[00:00.930 --> 00:01.660] All right. [00:02.340 --> 00:03.030] Thank you. [00:03.220 --> 00:03.700] Feedback. [00:04.360 --> 00:07.560] The name of this panel is Fun with 802.11b. [00:08.490 --> 00:13.820] Sitting next to me, we have Dragorn, who's author of Kismet, which is a wireless network sniffer. [00:14.080 --> 00:16.140] So if you enjoy sniffing, talk to this dude. [00:16.860 --> 00:17.980] We also have Porkchop. [00:18.180 --> 00:20.940] You may have seen him in the movie Freedom Downtime. [00:21.240 --> 00:23.400] He spent years of his life editing that film. [00:23.780 --> 00:28.040] And we also have Static Fusion on the end, who is an active war driver. [00:28.740 --> 00:30.080] Guys, take it away. [00:34.160 --> 00:35.280] Which one of these is on? [00:35.400 --> 00:36.020] Is any of these on? [00:37.120 --> 00:37.360] No. [00:38.040 --> 00:38.520] That one's on. [00:40.900 --> 00:41.340] Yeah. [00:43.620 --> 00:44.540] All right. [00:45.380 --> 00:46.480] Well, welcome, everyone. [00:47.240 --> 00:47.840] Packed house. [00:49.160 --> 00:58.260] We would like to start this talk off with talking a little bit about the theory of 802.11, how it works, what the packets are like, different types and so on and so forth. [00:58.960 --> 01:01.720] So some of you may be bored for the first 20 minutes. [01:02.360 --> 01:09.980] After that, we would like to show you what we have up here, what it does, and then go into some of the actual uses for this technology. [01:11.080 --> 01:13.700] And hopefully have some funny stories along the way. [01:14.060 --> 01:14.600] We'll see. [01:16.320 --> 01:19.820] And biggest guy knowing on theory is Dragorn here. [01:19.820 --> 01:20.340] Okay. [01:20.880 --> 01:23.240] Wireless networks have been around for quite a while now. [01:24.380 --> 01:25.840] Hams did it with packet radio. [01:26.260 --> 01:30.160] But it wasn't until 802.11b that things really began to take off for the consumer market. [01:30.580 --> 01:37.040] Since you can pick up a network access point now for about 120 bucks, you can get cards as cheap as 40 bucks now. [01:37.120 --> 01:39.700] A lot of people are setting up and they don't really have any idea what they're doing. [01:40.260 --> 01:43.400] Which means we can go find out for them. [01:46.600 --> 01:49.180] There's two main modes that 802.11b works in. [01:49.560 --> 01:52.380] There's also 802.11a and 802.11g is being defined. [01:52.900 --> 01:57.300] They all work basically the same fashion at different frequencies and different speeds. [01:58.680 --> 02:02.160] 802.11b operates either in infrastructure mode or in ad hoc mode. [02:03.740 --> 02:07.680] Actually, as you can see from behind us, there's a lot of people here working in ad hoc mode. [02:11.260 --> 02:15.180] With ad hoc mode, it's more of a mesh where every computer can see every other. [02:16.140 --> 02:19.540] And you just... How are you doing? [02:20.240 --> 02:21.220] Sorry by last time. [02:31.950 --> 02:37.030] With ad hoc networking, you can bring it up without an infrastructure mode, without an access point. [02:37.250 --> 02:42.850] You just have any number of laptops in an area, all configured to use the same network name, and they just all talk to each other. [02:43.010 --> 02:44.090] It's good for... [02:44.850 --> 02:47.930] Small offices and things like that, but it's not as common. [02:49.250 --> 02:53.810] Some of the downsides to ad hoc mode is that every computer has to be able to see every other. [02:54.030 --> 03:02.650] If you've got three computers, if A can see B and B can see C, and A can't see C, then it's not going to work. [03:02.650 --> 03:06.050] Which is a big down point for big companies and big layouts. [03:06.730 --> 03:17.910] With infrastructure mode, you buy an access point, like a Linksys one or D-Link one or Cisco, and all the computers talk to that one and it redistributes the connections back out. [03:18.190 --> 03:22.410] So you just need the one access point and everything talks to that. [03:24.730 --> 03:26.070] Do you want to say something? [03:29.310 --> 03:41.210] The frequencies themselves are in the 2.4 gigahertz range, which is unfortunately the same range as microwaves and a lot of other consumer equipment, which creates some noises in the frequency range. [03:42.110 --> 03:45.150] And there's 12 channels in the U.S. and 14 internationally. [03:47.030 --> 03:50.870] Channels overlap a small percentage between channels. [03:51.270 --> 04:02.810] So if you're on channel 6, you can see some of what's on channel 5 and some of what's on channel 7, which means if you're setting up a network in a busy area, you have to be sure to set up different segments of it in different channels. [04:04.230 --> 04:15.150] As far as identifying networks themselves, each network has a service set identifier, or SSID, which is what's displayed... well, it's basically what's displayed under name there. [04:15.790 --> 04:18.290] And each network has a unique SSID, and it's how it's identified. [04:25.250 --> 04:29.470] In this particular screen, we're also seeing what type of network it is. [04:29.690 --> 04:37.270] The second column here, T for type, shows HDPH... there's an A at the bottom. [04:37.650 --> 04:38.910] A is an actual access point. [04:39.830 --> 04:41.410] H for ad hoc, D for data. [04:43.590 --> 04:49.590] As we said, there are different packet types, and so it's fairly easy to tell which type of a network these are. [04:52.070 --> 04:54.650] Access points will beacon every once in a while. [04:54.810 --> 05:00.770] There are packets sent once every thousandth of a second, I believe it is? [05:00.770 --> 05:01.890] It's configurable. [05:02.090 --> 05:03.870] Normally, it beacons a hundred times a second. [05:03.990 --> 05:04.690] A hundred times a second. [05:05.870 --> 05:14.310] Sending out information like what this access point is, what its name is, all sorts of information you would need to connect to the network. [05:15.350 --> 05:20.950] And there are many things that manufacturers do to this information to try and make their network more secure. [05:21.710 --> 05:26.490] Most notably, not sending beacons at all, which will... it's called a cloaked network. [05:28.590 --> 05:41.070] However, there are other types of packets, namely association packets, where one client associates to the access point, which have the SSID in it whether or not the network is cloaked. [05:42.030 --> 05:51.110] So, you can extract the name of a network despite the fact that the manufacturer is not letting you have it or not wanting you to have it by cloaking the network. [05:53.510 --> 06:04.290] And we don't have any here, but you would see brackets next to no SSID until it found the SSID in this particular program. [06:04.290 --> 06:06.590] And it would list the SSID for all to see. [06:08.490 --> 06:17.350] For example, when the H2K2 was setting up, the access points were named KNOCK, K-N-O-C-K. [06:17.450 --> 06:19.910] And they weren't beaconing, probably because they didn't want people on it. [06:20.070 --> 06:22.430] It took about 15 seconds. [06:22.950 --> 06:24.610] Fifteen, thirty seconds to pick them up. [06:24.850 --> 06:31.390] To find the SSID and, of course, log in and screw around with the H2K2 network as they were still setting up. [06:33.130 --> 06:34.090] Other things. [06:36.230 --> 06:37.230] Channels listed. [06:38.790 --> 06:39.890] Number of packets. [06:40.530 --> 06:41.070] Separate flags. [06:41.190 --> 06:41.870] Lots of different flags. [06:41.990 --> 06:42.930] Explain the flags a bit. [06:44.050 --> 06:44.650] Okay. [06:45.230 --> 06:51.450] For specific to this particular piece of software, which is Kismet, it uses the flags to extract information about the network. [06:51.650 --> 06:54.910] It tells if it's a factory default or if it's been a... [06:54.910 --> 06:57.190] Or how it detects the IP range. [06:57.190 --> 07:01.870] It'll extract the IP range from traffic from UDP, DHCP, ARP, TCP. [07:04.690 --> 07:11.430] And a lot of people figure just because they're not beaconing or just because they're cloaking the SSID, you can't figure out who they are or what they're doing. [07:12.270 --> 07:14.670] But this will pull the IP right out of it anyway. [07:17.050 --> 07:19.650] Finally, one thing to note here is the weak packets. [07:21.490 --> 07:24.530] Nowadays, current access points will not send weak packets. [07:24.670 --> 07:30.410] They actually check... the firmware checks each packet to see if it is cryptographically weak or cryptographically weak. [07:31.150 --> 07:32.390] If it is, it won't send it. [07:33.810 --> 07:38.010] And... but there are still a lot of old access points out there which still send weak packets. [07:38.210 --> 07:40.010] So Kismet will sense that. [07:40.470 --> 07:43.170] So far there have been none and I wouldn't expect any. [07:43.170 --> 07:45.790] Well, all it takes is one weak computer on a network. [07:46.130 --> 07:57.830] If all of your equipment is patched up to the latest stuff and you have one desktop or one laptop that's still generating weak packets, that's all that's needed to get the entire network exposed. [07:58.110 --> 07:59.470] That is, of course, if you're using WEP. [08:00.610 --> 08:11.050] A lot of people or a lot of large installations are no longer using WEP or they are using WEP in addition to VLANs which can be encrypted separately. [08:11.250 --> 08:11.790] And VPN. [08:11.790 --> 08:18.030] VPN, that's what I meant to say, not VLAN but VPN which is not as attackable. [08:20.310 --> 08:22.650] Getting 637 packets, that's a lot of packets. [08:23.030 --> 08:23.510] That is. [08:27.330 --> 08:31.450] Since we've shown some of the software, we might as well discuss how packets are detected actually. [08:31.990 --> 08:33.770] There's two main ways of detecting networks. [08:34.170 --> 08:36.370] Different software uses different methods of detecting them. [08:52.130 --> 08:53.510] I'll agree with one of those statements. [08:58.460 --> 09:01.020] Okay, maybe running that in the background wasn't such a good idea. [09:02.380 --> 09:08.640] So, anyway, there are two ways, two types of sniffing or wardriving or whatever you want to call them, programs. [09:08.880 --> 09:10.520] Two different ways you can sense networks. [09:11.440 --> 09:12.600] Kismet uses passive. [09:12.940 --> 09:13.780] Explain passive. [09:14.040 --> 09:14.220] Okay. [09:14.420 --> 09:20.480] Passive is probably the most effective way of detecting networks because instead of having to be... [09:20.480 --> 09:21.680] We'll talk about active first. [09:21.900 --> 09:22.840] Okay, let's talk about active. [09:23.220 --> 09:25.780] With active sniffing, it's not really sniffing. [09:25.840 --> 09:27.760] It's looking for networks that allow it to connect to them. [09:27.760 --> 09:32.840] So, you drive around and your computer constantly sends out a packet saying, let me into the network. [09:32.980 --> 09:33.620] It's a probe request. [09:33.920 --> 09:37.400] And if an access point allows anonymous connections like that, it'll respond. [09:38.040 --> 09:40.300] And it'll allow you in and the software will record it. [09:40.440 --> 09:42.300] And this is basically how NetStumbler works. [09:42.400 --> 09:46.300] They use a few other tricks to make it a little more effective than that. [09:46.300 --> 09:53.520] But if they're not in transmission range of a network or if the network isn't allowing unauthorized or random connections... [09:55.820 --> 09:59.140] If the network isn't allowing unauthorized or random connections, it won't let you in. [09:59.320 --> 10:01.240] And it won't be detected with active sniffing. [10:02.000 --> 10:08.460] With passive sniffing, it's more like tuning a radio to a radio station and just listening to what there is. [10:09.400 --> 10:11.360] You just capture every packet from the card. [10:11.360 --> 10:13.980] So, all it takes is a single packet to detect the network. [10:15.380 --> 10:19.220] And it will allow you to record the... [10:24.720 --> 10:24.980] Hmm. [10:26.180 --> 10:26.640] Wow. [10:28.860 --> 10:29.380] 149. [10:33.710 --> 10:34.570] Where were we? [10:34.730 --> 10:36.430] We were talking about passive. [10:36.650 --> 10:36.810] Right. [10:40.050 --> 10:42.250] Until we were distracted by the crowd. [10:44.210 --> 10:47.050] But with passive sniffing, you can record all the data on a network. [10:47.050 --> 10:49.310] You can record if a network is cloaked. [10:50.330 --> 10:53.710] And all it takes to decloak a network is a single data packet. [10:54.090 --> 10:59.670] So, a lot of companies and a lot of individuals cloak their networks thinking, if I don't beacon, nobody will see me. [10:59.790 --> 11:01.570] And it's true of active sniffers. [11:01.730 --> 11:05.910] But if you create noise in the air, someone's going to be able to see it. [11:06.130 --> 11:11.670] Of course, you are completely invisible if you don't have any probes being sent and... [11:11.670 --> 11:14.790] Or so you don't have any beacons being sent and no one's using the network. [11:14.790 --> 11:20.290] In that case, there's no transmissions at all and the network is invisible for all intents and purposes. [11:21.810 --> 11:22.630] But useless. [11:23.990 --> 11:24.770] Can't use it? [11:24.830 --> 11:25.790] Yes, it is kind of useless. [11:28.070 --> 11:28.970] What else do you have? [11:29.130 --> 11:30.410] Well, you've seen Kismet running. [11:30.710 --> 11:35.090] Statix brought NetStumbler and several other active detection methods with them that run on Windows. [11:35.090 --> 11:36.770] Do you have a... [11:36.770 --> 11:37.530] What are the names? [11:38.450 --> 11:39.910] Uh, I'm using... sorry. [11:42.510 --> 11:44.210] Okay, I'm using NetStumbler. [11:45.690 --> 11:46.730] Lean in your mic. [11:47.150 --> 11:48.170] Move it closer. [11:48.470 --> 11:48.650] Move it closer. [11:48.970 --> 11:49.330] Move it closer. [11:49.330 --> 11:49.730] Move the mic closer. [11:50.570 --> 11:50.950] Whoa. [12:05.010 --> 12:07.690] Okay, so I'm using NetStumbler here. [12:08.470 --> 12:16.530] Uh, it's similar to Kismet in how it's sniffing the network traffic, but as you can see, I'm not picking up quite as much as, uh, Dragorn is over here. [12:17.310 --> 12:23.550] Uh, another program I've found to use is the wireless USB configure on older Prism cards. [12:23.750 --> 12:27.470] Because if you're using a Prism chip, you're not able to use NetStumbler. [12:27.830 --> 12:33.810] So, if you use the software that comes with your card, it's not as effective for picking up ad hoc modes. [12:34.190 --> 12:35.510] But you can, you know, search here. [12:40.790 --> 12:43.030] It's actually the first time I've seen NetStumbler running in person. [12:45.710 --> 12:49.090] Like right now, you can only see, uh, two different networks I can connect to. [12:49.230 --> 12:52.670] So it's not quite as powerful as the other sniffing. [12:52.770 --> 12:56.010] But if you have a Prism chip, it's an effective way to do it from Windows. [12:57.010 --> 13:00.310] We should talk, uh, really quickly about the different types of cards that are out there. [13:00.770 --> 13:03.030] Um, there's Cisco, Prism 2, and Hermes? [13:03.830 --> 13:04.230] Orinoco. [13:05.310 --> 13:06.390] Which is the same. [13:06.970 --> 13:12.530] Um, Cisco, uh, as often the case, is the best of the bunch. [13:12.530 --> 13:16.670] Uh, they transmitted a higher, uh, power. [13:17.030 --> 13:21.290] 100 milliwatts versus Prism 2's normal 40 to 80. [13:21.290 --> 13:24.410] Well, Prism 2 is normally about 20 to 30 milliwatts. [13:24.630 --> 13:27.710] Uh, airports found in Macintoshes are basically Lucent cards. [13:28.070 --> 13:30.190] Um, they all transmitted about 30 to 35. [13:30.570 --> 13:33.110] For passive sniffing, the transmit power doesn't make much difference. [13:33.390 --> 13:36.090] For actually using it, it makes all the difference. [13:37.590 --> 13:47.810] The, uh, Cisco's are also a lot more sensitive to receive, which makes them better for, um, war driving applications, obviously, or, or, um, mapping your networks. [13:51.340 --> 13:52.420] What else do we have? [13:53.340 --> 13:55.820] Um, well, do you have any other software? [14:13.560 --> 14:14.120] Um... [14:14.120 --> 14:18.600] You can see the Mac address of the, uh, card you're getting here. [14:19.080 --> 14:23.220] The SSID is the same, you know, with the other sniffing software. [14:25.640 --> 14:26.120] Uh... [14:27.140 --> 14:31.840] You can go up here and see clients, uh, you get the channels, the vendor. [14:32.080 --> 14:32.760] I'll expand that. [14:38.380 --> 14:38.700] Yeah. [14:39.200 --> 14:40.460] I'll let you do that since you've got the keyboard. [14:47.320 --> 14:47.640] Uh... [14:47.640 --> 14:51.560] So you can see the vendor of, uh, the various different things you're connecting to. [14:52.040 --> 14:57.020] Often, when you're doing that, you can look for default passwords, or common stuff, if it's, uh, an access point. [14:57.800 --> 14:58.240] It's... [15:07.460 --> 15:08.770] You don't have any GPS, right? [15:09.030 --> 15:12.720] I should also point out that, uh, a lot of war drivers have, uh, GPS units. [15:13.080 --> 15:17.860] Um, and connecting the GPS unit to either Kismet or, I guess, uh, this one does it too. [15:18.360 --> 15:21.790] Uh, you can find the location of a network and later map them. [15:22.290 --> 15:27.540] Um, actually, if you picked up the latest issue of 2600, the front cover is the Hotel Pennsylvania. [15:27.790 --> 15:32.600] That's the Hotel Pennsylvania, the three things in the center, uh, and the area surrounding it. [15:34.220 --> 15:34.670] Um... [15:34.670 --> 15:37.440] There are, I think it was 450 networks. [15:37.960 --> 15:38.680] Over 450... [15:38.680 --> 15:41.670] Over 450 networks within about a three block radius of this place. [15:41.920 --> 15:45.650] Of them, about 28% were factory default. [15:45.910 --> 15:49.220] Which means somebody took it, pulled it out of the box, and plugged it into their network. [15:49.790 --> 15:52.390] It's got the factory passwords or no passwords. [15:54.030 --> 15:54.580] Um... [15:54.580 --> 15:54.680] Yeah. [15:55.080 --> 15:56.410] Roitable community strings. [15:57.300 --> 15:59.360] Go in, reconfigure their network for them. [15:59.680 --> 16:01.120] Not that I recommend doing that. [16:01.390 --> 16:03.620] But people leave themselves that exposed. [16:03.620 --> 16:07.940] Speaking of which, for most of this hotel, there's an access point called Default that's available. [16:08.100 --> 16:08.580] It's a D-Link. [16:08.960 --> 16:12.600] Uh, you might have seen it around, if you, uh, if you've been playing around. [16:13.240 --> 16:15.480] Um, which was factory default. [16:15.770 --> 16:19.410] And, uh, I think somebody was playing with it earlier, so it no longer is factory default. [16:22.060 --> 16:30.300] But, uh, the password was admin, which is the default, uh, password for all D-Link, or not all, but most D-Link equipment. [16:32.950 --> 16:35.290] Um, do you have anything more to show there? [16:35.490 --> 16:36.390] Or shall we... [16:37.570 --> 16:39.670] We're gonna jump back over to Kismet for a minute. [16:39.930 --> 16:48.130] Um, since we have the creator of Kismet here, uh, we figured we'd, uh, spend a little bit more time on Kismet, and then we're gonna talk to you about, uh, the actual equipment we have here. [16:48.250 --> 16:48.950] Some eye candy. [16:51.570 --> 16:53.890] Of course, eye candy for nerds is equipment. [16:57.190 --> 17:03.790] It's amazing, considering how much press, and how much negative press, wireless networking has been getting lately. [17:04.010 --> 17:09.310] With Best Buy running, um, unencrypted credit cards over their wireless network. [17:09.810 --> 17:14.690] Um, a number of other companies have gotten caught doing similar things. [17:14.690 --> 17:20.590] And just a number of articles that have been out there about the weaknesses of WEP, and the weaknesses of wireless networks. [17:21.070 --> 17:24.970] It's phenomenal how many networks there still are that are completely unprotected. [17:25.450 --> 17:38.510] And how many people, and I'm sure some of them are network administrators, still have no clue that just because it's a standard piece of equipment doesn't mean it's not gonna suddenly make your network vulnerable to a whole new crowd of people. [17:39.310 --> 17:43.270] Uh, a lot of people rely on physical security of their networks. [17:43.270 --> 17:47.610] If you can't get into their building, you can't plug in, so you can't get at their unpatched servers. [17:48.550 --> 17:52.230] With wireless, you can pick things up four and a half, five miles away. [17:52.550 --> 17:53.490] Sometimes, literally. [17:53.890 --> 17:59.810] I believe it was Office Depot that was running a, uh, a demo, uh, of a wireless unit on their network. [18:00.170 --> 18:05.090] The thing about doing that is that it was on their physical network, and it was a wireless access point. [18:05.170 --> 18:15.570] So you could be sitting out there, um, after hours, uh, linking to that access point and start browsing their corporate network from inside, from behind the firewalls. [18:16.770 --> 18:21.450] Obviously, it's a little bit of a security hole for that, uh, most people probably didn't think of. [18:21.610 --> 18:23.710] And it was probably just some clerk that plugged it in. [18:23.930 --> 18:25.230] Um, not really thinking too hard. [18:25.230 --> 18:35.110] But, uh, if you, if you ever wanted to explore Office Depot's internal network, or any other, uh, group that, uh, sells wireless, uh, equipment, you might wanna try just sitting outside their store. [18:38.180 --> 18:46.960] I've actually run into other situations like that, where you'll connect to a store that's running a wireless network, and it's all their corporate stuff, not, you know, for customers. [18:46.960 --> 18:54.000] And I've had instances where I find mug shots of people who've been banned from the store, located on desktops on their wireless networks. [18:54.340 --> 19:00.480] So a lot of people out there are running these completely unsecure networks, and they're not really doing anything about it. [19:01.480 --> 19:06.720] The other very frightening place that often runs completely insecure networks are hospitals. [19:07.940 --> 19:12.260] These people are handling your medical data, and they're broadcasting it miles without encryption. [19:13.940 --> 19:18.680] Often what they're doing is, um, in one case, uh, near where we live. [19:18.880 --> 19:26.440] There is a, uh, a wireless... there's a hospital that uses a wireless network to communicate, uh, between it and another hospital, another local area hospital. [19:27.040 --> 19:30.000] Um, and that connection is not encrypted whatsoever. [19:30.520 --> 19:33.300] Um, we haven't actually... or I haven't, anyway. [19:33.620 --> 19:34.760] Um, I don't think you have either. [19:34.900 --> 19:36.780] I actually looked at the data going through there. [19:36.940 --> 19:38.580] Um, we just noticed that it was there. [19:39.200 --> 19:43.980] Um, but I do not... I wouldn't put money on, uh, that being encrypted at all. [19:44.120 --> 19:46.500] There's probably just free open data right there. [19:49.560 --> 19:58.580] Okay, well, we'll show off a few of the features of Kismet, and then we'll, um, talk about the hardware that, uh, we use to do things like generate the cover of this, um, issue of 2600. [19:58.960 --> 20:00.980] Uh, you've already seen the default screen. [20:01.520 --> 20:07.540] Um, you can get specific information about the network that won't fit on one screen. [20:08.660 --> 20:09.940] Oh, that was the wrong key. [20:11.500 --> 20:14.980] Um, it displays the SSID, the manufacturer, if it can extract it. [20:14.980 --> 20:17.840] Uh, those are just extracted from the hardware addresses of the cards. [20:18.880 --> 20:24.800] Um, the beaconing rate of, if it's an access point, and any IP information that's extracted. [20:25.100 --> 20:27.620] And all of this is done by just what's already going through the air. [20:27.900 --> 20:30.240] The net, it's completely invisible to the owners of the network. [20:33.410 --> 20:37.150] The other thing it'll do is extract any printable ASCII strings from the network. [20:37.150 --> 20:45.270] So, if somebody's looking at a web page, or if they're doing some other traffic that's got printable text, there you go. [20:45.950 --> 20:51.810] That's the same thing as basically doing string space file name on, uh, any Linux, Unix type platform. [20:54.070 --> 20:54.890] What was that? [20:56.830 --> 21:01.290] That's a, uh, graph of the packet rate of when it's received networks. [21:01.290 --> 21:05.050] So, uh, we're averaging about 300 to 600 packets a second. [21:05.230 --> 21:06.590] That's, uh... [21:06.590 --> 21:09.210] And if somebody starts a file transfer, you'll see that shoot straight up. [21:10.990 --> 21:14.710] That's actually a bit higher than you'll normally see in a busy area when you're driving around. [21:15.670 --> 21:16.070] But... [21:16.070 --> 21:18.330] It's very rare you see over 100 packets a second. [21:18.510 --> 21:22.210] So, uh, 400, 600, 300 is a lot. [21:26.790 --> 21:31.770] Uh, like NetSumbler, it also reports the power levels of the last received information from the card. [21:32.450 --> 21:33.870] Which is fairly typical. [21:34.650 --> 21:37.110] That's common between all the, uh... [21:37.110 --> 21:39.110] You can't always trust that information, though. [21:39.550 --> 21:40.290] Um, it's... [21:40.290 --> 21:41.270] It doesn't always make sense. [21:41.390 --> 21:42.890] It doesn't always relate to, uh... [21:42.890 --> 21:45.590] Of course, obviously, your distance to the, uh, the card. [21:45.750 --> 21:50.230] Of course, there are a lot of factors that impact on your, uh, reception of radio signals. [21:50.670 --> 21:52.430] Uh, and distance is just one of them. [21:52.930 --> 22:01.730] Um, but still, uh, even in accounting for all that, it doesn't seem that there is, uh, any relation, or very much of a relation between the signal strength and actual perception. [22:06.840 --> 22:15.640] As you can see, it picks up a few more networks than NetSumbler does, since all it has to receive is a packet, single packet, and it will get everything. [22:15.640 --> 22:18.540] Each node in an ad hoc network is reported separately, I believe. [22:18.900 --> 22:29.740] Um, also, uh, it's, uh, interesting to note that if there, if Kismet sees a probe first, and then sees the actual network, uh, that it belongs to, it will associate, it will bring the two together. [22:30.340 --> 22:35.080] Um, and one of the other things that, uh, Kismet will do is allow you to group, uh, things. [22:35.080 --> 22:41.420] You can tag certain networks, say you have, pass by an installation of, uh, 20 access points and part of the same network. [22:41.640 --> 22:45.580] You can tag them all and group them as a single access point. [22:50.820 --> 22:51.600] You have a question? [22:51.820 --> 22:51.940] Yeah. [22:54.160 --> 22:59.340] Cisco cards cost, um, well, if you look around a whole lot, you can get them for under a hundred. [22:59.980 --> 23:01.540] Um, a whole lot, you have to look around, though. [23:01.540 --> 23:11.540] Uh, for my PCI version, which is a PCI to PCI-MCA bridge, basically, uh, with a Cisco card in it, it was, uh, 150. [23:12.000 --> 23:14.100] Uh, not that long ago. [23:14.420 --> 23:20.860] Uh, I should also point out that the best Cisco card to get is the 350 series, which is, more specifically, the 352. [23:21.520 --> 23:30.060] Um, we'll show you in a second, uh, what these cards look like, uh, and point out that, um, some of them have antennas built in. [23:30.060 --> 23:32.500] The good ones to get do not have antennas built in. [23:32.580 --> 23:33.460] They just have jacks. [23:33.600 --> 23:34.840] And so you can attach your own antennas. [23:34.920 --> 23:36.060] And antennas make a lot of difference. [23:38.040 --> 23:39.300] We've got another question over there. [23:39.460 --> 23:42.680] Uh, your program that Kismet only works with Hermit's cards? [23:43.020 --> 23:43.660] Uh, no. [23:43.720 --> 23:45.720] Kismet will work with almost every card out there. [23:45.860 --> 23:52.300] It works with Prism 2, with the WLAN-NG drivers under Linux, and with the drivers under BSD. [23:52.700 --> 23:55.720] And it'll work with Orinoco, and it'll work with Cisco. [23:55.960 --> 23:58.490] Do you need the WLAN-NG drivers? [23:58.870 --> 24:00.910] Uh, do you need the WLAN-NG drivers in Linux? [24:00.910 --> 24:01.410] Uh, yes. [24:01.730 --> 24:05.390] Um, for Prism 2 and Linux, they're designed to run it. [24:05.670 --> 24:09.010] There's some drivers in the Linux kernel by default, but they're not really... [24:09.670 --> 24:14.350] They're more designed for Orinoco than for Prism 2, and they will work, but not usually very well. [24:14.450 --> 24:17.450] No, is it okay to use the Linux built-in stuff for Orinoco? [24:17.930 --> 24:19.090] Uh, the... [24:19.090 --> 24:20.990] Is it okay to use the Linux built-in stuff for Orinoco? [24:21.090 --> 24:22.370] I'll repeat that for the back of the room. [24:22.730 --> 24:34.590] Um, if you're going to be doing raw packet sniffing, um, which is what you need to do with Kismet, um, there's a patch from a guy called Snacks, um, which enables monitor mode on them. [24:34.750 --> 24:41.730] And it applies to the latest Orinoco drivers that are available from the Orinoco distribution site. [24:41.730 --> 24:43.470] I don't remember the URL offhand. [24:43.670 --> 24:47.750] Did you show the, uh, the status with the, uh, which percentage was swept? [24:47.890 --> 24:48.610] Which percentage was not? [24:48.650 --> 24:48.790] Oh, right. [24:52.380 --> 25:00.880] So, not particularly useful in this sampling, but one network here was encrypted. [25:03.760 --> 25:05.620] That's quite typical, uh, generally. [25:06.040 --> 25:08.760] Uh, not very large percentage of networks are encrypted. [25:08.760 --> 25:13.200] As we went on the, from the cover, the dataset, uh, made for the cover. [25:13.460 --> 25:13.740] Right. [25:13.860 --> 25:20.780] From the 450 networks in the three block radius of here, about 45% had web encryption on. [25:24.560 --> 25:25.520] And about... [25:26.000 --> 25:26.800] 20%, 25? [25:27.820 --> 25:28.300] 25%. [25:28.300 --> 25:29.660] 25% factory default. [25:31.940 --> 25:32.680] Got a question? [25:32.780 --> 25:33.280] I have a question. [25:33.620 --> 25:35.040] Uh, how often do you switch channel? [25:35.320 --> 25:37.220] Uh, how often does it switch channel? [25:37.220 --> 25:38.760] Uh, the, it depends on the card. [25:39.220 --> 25:44.140] Um, how does, how does NetStumble, how does NetStumble switch channels? [25:44.180 --> 25:44.920] Uh, where you can actually... [25:44.920 --> 25:45.700] Settable. [25:45.900 --> 25:46.820] Yeah, it's settable. [25:47.620 --> 25:48.040] Settable. [25:48.400 --> 25:49.160] The, uh... [25:49.160 --> 25:49.260] The, uh... [25:49.260 --> 25:49.960] For what range? [25:50.100 --> 25:51.900] What, uh, what type of timing can you use? [25:51.960 --> 25:52.480] Can you use, uh... [25:52.480 --> 25:54.060] Tenth of a second every couple seconds. [25:54.300 --> 25:55.700] Tenth of a second every couple seconds. [25:55.920 --> 26:04.200] Um, Kismet, uh, ships, or is sent out, uh, with, uh, a copy of a program called, uh, Prism 2 Hopper. [26:04.200 --> 26:05.300] It's actually, it's Kismet Hopper. [26:05.300 --> 26:06.040] Kismet Hopper now. [26:06.240 --> 26:09.600] Um, which will hop, I believe, every one-third of a second. [26:10.300 --> 26:15.800] Uh, we believe, though we don't have hard, hard evidence, because we don't, we don't have access to the actual internals of a Cisco card. [26:15.980 --> 26:21.840] But the Cisco cards actually also, um, instead of listening on all channels at once, like it seems to, uh, hop. [26:22.000 --> 26:23.620] And we believe it hops every... [26:24.300 --> 26:27.440] It, it hops at a very, very small fraction of a second. [26:27.440 --> 26:36.340] Uh, the Cisco cards are interesting in some ways because they'll hop between channels quickly, but they sometimes gravitate towards one. [26:36.520 --> 26:41.880] So if you've got one channel that's very powerful and one channel that's very weak, you won't always get the weak channel with a Cisco card. [26:42.740 --> 26:50.400] It, it's great for general purpose, but if you're doing really dedicated capture on a certain channel, um, something like an Amplified Prism 2. [26:51.080 --> 26:54.780] Let's, uh, go through the hardware we have up here before we run out of time answering questions. [26:54.780 --> 26:59.580] Um, let's start with antennas, um, the different antennas we have. [27:00.040 --> 27:05.240] Um, one of the best antennas, uh, we have is a Yagi. [27:05.500 --> 27:09.020] Uh, this is 14.5, I believe, 14.5 dB. [27:09.460 --> 27:11.160] Um, very directional. [27:11.640 --> 27:16.180] Um, the distribution pattern is, you would think it's sort of like a cone-ish or straight-ish. [27:16.340 --> 27:20.720] It's actually has a little bubble in the front and then sort of goes out in a thin cone. [27:21.240 --> 27:32.340] Um, uh, yes, we have, uh, from one of the other people I saw coming in at registration, we have, uh, one of these, uh, very long, for very long range. [27:32.420 --> 27:34.280] I believe these are rated for five miles. [27:35.040 --> 27:35.600] Is that right? [27:35.940 --> 27:37.700] If, if you have them on both ends of the lane. [27:37.780 --> 27:40.440] If you have them on both ends, uh, then you would see about five miles. [27:40.580 --> 27:42.620] I don't know what the, uh, the gain on this antenna is. [27:42.620 --> 27:45.960] I want to say, this, this antenna is a lot of fun. [27:46.200 --> 27:49.020] You know, sitting on a train, people are looking at you like, what's that? [27:53.920 --> 27:56.140] It's so the aliens can control my mind. [27:57.740 --> 27:59.500] We have, uh, other antennas as well. [27:59.720 --> 28:02.920] Uh, one of the best general antennas, uh, is this little doohickey here. [28:03.060 --> 28:06.160] And I've seen probably about 15 of these since I got here. [28:06.900 --> 28:09.260] Um, this is sold by what group? [28:10.140 --> 28:12.880] Uh, Frank Keeney of Pasadena.net sells these. [28:13.060 --> 28:14.420] I don't know of any other distributors. [28:15.660 --> 28:16.020] Um... [28:16.020 --> 28:16.520] Fabcor. [28:18.480 --> 28:19.540] It's very small. [28:19.740 --> 28:21.540] It's got a built-in backplane and it's magnetic mount. [28:22.000 --> 28:25.040] Uh, slap it on the roof of your car, you'll about triple the number of networks you say. [28:25.200 --> 28:25.640] Five point... [28:25.640 --> 28:26.020] Or... [28:26.020 --> 28:26.560] You put it on your hat. [28:26.800 --> 28:27.380] Slap it on your head. [28:28.940 --> 28:31.500] It's a 5.5 dB gain, I believe it is. [28:31.660 --> 28:36.300] And, uh, you gain a lot by putting it outside of the big metal box you drive around in. [28:37.020 --> 28:37.280] Um... [28:37.280 --> 28:38.420] What's the website again? [28:39.140 --> 28:40.420] Pasadena.net and... [28:41.000 --> 28:46.340] Fab-corp.com Fab-corp.com How much do those costs? [28:47.300 --> 28:49.540] Uh, ask for the Stumbler special. [28:51.240 --> 28:52.320] Don't really know how much... [28:52.320 --> 28:54.920] 85 bucks for the pigtail and antenna from the crowd. [28:55.440 --> 28:57.820] 85 bucks for the pigtail and antenna from the crowd. [28:58.120 --> 29:01.040] Fabcorp, say you use the NetStumbler groups and you get a discount. [29:01.380 --> 29:01.560] Yeah. [29:01.860 --> 29:03.500] Some discount for using the NetStumbler groups. [29:03.580 --> 29:03.840] Alright. [29:05.040 --> 29:05.480] Um... [29:05.480 --> 29:09.340] You've probably seen something like this, just a little bit larger than this version, uh... [29:09.340 --> 29:10.940] On the top of buildings all over the place. [29:11.080 --> 29:11.840] It's a sector antenna. [29:13.200 --> 29:13.640] Um... [29:13.640 --> 29:14.500] We'll cover... [29:14.500 --> 29:17.760] One third, roughly, of a 360 degree circle. [29:18.300 --> 29:18.720] Um... [29:18.720 --> 29:24.900] The idea being that you put three of these or six of these around in a circle or in a triangle formation. [29:25.500 --> 29:25.900] Um... [29:25.900 --> 29:28.320] This particular one, I believe, is the most powerful antenna we have. [29:28.440 --> 29:29.200] It's, uh... [29:29.200 --> 29:29.880] 18 dB. [29:30.460 --> 29:31.020] And, uh... [29:31.020 --> 29:33.540] We don't actually use it a whole lot because it's kind of unwieldy. [29:33.860 --> 29:34.260] Uh... [29:34.260 --> 29:35.520] I tried to mount it on my car once. [29:35.580 --> 29:36.800] It was nothing but pain. [29:37.900 --> 29:38.960] Where did you get it? [29:39.260 --> 29:40.680] This I picked up off eBay. [29:40.940 --> 29:42.440] Amazing what you can find on eBay. [29:43.640 --> 29:44.820] I found it for $100. [29:45.440 --> 29:45.820] Um... [29:45.820 --> 29:46.880] It came with, uh... [29:46.880 --> 29:48.540] A lot of water-damaged case and all that. [29:48.720 --> 29:51.320] But, obviously, it's a waterproof, weatherproof... [29:51.780 --> 29:52.580] Everything, uh... [29:52.580 --> 29:54.160] Stands up to a hundred miles an hour winds. [29:54.340 --> 29:55.000] You know, that kind of thing. [29:55.420 --> 29:55.780] Antenna. [29:55.960 --> 29:56.540] So, uh... [29:56.540 --> 29:57.380] It was not damaged. [29:57.840 --> 29:59.580] Although, you can see some discoloration on it. [30:01.260 --> 30:01.620] Um... [30:01.620 --> 30:05.080] All of these antennas, or most of these antennas, come with one standard connector. [30:05.280 --> 30:06.060] And that is the N. [30:07.740 --> 30:08.420] N connector. [30:09.840 --> 30:10.820] It's a, uh... [30:11.540 --> 30:12.840] Really big, uh... [30:12.840 --> 30:13.940] As connectors go, connector. [30:14.580 --> 30:14.900] Um... [30:14.900 --> 30:18.680] On the cards themselves, for example, the Cisco cards, um... [30:18.680 --> 30:19.840] I don't know if you can pull that one out. [30:20.020 --> 30:21.260] I'm not gonna pull it out, but... [30:21.260 --> 30:21.920] You're not gonna pull it out. [30:22.320 --> 30:23.060] I can do them. [30:23.140 --> 30:25.220] Actually, we wouldn't even be able to see it even if we did. [30:25.380 --> 30:25.740] But, uh... [30:25.740 --> 30:26.900] They're really, really tiny. [30:27.120 --> 30:29.840] You know, a couple millimeters wide, uh... [30:29.840 --> 30:30.320] Connectors. [30:30.680 --> 30:35.320] Mostly, or usually, they're MMCX connectors, although they're different versions and different cards. [30:36.660 --> 30:37.300] So, um... [30:37.300 --> 30:39.060] You have to get pigtails, different converters. [30:39.260 --> 30:41.640] And these are sold all over the internet as well, including eBay. [30:42.500 --> 30:42.980] Uh... [30:42.980 --> 30:45.520] A lot of companies advertise on eBay for, uh... selling. [30:45.700 --> 30:46.240] And, uh... [30:46.240 --> 30:47.380] We probably have a couple here. [30:48.660 --> 30:49.140] Um... [30:49.140 --> 30:49.860] They break easy. [30:50.060 --> 30:50.740] Get a lot of them. [30:52.140 --> 30:53.600] They're usually run about... [30:55.520 --> 30:56.380] Between, uh... [30:56.380 --> 30:57.740] 20 and 30, 40 dollars. [30:58.100 --> 30:59.240] Some of them are 40 dollars. [30:59.360 --> 30:59.640] Those are... [30:59.640 --> 31:01.180] Don't go 40 dollars high. [31:01.320 --> 31:02.420] But, uh... [31:02.420 --> 31:03.480] Go to, uh... [31:03.480 --> 31:03.780] Probably... [31:04.580 --> 31:05.760] 20, 30 dollars. [31:06.140 --> 31:06.580] Uh... [31:06.580 --> 31:07.200] For a good connector. [31:09.600 --> 31:10.040] Um... [31:10.040 --> 31:13.480] While we're talking about antennas, an interesting thing about 802.11 is... [31:13.480 --> 31:14.420] It's line of sight. [31:14.800 --> 31:16.020] And it's straight line. [31:16.280 --> 31:19.540] So, if you're trying to do a very long link, you're going to need fairly tall towers. [31:20.840 --> 31:21.340] Um... [31:21.340 --> 31:23.560] With a directional antenna, you can hit earth curvature. [31:24.080 --> 31:24.580] Easily. [31:25.980 --> 31:26.480] Um... [31:26.480 --> 31:27.020] But... [31:27.020 --> 31:29.000] It's gotta be line of sight. [31:29.560 --> 31:30.060] Uh... [31:30.060 --> 31:30.840] Water... [31:30.840 --> 31:31.440] Kills the signal. [31:32.240 --> 31:34.420] People standing in front of your antenna kill the signal. [31:34.800 --> 31:38.580] And I wouldn't necessarily recommend standing in front of an antenna for a long period of time. [31:39.820 --> 31:40.920] One thing that's, uh... [31:40.920 --> 31:41.600] Good to test, actually. [31:41.740 --> 31:46.440] If you want to see if something will let 802.11 traffic through or not, stick it in the microwave. [31:46.780 --> 31:48.140] Because that's what the microwave is. [31:48.340 --> 31:48.520] It's... [31:48.520 --> 31:48.840] It is a... [31:48.840 --> 31:50.120] This is microwave links. [31:50.680 --> 31:51.020] Um... [31:51.020 --> 31:53.460] So, if you stick it in the microwave and it comes out hot, um... [31:53.460 --> 31:53.960] Don't use it. [31:55.420 --> 31:56.500] Otherwise, uh... [31:56.500 --> 31:57.320] You should be alright. [31:57.600 --> 31:59.700] Just don't leave something in the microwave for, you know... [31:59.700 --> 32:02.380] A real world example of that being, um... [32:02.380 --> 32:10.420] At the apartment I'm at, about five miles away across the Hudson River, and up on a hill, there's two radio towers, which now host a wireless ISP. [32:10.900 --> 32:17.560] With this antenna, and actually even with this little one, I can see it from my front yard, and see all the traffic on it. [32:18.740 --> 32:19.700] Pointing that antenna... [32:19.700 --> 32:25.540] About ten feet the other direction, through the bushes in the front of the house, is the other half of the apartment, with his access points in it. [32:26.300 --> 32:26.660] Nothing. [32:29.420 --> 32:32.900] They're 45 dB, or 45 milliwatt transmitters as well. [32:33.040 --> 32:35.280] So, it's not like it's a small thing, it just seems to be... [32:35.280 --> 32:36.440] So, if you're trying to do... [32:36.440 --> 32:37.720] Line of sight is really important. [32:38.140 --> 32:41.120] When you lay out the wireless network, line of sight. [32:41.760 --> 32:45.280] Also related to antennas, we have a amplifier here. [32:45.440 --> 32:48.400] This is specifically a 500 milliwatt amplifier. [32:48.560 --> 32:49.360] It comes in two pieces. [32:49.600 --> 32:52.320] A power injector, and the actual amp itself. [32:53.320 --> 32:53.840] Um... [32:53.840 --> 32:57.840] It will transmit, or it'll increase your transmit power, 500 milliwatts. [32:57.920 --> 32:59.440] Of course you can get them up to... [32:59.440 --> 33:03.060] The largest one I ever saw was for 100 watts. [33:03.060 --> 33:05.680] The largest one you're ever going to be able to buy was one watt. [33:06.200 --> 33:06.600] Um... [33:06.600 --> 33:08.900] The one for 100 watts was for military use only. [33:09.100 --> 33:09.880] And, um... [33:09.880 --> 33:12.900] To be honest, if you used it and pointed it at someone, they'd probably... [33:13.380 --> 33:14.760] Well, they'd literally cook. [33:32.640 --> 33:33.040] Um... [33:33.040 --> 33:33.060] To be honest. [33:33.060 --> 33:33.440] The one for 100 watts is on transmit. [33:34.300 --> 33:37.140] Combined with the amp, it gives you an additional 14 dB on transmit. [33:37.340 --> 33:38.440] And 30 dB on receive. [33:38.860 --> 33:46.260] So if you're trying to establish a long range link, or if you're trying to see everything through your neighbor's houses, an amplifier could be a good investment. [33:47.720 --> 33:48.160] Uh... [33:48.160 --> 33:51.880] We also obviously use GPS's whenever you're rolling around. [33:52.260 --> 33:52.820] Um... [33:52.820 --> 33:57.000] And trying to create maps like you see on the cover of 2600. [33:57.600 --> 33:57.880] Um... [33:57.880 --> 34:00.060] Any GPS will do very much. [34:00.360 --> 34:00.840] Um... [34:00.840 --> 34:02.460] Kismet uses GPSD. [34:02.740 --> 34:06.060] And GPSD can read pretty much every UPS with a serial out. [34:06.580 --> 34:07.040] Um... [34:07.040 --> 34:08.640] Including the, um... [34:08.640 --> 34:09.660] Ugly Magellan ones. [34:09.820 --> 34:13.080] If you want to buy a GPS for this use, I suggest Garmin. [34:13.440 --> 34:15.020] And I do not suggest Magellan. [34:16.440 --> 34:16.840] Uh... [34:16.840 --> 34:22.840] For what we used for generating the map, we actually just picked up a crappy little $99 e-trex. [34:23.480 --> 34:24.240] It works. [34:25.040 --> 34:25.440] Um... [34:25.440 --> 34:26.980] Of course adjusts to your needs. [34:27.240 --> 34:35.480] If you're going to be doing a lot of driving in cities with tall buildings, you'll probably want an external antenna on the GPS as well as an external antenna on your car for the 802.11. [34:37.600 --> 34:38.400] Finally, um... [34:38.400 --> 34:41.360] The last bit of technology I see up here, um... [34:41.360 --> 34:43.440] Is something that got me a lot of looks. [34:43.980 --> 34:45.180] I built this a while ago. [34:53.730 --> 34:56.870] Once you get over the fact that it's actually a suitcase and computer, um... [34:56.870 --> 34:57.970] It's not all that great. [34:58.270 --> 34:59.570] However, um... [34:59.570 --> 35:00.790] I built this to put it in my car. [35:01.430 --> 35:01.710] Uh... [35:01.710 --> 35:07.570] Its main purpose was to play MP3s for me because I got really tired of listening to commercial radio, which if, uh... [35:07.570 --> 35:09.010] Any of you, uh... [35:09.010 --> 35:11.410] Many of you apparently have an appreciation for. [35:11.850 --> 35:14.070] Commercial radio is getting worse and worse and, uh... [35:14.070 --> 35:15.730] Well, anyway, I got sick and tired of it. [35:15.730 --> 35:16.490] So, uh... [35:16.490 --> 35:17.190] I decided to leave. [35:18.250 --> 35:18.630] Um... [35:18.630 --> 35:20.050] So, I built this, uh... [35:20.050 --> 35:20.810] And, uh... [35:20.810 --> 35:22.430] With the intention of playing MP3s. [35:22.590 --> 35:24.790] Later, I discovered that, uh... [35:24.790 --> 35:27.250] Well, I'm gonna need to update my MP3 collection every once in a while. [35:27.570 --> 35:28.730] Maybe I should run, uh... [35:28.730 --> 35:31.470] Well, Ethernet wire out to my car every once in a while. [35:31.670 --> 35:33.970] And so, I added a, uh... [35:33.970 --> 35:34.650] A, uh... [35:34.650 --> 35:36.030] Ethernet card for that purpose. [35:36.710 --> 35:40.110] And then I realized, about 15 seconds later, that, uh... [35:40.110 --> 35:41.930] 802.11 was really starting to get big. [35:42.090 --> 35:45.190] So, I added a, uh... [35:45.190 --> 35:45.610] A, uh... [35:45.610 --> 35:46.750] Prism 2 card at the time. [35:46.930 --> 35:48.330] And then I replaced it with a Cisco card. [35:49.970 --> 35:50.410] Um... [35:50.410 --> 35:55.830] This has the added advantage of being able to run Kismet whenever I'm in the car and moving around. [35:56.790 --> 35:59.970] Just because I had nothing else to make the machine do other than play MP3s. [36:00.070 --> 36:01.810] Which doesn't do a whole lot of, uh... [36:01.810 --> 36:02.670] Of usage for this computer. [36:02.810 --> 36:06.890] So, in the interest of using more of this computer's, uh... [36:06.890 --> 36:09.230] capabilities, I started running Kismet, uh... in the background. [36:09.490 --> 36:11.450] And I never actually got it to work with the GPS too well. [36:11.530 --> 36:13.150] So, I never got any, uh... [36:13.150 --> 36:14.730] Interesting results with this particular machine. [36:14.910 --> 36:16.510] But still, um... [36:16.510 --> 36:18.010] It is an interesting, um... [36:18.710 --> 36:20.610] And worthwhile, uh... use for this thing. [36:22.770 --> 36:23.570] Yeah, um... [36:23.570 --> 36:26.050] Another note on Kismet is it will run on handhelds. [36:27.010 --> 36:27.410] And... [36:27.410 --> 36:29.910] So, if you want to look at a storage network, for example. [36:30.370 --> 36:31.450] Throw it on an IPAC. [36:31.570 --> 36:32.370] Throw it on a Zorus. [36:32.810 --> 36:33.750] Put it in your pocket. [36:34.570 --> 36:36.610] Pretty much anything that runs Linux, um... [36:36.610 --> 36:37.430] And has, uh... [36:37.430 --> 36:38.350] A wireless card on it. [36:38.510 --> 36:38.870] Um... [36:38.870 --> 36:40.410] Well, with some exceptions. [36:41.070 --> 36:41.290] Uh... [36:41.290 --> 36:42.170] We'll, uh... [36:42.170 --> 36:45.110] We'll be running Kismet and you can run it in this type of, uh... [36:45.110 --> 36:45.330] Method. [36:48.650 --> 36:49.050] Question. [36:50.210 --> 36:51.010] Questions, go ahead. [36:51.010 --> 36:54.190] Can Kismet give access to the raw packets and have a web bracket? [36:54.850 --> 36:55.310] Uh... [36:55.310 --> 36:56.030] If you... [36:56.030 --> 37:01.370] If you've ever used Ethereal, it's pretty much the best network sniffer out there for free platforms. [37:01.550 --> 37:02.690] And it actually runs on Windows as well. [37:02.890 --> 37:06.630] Kismet will write all the data packets out in a format compatible with Ethereal. [37:07.090 --> 37:10.470] That you can pull open and process any way you wish. [37:10.910 --> 37:16.510] And it will identify weak packets and save it in a file for AirSnort to attempt to crack the web key. [37:17.170 --> 37:17.630] Uh... [37:17.630 --> 37:19.730] I should add right now because I'm gonna forget it otherwise. [37:20.030 --> 37:20.410] Uh... [37:20.410 --> 37:23.150] We have a workshop scheduled for 9pm tonight. [37:23.370 --> 37:24.350] In which, uh... [37:24.350 --> 37:25.750] We will show, uh... [37:25.750 --> 37:27.030] Different things, uh... [37:27.030 --> 37:28.670] As in how to set up, uh... [37:28.670 --> 37:30.370] Wireless Ethernet for at least Linux. [37:30.650 --> 37:31.610] And, um... [37:31.610 --> 37:33.470] If you're gonna be around for Windows as well. [37:34.390 --> 37:34.830] Um... [37:34.830 --> 37:35.690] More about Kismet. [37:35.790 --> 37:36.610] More about our stories. [37:36.770 --> 37:39.630] And if you're interested in hearing it or seeing any of this stuff up close. [37:40.250 --> 37:40.470] Uh... [37:40.470 --> 37:42.110] So, 9pm tonight in Area C. [37:42.410 --> 37:43.550] Which is the, uh... [37:43.550 --> 37:44.010] Third track. [37:47.830 --> 37:48.350] Go ahead. [37:49.050 --> 37:49.470] Uh... [37:49.470 --> 37:49.690] Yes. [37:49.950 --> 37:50.830] Our microphone. [37:51.530 --> 37:51.950] Hi. [37:52.590 --> 37:53.010] Um... [37:53.010 --> 37:54.470] I just had two short questions. [37:54.690 --> 37:56.540] The first is, can Kismet, uh... [37:56.870 --> 37:58.770] Log all this information to a file? [37:58.950 --> 38:03.370] In other words, can you drive around and save it and then retrace your route? [38:03.490 --> 38:05.610] Or do you have to sort of keep an eye on it as it's happening? [38:06.010 --> 38:06.250] Uh... [38:06.250 --> 38:06.310] Uh... [38:06.310 --> 38:07.510] Kismet is actually, uh... [38:07.510 --> 38:10.010] It writes all the GPS data to an XML file. [38:10.870 --> 38:11.350] Um... [38:11.350 --> 38:15.750] That has all the data that a program that comes with Kismet called GPS map uses. [38:16.150 --> 38:16.510] Uh... [38:16.510 --> 38:17.790] Which is what we use to generate the cover. [38:18.570 --> 38:19.530] And so... [38:19.530 --> 38:19.590] Yeah. [38:19.690 --> 38:21.010] It saves everything you do. [38:21.270 --> 38:21.950] And, uh... [38:21.950 --> 38:24.750] You can even replay your saved files later through Kismet again. [38:25.690 --> 38:26.170] Um... [38:26.170 --> 38:27.490] To look at what networks you had. [38:27.690 --> 38:29.750] Or if you want to reprocess them with something different. [38:31.450 --> 38:31.890] Question. [38:33.270 --> 38:33.710] Um... [38:33.710 --> 38:34.410] A second thing. [38:34.670 --> 38:35.330] If I were... [38:35.330 --> 38:38.090] I know this is sort of the opposite direction from what you've been talking about. [38:38.230 --> 38:48.290] But if I wanted to take an external antenna mounted on my roof, leading down to my wireless access port, to try to get the 802 to 11B signal out further. [38:49.270 --> 38:49.710] Uh... [38:49.710 --> 38:50.110] Is... [38:50.110 --> 38:50.810] Is that possible? [38:51.810 --> 38:53.770] And if so, what would you recommend to try to do that? [38:53.870 --> 38:55.290] Is it an antenna booster like that? [38:55.510 --> 38:57.950] Or a particular type of omnidirectional antenna? [38:59.030 --> 38:59.470] Uh... [38:59.470 --> 39:01.610] Do you mean to transmit it further or receive from further away? [39:01.610 --> 39:02.270] Transmit it further. [39:03.390 --> 39:03.790] Uh... [39:03.790 --> 39:05.130] Your best bet would be directional. [39:05.410 --> 39:07.470] But we could probably talk about that at 9 o'clock at the workshop. [39:07.750 --> 39:09.490] We can answer more specific questions like that. [39:10.030 --> 39:10.450] Thank you. [39:10.870 --> 39:13.710] Why is it that ad hoc and infrastructure are different speeds? [39:15.150 --> 39:15.710] I'm sorry? [39:15.830 --> 39:18.430] Why is it that ad hoc and infrastructure are different speeds? [39:19.490 --> 39:21.870] It just depends on what the speed it was set up for. [39:22.830 --> 39:23.230] Uh... [39:23.230 --> 39:23.490] They'll... [39:23.490 --> 39:25.010] They'll all perform at 11 megabit. [39:25.770 --> 39:27.330] Minus overhead, minus WEP. [39:27.410 --> 39:28.970] So you get down to about 7 megabit usable. [39:29.770 --> 39:30.210] Uh... [39:30.210 --> 39:33.410] You should be able to drive a full speed connection between two ad hocs. [39:34.010 --> 39:34.450] Uh... [39:34.450 --> 39:40.310] But again, the transmitters in a PCMCIA card and the receivabilities of it are a lot lower than from an access point. [39:40.490 --> 39:44.910] So it may be automatically scaling down the speed because of noise or weak signals. [39:45.890 --> 39:53.410] You may not know the answer to this, but can we assume that any data that's broadcast in the public, you can do anything with and it becomes your data as it's been broadcast? [39:54.550 --> 39:58.390] I don't know that anyone's ever answered that in a legal capacity. [40:00.590 --> 40:01.030] Um... [40:01.030 --> 40:03.370] I don't know what the FCC regs on that are. [40:03.370 --> 40:05.550] I know they've restricted things like the cell band. [40:05.730 --> 40:06.330] So even that's... [40:06.330 --> 40:13.990] Even though it's broadcasted in public, you can't buy a radio tuner that will tune to some of the cell bands. [40:14.170 --> 40:15.510] This is unlicensed frequency. [40:15.630 --> 40:16.690] 2.4 is unlicensed. [40:16.830 --> 40:18.370] It's used by a lot of different people. [40:18.370 --> 40:22.690] Even EasyPass uses it for their active EasyPass tags. [40:24.110 --> 40:29.850] Which is obviously different than the highly restrictive and licensed cellular bands. [40:30.070 --> 40:31.430] So there is a difference there. [40:33.030 --> 40:37.750] I wouldn't want to be the one to go before a lawsuit or something for it. [40:38.230 --> 40:43.510] But since it's an unlicensed band, you have a pretty good chance of it being classified as... [40:43.510 --> 40:45.250] If it's public... if it's broadcast publicly. [40:46.290 --> 40:48.470] And obviously, no one's trying to hide this stuff. [40:48.650 --> 40:51.030] This is wide open for everybody to see by design. [40:51.370 --> 40:52.430] Not by... [40:52.430 --> 40:53.550] Not for... [40:53.550 --> 40:55.350] Nobody's actually trying to hide this stuff. [40:55.870 --> 40:57.470] If it's being transmitted, obviously. [40:57.750 --> 40:58.890] It's being transmitted in clear text. [40:59.090 --> 41:01.510] If it's being webbed, another story probably. [41:03.370 --> 41:03.770] Yeah. [41:04.090 --> 41:06.550] I know you said it works in all Linux's and Unix's. [41:06.710 --> 41:09.470] But just because Apple's kind of funny, is it going to work in OS X? [41:10.850 --> 41:14.970] In theory, with some cards, it will work on OS X. [41:14.970 --> 41:25.510] The problem is the Apple drivers for the airport cards don't provide any way to go into monitor mode, which is what you need to get the raw packet data for how Kismet does all its magic. [41:26.710 --> 41:37.030] There's a group called Wireless Drivers on the SourceForge site, which is basically a clone of the BSD drivers for OS X, but they don't work on airport cards. [41:37.030 --> 41:42.930] And we don't have an OS X machine around with PCMCIA slots to try to force another card in. [41:43.150 --> 41:46.630] It might work with another brand card on an OS X box, but it might not. [41:47.010 --> 41:48.630] The goal is to get it working at some point. [41:50.330 --> 41:54.130] You said that the EasyPass uses the same thing as the wireless card. [41:54.330 --> 41:58.350] Could you use a wireless laptop to gain access into EasyPass? [41:58.510 --> 41:59.630] It just uses the same frequency. [41:59.770 --> 42:00.770] It doesn't use the same protocols. [42:01.490 --> 42:04.610] Yeah, two, four gigahertz is a general unlicensed frequency. [42:05.170 --> 42:07.030] A lot of the X10 equipment uses it. [42:07.090 --> 42:08.450] A lot of the wireless cameras use it. [42:09.790 --> 42:14.730] As he said, the EasyPass uses it, but it's not necessarily all 802.11b. [42:14.830 --> 42:15.710] All right, one last question. [42:16.730 --> 42:23.090] I remember a couple weeks ago, Crane was writing about these fluorescent light bulbs that are going to be coming out that's going to cause interference. [42:23.530 --> 42:32.650] Which part of the 8.11b, I mean, 8.11 protocol would it affect, and how long do you figure before people have to go to hold the totally new hardware to keep doing wireless? [42:33.250 --> 42:42.770] If I recall, those light bulbs that you're talking about, the way they worked was there were essentially little microwaves that microwaved a hunk of tungsten to make it glow. [42:43.610 --> 42:48.950] And once you start blasting out noise in 2, 4 gigahertz around a wireless network, you're probably going to drown it out. [42:49.930 --> 42:51.170] Both 11a and B? [42:52.070 --> 42:53.690] 11a uses 5 gigahertz. [42:54.470 --> 42:58.770] So it wouldn't affect A, but A isn't that common yet, either. [42:59.290 --> 43:01.430] It's also unknown how much it would affect B. [43:01.690 --> 43:02.410] Or G. [43:02.410 --> 43:06.910] Or G, but G is supposed to use 2, 4 gigahertz as well. [43:07.110 --> 43:07.510] Yeah. [43:07.510 --> 43:10.670] So figure two years that everyone has to be moving the new hardware? [43:11.130 --> 43:12.930] Not necessarily those bulbs. [43:13.210 --> 43:18.990] The other thing is not a lot of people are going to buy those bulbs if they're going to impact their corporate networks, et cetera. [43:19.430 --> 43:22.190] So it really depends whether or not those bulbs... [43:22.190 --> 43:35.030] I don't know if those bulbs do that stuff by design or by accident, but my bet is that those bulbs are not going to take off rather than networks having to move because there's been a lot of money spent in 2.4 gigahertz. [43:35.470 --> 43:39.390] Once again, we are doing a workshop at 9 p.m. tonight in Area C. [43:40.790 --> 43:41.650] That's the third track. [43:42.770 --> 43:44.090] And you can come talk to us after. [43:44.090 --> 43:46.990] Come talk to us after if you want to get a closer look at some of this stuff. [43:48.790 --> 43:50.170] And one quick note. [43:55.520 --> 44:02.540] There's some guy that wants to talk to a Long Island war driver, and he's over there if you want to talk to him. [44:02.580 --> 44:04.020] He's a reporter from somewhere. [44:04.460 --> 44:11.400] So if you're from Long Island and you want to demonstrate some of the war driving and sniffing stuff, come up here after. [44:11.400 --> 44:12.400] And good advice. [44:12.540 --> 44:13.480] Don't be stupid about it. [44:13.600 --> 44:13.760] And good advice. [44:13.760 --> 44:14.120] Don't be stupid about it. [44:18.620 --> 44:19.520] Get some core. [44:19.660 --> 44:21.020] I just released it this morning. [44:21.560 --> 44:22.600] Eliminates that whole problem. [44:22.860 --> 44:23.120] Oh, good. [44:27.320 --> 44:29.340] And he was going to have a problem with data. [44:34.830 --> 44:36.150] Some people go away. [44:36.570 --> 44:38.790] Never discourage casual people. [44:40.330 --> 44:43.630] Your best bet is to not rely on... [44:46.110 --> 44:47.230] Protocol of encryption. [44:48.730 --> 44:49.690] VPN, SSH. [44:49.850 --> 44:51.010] Set it up with VPN. [44:51.230 --> 44:53.670] Set it up with strong authentication. [44:54.130 --> 44:55.910] Like, you don't allow your router to move.