Skip to main content

Posts

WiFi Pineapple: It’s Not a Fruit

Credits: https://fractionalciso.com/wifi-pineapple Suppose you see a few people in a rented car, parked across a street at a hotel, next to an office. Does this sound suspicious to you at all? Not at all! Right? In a real-life version of this story, those people were attempting to perform a cyber-attack on the Organization for the Prevention of Chemical Weapons (OPCW). According to  reporting on the incident , Dutch law enforcement foiled their attempts when they discovered their ‘weaponized’ car with long-range high-gain WiFi antennas, battery backup, and power inverter and something that looked to be a WiFi Pineapple kit.  Such “close access” attacks on WiFi networks are well known in the cybersecurity world, as an established technique for penetrating a target. The news of the Dutch attack validates that the threat is real .  The WiFi Pineapple just makes it easy to target WiFi access points, as well as employee’s WiFi-enabled devices. WiFi Pine...

WIFIPHISHER

Introduction Wifiphisher is a rogue Access Point framework for conducting red team engagements or Wi-Fi security testing. Using Wifiphisher, penetration testers can easily achieve a man-in-the-middle position against wireless clients by performing targeted Wi-Fi association attacks. Wifiphisher can be further used to mount victim-customized web phishing attacks against the connected clients in order to capture credentials (e.g. from third party login pages or WPA/WPA2 Pre-Shared Keys) or infect the victim stations with malwares. This site aims to provide with resources regarding the tool usage and the ongoing research. The most important changes (features, bugfixes etc) in each Wifiphisher version are described on the  Changelog . Using Wifiphisher is covered on the  Documentation Guide . You can also follow us on  Twitter  or like us on  Facebook  or star us on  Github . Happy phishing! :) News Wifiphisher v1.4 is out! Date:  2...

HACK WIFI USING DRAGONBLOOD

DRAGONBLOOD Analysing WPA3's Dragonfly Handshake By  Mathy Vanhoef  (NYUAD) and  Eyal Ronen  (Tel Aviv University & KU Leuven) Currently, all modern Wi-Fi networks use WPA2 to protect transmitted data. However, because WPA2 is more than 14 years old, the Wi-Fi Alliance  recently announced  the new and more secure WPA3 protocol. One of the main advantages of WPA3 is that, thanks to its underlying Dragonfly handshake, it's near impossible to  crack  the password of a network. Unfortunately, we found that even with WPA3, an attacker within range of a victim  can still recover the password of the Wi-Fi network . Concretely, attackers can then read information that WPA3 was assumed to safely encrypt. This can be abused to steal sensitive transmitted information such as credit card numbers, passwords, chat messages, emails, and so on. The Dragonfly handshake, which forms the core of WPA3, is also used on certain Wi-Fi n...

DIY INTERNET SERVICE PROTOCOL (ISP)

Many people complain about their internet service, but Brandt Kuykendall did something about it. A resident of the small town of Dillon Beach, CA, he found the service to his town was too slow and expensive. After months chasing down companies to get access to internet infrastructure, he finally started a DIY ISP in his garage - and neighbors were clamoring for access to his faster, cheaper, and better-serviced network.  To continue to know about his story about How he make DIY ISP in his area. watch the link below. Published by: Freethink Youtube: https://www.youtube.com/watch?v=p52PY_cwIsA

PLDTHOMEDSL DEFAULT EXPLOIT

Good day to all doing good?  This is my first blog in cyber-security and i hope this post will help you to secure your own home router and your ISP provider that you use in your home. and this blog post is for EDUCATIONAL PURPOSES only.  Now a days many blog posts sharing how you secure your WIFI Network and how other hackers can exploit it and how can steal our private data etc.. that's the consequences of neglecting and not securing our home network not only our INTERNET CONNECTION can be compromise but also your identity and other personal and private data will expose when it exploit online. Now this is what i discover one of the internet provider here in the philippines the PLDTHOMEDSL i run some test and i tested and it works, I discover that many PLDT clients didn't change their WIFI BSSID or what we called WIFI NAME in Broadcast Mode and sadly also their WIFI PASSWORD they leave it Default Password. Here is the sample of the PLDTWIFI i discover. As ...