't work on open networks, because I'm now the AP talking to you, your AP doesn't get to make any decision at all about whether or not that packet goes through. [25:41.260 --> 25:46.400] So all you have to do is generate an A211 header from the AP MAC address to the client MAC address. [25:46.580 --> 25:49.740] The client thinks the packet's legit, the AP has no opportunity to do anything about it. [25:49.880 --> 25:53.200] We communicate directly with protected clients, air quotes, protected. [25:56.300 --> 25:59.020] So doing this, most modern cards use soft MAC layers. [25:59.320 --> 26:02.440] That means most of the Wi-Fi code is offloaded into the operating system. [26:02.580 --> 26:04.620] This is good for us, because it means we can make packets. [26:05.640 --> 26:11.280] Older cards like Prism 2 did most of it in the hardware, which meant it was a real big pain in the ass and didn't work very well. [26:13.220 --> 26:15.080] Unfortunately, there aren't any real good standards for that. [26:15.240 --> 26:19.760] Every operating system does it differently, different drivers do it differently, sometimes you need custom headers per packet. [26:20.820 --> 26:22.620] So Josh Wright and I went, hey, this sucks. [26:22.780 --> 26:26.100] Writing the same code for every app, or the same code for every different app sucks. [26:26.220 --> 26:27.620] Writing custom code for every driver sucks. [26:27.780 --> 26:29.140] Rewriting it for every operating system sucks. [26:29.440 --> 26:30.500] So we made this thing called Lorcon. [26:30.880 --> 26:31.940] Hopefully it doesn't suck. [26:32.740 --> 26:34.080] Unfortunately, Lorcon kind of sucked. [26:35.960 --> 26:39.040] So we have Lorcon 2, which is a new API modeled off PCAP. [26:39.340 --> 26:41.720] It's really easy to use with C and Ruby API. [26:42.320 --> 26:44.780] Right now it supports all the Linux cards. [26:44.980 --> 26:47.700] It'll support the rest of the stuff that Lorcon 1 did soon. [26:48.000 --> 26:50.020] The URL will be at the end, so don't worry about it. [26:51.480 --> 26:53.220] So it automatically determines the driver now. [26:53.340 --> 26:56.940] It automatically configures the virtual network interfaces for injection mode. [26:57.280 --> 27:01.080] You can send arbitrary bytes or build packets with the packet assembly API built into it. [27:02.720 --> 27:05.120] We'll just skip over this because we're running a little short. [27:05.660 --> 27:07.260] So the inspiration for all this fun. [27:07.460 --> 27:08.820] Wi-Fi session hijacking. [27:08.940 --> 27:11.960] About five years ago, Toast debuted Airpone. [27:12.860 --> 27:16.300] I need to stop rocking back and forth or something because I keep finding the feedback zone here. [27:16.940 --> 27:21.780] About five years ago, this guy Toast wrote Airpone, which is TCP stream hijacking on 802.11. [27:21.960 --> 27:24.220] Why hasn't everyone been using this ever since? [27:24.380 --> 27:25.620] It is fun as hell. [27:25.920 --> 27:28.740] It's awesome, and it's not just for shock porn anymore. [27:30.820 --> 27:33.320] If you don't get it, ask the person next to you. [27:33.320 --> 27:35.100] They'll be happy to explain it to you. [27:38.500 --> 27:48.400] I did give a version of this talk to some corporate people, and at the end, this lady timidly raises her hand and goes, I didn't get the slide about the goat. [27:48.520 --> 27:49.260] Can you explain it? [27:51.760 --> 27:53.380] And I said, I need an Internet connection. [27:58.720 --> 28:09.500] So typically, on a layer 2 attack, it's secure because we know that you can't slide packets in because you've got sequence numbers and the acknowledgement numbers. [28:10.900 --> 28:12.180] Everything has to come in order. [28:12.320 --> 28:15.680] If it doesn't, okay, it's dropped on the floor and re-requested. [28:16.180 --> 28:25.260] So as an attacker, if I can see your sequence numbers, I can just go a couple of hundred ahead and start transmitting there and everything's still nicely in line. [28:25.720 --> 28:33.520] And because I'm now transmitting further up ahead, all the stuff that was still coming in from the valid access point gets dropped on the floor because it's now out of sequence. [28:35.380 --> 28:39.860] So this gets really fun when you start looking at the anatomies of a lot of these sessions. [28:40.780 --> 28:48.260] You know, standard handshake when you're getting a file from like Google or whatever, you know, client says to the server, get me this file. [28:49.560 --> 28:53.340] Server backed, you know, here's a sequence number, your acknowledgement number. [28:53.660 --> 28:56.340] Server to the client, you know, here's your header, here's your content. [28:58.080 --> 29:03.620] So let's take this, add a Ruby wrapper, a little PCAP, a little TLC. [29:05.340 --> 29:07.900] So you get client, goes to the server, requests the page. [29:08.980 --> 29:19.080] Metasploit sees this and says, oh, yeah, I'm now going to respond in much faster than the remote server can, you know, because Google is 200 milliseconds away, I'm, you know, two milliseconds away. [29:19.380 --> 29:25.260] I'm going to reply with sequence numbers that are in line with my own content, malicious content. [29:25.920 --> 29:28.880] So yeah, here's your content, close the session. [29:30.020 --> 29:33.060] The remote server is still sending data and it's like, it doesn't care. [29:34.240 --> 29:36.820] And then, yeah, we now own you. [29:37.300 --> 29:38.960] We've just fed you God knows what. [29:40.280 --> 29:45.140] Basically with Metasploit, there's now a module for doing Airpone within Metasploit. [29:49.680 --> 29:54.040] You mix and match what you want to replace on the, on these through regex. [29:54.200 --> 29:58.920] So you can replace not just HTTP headers, but you can replace whatever kind of content you want. [29:59.180 --> 30:02.820] The idea is that, you know, you're asking for Google's front page image. [30:03.240 --> 30:05.300] I'm responding back with, you know, goatse. [30:08.300 --> 30:18.060] Yeah, the Metasploit version of Airpone's also got the YAML file for matching specific sites so you can, you know, fine tune what your content you're sending for specific sites. [30:18.700 --> 30:21.300] You know, basically be as badass as you want. [30:24.920 --> 30:26.160] So what does that get us? [30:26.200 --> 30:28.360] It gets us HTTP content replacement. [30:30.160 --> 30:37.260] Or in other words, we control the DOM, we control the forms, we control the browser, we can access anything in the security context of the page we've injected something into. [30:38.780 --> 30:39.900] So we can replace content. [30:40.060 --> 30:40.480] What do we do now? [30:41.020 --> 30:46.260] Most complex sites include a whole crap ton of little JavaScript helper files that get included in the background. [30:46.660 --> 30:47.780] So what happens if we replace one of those? [30:48.200 --> 30:51.640] Well, so for example, here's CNN loading 400K of JavaScript. [30:53.200 --> 30:54.340] These are really attractive. [30:54.560 --> 30:55.560] They're totally invisible to the user. [30:55.680 --> 30:56.540] You never see them get loaded. [30:57.380 --> 31:01.020] Multiple requests, which means we've got 20 attempts to land this race condition. [31:01.520 --> 31:05.380] And they run the same privilege domain as the web page, so we can change anything on that web page. [31:05.720 --> 31:08.680] So I'm rewriting your DOM, the document object model. [31:09.040 --> 31:11.720] It's a programmatic JavaScript manipulation of page content. [31:11.920 --> 31:14.440] Once we're in the DOM, we can do anything we want to the site. [31:18.950 --> 31:27.870] So that nasty little bit of code basically just goes, I'm going to look through the DOM for anything named CNN T1 image and replace that with my own image. [31:28.130 --> 31:31.310] And I'm going to look for anything that says CNN T1 text and replace that with my own text. [31:31.570 --> 31:35.890] So that's all just, you know, looking through the source code for CNN's page and you can find what they named things. [31:36.750 --> 31:38.090] So that's really fun. [31:38.250 --> 31:38.730] What else can we do? [31:38.830 --> 31:42.430] We can create all the forms on the page to proxy through a hostile server that logs everything. [31:42.610 --> 31:43.090] Yeah, that works real well. [31:43.430 --> 31:49.910] We could write all the encrypted links on an unencrypted page so that you might hope you're clicking on HTTPS link, but you're not. [31:51.050 --> 31:53.050] You could poison content topical to a conference. [31:53.250 --> 31:58.530] It's kind of tinfoil hattie, but what if you're at a banker conference and every finance website suddenly says the market crashes? [32:03.520 --> 32:05.140] You mean we actually have to fake that? [32:07.320 --> 32:07.720] Shit. [32:09.740 --> 32:10.520] Go back up one. [32:11.680 --> 32:18.880] So all we're doing here is looking for everything that begins with HTTPS and doing a regex replace to make it HTTP. [32:19.220 --> 32:23.580] Oh look, now nothing's encrypted anymore and all the future pages you look at I can also poison. [32:24.640 --> 32:26.020] So this matters a lot. [32:26.200 --> 32:28.100] No, like seriously, seriously matters. [32:28.760 --> 32:29.940] Who's read our snake's paper? [32:32.200 --> 32:32.980] That's about typical. [32:33.160 --> 32:34.060] I see like five people. [32:34.280 --> 32:34.880] Six people. [32:35.020 --> 32:36.780] And I think some of them have heard me ask that before. [32:37.840 --> 32:40.020] You can attack HTTP clients via cache control. [32:40.480 --> 32:43.660] So you can do layer two attacks against the web that is then made persistent. [32:43.920 --> 32:46.440] So once you leave the area of the Wi-Fi network, you're still owned. [32:49.120 --> 32:49.780] Short version. [32:49.880 --> 32:50.640] Browsers have cache. [32:50.700 --> 32:51.440] Cache remains around. [32:51.580 --> 32:52.000] It's what it does. [32:52.220 --> 32:53.300] Users don't notice cache. [32:53.780 --> 32:56.000] If I own your TCP session, I own your cache control. [32:57.460 --> 33:00.320] So I feed you a spiked JavaScript file set to cache for 10 years. [33:00.700 --> 33:01.380] It remains there. [33:01.640 --> 33:06.280] It's reused every time you visit the site from whatever network you're on then, like your corporate network. [33:06.780 --> 33:15.000] And nobody would ever visit a site that they visited, you know, a coffee shop back in their corporate network like, you know, Facebook or Twitter or any, you know, any little site like that. [33:15.220 --> 33:15.680] It never happened. [33:15.940 --> 33:16.060] No. [33:17.020 --> 33:20.100] Oh, look, 400K of JavaScript pages that are cached. [33:21.360 --> 33:23.320] So none of the files are visible to the end user. [33:23.460 --> 33:26.000] We can keep trying to poison them. [33:26.220 --> 33:31.540] So all you have to do, cache control header, max age, whole bunch of nines, public, or just set it to expire some, I don't know, 2011. [33:32.080 --> 33:32.320] That's good. [33:32.780 --> 33:34.760] I mean, the world's going to end in 2012, so 2011's good. [33:34.860 --> 33:35.800] We can own everyone before that. [33:36.840 --> 33:39.780] Hijack a common JavaScript file, spike it with malicious code, set it to cache. [33:39.980 --> 33:46.500] And when the user goes back to work and goes to Twitter again, oh, look, they're loading our cached JavaScript file we gave them with whatever we put in it. [33:46.660 --> 33:48.400] So it'll keep using it every time until it expires. [33:48.580 --> 33:49.880] So we could put iframes in there. [33:50.460 --> 33:53.300] Dan Kaminsky a couple years ago came up with this thing called Socket and Suckit. [33:53.580 --> 33:54.820] Suckits are sockets that suck. [33:55.200 --> 33:57.900] He implemented TCP over JavaScript and Ajax. [33:58.540 --> 33:59.820] The man is not okay. [34:00.080 --> 34:01.040] Stick around for his talk. [34:01.200 --> 34:01.840] It will be awesome. [34:03.700 --> 34:08.000] So you could use that to tunnel into the corporate network and then run nmap on them through their browser. [34:08.460 --> 34:10.680] You could load, you know, new browser exploits. [34:11.000 --> 34:12.340] I mean, a user would never go to Twitter at work, though. [34:14.620 --> 34:16.040] Also, how many sites use Urchin? [34:16.660 --> 34:18.100] Hosted off the same URL on Google. [34:18.500 --> 34:23.360] And if we, you know, poison that to rewrite every page that uses it. [34:23.820 --> 34:24.760] Oh, so sad. [34:27.200 --> 34:30.800] You could also have a cached JavaScript file that calls home every time the page is visited. [34:31.040 --> 34:32.900] So there's no good attacks for the browsers this week. [34:33.140 --> 34:34.400] Oh, we'll wait a week. [34:34.580 --> 34:40.120] So, you know, just wait for browser Oday and then, you know, drop a file on your server that exploits it. [34:40.300 --> 34:45.200] And every system that has a cached JavaScript file that's looking for it will pull it in and exploit the browser instantly for you. [34:47.340 --> 34:49.200] You can do the same thing with a JavaScript shim. [34:49.420 --> 34:54.940] You could make a little bit of JavaScript that then AJAX is the original content, manipulates the DOM, does whatever you want to it. [34:55.960 --> 34:57.500] New browser vulnerabilities dumped in there. [34:58.120 --> 35:00.300] But I mean, there haven't been any big browser phones lately, right? [35:00.620 --> 35:01.300] That's old news. [35:01.420 --> 35:02.420] We don't have to worry about browsers anymore. [35:02.560 --> 35:02.980] They're secure. [35:03.260 --> 35:04.160] We have Google Chrome. [35:05.860 --> 35:08.000] Basically, this means that no website is innocent. [35:08.240 --> 35:12.420] You know, the old thing of having to visit, you know, don't visit an evil malicious website. [35:12.600 --> 35:13.320] You might get infected. [35:13.520 --> 35:16.980] Well, no, any website now on an open network can be infected. [35:17.340 --> 35:19.400] Also, it means websites that don't ask for it. [35:19.440 --> 35:22.180] Like, a lot of people know, don't go to your bank on a Starbucks AP. [35:23.180 --> 35:25.180] But it doesn't have to be your bank anymore. [35:25.700 --> 35:26.060] Anything. [35:27.940 --> 35:29.420] So, SSL will solve it, right? [35:29.640 --> 35:32.240] Well, you still have to be smart enough not to accept a bad certificate. [35:32.480 --> 35:34.000] And users would never do anything insecure. [35:35.020 --> 35:37.280] Obviously, Britney Spears wants me to see her boobs. [35:38.480 --> 35:40.180] And users would never make bad choices. [35:40.180 --> 35:41.720] I mean, that would never happen. [35:41.940 --> 35:44.060] There would never be anything like that. [35:47.000 --> 35:48.260] I wonder why we drank. [35:49.640 --> 35:50.700] Told you it would get depressing. [35:51.200 --> 35:53.100] So, self-signed certificates are obvious to us. [35:54.160 --> 35:56.220] Signed by VeriSign versus signed by VeriSign. [35:56.940 --> 36:00.520] Assuming a user even looks at that, I think most people are just going to click OK. [36:01.040 --> 36:02.600] Because, you know, click OK until tits. [36:03.060 --> 36:03.920] Is there porn yet? [36:04.020 --> 36:04.240] No. [36:04.500 --> 36:04.980] Is there porn yet? [36:05.100 --> 36:05.220] No. [36:05.360 --> 36:05.680] Oh, good. [36:05.800 --> 36:06.360] Now I have porn. [36:08.080 --> 36:10.080] The old users will always find a way to expose themselves. [36:10.360 --> 36:11.080] But we're smart, right? [36:11.900 --> 36:18.980] Well, but if you remember Moxie Marlin Spike's attack, yeah, that was, you know, that would hit all of us running Firefox. [36:19.420 --> 36:23.240] And it would be very easy to implement over Wi-Fi using sessions like this. [36:23.960 --> 36:25.120] Well, they have us to try to. [36:26.120 --> 36:26.340] Yeah. [36:26.720 --> 36:27.400] What's going on? [36:27.520 --> 36:27.680] Yeah. [36:28.400 --> 36:29.540] So, yeah, that one's fixed. [36:29.720 --> 36:30.900] What about the next one that's similar? [36:31.260 --> 36:34.380] How about the Debian random number generator thing from a couple years ago? [36:34.460 --> 36:35.240] That hit all of us. [36:35.900 --> 36:38.420] And, you know, nicely exploitable via this kind of attack. [36:39.880 --> 36:42.620] And, you know, you slip up once. [36:42.700 --> 36:44.680] Once your cache is poisoned, it's going to stay there. [36:44.760 --> 36:46.220] How often do you use public Wi-Fi? [36:46.500 --> 36:48.440] I've ruined Wi-Fi for myself with this talk. [36:48.640 --> 36:49.560] It makes me sad. [36:50.980 --> 36:52.740] So, you know, I use a VPN. [36:53.000 --> 36:55.080] Or, I control a corporate network with an iron fist. [36:55.160 --> 36:56.680] I force my users to use a VPN. [36:56.800 --> 36:58.600] They might want to set me on fire, but damn it, they're secure. [36:58.980 --> 36:59.700] This won't work. [36:59.840 --> 37:03.720] Well, it wouldn't, except your browser has no freaking clue that if you're on a VPN or if you're not. [37:03.900 --> 37:07.720] So, if you get something cached in an secure domain, it will remain around when you're in a secure one. [37:08.720 --> 37:11.440] So, like, how many hotspots have a landing page where you have to agree to the EULA? [37:11.620 --> 37:13.040] How many of those are on HTTPS? [37:13.140 --> 37:14.700] Not many if they're not accepting credit cards. [37:15.080 --> 37:16.280] Unencrypted page on an open network. [37:16.360 --> 37:17.540] That looks like a good target to me. [37:18.780 --> 37:21.180] So, I control your pre-landing page. [37:21.460 --> 37:22.340] I control your browser. [37:22.580 --> 37:28.360] I can make iframes in the background or do AJAQ queries that keep looking for pages I think you're likely to visit in the future. [37:29.560 --> 37:35.880] All you have to do is, you know, go to the top 500 pages I think you're likely to go to, request it in the background and cache a page you've never seen. [37:36.020 --> 37:38.020] So, when you go to it legitimately, it's already owned. [37:39.540 --> 37:45.420] Even better, that JavaScript that's doing that can inspect the page it got and see whether or not it has the little Easter egg we put in it. [37:45.620 --> 37:47.680] And if it didn't, request it again until it does. [37:47.880 --> 37:53.200] So, we can just keep cranking through them as fast as we can issue requests until we get the attack to land for the timing attack. [37:53.940 --> 37:57.520] So, now we have arbitrary sites that we've owned in-cache pre-VPN. [37:58.260 --> 37:58.900] We win. [37:59.440 --> 38:00.480] How about one step further? [38:00.620 --> 38:02.280] VPN gets you to internal pages, doesn't it? [38:02.500 --> 38:05.680] So, if we control your layer 2, can we attack other protocols? [38:05.980 --> 38:06.200] Yeah. [38:06.580 --> 38:08.420] Hey, DNS, that's one packet over UDP. [38:08.760 --> 38:13.860] So, we get a DNS query, flip the QR bit on it, give it an IP, and send it back to you. [38:14.960 --> 38:17.260] Yeah, DNS Pwn and Metasploit, it's in there now. [38:17.620 --> 38:22.360] Same thing as AirPwn, YAML configs, et cetera, map your own DNS names, layer 2. [38:23.160 --> 38:28.240] So, we control the browser, we control DNS resolution, we can ask the browser to keep requesting this as many times as we want. [38:28.580 --> 38:30.860] What stops us from guessing, hey, maybe your site's named intranet. [38:31.040 --> 38:34.600] Here's an IP for intranet, here's some content for it, you should cache that for 10 years. [38:35.280 --> 38:36.420] Nothing stops us from doing that. [38:37.660 --> 38:52.960] So, we, you know, cache you a little bit of page, a little bit of code on intranet that says, get the real intranet page, and then send it to me from an HTTP post to a remote server, and rewrite all that to proxy it, and then crawl the DOM and find all the links that you can get to over your VPN now, [38:53.120 --> 38:55.760] and forward those along, too, all using your browser and JavaScript. [38:58.300 --> 39:00.540] Browsers are great, because they want things to go quickly. [39:00.860 --> 39:02.720] So, let's cache the DNS in the browser, too. [39:03.140 --> 39:04.000] And most of them do this. [39:04.100 --> 39:04.880] It really kind of sucks. [39:05.320 --> 39:08.640] So, you can poison the DNS before they launch their VPN. [39:09.340 --> 39:13.260] And then you can, you know, control DNS names they resolve after VPN. [39:13.500 --> 39:14.160] It's good times. [39:15.400 --> 39:16.380] What else has cache? [39:16.500 --> 39:18.280] Fun fact, Flash maintains its own cache. [39:18.720 --> 39:24.340] I found this out when they broke volume control on Linux, and everybody went, it's fixed, and it didn't work for another six months. [39:24.480 --> 39:25.640] And I'm like, oh, it has its own cache. [39:30.550 --> 39:30.910] Okay. [39:31.390 --> 39:34.030] So, so many of these smartphones are now general purpose computers. [39:34.730 --> 39:38.890] You know, really complex browsers, you get like versions of Opera on there, and Safari, and everything else. [39:39.590 --> 39:44.930] Typically for lower bandwidth networks, and very happy to cache data because of these lower speed connections. [39:45.350 --> 39:47.750] Of course, all the smartphones are on cell connections, right? [39:47.830 --> 39:49.290] Nobody is using the wireless network. [39:49.410 --> 39:51.510] They're all in your 3G phones, right? [39:52.670 --> 39:55.410] Yeah, well, I won't be able to see you there, really. [39:55.710 --> 40:04.170] Well, it's not like, you know, the 3G ever fails, and you have to, you know, go over to other wireless services that might be around in your local coffee shop or conference. [40:04.850 --> 40:07.630] Or maybe you picked up your iPhone by the wrong corner. [40:11.840 --> 40:13.520] Smartphone users used to go into Wi-Fi. [40:13.980 --> 40:17.620] You know, they'll automatically connect in when they get home, and sync their mail, or whatever. [40:18.000 --> 40:20.940] They prefer power, speed, whatever reasons. [40:21.120 --> 40:24.260] But, you know, maybe we could help them along into going into their Wi-Fi things. [40:24.520 --> 40:27.260] It's not like, you know, you couldn't find things. [40:27.820 --> 40:29.720] Not that you should go to an import site. [40:29.880 --> 40:33.640] Not that you should buy an illegal cell phone jammer and force victims to use Wi-Fi. [40:35.000 --> 40:38.420] And no one would ever do something illegal to break into your network, right? [40:38.680 --> 40:39.720] I mean, that would be... [40:39.720 --> 40:40.160] Wrong. [40:40.340 --> 40:40.580] Wrong. [40:40.920 --> 40:41.280] Very wrong. [40:44.180 --> 40:49.100] How many of your users, or more quickly, your executives, carry their smartphones between the offices and the airports? [40:50.460 --> 40:53.220] Gee, where do I get really bored a lot of times? [40:55.040 --> 40:59.940] Um, it took me a long time, because there's no manual in an iPhone box. [41:00.280 --> 41:03.680] You know, I have an iPhone, there's no manual in the box that tells you how to clear the cache on an iPhone. [41:03.800 --> 41:06.360] You can get it drilled down to like a bunch of menus. [41:09.580 --> 41:10.840] So what else can we do with layer 2? [41:11.400 --> 41:12.160] DHCP is good. [41:12.900 --> 41:16.540] A smart AP can filter DHCP so that only authorized servers hand it out. [41:17.800 --> 41:20.980] But if we're talking directly to clients, same thing as DNS. [41:23.580 --> 41:24.820] We're running a little short on time. [41:25.380 --> 41:26.420] So another fun attack. [41:26.620 --> 41:28.540] We can use a similar trick to append it to streams. [41:28.780 --> 41:31.860] Instead of hijacking a stream in the middle, so what does an HTTP stream look like? [41:32.800 --> 41:36.400] Handshaky stuff, some data, headers, new line, data, fin. [41:36.640 --> 41:37.900] So what happens if we beat the fin? [41:38.120 --> 41:39.460] Well, we keep controlling the socket. [41:39.620 --> 41:40.540] We continue writing data. [41:40.740 --> 41:47.540] The client drops the, uh, the, uh, the, uh, the, the fin, because we already accelerated past that. [41:47.920 --> 41:55.200] And, uh, fun fact, most browsers really don't care if you put script after HTML, and they also don't really care about the HTTP content length field in the HTTP headers. [41:55.320 --> 41:56.480] They'll keep processing it. [41:56.880 --> 41:59.220] So you can defeat server filters by pending conflicting content. [41:59.220 --> 42:01.800] You can poison stuff going from the client to a remote server. [42:01.960 --> 42:04.540] You can poison stuff going to the client from a remote server. [42:05.020 --> 42:08.180] Uh, things like the GIFR attack is a, a jar file appended to a GIF. [42:08.600 --> 42:10.620] Uh, since zip can be appended after other content. [42:11.120 --> 42:13.180] Uh, how this happens depends on the browser. [42:13.360 --> 42:18.320] But if you had a good Java exploit, you could tack it on after a GIF and hope the, the browser's Java plugin loads it. [42:18.820 --> 42:20.380] Uh, let's just sneak content in that way. [42:20.960 --> 42:24.400] Um, this is kind of just a little gimmick, because beating the fin is really hard to do. [42:24.520 --> 42:25.380] It doesn't work very often. [42:25.380 --> 42:32.580] It makes HTTP 1.1 really mad when it tries to do the, uh, the, the, the, the multiple data, uh, multiple queries per socket. [42:32.860 --> 42:34.120] Uh, and you can't control caching. [42:34.240 --> 42:35.780] But still, if it works sometimes, it's still fun. [42:36.840 --> 42:39.220] Um, Lorcon doesn't do encryption yet. [42:39.400 --> 42:39.840] It will. [42:40.540 --> 42:41.320] Uh, WEP is easy. [42:41.540 --> 42:47.160] WPA is monitorably more difficult for PSK, but there's still ways to do it if you know the PSK. [42:47.520 --> 42:50.780] Uh, so PSK uses one secret, shared by everyone. [42:50.940 --> 42:53.480] They all get their own, uh, second key when they sign in. [42:53.560 --> 42:57.200] But if you know the PSK, and you watch them join, then you can start decrypting their traffic. [42:57.720 --> 43:00.080] Uh, lots of conferences use WPPSK. [43:01.260 --> 43:03.440] It's... someone has a phone call. [43:04.240 --> 43:09.940] Uh, lots of, uh, websites use PSK, but, uh, or lots of conferences, uh, it's good now. [43:10.240 --> 43:11.640] Hopefully we'll stop that trend. [43:12.580 --> 43:13.900] Um, skip ahead. [43:14.220 --> 43:15.440] We'll try to have a little time for questions. [43:15.860 --> 43:17.720] Uh, there's lots of opportunities for fuzzing with Lorcon. [43:18.040 --> 43:20.300] Um, you can do packet assembly with that. [43:20.500 --> 43:22.220] Uh, it's really hard to detect these. [43:22.360 --> 43:23.500] The attacker's not spoofing an AP. [43:23.500 --> 43:26.000] Most IDS's go, hey, there's a bunch of beacons from this AP. [43:26.140 --> 43:26.640] I don't know. [43:27.060 --> 43:30.080] Or, you know, a bunch of beacons from a place where I know that my AP isn't. [43:30.300 --> 43:35.840] Uh, but to detect these attacks, the IDS has to know every packet being legitimately sent, and it has to be able to see the packet in the air. [43:37.320 --> 43:47.060] Uh, if the IDS can even see it, I mean, I could be sitting near you in a coffee shop with a really low power card with a directional antenna aimed at you that pretty much nothing else is ever going to see. [43:47.560 --> 43:49.240] Uh, wireless IDS doesn't have much of a chance. [43:49.360 --> 43:50.940] Wired IDS never sees the malicious packets. [43:50.940 --> 43:57.740] So they might see, you know, a client sending a couple of out-of-sequence errors back, but, hmm. [44:00.540 --> 44:02.460] So we've more or less figured out how to defend access points. [44:02.600 --> 44:03.480] It's hard to defend clients. [44:03.640 --> 44:07.680] It's really hard to defend clients when we let them go off into the world and use crappy unsecured access points. [44:09.160 --> 44:10.900] So such you think you can trust, you can't. [44:11.140 --> 44:12.660] Spiked attacks we can make stay resident. [44:12.800 --> 44:14.840] Your users might be bringing something nasty back with them. [44:15.680 --> 44:17.240] Uh, this is bad even for us. [44:17.360 --> 44:18.940] Normal people don't stand a chance at all. [44:19.100 --> 44:20.020] We may already be screwed. [44:20.360 --> 44:21.140] Who wants to go drinking? [44:23.860 --> 44:24.900] You can use a VPN. [44:25.180 --> 44:26.200] It's hard for a lot of people. [44:27.920 --> 44:29.640] But, uh, you can use SSH. [44:30.160 --> 44:31.740] Again, most people aren't going to. [44:31.980 --> 44:33.520] You can force updates on your users. [44:33.700 --> 44:34.640] Easier said than done. [44:35.000 --> 44:35.880] Mandate policies. [44:37.060 --> 44:39.720] Um, you can just not give out laptops if you run a corporate network. [44:40.240 --> 44:41.060] I don't go well. [44:41.460 --> 44:42.880] We pretty much don't have time for this. [44:43.020 --> 44:44.080] We'll make sure the slides get posted. [44:44.400 --> 44:49.520] Uh, pretty much WPA has a problem where you have to distribute the certificate ahead of time if you're going to do certificate-based authentication. [44:50.060 --> 44:52.340] So how do you get certificates to people securely? [44:52.620 --> 44:55.340] You can't put them on a public website because I'll just replace them. [44:55.860 --> 44:58.480] You can't, you know, here, run this flash drive. [44:59.580 --> 45:01.000] Here, download this software and run it. [45:01.060 --> 45:01.920] It'll configure your network already. [45:02.220 --> 45:02.480] Oh. [45:03.840 --> 45:06.420] So, um, we're kind of screwed right now. [45:08.560 --> 45:14.120] Uh, so you can protect yourself by manually enforcing security domains with your browser. [45:14.320 --> 45:16.000] Use different browsers for login and normal use. [45:16.280 --> 45:20.600] Uh, you know, use links to agree to the EULA and then fire up your VPN or your SSH tunnel. [45:21.180 --> 45:22.520] Uh, manually clearing cache. [45:22.600 --> 45:24.400] I don't like that because it means the attacks already hit you. [45:25.240 --> 45:28.260] Uh, never keep windows open between security domains. [45:28.480 --> 45:34.380] So even if, like, even if you disable cache and browse in privacy mode, if you keep the window open, then the JavaScript still resident in it. [45:34.740 --> 45:37.420] And when you go back to your corporate network, it'll still be there running. [45:38.240 --> 45:47.100] Uh, special thanks to, uh, to our snake and render man, uh, HDM, uh, toast, uh, Jesse Burns and anyone else who, uh, I've talked to over the last couple of months developing this. [45:47.900 --> 45:50.340] And, uh, I think we probably have, what, five minutes? [45:50.640 --> 45:51.600] Hey, five minutes. [45:51.600 --> 45:52.300] I just went up. [45:52.540 --> 45:54.220] So we can handle, you know, a couple of questions. [45:54.520 --> 45:56.780] I think there's mics in the middle here, so. [45:57.720 --> 46:00.540] Maybe he's got questions, accusations, whatever. [46:00.740 --> 46:02.400] Or everyone just stares at us. [46:02.980 --> 46:04.720] And we all shuffle uncomfortably. [46:04.980 --> 46:06.120] Do a demo on the network. [46:06.260 --> 46:07.040] We don't have the stuff set up. [46:07.120 --> 46:10.260] How does IPv6, the microphone, the microphone. [46:10.360 --> 46:12.840] Uh, the question was, how does IPv6 protect against this? [46:13.520 --> 46:14.860] Uh, affect this. [46:15.160 --> 46:15.880] Um, not much. [46:16.720 --> 46:20.460] And we haven't seen enough IPv6 deployed yet for it to be relevant. [46:20.680 --> 46:26.140] Um, I haven't looked too deeply into how IPv6 protects the, uh, the, the sequence numbers if it does. [46:27.000 --> 46:32.080] Um, I still think we're probably, what, four years off from seeing widespread deployment of that. [46:33.660 --> 46:34.480] We'll let you know. [46:34.840 --> 46:41.680] This is probably a question that everybody knows, but what is the legal issue of actually sniffing packets? [46:41.840 --> 46:42.660] I mean, not even sniffing. [46:42.800 --> 46:44.880] The sniffing the L2 packets. [46:45.680 --> 46:48.620] Okay, so the question was, what's the legal repercussions of sniffing the L2 packets? [46:48.860 --> 46:54.360] Um, I do not yet know of a court case in the U.S. [46:54.460 --> 46:55.660] that proves this one way or another. [46:56.360 --> 47:05.980] Um, actually, the latest release of Kismet, I added a new, uh, field in the config that, uh, not only doesn't log data, but as soon as it detects a data packet, it truncates it. [47:06.100 --> 47:09.640] So it will look at the MAC addresses that are unencrypted and then throw everything away. [47:09.780 --> 47:11.280] It won't even look at the IP data. [47:11.540 --> 47:17.540] So although I have no true legal backing to say, I think that's the safest way to do it. [47:17.640 --> 47:23.800] If you're sniffing on networks that you don't own and you're worried that, uh, turn that option on, it will not look at any data at all. [47:23.940 --> 47:36.580] It will only look at the, the announcement frames and the control frames, um, which I, technically there's no way they can say that that's not legal because that's what your system does all the time to create that list of networks near you. [47:36.840 --> 47:40.720] Uh, but who knows what sanity has to do with our legal system? [47:41.360 --> 47:44.160] Um, it's going to be interesting to see what happens with Google. [47:44.360 --> 47:51.580] Uh, I know Google's lawyers said that, yeah, we're real sorry we did this, but according to the, our interpretation of the U.S. law, it wasn't actually illegal. [47:52.500 --> 47:54.720] Uh, but that hasn't gone to court yet either. [47:55.760 --> 48:02.740] Um, don't put yourself in the situation where the cops come and get you for sniffing Wi-Fi. [48:02.980 --> 48:05.040] I think that's what we learned here today. [48:07.120 --> 48:08.580] Okay, one more at least. [48:08.880 --> 48:15.540] Um, when you were talking about, uh, smartphones, you said, yeah, they have the option of just using their 3G network or whatever. [48:16.060 --> 48:17.820] And then, so it's just forced them off it. [48:17.960 --> 48:25.840] But it seems like, uh, it should be possible given the right hardware to set up a man in the middle attack on a person's use of the 3G network as well. [48:26.020 --> 48:27.020] What's the state of that? [48:27.520 --> 48:29.840] Uh, uh, 2G, yes. [48:30.140 --> 48:33.520] 3G, I believe, has not yet been cracked to the point that you can do that. [48:33.720 --> 48:41.320] However, uh, DEFCON, um, Chris Padgett from hardware is giving a talk on doing attacks against GSM. [48:41.780 --> 48:45.840] Uh, see that or listen to it when it comes out. [48:46.000 --> 48:48.900] And I think there's some new stuff coming out in there, although I'm not sure. [48:49.300 --> 48:52.180] So, yes, theoretically, you can attack 3G. [48:52.640 --> 48:56.940] Uh, it... You can generally assume that sooner or later something like that's gonna happen, so. [48:57.200 --> 49:04.000] Um, I strongly suspect 3G is one of those things where government actors can go and do something to you. [49:04.540 --> 49:10.980] Uh, then again, they could always just subpoena AT&T and patch into fiber in San Francisco and man in the middle of your sessions that way. [49:11.580 --> 49:20.100] Um, yeah, I, I think 2G, uh, is now vulnerable for a cost that we could afford. [49:20.460 --> 49:27.220] Uh, I have not heard of 3G having that yet, but, you know, uh, if you're doing something secure, don't do it over wireless. [49:30.730 --> 49:34.290] Is there any way to scan the cache looking for malicious, uh, content? [49:34.670 --> 49:35.590] Is there any way to scan the cache? [49:35.730 --> 49:36.190] Uh, yeah, grip. [49:37.370 --> 49:41.990] I mean, uh, is what comes to mind first. [49:42.270 --> 49:46.450] If, if you have any inkling what you're looking for, you can just go to the, the go to your cache directory and start grepping. [49:46.750 --> 49:48.190] I kind of, I kind of meant automated. [49:48.610 --> 49:51.170] Automated, um, cron grep. [49:52.430 --> 50:01.990] Uh, I don't know of any tools that, uh, I don't know of any Firefox plugins or anything yet that look for this kind of thing, although that might be an interesting thing for someone to write. [50:02.210 --> 50:06.210] We got one minute, so we, uh, you're probably the last question, because you're the only one I see standing. [50:06.850 --> 50:08.910] I have a question about, uh, encryption. [50:09.630 --> 50:11.930] Um, encryption on a wireless network. [50:12.130 --> 50:22.950] Is, is it true that it encrypts so that, uh, hosts that are not attached to the network can't see it, but hosts that are in the network can see each other's traffic? [50:23.670 --> 50:25.290] Depends on the type of network. [50:25.730 --> 50:32.430] Uh, WEP uses one key that everybody has, and if you know that WEP key, you can decrypt all traffic on the net that you see. [50:33.350 --> 50:38.610] Uh, WPA, on the other hand, does per-user keying, so inter-user traffic on a WPA network goes to the AP. [50:38.870 --> 50:40.990] One user encrypts it with their key, it goes to the AP. [50:41.090 --> 50:45.510] The AP decrypts it, re-encrypts it with the other, with the destination user's key, and sends it to them. [50:45.830 --> 50:55.690] So, you, even if you know your key exchange on a WPA network, you can't sniff another user's traffic because they have a different key, a different temporal key. [50:55.930 --> 51:02.670] Uh, if it's a PSK network and you know the PSK, then you can try to capture their key exchange and decrypt it with their temporal key. [51:03.030 --> 51:11.390] Uh, if it's using EEP, then that key exchange is protected by SSL, and there's no current attack other than owning the SSL. [51:13.310 --> 51:15.430] So, I think that's it. [51:15.610 --> 51:19.450] Uh, and we will be somewhere probably... We'll be all over the place. [51:19.570 --> 51:21.110] Yeah, we'll be around if anybody has other questions. [51:31.240 --> 51:33.100] Coming up next will be our keynote...