Workshop
04. WiFi Security
Trainer
Cedric Blancher (FR
Date
TBA
Duration
1 Day
Price
Rp. 9.000.000,-
Requirement
Participants are required to bring their own laptops
Overview
This workshop aims at providing attendees a broad overview of WiFi security state of the art, mainly from the attacker point of view. It will expose all known and exploited vulnerabilities in WiFi networks, their inner basis (the why) and exploitation (the how), so one can truely understand how to secure a wireless network using whether latest security standards, i.e. WPA or WPA2, or higher level security, such as IPSEC.
After a quick introduction to 802.11, the second an main part
of the workshop will be focused on vulnerabilities and attacks,
such as network enumeration technics (wardriving), management
traffic injection, rogue APs, WEP cracking, traffic injection,
isolation bypass, captive portal bypass, etc. A big part will
address WEP cracking theoritical aspects and exploitation
technics (injection, auth bypass, fragmentation, IV/PRGA tables,
weak keys, statistical attacks from Korek). This part will show
where vulnerabilities are and introduce the last part, how to
secure the stuff. Cosmetic protections (MAC filtering, SSID
cloaking, stations isolation, WEP+/WEP2) efficiency will be
discussed as well.
The last third of this workshop aims are exposing and/or
clarifying WPA/WPA2 security scheme. As one can see by just
browsing public security mailing lists archives (just have a
look at wifisec@securityfocus.net), there's a lot of confusion
in people's mind regarding what are WPA and WPA2. This part
provides an in-depth description of thoses protocols and the
solution they bring to previously exposed attacks. Known
vulnerabilities will also be discussed. Workshop will end on
showing WPA and WPA2 availability on commonly used OS and
hardware, and the requirements to deploy and use them, to give
people WiFi security deployement best practices.
top ^
Course Outline
802.11 quick 101/reminder
Physical considerations
Frame format
Basis and functionalities
Intrinseque flaws
Physical jamming (DoS)
Bandwidth reservation (DoS)
802.11 early security: WEP
RC4 reminder
WEP data encryption
WEP authentication
Vulnerability sources identification
802.11 flaws...
Enumeration/identification technics (wardriving)
Management trafic injection
Rogue APs
WEP abuse and cracking
Bypassing WEP authentication
Exploiting known-cleartext attacks
Fragmentation attack
Arbitrary trafic injection
Arbitrary frame tampering
Inductive packet decrypting
IV/PRGA tables
Weak IVs
Final key recovery attack
Fix attempts (WEP+/WEP2)
Trafic injection an tampering
Open infrastructure abuse
Captive portal bypass
Clients attacks
Isolation bypass
Protection means
WPA
Authentication: PSK vs. EAP
TKIP+Michael
Key scheduling
Ext. IV & anti-replay
PSK brute force flaw...
WPA2
Authentication: PSK vs. EAP
What differs from WPA
AES/CCMP+CCMP MIC
Ext. IV & anti-replay
Identified flaws
Replay counter-measures abuse (DoS)
AP handshake flood (DoS)
Configuration guidelines
WPA/WPA2 support for clients
Adapters
Unices: GNU/Linux, BSD, OSX
Windows: 2k, XP
WPA/WPA2 support for APs
Off the shelf hardware
Unices: GNU/Linux, BSD
Configuration tricks
WPA vs. WPA2
PSK vs. EAP
EAP flavors (PEAP, TLS, etc.)
TKIP vs. AES
etc.
top ^
About the tutor
Cedric Blancher has spent the last 5 years working in network security field, performing audits and penetration tests. In 2004, he joined EADS Corporate Research Center in France to work at IT Security Reseach lab, focusing on networking and wireless links security. He is an active member of Rstack team and French Honeynet Project with studies on honeynet containment, honeypot farms and network traffic analysis.
He's been delivering technical talks worldwide (Cansecwest/core06, Recon, Ruxcon, Pacsec/core05, etc.), published research papers, magazine articles (MISC) and trainings (Eusecwest/core06, Cansecwest/core06, etc.) on network and wireless security. He also authored Wifitap, a 802.11 communication tool based on trafic injection.
For questions regarding event registration, please call +62-21-570-5800 (Ms. Astri). For general questions, please email bcs2006@bellua.com or send an empty message to bcs-announce-subscribe@bellua.com to receive future event information.
< back
top ^