[00:00.840 --> 00:05.780] And has been downloaded exactly a billion, million times. [00:13.290 --> 00:15.030] Keeping the sunglasses on the whole time? [00:15.890 --> 00:16.870] They're prescription. [00:17.450 --> 00:19.230] They're prescription, I love it. [00:26.330 --> 00:28.470] Are you going to be sniffing packets? [00:30.370 --> 00:31.790] For part of it, but... [00:31.790 --> 00:33.290] Can we get that? [00:40.380 --> 00:41.920] How did you get the name Dragorn? [00:42.980 --> 00:44.340] No real good story to it. [00:44.820 --> 00:46.140] That's the best kind of name. [01:07.270 --> 01:11.170] Okay, well, that guy was a bit more interesting than me, so I figured we'd give him a little extra time. [01:13.730 --> 01:19.830] Manuel thought it would be a good idea if I talked a bit about how Kismet got started and some of what it can do for people who haven't seen it before. [01:20.350 --> 01:26.710] And then I figured I'd take some questions from the audience and, you know, be entertaining for half an hour or 45 minutes. [01:26.890 --> 01:27.230] Thank you. [01:31.590 --> 01:38.610] So, for anybody who doesn't know, I'm not entirely sure why you'd be here if you don't know this yet, but Kismet's a 802.11 sniffer. [01:39.570 --> 01:43.850] It can sniff all the 802.11 bands if you have the right cards that can do it. [01:44.910 --> 01:48.330] It's completely passive and we'll go into why that's good later. [01:49.570 --> 01:54.710] It can do some signatures and some trend IDS features on it. [01:55.890 --> 01:59.950] It runs on just about anything that has drivers that can help it, that can support it. [02:00.070 --> 02:02.150] So, it'll run on Linux and BSD and OSX. [02:03.250 --> 02:05.170] And it plays nice with the other kids on the block. [02:06.150 --> 02:07.610] It'll integrate with the other tools. [02:07.870 --> 02:09.590] Why duplicate effort when you don't need to? [02:09.590 --> 02:09.650] Yeah. [02:10.850 --> 02:20.570] If you're doing war driving stuff, which a lot of people obviously are, you can do GPS coordinate logging and use them to extrapolate where the center of a network is. [02:20.970 --> 02:22.110] Good stuff like that. [02:29.540 --> 02:33.680] And it's client server architecture, so you can have multiple GUIs connecting to it. [02:34.020 --> 02:38.560] If you don't like the end curses one I did, there's some GNOME based or GTK based ones. [02:38.980 --> 02:40.700] And good stuff like that. [02:45.500 --> 02:47.020] I wonder why that is. [02:47.600 --> 02:48.080] Okay. [02:48.320 --> 02:48.460] Well, [02:56.360 --> 02:58.820] we'll just pretend. [02:59.100 --> 03:00.580] This is why I don't like doing slides. [03:01.420 --> 03:03.860] I figured I'd start with, everybody asks me where did I get the name. [03:04.720 --> 03:08.260] Go to dictionary.com, click on synonyms, profit. [03:08.740 --> 03:10.380] There's no real good story behind the name. [03:10.580 --> 03:14.600] I think I put Stumblr in and just clicked through synonyms until I hit something. [03:15.980 --> 03:16.040] So. [03:21.700 --> 03:22.900] Oh, and now it's working. [03:23.940 --> 03:24.360] Okay. [03:26.100 --> 03:27.340] Why did I write it? [03:27.740 --> 03:28.760] To scratch an itch. [03:28.860 --> 03:31.000] I think that's the reason most open source software gets written. [03:32.120 --> 03:34.300] A couple of years ago I picked up a wireless card. [03:35.000 --> 03:36.020] Air Snort had just come out. [03:36.140 --> 03:38.460] It was a little text based thing. [03:39.280 --> 03:41.480] And I was playing with it and it didn't do what I needed. [03:41.720 --> 03:43.160] So, scratch the itch. [03:43.720 --> 03:44.880] Cobbled up something together. [03:45.340 --> 03:48.040] It was just modifications to Air Snort in the beginning. [03:49.140 --> 03:53.000] And then I got a Cisco card which didn't work with Air Snort so I added support for that. [03:53.220 --> 03:55.400] And, well, if you're going to support one, why not support both? [03:55.620 --> 03:58.380] If you're going to support both, why not make a front end to it that makes sense? [03:59.320 --> 04:04.400] And it kind of took on its own life from there and has eaten all of my free time for the last two years. [04:08.430 --> 04:11.990] For supported platforms, the core development I do is all on Linux. [04:13.790 --> 04:24.430] You could try to argue me to try to get me to switch to BSD or something but really it's taken me six months to get Linux to behave on my laptop hardware and I'm not too likely to reinstall at the moment. [04:24.650 --> 04:33.850] So, for the foreseeable future, the best supported platform will be Linux but I'm willing to help anyone with other platforms as long as there's drivers that'll run. [04:36.050 --> 04:37.810] OSX support got added last summer. [04:38.610 --> 04:45.130] The original Airport cards will work with OSX but the Airport Extreme will not and that gets mentioned, I'll mention later why that is. [04:45.590 --> 04:48.630] But some BSD systems work, some don't. [04:49.170 --> 04:50.370] It's because of the drivers. [04:51.310 --> 04:53.710] On OpenBSD, the Prism 2 drivers work. [04:54.990 --> 04:59.690] Unfortunately, the rest of the chipsets don't seem to have drivers that report packets in raw monitor mode correctly. [05:01.690 --> 05:03.870] Atheros and Prism 2 work on FreeBSD 5. [05:04.130 --> 05:07.110] They don't work on FreeBSD 4, again, because of problems with monitor mode. [05:07.850 --> 05:11.270] And I haven't heard anyone really trying to run it on NetBSD. [05:11.630 --> 05:14.290] So, if you're running it on NetBSD, come talk to me afterwards. [05:16.210 --> 05:18.970] Windows can run it sort of. [05:21.810 --> 05:24.910] There's no public drivers that can do raw packet mode yet. [05:25.790 --> 05:29.770] There's been some people working on hacking it into existing drivers. [05:30.230 --> 05:39.050] But the only one I've heard of recently was hacks to the Prism 2 drivers and that was just last week so we haven't investigated it too much. [05:39.050 --> 05:46.410] You can use it as a client for other systems running supported drivers. [05:46.670 --> 05:57.910] So, if you have a WSP100 embedded sniffer from network chemistry or a Kismet drone or a WRT54G access point running it, you can get your data on the windows that way through SIGWIN. [06:00.570 --> 06:01.950] Now, here's where it gets interesting. [06:02.090 --> 06:03.810] The difference is between a sniffer and a stumbler. [06:04.590 --> 06:05.850] Kismet's actually a sniffer. [06:07.230 --> 06:14.050] I just kind of referred to the others as stumblers, NetStumbler, MiniStumbler, MacStumbler, there's a whole bunch of them. [06:15.270 --> 06:17.550] Sniffers will actually capture the raw packet data. [06:18.430 --> 06:22.450] Kismet requires monitor mode to be on so it captures the raw 8.0211 layer data. [06:23.110 --> 06:36.150] But while stumblers will query the card's firmware, the card will constantly look for networks to join and report to the operating system what networks it found that allow it in and the stumbler just queries that. [06:36.330 --> 06:39.730] So, you can't get data frames but you don't usually need special drivers. [06:40.250 --> 06:43.650] So, there's advantages and disadvantages to both. [06:46.450 --> 06:47.150] Monitor mode. [06:47.290 --> 06:48.450] This is one that gets a lot of people. [06:48.850 --> 06:50.870] Monitor mode versus promiscuous mode. [06:51.430 --> 06:56.390] Monitor mode puts the card into raw mode where it is not part of any network. [06:56.650 --> 06:58.590] It's just reporting all packets it sees. [06:59.250 --> 07:03.650] 802.11 management, the data frames, and everything else get reported to the operating system. [07:03.990 --> 07:06.530] But it can't transmit while it's in monitor mode. [07:07.630 --> 07:13.030] Promiscuous mode on wired Ethernet means it turns off the filter and receives all traffic on the network. [07:13.290 --> 07:22.490] In wireless mode, usually it means that you get all of the data frames on the network but without the management headers and only on the network you're associated with. [07:22.490 --> 07:24.230] On some drivers it means nothing. [07:25.510 --> 07:27.170] Different drivers supported it differently. [07:28.030 --> 07:31.870] And monitor mode requires support from the chipset which almost all of the chipsets do. [07:32.070 --> 07:33.870] There's a few exceptions. [07:34.850 --> 07:37.790] And not all of the drivers support it. [07:38.050 --> 07:41.130] And not all the drivers on all of the platforms support it in a way that's useful. [07:44.090 --> 07:46.830] Kismet does all of its network detection completely passively. [07:47.690 --> 07:55.670] If you're running it other than, you know, the RF interference generated by a running electronic device, there's no way to know you've got anything sniffing the area. [07:55.930 --> 07:58.210] It's as if your car radio was tuned to a station. [08:00.410 --> 08:03.310] With monitor mode, we can get all of the management frames. [08:03.850 --> 08:09.650] When we get all the management frames, we can infer that a network is there, even if it's not advertising itself as an open network. [08:11.270 --> 08:17.290] Access points, ten times a second usually advertise, here I am, I'm an access point. [08:17.570 --> 08:18.410] They're easy to find. [08:19.030 --> 08:21.150] Ad hoc networks usually beacon the same way. [08:21.150 --> 08:25.550] We can also find people with laptops who are looking for a network. [08:26.210 --> 08:29.150] If it's a network that's there, we can find that they're connected to a network. [08:29.370 --> 08:42.150] Or if it's a network that isn't around, like say they work for a big company and then took their laptop home, we can find out what company the guy in the apartment next door works for, if he's looking for a network that has the company's name in it. [08:44.490 --> 08:46.990] And no packets are sent by the sniffer ever. [08:48.610 --> 08:52.870] The only exception to that is there's a few buggy drivers, which leave the card probing. [08:53.150 --> 08:58.070] But it's something in the card firmware itself and not controllable by the operating system. [08:58.990 --> 09:05.710] And passive sniffer can detect active stumblers like NetStumbler because the card NetStumbler is constantly seeking out networks. [09:06.270 --> 09:11.610] And NetStumbler itself sometimes specifically sends frames saying, I'm NetStumbler. [09:11.810 --> 09:15.650] And it's trying to uncover networks using that. [09:26.130 --> 09:31.790] I'll just fire it up, do a little quick demo of the features it's got and cover a few more things after that. [09:35.160 --> 09:37.460] So that's your standard, is that readable? [09:39.720 --> 09:41.000] That's your standard window. [09:43.120 --> 09:46.360] It just summarizes all the networks Kismet is seeing at the time. [09:47.180 --> 09:50.340] You can sort the network list by various methods. [09:50.340 --> 09:54.700] And then extract info about each network in detail. [09:55.540 --> 09:57.380] Like this is Speedstream. [09:57.620 --> 09:58.700] They're somewhere around here. [10:02.100 --> 10:04.100] They're talking on 11B only. [10:05.300 --> 10:06.960] Max rate of 11 megabit. [10:07.320 --> 10:09.840] And then just other information about the network. [10:10.700 --> 10:13.600] You can do packet rate graphs. [10:14.560 --> 10:18.240] And, well, people probably used it. [10:19.160 --> 10:22.700] Is there anything specifically that people would be interested in having and seeing it? [10:23.720 --> 10:24.320] What's that? [10:25.200 --> 10:25.640] SSID. [10:26.300 --> 10:26.740] Right. [10:27.400 --> 10:29.020] Here's one that is cloaked. [10:29.240 --> 10:30.920] We haven't seen enough data to uncloak it. [10:32.740 --> 10:35.100] The question was uncloaking SSIDs. [10:35.560 --> 10:40.000] Kismet will automatically decloak the SSID as soon as it sees enough data to do it. [10:40.660 --> 10:42.780] I actually mention that in the next part of the presentation. [10:49.490 --> 10:51.250] That's the least interesting part actually. [10:51.530 --> 10:54.210] So, we'll just... [11:05.490 --> 11:06.090] Okay. [11:06.190 --> 11:06.630] Well, here we go. [11:06.730 --> 11:07.490] Detecting networks. [11:08.030 --> 11:08.970] Security that isn't. [11:09.070 --> 11:13.750] Vendors like to come up with measures that they call security features that don't mean anything in the end. [11:15.190 --> 11:18.110] One of the most common ones that's been up is cloaking your SSID. [11:18.830 --> 11:22.030] I think Linksys started it, but now just about everyone supports it. [11:22.870 --> 11:27.190] All it means is the AP doesn't put your SSID in the beacon packets. [11:27.470 --> 11:29.650] The idea was to keep people from knowing your... [11:29.650 --> 11:32.530] People who didn't know your network name wouldn't be able to connect to your network. [11:32.910 --> 11:37.290] Which seems like a good idea, except the protocol was never designed to hide that field. [11:37.590 --> 11:41.490] So, as soon as someone connects to your network, your AP says, oh, right, that's me. [11:41.670 --> 11:42.330] And answers. [11:44.190 --> 11:46.670] If you can see all the frames, you can see that exchange. [11:46.970 --> 11:48.330] You've automatically decloaked the network. [11:48.450 --> 11:50.210] You don't even have to touch the airwaves to do it. [11:50.910 --> 11:52.390] There are active ways to do it. [11:52.950 --> 11:54.510] Other people have written tools to do that. [11:56.490 --> 12:04.930] Another attempt was turning off beaconing or reducing the beaconing of access points so that if there are no users on it, they wouldn't generate data themselves to announce their presence. [12:05.550 --> 12:08.130] Which is a good idea until you have a user on your network. [12:08.290 --> 12:10.810] At which point, there you go. [12:10.910 --> 12:11.470] There's a network. [12:11.590 --> 12:12.190] You're open again. [12:13.930 --> 12:20.470] And hiding a network from a passive sniffer, be it Kismet or Ethereal or TCP dump or anything else sniffing the airwaves that way, it's impossible. [12:20.710 --> 12:25.650] As soon as you're transferring data, you're talking the protocol, you're in the air, someone can intercept it and see that you're there. [12:25.790 --> 12:27.410] No matter what you try to try to hide it. [12:29.090 --> 12:31.750] Of course, you can encrypt it securely and then you don't have a problem. [12:34.330 --> 12:40.430] Wireless IDS functions in Kismet are rudimentary at the moment, but they'll be expanded in the future. [12:41.230 --> 12:43.210] The easiest part of it is fingerprint matching. [12:43.650 --> 12:45.690] Some tools send out very specific frames. [12:46.530 --> 12:48.250] NetStumblr, as I mentioned, sends out a frame. [12:48.590 --> 12:54.190] Different versions have little different bits of text in them so we can even identify what version of NetStumblr someone is running in the area. [12:55.530 --> 13:03.790] Lucent Site Survey, Wellenreiter, which I know I'm not pronouncing right, but nobody... I don't know if anybody really knows how to pronounce that one right. [13:04.990 --> 13:09.870] And some of the 802.11 attacks where it's a single frame sent are very easy to fingerprint. [13:10.090 --> 13:11.630] So those are always 100%. [13:11.630 --> 13:14.090] You see that frame, you know someone's doing that attack. [13:14.510 --> 13:16.290] So that's the easiest IDS to do. [13:16.290 --> 13:19.570] Trend based IDS thing is a little bit more difficult. [13:20.230 --> 13:28.590] Kismet basically uses a finite state autonomous machine where it hops through different states depending on what the protocol is doing. [13:28.790 --> 13:39.410] So we can tell if someone is going outside the protocol, if they're trying to corrupt things, or if there's a certain number of standard packets in a short amount of time, we can detect that pattern. [13:39.710 --> 13:44.630] And that's an attack when otherwise a single frame wouldn't constitute an attack. [13:44.630 --> 13:52.750] So flooding, access point spoofing, and detection of active sniffers that aren't sending out specific frames. [13:53.710 --> 13:55.070] NetStumbler doesn't always do it. [13:55.290 --> 14:02.410] But we can tell by their behavior that they're trying to connect to all the networks in the area, the networks are allowing them in, and then they're never using the networks. [14:02.750 --> 14:04.250] So they're scanning. [14:07.430 --> 14:09.890] You can do distributed IDS with Kismet now. [14:10.670 --> 14:16.850] There's a lightweight version of the Kismet server that simply captures packets off the wireless and dumps them onto the wire. [14:17.270 --> 14:32.130] So you can cover an entire building with very small sniffers and report all back to a central location, decrypt the data, run it through IDS, and have your networks management console displaying all of that. [14:32.330 --> 14:36.950] The stripped down drones run on 4 46's, 46's, access points, handhelds. [14:37.870 --> 14:39.550] Pretty much anything you want will run it. [14:39.650 --> 14:41.070] It's a very small application. [14:42.450 --> 14:48.190] And we can do web decryption on the entire network in one location. [14:50.630 --> 14:53.170] And cooperating with the other kids in the playground. [14:53.850 --> 14:59.970] The Unix philosophy has always been write a number of small tools to do specific things that interoperate with each other. [15:00.070 --> 15:02.910] So you can build larger emergent systems out of the smaller tools. [15:02.910 --> 15:07.730] If you look at string utils, all the things like that, core utils that come with Unix. [15:07.930 --> 15:09.290] It's designed with that philosophy. [15:09.570 --> 15:12.410] So I tried to go along with that with Kismet. [15:13.430 --> 15:14.890] There's no reason to duplicate effort. [15:15.010 --> 15:18.930] Ethereal is one of the best open source packet detectors out there. [15:19.190 --> 15:23.610] There's no point replicating 2 meg of code for no gain. [15:23.790 --> 15:25.250] So Kismet works with Ethereal. [15:25.450 --> 15:27.810] Anything that can read PCAP files can read Kismet files. [15:29.410 --> 15:36.730] So you can load it in drift net, TCP dump, ethereal, dsniff, anything you like that dissects packets. [15:38.770 --> 15:41.570] You can do live packet streaming for IDS functions. [15:42.030 --> 15:46.070] So Kismet can dump live all the packets after it decrypts the web to a pipe. [15:46.290 --> 15:49.330] Link that to snort and you get layer 3 IDS even if your network's encrypted. [15:50.630 --> 15:56.890] And you can connect the entire drone or the entire network worth of drones through the one pipe to the IDS. [15:56.890 --> 16:01.230] And use that as layer 3 IDS as well as layer 2. [16:02.330 --> 16:04.550] And all of the log files are written as XML. [16:04.870 --> 16:16.870] So anyone who needs to reprocess that into another network, into another tool, web page viewers, log aggregators, audit records, things like that, all of the output is saved in XML. [16:19.770 --> 16:42.450] For word driving and site auditing, the more interesting component of it is GPS map, which takes all of the XML files that are generated, overlays it on top of maps from public sites like Terra Server or MapQuest, MapBlaster, a few other map sources, and lets you plot graphically the maps you had. [16:42.930 --> 16:46.850] It can graph networks about a dozen different ways. [16:46.850 --> 16:50.550] The best ways, the best ways to look at the ReadMe and see what's appropriate for what you do. [16:51.390 --> 16:52.930] You can do network center guessing. [16:53.230 --> 16:56.970] You can do the smallest polygon that fits all the sample points. [16:57.050 --> 16:59.750] So you can see what the absolute coverage of your network is. [17:00.030 --> 17:01.750] You can do range estimation. [17:01.790 --> 17:04.590] You can do power estimation and interpolation. [17:05.410 --> 17:07.330] And you can color it by channels. [17:07.490 --> 17:13.610] So if you're doing a site audit, you can see where other access points are going to be stomping on your channels and causing contention. [17:14.110 --> 17:15.870] And other things like that. [17:15.870 --> 17:17.070] I've got a few. [17:18.510 --> 17:20.030] Yeah, that was what I was afraid of. [17:20.090 --> 17:24.170] They're not too visible, but that's a map of all the access points near my apartment. [17:25.490 --> 17:34.510] And that's the signal interpolation, where it attempts to use the signal levels it knows to guess estimated signal levels around the known sample points. [17:35.170 --> 17:36.910] And it's good for auditing. [17:38.830 --> 17:40.610] So, cards that work well. [17:40.810 --> 17:46.450] I'm hesitant to endorse specific cards more than others, but these are known to work quite well. [17:46.830 --> 17:48.230] Prism 2-based cards. [17:50.090 --> 17:56.830] Cinaio, NGenius, DeMarc Tech, and high power SMC cards, 200 milliwatt ones, are all really good cards. [17:57.050 --> 18:00.850] They've got external antenna jacks, and the Prism 2 chipset is very well understood. [18:01.010 --> 18:04.170] Intercell has been working with open source for a while now. [18:04.870 --> 18:18.150] And if you're looking to doing wireless hacking stuff, if you're looking to set up your own software controlled access points, running Kismet, running Sniffers, doing raw transmission, if you're experimenting with that, Prism 2 is the way to go. [18:18.630 --> 18:19.110] Orinoco. [18:19.110 --> 18:23.010] Probably the best cards you can get out now, and they're only about $50, $60 for a really good card. [18:24.630 --> 18:25.110] Orinoco. [18:25.350 --> 18:26.970] Old Orinocos work very well. [18:27.190 --> 18:29.070] The original ones with the square antennas. [18:29.930 --> 18:36.290] The new Orinocos have a shorter round antenna and a really excited guy in the front going with a suitcase. [18:36.850 --> 18:40.330] I don't know why he's carrying a suitcase and being really excited about wireless. [18:40.670 --> 18:41.590] They don't work. [18:44.530 --> 18:47.750] So maybe he's saying, yay, I can't use my card. [18:50.490 --> 18:54.650] So it's really, it's an unfortunate thing because they have the same name. [18:55.210 --> 19:00.790] And Orinoco even, or rather, Proxim, who now owns them, branded them the same as Orinoco Classic. [19:01.390 --> 19:04.470] So you can't even say, yeah, the original Classic cards. [19:05.830 --> 19:07.650] So if you're going to get one, get it off eBay. [19:08.010 --> 19:10.390] Be really sure about what you're getting. [19:11.010 --> 19:13.450] Hopefully the new ones will have monitor mode support soon. [19:14.030 --> 19:17.310] But at the moment, they don't work in 2.6 and they don't have monitor mode. [19:19.090 --> 19:20.190] Atheros-based cards. [19:20.970 --> 19:24.170] Actually, the Orinoco B and G cards are Atheros-based. [19:25.310 --> 19:29.170] Most of the other A, B, and G cards are also Atheros-based. [19:29.410 --> 19:30.330] They work well. [19:30.750 --> 19:34.470] The Mad Wi-Fi drivers in Linux and FreeBSD work well with them. [19:34.890 --> 19:38.650] And they do the job if you need to sniff across multiple bands. [19:39.070 --> 19:42.870] And Prism GT 802.11 G cards also work well. [19:43.330 --> 19:44.650] There's drivers for them in Linux. [19:44.870 --> 19:46.870] I don't know if there's drivers for them in BSD. [19:46.870 --> 19:50.190] Anyone happen to know? [19:50.570 --> 19:51.470] Wave your hand up. [19:51.670 --> 19:51.730] No? [19:52.230 --> 19:52.470] Okay. [19:52.790 --> 19:54.090] I'm going to assume they don't work in BSD. [19:54.210 --> 19:56.090] I haven't heard anything about them working in BSD. [20:01.990 --> 20:02.730] Right, right. [20:02.910 --> 20:06.450] The Mad Wi-Fi drivers were BSD and ported to Linux. [20:06.950 --> 20:11.070] And I think they're pretty much co-developed now on both platforms with the same binary core. [20:11.490 --> 20:11.890] Right? [20:13.550 --> 20:14.330] Whoever was saying. [20:14.630 --> 20:19.770] Well, anyhow, they were originally written for BSD, ported to Linux, and now they're operating on both. [20:19.910 --> 20:21.530] And they're a pretty good driver set. [20:21.710 --> 20:25.370] And they're the most reliable one on FreeBSD if you need to run Kismet there. [20:26.590 --> 20:31.930] Cards that work but aren't as stable or the drivers haven't been around as long as others. [20:32.870 --> 20:33.950] Airports on OSX. [20:34.770 --> 20:37.210] Loading the drivers in under OSX is a little funny. [20:37.550 --> 20:45.030] And I've been told that under the new versions of OSX, once you load the driver for sniffing, you have to reboot to get normal operation back. [20:46.730 --> 20:52.770] Centrino, drivers just added monitor mode for Linux about a month ago. [20:53.170 --> 21:01.410] But they added the, they decided to not screen corrupted packets but remove the field that lets you detect that it's a corrupted packet. [21:02.370 --> 21:06.810] So, you're going to see thousands of fake networks when you're sniffing at the moment. [21:07.090 --> 21:07.970] That should be fixed soon. [21:08.770 --> 21:09.090] Cisco. [21:09.370 --> 21:11.230] Two years ago we thought Cisco was really good. [21:11.850 --> 21:14.270] Anyone who was here two years ago for the talk was saying, well, Cisco. [21:14.630 --> 21:15.290] Get a Cisco. [21:15.470 --> 21:15.730] They're good. [21:16.390 --> 21:17.350] The hardware is good. [21:17.610 --> 21:18.330] The drivers aren't. [21:18.870 --> 21:21.470] They're, unfortunately, seem to be going downhill a bit, in fact. [21:21.890 --> 21:24.450] I stopped using my Cisco as my full-time card. [21:24.590 --> 21:25.890] They were getting so flaky. [21:26.730 --> 21:33.270] With monitor mode, the Cisco drivers don't hop, or they hop channels but you can't control where they're hopping. [21:33.990 --> 21:36.210] So, they're unfortunate. [21:36.470 --> 21:38.170] I wouldn't really recommend a Cisco at this point. [21:38.830 --> 21:42.350] Also, the latest firmware from Cisco doesn't work with any of the open source drivers. [21:42.770 --> 21:45.890] And as far as I know, they haven't released any info to let that happen. [21:47.870 --> 21:53.270] ACX100 is a set used in the 22-megabit cards from D-Link and a few others. [21:53.550 --> 21:54.390] They work. [21:55.610 --> 21:57.230] The drivers are fairly new. [21:58.270 --> 22:00.230] They weren't that stable when I played with them. [22:00.590 --> 22:04.330] But if you need a card that works, it will probably work. [22:04.490 --> 22:10.190] And ADM tech, recently there's GPL drivers that added monitor mode support. [22:10.450 --> 22:12.110] Kismet will support those drivers soon. [22:13.830 --> 22:17.570] The other binary drivers, there was a hack to them to let them work. [22:18.110 --> 22:20.130] But they weren't entirely stable. [22:21.150 --> 22:23.850] Cards that definitely will not work, unfortunately. [22:24.510 --> 22:24.910] Broadcom. [22:25.290 --> 22:27.830] Anything that uses Broadcom, you're basically screwed. [22:28.050 --> 22:36.010] You can't even get it working in normal mode on a free operating system right now without using something like NDis wrapper that loads Windows drivers into the Linux kernel. [22:36.630 --> 22:38.910] Which isn't a good idea. [22:41.110 --> 22:42.710] Broadcom won't release specs. [22:42.930 --> 22:45.670] The last I heard, they weren't even willing to admit that people use Linux. [22:46.950 --> 22:51.690] So... Airport Extreme, it's just a Broadcom. [22:52.090 --> 22:54.390] The original Airport was basically just Norinoco. [22:54.590 --> 22:55.750] The Extreme is just a Broadcom. [22:55.970 --> 22:56.690] Same problems. [22:57.970 --> 23:02.370] As near as anyone has been able to tell, Atmel has no monitor mode in the firmware. [23:04.030 --> 23:05.430] It just can't do it. [23:05.790 --> 23:07.430] So those aren't supported. [23:07.550 --> 23:08.450] They probably never will be. [23:09.370 --> 23:09.770] Realtek. [23:10.690 --> 23:13.690] There's no monitor mode support in the drivers that there are now. [23:13.950 --> 23:17.690] And I hadn't heard of anyone working on adding it or if the radio even supports it. [23:18.310 --> 23:21.510] And Hermes 2 is the new Orinoco chipset. [23:22.030 --> 23:25.250] There's no support now, but there will be hopefully soon. [23:25.390 --> 23:31.190] Either in the 2.6 drivers, they're looking at adding support for it or they'll get added to the Proxim drivers. [23:33.270 --> 23:38.470] And some other tools that people might want to check out if they don't want to run Linux or BSD for this. [23:39.150 --> 23:40.590] NetSumbler for Windows, obviously. [23:41.810 --> 23:50.810] Kismac for OSX is actually has nothing to do with Kismet other than a name similarity, but the functionality is almost the same and they've got a very nice GUI. [23:50.970 --> 23:53.550] So if you're looking to use it on a Mac, that might be a better choice. [23:54.370 --> 24:00.090] And of course, Ethereum and TCP dump, which everyone's favorite packet sniffers. [24:01.930 --> 24:04.310] And that's all I had pre-written. [24:05.650 --> 24:07.490] I can take some questions if people want. [24:07.630 --> 24:12.650] I'd like to try to keep it away from the tech support and more on the, like, planning or whatever, but... [24:16.120 --> 24:19.120] I guess, yeah, I guess I'll just line up if there's enough people with questions. [24:22.120 --> 24:23.000] WEP is broken. [24:23.000 --> 24:24.340] What do you think of WPA? [24:25.060 --> 24:25.940] It's better than WEP. [24:26.100 --> 24:27.340] It's probably good enough for home. [24:28.200 --> 24:35.380] I haven't heard anything that convinces me it's good enough for a business or like a doctor's office where keeping the data secure is that important. [24:36.520 --> 24:40.000] Right now, Kismet doesn't detect WPA specifically, but it will soon. [24:41.860 --> 24:44.720] Later this summer, we'll be doing a big rewrite of it. [24:45.300 --> 24:46.880] I'll be doing a big rewrite of it anyway. [24:48.760 --> 24:49.460] Royal Wii. [24:50.640 --> 25:00.440] I'll be doing a big rewrite of a lot of the code, trying to make it smaller and faster, and I'll be adding a lot of things that have been pending for the past few months because I've been wrapped up helping these guys for the wireless here. [25:03.430 --> 25:10.170] Is 802.11 management its own, like, transport layer protocol? [25:11.130 --> 25:11.550] Yeah. [25:12.970 --> 25:17.150] It's got its own ARP headers, and, yeah, it's its own layer 2 protocol. [25:18.750 --> 25:22.650] Your best bet, the IEEE 11B specs are completely public now. [25:22.750 --> 25:23.750] You should be able to find them with Google. [25:25.030 --> 25:26.750] Or talk to me afterwards, I'll show you it. [25:28.430 --> 25:30.390] Yeah, it's its own layer 2 protocol. [25:30.630 --> 25:40.290] It's it defines what networks are there, it controls joining and leaving a network, and it's a really naive, bad protocol, honestly. [25:41.870 --> 25:44.270] We mentioned it somewhat in the talk yesterday, too. [25:44.630 --> 25:56.330] Most of the problems that we're seeing with wireless now is because of a naive protocol design in the beginning, and continuing backwards compatibility that has to retain the problems of the naive protocol. [25:58.150 --> 26:00.590] It defines networks at layer 2 with no encryption. [26:00.890 --> 26:02.290] You don't encrypt management frames. [26:02.510 --> 26:04.050] The only authentication is your MAC address. [26:05.050 --> 26:07.370] Who can't copy a MAC address and create a management frame? [26:07.590 --> 26:08.690] Oh, there's a new network. [26:08.830 --> 26:10.350] Oh, there's a network telling you it's gone. [26:11.290 --> 26:12.450] You know, take your pick. [26:14.590 --> 26:14.990] So... [26:15.490 --> 26:19.410] In terms of the IDS work that you're currently doing... Right. [26:19.550 --> 26:22.570] And the, you know, the patches that are coming out for the snort stuff to do wireless. [26:23.750 --> 26:28.450] Like, what is, like, your future that you see in terms of, like, wireless IDS? [26:28.730 --> 26:35.890] Like, do you think that it can become, like, something that's, like, an active IDS to where, like, you know, it can do, like, some funky things in between that can detect or... [26:35.890 --> 26:39.510] Well, we're actually running an active IDS here. [26:40.610 --> 26:42.370] We'll talk about it tomorrow at the network thing. [26:43.090 --> 26:47.130] It's a combination of some raw transmitter stuff, Kismet, and a bunch of custom code. [26:47.730 --> 26:51.530] So it, it, the, the APs will act to protect themselves to a certain extent. [26:52.870 --> 26:57.930] As far as IDS in general and Kismet, right now, I think it's at the very beginning of its lifespan. [26:59.590 --> 27:03.850] I want to make it so that it's more like snort where you can plug things into it without modifying the code. [27:05.670 --> 27:06.370] Modularize it more. [27:07.130 --> 27:10.150] Do you think that, because currently I'm running, like, a couple of drones. [27:10.570 --> 27:10.630] Yeah. [27:10.710 --> 27:20.610] And the thing is, is that it seems a little bit more easier and a little bit more manageable to pipe everything into, directly into snort without even doing any IDS, you know, using Kismet. [27:20.770 --> 27:22.070] Like, is that pretty much, like, the idea? [27:22.370 --> 27:27.150] Well, the idea with Kismet was to do the layer 2 IDS, the, the, the radio level. [27:27.670 --> 27:34.910] So 802.11 attacks, we could detect at that level and then let snort handle the TCP layer, the IP layer and up. [27:35.150 --> 27:35.630] Thanks. [27:36.150 --> 27:38.610] So, yeah. [27:40.350 --> 27:45.510] I have a couple of questions on data string logging for Kismet and I've noticed a couple of observations. [27:45.990 --> 27:53.410] I've seen data packets come through, through ethereal, running Kismet at the same time, that it misses versus the data strings. [27:53.890 --> 27:56.510] Also, is there provisions for data string logging? [27:57.290 --> 27:59.050] Right now, it doesn't do data string logging. [27:59.270 --> 28:01.690] That's waiting until I rewrite the whole logging system. [28:01.850 --> 28:02.850] I'm trying to make it all modular. [28:03.070 --> 28:08.150] So there can be plug-ins, so you can strip out stuff you don't need for hand-held systems and things like that. [28:10.170 --> 28:14.250] Well, Kismet determines if it's going to extract a string based on packet attributes. [28:14.450 --> 28:20.690] I'd have to see exactly what your packet was to figure out why it showed up in one and not the other. [28:20.890 --> 28:22.490] I'll use some log files on that. [28:22.610 --> 28:23.990] It was strange and I noticed it. [28:24.130 --> 28:26.050] I'm like, I thought it was my end. [28:27.310 --> 28:28.910] I'd have to take a look at the log files. [28:30.770 --> 28:33.750] Kismet does a lot to verify that the packet it's seeing is valid. [28:34.730 --> 28:35.630] Ethereum doesn't. [28:35.990 --> 28:42.550] So Kismet won't try to do too much processing on a packet that's corrupt, because there's a lot of drivers that feed us corrupt frames. [28:43.210 --> 28:45.710] So that might be what you're seeing. [28:45.830 --> 28:46.590] I'd have to see the log. [28:46.910 --> 28:52.690] I also wanted to ask you, how much overhead does the complete OUI table use for the Kismet? [28:52.830 --> 28:53.790] A lot of memory. [28:54.950 --> 28:56.610] A moderate amount of CPU. [28:56.910 --> 28:57.290] Okay. [28:57.870 --> 28:58.190] Thank you. [28:58.390 --> 29:08.710] I don't have exact numbers on it, but the built-in tables that Kismet runs are 40 or 50 lines in the big OUI tables to 2 meg text file. [29:09.350 --> 29:19.370] Once you map that into the hash map that it's used to do lookups internally, you're talking a big chunk of memory, which is why I don't do it automatically, but if you're running it on a laptop with plenty of RAM, go right ahead. [29:19.870 --> 29:20.590] Thank you. [29:23.950 --> 29:24.950] Two questions. [29:25.270 --> 29:25.530] Sure. [29:25.990 --> 29:31.110] One, could you comment some more on the relationship between Kismet and Kismac? [29:32.770 --> 29:35.750] The question was the relationship between Kismet and Kismac. [29:36.670 --> 29:40.250] The Kismac guys went out and wrote a sniffer and used a name that was similar. [29:40.570 --> 29:42.010] That's pretty much the only relationship. [29:42.410 --> 29:44.690] They did a good job, though. [29:44.810 --> 29:45.690] It's a pretty slick sniffer. [29:45.810 --> 29:46.930] It's all in Objective-C. [29:49.150 --> 29:50.470] I don't like Objective-C. [29:50.590 --> 29:53.070] I'm amazed they wrote that much of it, so good on them. [29:54.830 --> 29:57.270] They seem to be really doing a good job with the OSX stuff. [29:57.490 --> 30:00.210] The GUI is very nice, so if you're looking... I just recommend it. [30:00.270 --> 30:12.170] If you're looking for something with a prettier GUI than N-Curses, you might want to look into that because, you know, I don't have an OSX box to do development on, so I don't get to polish it quite as much on that platform. [30:17.020 --> 30:22.560] Second, are you aware of any attempts to detect passive sniffer? [30:22.860 --> 30:25.980] Any work in, like, detecting passive sniffers? [30:27.320 --> 30:28.780] I haven't really heard of much. [30:28.920 --> 30:31.540] I mean, the only way to really do it would be at the RF layer. [30:33.700 --> 30:37.960] Detecting that there is something resonant on that frequency in the area. [30:38.080 --> 30:40.440] I mean, the radio itself shouldn't transmit anything. [30:40.860 --> 30:45.260] Although it is an antenna hooked up to a hunk of electronics, so. [30:47.180 --> 30:49.080] I haven't heard of anyone really working on it. [30:49.500 --> 30:53.440] I suppose something kind of like Tempest would be able to detect that there is a laptop in the area. [30:57.560 --> 30:58.960] Anybody hear anything about that? [30:59.120 --> 30:59.520] Raise your hand. [31:09.500 --> 31:16.540] The answer was there's radio concepts that can be used to look for scanners, but they're really sketchy and probably not applicable to 802.11. [31:18.220 --> 31:24.520] I wouldn't take that as a guarantee that nobody is going to detect you doing something if you're somewhere you really shouldn't be, that they're really looking for you. [31:25.300 --> 31:33.110] But it's not something simple and it's not something most places would be able to handle doing. [31:34.140 --> 31:34.380] So... [31:39.840 --> 31:40.280] Okay. [31:40.280 --> 31:41.020] Two things. [31:41.440 --> 31:45.640] Are we ever going to be able to get channel hopping working on WRT 54Gs? [31:45.980 --> 31:48.020] Is that your end or their firmware? [31:48.820 --> 31:50.260] That's just my end. [31:50.700 --> 31:51.400] Good question. [31:51.500 --> 31:54.740] The question was channel hopping on Linksys access points. [31:55.680 --> 32:01.900] That's actually just that I hadn't written it in because when I wrote it, I didn't want to break people's access points. [32:02.100 --> 32:02.300] Yeah. [32:02.460 --> 32:05.860] From what I originally saw, it was just sheer luck it happened to compile for the thing anyways. [32:06.100 --> 32:06.380] Yeah. [32:06.800 --> 32:12.920] By stroke of luck, the Linksys access points can be an access point and monitor mode at the same time. [32:13.320 --> 32:18.360] So you can run Kismet on one, sniff your own network, and do IDS on your own network from your access point. [32:19.220 --> 32:19.660] But... [32:19.660 --> 32:21.480] That'd be a nice little product to have. [32:22.000 --> 32:30.260] Other thing is, if you're doing a rewrite anyways, ever thought about, since you're able to dump data strings, any sort of interoperability with DriftNet or anything like that? [32:30.260 --> 32:32.820] Actually, DriftNet will work with... [32:32.820 --> 32:35.240] It should read from the FIFO directly already. [32:35.860 --> 32:37.920] And it should... [32:37.920 --> 32:47.880] Rob Timko added support for it to understand 802.11 formatted frames so we can do... If you're just in monitor mode, you can fire up Kismet and DriftNet independently. [32:48.520 --> 32:56.000] And it won't do the packet filtering and what not Kismet does, but it would let you see images at the same time. [32:56.300 --> 32:58.440] Okay, that just makes my network management a little more interesting. [32:58.940 --> 33:06.880] But yeah, you should be able to just dump the FIFO pipe right to DriftNet and use that to view all the images from the drone network or whatever you have hooked up. [33:06.880 --> 33:09.720] What kind of antenna do you use when you're sniffing? [33:10.640 --> 33:15.540] I have a 8 dBi Omni bolted to the roof of my car and... [33:17.060 --> 33:18.260] Yeah, stereotypical, I know. [33:20.880 --> 33:22.220] It's my damn stereotype. [33:25.500 --> 33:34.040] Yeah, I just have an 8 dBi Omni that I have bolted to the car and a really modified IBM network PC that was designed to netboot token ring in a Java operating system. [33:36.060 --> 33:37.060] Tweaked into running. [33:37.340 --> 33:38.260] Yes, they made them. [33:38.380 --> 33:39.240] They were about $1600. [33:39.600 --> 33:40.440] They don't make them anymore. [33:40.600 --> 33:41.220] That's why. [33:43.640 --> 33:45.300] It's a Pentium 233. [33:45.540 --> 33:48.960] So I just have it booting off compact flash and it lives in my car and it runs all the time. [33:50.320 --> 33:52.320] So... Yeah. [33:53.200 --> 33:54.120] Am I low on time? [33:54.260 --> 33:55.060] Is that what I'm getting waved at? [33:55.180 --> 33:55.620] Five minutes. [33:55.880 --> 33:56.040] Okay. [33:57.280 --> 33:57.780] So yeah. [33:58.780 --> 34:02.400] I'd recommend if you're serious about doing war driving stuff or just curious about it. [34:02.780 --> 34:05.040] An external antenna will really help you. [34:05.540 --> 34:10.280] Getting the receiver outside that big metal box makes a really big difference. [34:12.740 --> 34:13.760] Any other questions? [34:20.390 --> 34:22.870] There's not a chance I can hear you without the microphone. [34:28.580 --> 34:29.100] Okay. [34:30.000 --> 34:36.640] So what you're saying is a two pipe kismet to some sort of like packet analyzer or anything. [34:36.820 --> 34:38.640] You can just do like a standard Unix pipe? [34:38.960 --> 34:39.400] Right. [34:39.600 --> 34:43.180] You can configure it to open a FIFO pipe anywhere you want. [34:43.460 --> 34:46.720] And it will do a live dump of the decrypted packets. [34:47.000 --> 34:48.680] It will also do packet mangling. [34:48.820 --> 34:56.500] So it will take a wept packet, decrypt it, mangle it into looking like it was a standard 802.11 unwept packet and shoot it into the pipe. [34:56.780 --> 35:00.640] It will screen out the junk packets and then you can just open that pipe with anything. [35:00.980 --> 35:01.420] Radical. [35:05.120 --> 35:07.260] Well, I will vacate for the next person then.