256
3 Hardware Trojans in Electronic Devices
Cl
ient
Facebook page
Facebook page
Plain text recognition
Identification of the Hypertext Protected
Data Transfer Protocol
Server
Fig. 3.18 Operating principle of the interception module
assess spots to which the phone has connected before (open the list of networks
on your smartphone—it is definitely going to be pretty long). Karma responds to
these requests, posing as the access point that the client is looking for. This applies
not only to open network requests that are not protected with WEP/WPA/WPA2
encryption; as a rule, nearly every modern user has at least one public hotspot, to
which the user has connected in a cafe or another public place at some moment. By
the moment of publication of this book, Karma’s effectiveness has declined, since
new devices and OS versions attempt to protect the user from this vulnerability; this
is where PineAP comes in. Its operating principle is reversed; instead of waiting for
a request, it floods the user with connection requests using the SSID list, which can
be drawn up either manually or with the help of the Autoharvest utility program.
The combination of these two methods ensures a very high possibility of hooking a
wireless client to the access point.
The second feature of the “pineapple” is SSLStrip, which, despite gradual decline
in relevance, still remains an important data interception tool. This MITM module
detects the client’s attempt to connect using the HTTPS protocol and imposes an
HTTP connection on the client, thus establishing an HTTPS connection with the
destination. The inattentive client enters his login information without noticing, and
this information is immediately saved in the log (Fig. 3.18).
WiFi Pineapple is designed as modular: it initially has only the basic elements
installed; other components can be downloaded from the control interface of the
developer’s site. They include such wonderful tools as ethercap, tcpdump, nmap,
deauth (the tool for jamming of other access points; forcibly sends disconnection
commands to clients of other access points), dnsspoof, urlsnarf, WPS service hacking
tool reaver/bully (selected by the hacker), and other useful hacking tools (Fig. 3.19).
As a rule, this device is controlled via web interface, although remote control
via SSH is also possible (reverse SSH tunnel, which is automatically set up upon
activation, is provided for remote access to the system installed in the target point).
The web interface is generally good; however, it is not perfect, and excessively fast
and active use of the interface sometimes forces the device to reboot; thankfully, all
the necessary services can be placed in the autostart. All components can be updated
directly from the interface; new firmware versions are also installed on-the-fly.
3 Hardware Trojans in Electronic Devices
Cl
ient
Facebook page
Facebook page
Plain text recognition
Identification of the Hypertext Protected
Data Transfer Protocol
Server
Fig. 3.18 Operating principle of the interception module
assess spots to which the phone has connected before (open the list of networks
on your smartphone—it is definitely going to be pretty long). Karma responds to
these requests, posing as the access point that the client is looking for. This applies
not only to open network requests that are not protected with WEP/WPA/WPA2
encryption; as a rule, nearly every modern user has at least one public hotspot, to
which the user has connected in a cafe or another public place at some moment. By
the moment of publication of this book, Karma’s effectiveness has declined, since
new devices and OS versions attempt to protect the user from this vulnerability; this
is where PineAP comes in. Its operating principle is reversed; instead of waiting for
a request, it floods the user with connection requests using the SSID list, which can
be drawn up either manually or with the help of the Autoharvest utility program.
The combination of these two methods ensures a very high possibility of hooking a
wireless client to the access point.
The second feature of the “pineapple” is SSLStrip, which, despite gradual decline
in relevance, still remains an important data interception tool. This MITM module
detects the client’s attempt to connect using the HTTPS protocol and imposes an
HTTP connection on the client, thus establishing an HTTPS connection with the
destination. The inattentive client enters his login information without noticing, and
this information is immediately saved in the log (Fig. 3.18).
WiFi Pineapple is designed as modular: it initially has only the basic elements
installed; other components can be downloaded from the control interface of the
developer’s site. They include such wonderful tools as ethercap, tcpdump, nmap,
deauth (the tool for jamming of other access points; forcibly sends disconnection
commands to clients of other access points), dnsspoof, urlsnarf, WPS service hacking
tool reaver/bully (selected by the hacker), and other useful hacking tools (Fig. 3.19).
As a rule, this device is controlled via web interface, although remote control
via SSH is also possible (reverse SSH tunnel, which is automatically set up upon
activation, is provided for remote access to the system installed in the target point).
The web interface is generally good; however, it is not perfect, and excessively fast
and active use of the interface sometimes forces the device to reboot; thankfully, all
the necessary services can be placed in the autostart. All components can be updated
directly from the interface; new firmware versions are also installed on-the-fly.
