Post
Topic
Board Beginners & Help
Re: Save your crypto, Disable WPS!
by
Artemis3
on 15/03/2019, 04:20:50 UTC
It’s not only about people getting to use your WIFI for free, but also about the security of the files and information you’ve actually got on your personal network.

Not too long ago, I was checking my personal security, trying to hack my own password with some powerful software I got hold off that ran on Ubuntu. While trying out the software, I also managed to retrieve the WIFI password of four or five neighbouring networks. Now what was even worse was that three of them still had the default router username and password, so I got access to being able to control their routers and snoop around their phone logs. On one on the networks I managed to obtain access to a hard drive with tons of personal files.

Now that was really a one off thing for trial purposes, but it showed me that one has to be wary of WPS, the actual security protocol, router passwords (change default) and personal network security. Fortunately, I’m rather ethical, so besides learning how to do it, I was never inclined to doing any harm.

Edit: Back then I used Wifislax. There are probably better alternatives now, but that did the job at the time. Another interesting feature was to use it as a WIFI jammer: you could target a WIFI and basically overload it with petitions. You have to be pretty near though for this to work, but when I tried it, it caused the jammed wifi to reboot itself repeatedly if I recall correctly (no need to be actually logged-on the the target network).
You are not supposed to do this without permission, even with good intentions, as this is the border from white into gray area...

Try running Wireshark or similar on your own LAN and see how much info you are leaking. Someone entering your LAN via WIFI might be getting more info than you think. As for tools, the usual aircrack-ng and friends available for most distros (or all if you bother compiling). You can download a live iso for security testing such as the Debian based Kali or Ubuntu based Backbox among many which already come with the most popular tools included.

Of course you can make your wifi secure in many other creative ways, but that would be way beyond the topic of this thread.



If wireless network is hacked through WPS, hacker have only access to network, means he can use your internet for surfing. I think that in case of such hack only damage is in possibly slow internet, and in the fact that hacker can do bad things using your IP address.
...
Not true,
If wireless network is hacked it will be much more easier for the hacker to hack all devices on the local network.

Besides, if someone is too lazy to turn off WPS, there is high chances he forgot to change the default password for his router too.

You should indeed neglect neither. Disable WPS, set WPA2+ and set a decent admin password and a DIFFERENT decent wifi password. Disturbingly many Asic miner owners tend to neglect changing default passwords as well... Braiins OS is nice to nag you about it, but Bitmain and others don't care...