| Home > Defeating Evil Twin attacks | |
| Security School: |
|
||
How Evil Twins work Why is an AP that uses someone else's SSID dangerous? Wireless stations generally do not connect to specific APs; they connect to any AP with a given SSID and the best signal. Worse, many stations automatically reconnect to any SSID used in the past. Just placing an Evil Twin near business users can be enough to trick their wireless devices into associating with a phony AP. An attacker who gets impatient waiting for users to roam to the Evil Twin can use AirJack to deauthenticate everyone, forcing immediate reassociation. Once connected, the Evil Twin can use its vantage point to launch many other attacks. For example, a laptop can run HostAP and Airsnarf, creating an Evil Twin that presents a fake login page to solicit user names, passwords or credit card numbers. Any Web request can be redirected to the local host through DNS spoofing. A tool like Airpwn can return malicious responses to users, like Web pages containing embedded viruses or Trojans. A cracker tool like Cain can extract passwords from common application protocols when victims check e-mail or download files. Man-in-the-middle tools like Dsniff can even compromise SSL or SSH sessions by posing as the target server, then relaying client requests to the legitimate server. In short, an Evil Twin is a perfect platform from which to run attacks against unsuspecting users.
Stopping these attacks Informed users are more likely to make good choices, but no company should rely exclusively on well-behaved users. Provide your users with tools that detect -- or better yet, prevent -- unauthorized wireless connections. For example:
Although there are many steps that you can take to evade Evil Twins, it may not be practical to eliminate all risk. For example, you may not be able to force users to employ 802.1X when working from home or you may need to support wireless devices that lack 802.1X support. For best results, combine 802.1X server authentication with wireless client monitoring.
'); // -->
|
||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||
|
||||||||||