Field report: wifi hacking in practice

Field report: wifi hacking in practice

Experience report: wifi hacking in practice

"Would you please hack our wifi?"

Hello, my name is Jochen Meyer and I work as an IT security consultant at suresecure. I have always had a particular soft spot for IT security, especially for testing security incidents, reverse engineering and malware analysis. In my position as a consultant, I want to support our partners in making the world a little more secure every day. I work with you to develop security concepts or determine where security can be optimised through audits and active checks such as penetration tests or hacking simulations.

An unusual assignment

I wasn't called in to develop security concepts or play malware firefighter. Instead, the partner actively approached us with a request to assess the company's IT security, especially the WLAN. And not just on the basis of a catalogue of questions according to BSI, PCI or similar, but we should actively try to bypass the security mechanisms on site and hack into the WLAN - on the condition, however, that the partner's productive IT landscape is not affected in any way.

Why is this so special?

Penetration tests from the inside and outside are of course our bread and butter, just like security audits. However, in my opinion, being asked to "hack our WLAN" is a whole different ball game. It's not a straightforward job based on a catalogue of measures, but requires a sure instinct - you shouldn't break anything - intuition and, of course, the know-how and technical equipment. You also need to familiarise yourself with the structure of the company - many findings do not relate directly to the WLAN, but to the company structure and even the design of the office space can play a major role. But more on that later.

Equipment is packed

Why actually check the WLAN security?

Depending on the structural conditions of the office building, Wi-Fi may also radiate to the outside and may even be received on the street. If a company only operates a guest WLAN that is completely separate from the network and does not have any interfaces to productive systems, this is not necessarily a bad thing. Provided that productive notebooks and PCs are not given the opportunity to connect to the guest WLAN with their productive systems.

Attackers could possibly simply sit in their car in the car park completely undetected, switch on their notebook and powerful WLAN antenna and get started. If they are successful, they have access to company data without ever having entered the office building.

Don't break anything!

The partner's greatest wish was: Don't break anything! Productive clients should not even realise that I am present, let alone be kicked out of the WLAN or otherwise compromised. An attempt to paralyse one of the WLAN-emitting access points was also undesirable.

So a procedure had to be designed that nevertheless came as close as possible to the following scenario: An attacker tries to hack into the WLAN from outside. I therefore decided to only simulate the hacking and still use the methods that a "normal" attacker would also use. However, I limited this to a single company notebook that was fully under my control. I was given a user name and password for this company notebook and was allowed to use it freely in the productive and guest WLAN. Attacks that were intended to target a specific Wi-Fi client were aimed at this individual notebook.

Instead of acting as inconspicuously as possible like a potential attacker and, for example, cloning the SSID of the productive Wi-Fi and broadcasting it myself, I broadcast Wi-Fi messages such as "SECURITY_CHECK_DON'T_USE" so that no employee had the idea of logging in there.

Image

My hacking notebook was given a face-lift so that it clearly stood out from the conventional company notebooks. As a practical side effect, I was able to test how many people approach me in the company when I walk through the rooms with this notebook and a directional antenna.

The 4 phases

The plan was to divide the analysis into 4 phases. This resulted in the following findings, which are described here briefly - and anonymised, of course.

  1. Assessment of the WLAN: Using Recon tools and based on an interview as well as walking around with a WLAN scanner to check the coverage and range of the WLAN networks.

  2. The hacking or simulation with various hardware and Linux tools.

  3. Assumption: I have penetrated the WLAN with the hacking notebook and have brought along an armada of hacking and sniffing tools. What can I do without being discovered?

  4. Assumption: I have hijacked the company notebook including the login and can access the productive WLAN from there. What can I achieve?

The reception

In my opinion, the reception of a company is already the first sign of the overall security strategy. It can be compared to the guards of a castle who lower and raise the drawbridge.

In the case of my current project, the drawbridge was lowered - to the extent that a large sign on the glass door greeted me even before I reached the entrance area: "Bell defective, please just enter". So you simply enter the property through the main entrance. If the castle guard is still absent, uncontrolled access to the grounds is no longer a challenge.

In my case, reception was virtually manned. The employee was obviously in an intense exchange with his colleague, so I briefly considered simply walking past them and greeting them in a friendly manner. My camouflage clothing, consisting of a shirt and jeans, coupled with a little self-confidence, would have been enough to avoid attracting attention.

But as a polite person, I waited until the two had finished talking, introduced myself and asked to speak to my contact person. They called and picked me up.

As a registered visitor, I was not asked for my name or signature, nor was I given a clear visitor badge. The lack of identification through visible badges makes it extremely easy for unwanted guests to move around the building without attracting particular attention.

Anonymity

The site where I was invited to analyse the situation is one of the partner's smaller external sites with 200 employees. However, due to the company's success and the associated growth, there is now room for more employees at the site than originally planned. To counteract a crowded working environment, open-plan workstations and shared desk solutions were set up. These are located in the centre of the elongated rooms and are surrounded by office and conference rooms.

A high turnover at the shared desk workstations takes place in particular due to colleagues from other locations who use the workstations for a few hours or days. As the company is strongly committed to promoting young talent, there is also a lively flow of students and trainees.

Due to this high turnover, I always had the feeling of being "part of the crowd". I was also always greeted in a friendly manner while I was working - even when I took off my shoes, climbed onto a lounge chair and took photos of the access point mounted on the ceiling.

Max Mustermann

Nobody questioned the fact that I was walking through the corridors with my conspicuously designed hacking notebook and plugged-in directional antenna. Everyone I met greeted me in the usual manner.

The fact that technicians lug around all kinds of equipment to do their work seems to have become a familiar sight. Because at some point, after the 5th or 10th technician, people no longer question their work at all. Or you just assume that the guy with the directional aerial already knows what he's doing and must surely have logged on to reception. He does look strange with his taped-up notebook, but that will be fine...

Remote control

A lack of access control is also a security vulnerability when it comes to the security of the Wi-Fi network. There is some pretty impressive hacking hardware the size of a USB stick. You configure it accordingly, plug it into a victim PC and voilà: The hardware broadcasts its own WLAN network. If I connect to this network as an attacker, I can send any type of input to the hijacked PC - without being physically present. Anything is possible, from harmless disruption of business operations to infiltration of the entire network, especially if the logged-in user has local or global administrator rights.

But even without administrative rights, this is highly likely to be dangerous: you can use simple Windows commands without admin rights to display all the passwords of WLANs that are only protected with WPA2-PSK in plain text .

And if the productive WLAN is only protected with WPA2-PSK and I have the password... Well, jackpot hit, right?

WPA2 - What?

WPA2-PSK is a WLAN encryption method and you have this with every Fritz!Box, Teledat or other routers. A password is entered to connect to the WLAN. Of course, you click on "Connect automatically" so that the password is saved on the PC and can unfortunately also be easily read out.

To ensure that the WLAN client and access point actually talk to each other in encrypted form, but also really understand each other, the corresponding encryption is agreed between the client and router using a handshake. I don't want to go into this handshake in detail, as there are entire treatises on this on the Internet and it would go beyond the scope of this article.

However, you can record this handshake with special tools and thus at least get the hash value of the Wi-Fi password, i.e. a mathematically coded variant of it. The trick is that the handshake is performed every time a WLAN client wants to connect to the AP - even if the connection is briefly interrupted. And with a special tool, it is possible to "kick" clients out of the WLAN remotely without WLAN access data. You then capture the handshake and obtain the hash of the password.

If you then have a password collection with the 1,000 or 5,000 most frequently used passwords worldwide, you might be lucky to find the password that corresponds to the hash you have sniffed. Or you could run a cracking tool over it and eventually come up with the right password.

Radius

The productive WLAN was additionally secured with RADIUS. Here, too, for anyone who is particularly interested: Please refer to the Internet ????

In any case, a user name and the corresponding password must be entered to access the WLAN with an external notebook - that of a Windows user. The RADIUS server checks whether the data entered actually corresponds to that of an AD user in the domain and then sends the client on to negotiate the encryption modalities.

With a company notebook, you already log in locally with the Windows user anyway. Therefore, further authentication is not necessary to connect to the WLAN. You just connect and you're in.

And if a password request does come up? Well, it could be that an attacker has cloned the Wi-Fi with a "rogue access point" and is waiting until someone doesn't notice this difference and actually enters their user name and the corresponding password. After all, the WLAN is called correctly and the fact that you are not automatically logged in but prompted to enter the user data is surely just a mistake, right? Unfortunately only the hash of the password, as with WPA2, but here too password lists and a lot of patience help to get the actual password. I then used my hacking notebook in the productive WLAN.

Of course, I stuck to the agreement and chose a conspicuous name for my "safety net WLAN" such as "SICHERHEITS_TEST_NICHT_BENUTZEN". The effect was the same - by trying to connect to the WLAN from the productive client, I got the user name and NTLM hash. And was then "in" the productive WLAN.

Image

Alternatively, you could also use the remote control USB device mentioned above to delete all WLAN profiles from the PC with simple commands and set up mine as the only known WLAN connection. The PC restarts, automatically connects to my WLAN, asks for a user name and password, and the user enters it.

The guest WLAN

The partner also operates a guest WLAN. I received a printout with the user name and password for the guest WiFi and had to document this as a negative finding.

Why? For three reasons:

  • The company logo was displayed in large letters on the note.

  • The token was valid for more than 48 hours.

  • There was no limit to how many devices you could log into the guest WLAN with this user data.

Not bad? Okay, the following scenario: An external person visits the company and is given guest Wi-Fi access. He leaves again and throws the note away on the way or leaves it somewhere. Then someone finds the piece of paper and there - under the large company logo - you can see the user name and password and that the token is still valid for almost a whole day or longer. And he finds out that he can also receive the WLAN from the street. Yes, who wouldn't want to have a snoop?"

You might say: "So what? It's only guest WLAN. Then he can surf for free without using up the data volume on his mobile phone." But: Can you guarantee that no company notebooks are roaming around in this guest WLAN? Users may not be allowed to do some things in the productive WLAN. For example, access to the Internet radio is blocked or something similar. So you just go to the guest WLAN and listen to Internet radio there.

To make matters worse, the guest WLAN has the same name at all locations and the clients are packed into the same network and can therefore communicate with each other regardless of their location. So once I am in the guest WLAN with the access data I have found and use my tools to find vulnerabilities in one of the company notebooks, I am in and may even be able to install a back door so that I still have access to the notebook when it is in the productive WLAN. Then I also have access to the productive WLAN.

Luckily, it was not possible to reach and scan the productive WLAN with port IP or vulnerability scanners simply from the guest WLAN IP address.

No proxy available

Another finding I stumbled across without it being my job: The company does not use a proxy in both the guest and production networks. This means that users can surf wherever they want, even on private web mailers. The lack of proxies also means that if an attachment from a fake Amazon or UPS invoice is opened from the GMX account, only the local virus scanner can intervene before the user's own system and all associated network drives are encrypted by the ransomware they have downloaded.

Can you really trust the local virus scanner that much? Can you be sure that it really finds all malware - even unknown malware that has not received a signature from the virus scanner operator - and can block it in good time?

The answer is: No. It is always good for security to place an additional instance between the user and the Internet, which possibly also regulates that users may only surf on websites that have been categorised as "OK" by the company.

So how can you better secure the WLAN?

Some findings can be fixed quickly, some take a little longer.

  • Reception: Repair the doorbell and only open the door if the reception is manned.

  • Access: Card reader, barrier or similar between reception and productive offices.

  • USB: Introduce USB device control and block unknown sticks.

  • WPA2-PSK: Avoid using it in companies if possible.

  • Radius: Use certificates instead of user names/passwords.

  • Security awareness: Train employees in security matters.

  • Guest WLAN: Shorten token runtime, remove company names and prohibit communication between clients.

Conclusion

Each finding on its own is not particularly bad. But if you take them all together, it all adds up.

I walk past reception, insert a hacking USB stick into a PC and I'm in. Or I pick up a printed token from the rubbish for the guest Wi-Fi, which is kindly still accessible on the street, catch a company notebook that hasn't been properly patched, which at some point reconnects to the productive Wi-Fi and I'm also in. Or I use the USB stick to set the client to connect to my WLAN automatically, get the user name and crack the password and I'm in. There are so many possibilities.

WLAN hacking is not just about the WLAN. Sometimes the use of hacking tools is not even necessary and it is essential to take appropriate organisational measures and train employees.

I would personally recommend such a security check to any company that maintains a productive WLAN network to which clients are allowed to connect.

Max Mustermann