
Un framework per il pentesting wireless.
SniffAir è un framework di sicurezza wireless open-source che offre la possibilità di analizzare facilmente dati wireless raccolti passivamente, oltre a lanciare sofisticati attacchi wireless. SniffAir gestisce la complessità legata alla gestione di file pcap grandi o multipli, incrociando e analizzando approfonditamente il traffico alla ricerca di potenziali falle di sicurezza. Oltre alle query predefinite, SniffAir consente agli utenti di creare query personalizzate per analizzare i dati wireless memorizzati nel database SQL backend. SniffAir è costruito sul concetto di utilizzare queste query per estrarre dati per i report di test di penetrazione wireless. I dati possono anche essere sfruttati per impostare sofisticati attacchi wireless inclusi in SniffAir come moduli.
SniffAir è sviluppato da @Tyl0us e @theDarracott
SniffAir è stato sviluppato con Python versione 2.7
Testato e supportato su Kali Linux, Debian e Ubuntu.
Per installare esegui lo script setup.sh
$./setup.sh
% * ., %
% ( ,# (..# %
/@@@@@&, *@@% &@, @@# /@@@@@@@@@ .@@@@@@@@@. ,/ # # (%%%* % (.(. .@@ &@@@@@@%.
.@@& *&@ %@@@@. &@, @@% %@@,,,,,,, ,@@,,,,,,, .( % % %%# # % # ,@@ @@(,,,#@@@.
%@% %@@(@@. &@, @@% %@@ ,@@ /* # /*, %.,, ,@@ @@* #@@
,@@& %@@ ,@@* &@, @@% %@@ ,@@ .# //#(, (, ,@@ @@* &@%
.@@@@@. %@@ .@@( &@, @@% %@@%%%%%%* ,@@%%%%%%# (# ##. ,@@ @@&%%%@@@%
*@@@@ %@@ .@@/ &@, @@% %@@,,,,,, ,@@,,,,,,. %#####% ,@@ @@(,,%@@%
@@% %@@ @@( &@, @@% %@@ ,@@ % (*/ # ,@@ @@* @@@
%@% %@@ @@&&@, @@% %@@ ,@@ % # .# .# ,@@ @@* @@%
.@@&/,,#@@@ %@@ &@@@, @@% %@@ ,@@ /(* /(# ,@@ @@* @@#
*%@@@&* *%# ,%# #%/ *%# %% #############. .%# #%. .%%
(@Tyl0us & @theDarracott)
>> [default]# help
Commands
========
workspace Manages workspaces (create, list, load, delete)
live_capture Initiates a valid wireless interface to collect wireless packets to be parsed (requires the interface name)
offline_capture Begins parsing wireless packets using a pcap file-kismet .pcapdump work best (requires the full path)
offline_capture_list Begins parsing wireless packets using a list of pcap file-kismet .pcapdump work best (requires the full path)
query Executes a query on the contents of the acitve workspace
help Displays this help menu
clear Clears the screen
show Shows the contents of a table, specific information across all tables or the available modules
inscope Add ESSID to scope. inscope [ESSID]
SSID_Info Displays all information (i.e all BSSID, Channels and Encrpytion) related to the inscope SSIDS
use Use a SniffAir module
info Displays all variable information regarding the selected module
set Sets a variable in module
exploit Runs the loaded module
run Runs the loaded module
exit Exit SniffAir
>> [default]#
Prima crea o carica un workspace nuovo o esistente usando il comando workspace create <workspace> o workspace load <workspace>. Per visualizzare tutti i workspace esistenti usa il comando workspace list e il comando workspace delete <workspace> per eliminare il workspace desiderato:
>> [default]# workspace
Manages workspaces
Command Option: workspaces [create|list|load|delete]
>> [default]# workspace create demo
[+] Workspace demo created
Carica i dati in un workspace desiderato da un file pcap usando il comando offline_capture <percorso completo del file pcap>. Per caricare una serie di file pcap usa il comando offline_capture_list <percorso completo del file contenente l'elenco dei nomi pcap> (questo file deve contenere i percorsi completi di ogni file pcap). Usa il comando live_capture <nome interfaccia> per catturare traffico wireless in tempo reale usando un'interfaccia wireless.
>> [demo]# offline_capture /root/sniffair/demo.pcapdump
[+] Importing /root/sniffair/demo.pcapdump
\
[+] Completed
[+] Cleaning Up Duplicates
[+] ESSIDs Observed
Il comando show visualizza il contenuto di una tabella, informazioni specifiche su tutte le tabelle o i moduli disponibili, usando la seguente sintassi:
>> [demo]# show table AP
+------+-----------+-------------------+-------------------------------+--------+-------+-------+----------+--------+
| ID | ESSID | BSSID | VENDOR | CHAN | PWR | ENC | CIPHER | AUTH |
|------+-----------+-------------------+-------------------------------+--------+-------+-------+----------+--------|
| 1 | HoneyPot | c4:6e:1f:##:##:## | TP-LINK TECHNOLOGIES CO. LTD. | 4 | -17 | WPA2 | TKIP | MGT |
| 2 | Demo | 80:2a:a8:##:##:## | Ubiquiti Networks Inc. | 11 | -19 | WPA2 | CCMP | PSK |
| 3 | Demo5ghz | 82:2a:a8:##:##:## | Unknown | 36 | -27 | WPA2 | CCMP | PSK |
| 4 | HoneyPot1 | c4:6e:1f:##:##:## | TP-LINK TECHNOLOGIES CO. LTD. | 36 | -29 | WPA2 | TKIP | PSK |
| 5 | BELL456 | 44:e9:dd:##:##:## | Sagemcom Broadband SAS | 6 | -73 | WPA2 | CCMP | PSK |
+------+-----------+-------------------+-------------------------------+--------+-------+-------+----------+--------+
>> [demo]# show SSIDS
---------
HoneyPot
Demo
HoneyPot1
BELL456
Hidden
Demo5ghz
---------
Il comando query può essere usato per visualizzare un set di dati univoco basato sui parametri specificati. Il comando query utilizza la sintassi SQL.
Il comando inscope <SSID> può essere usato per aggiungere un SSID alle tabelle inscope, caricando tutti i dati correlati nelle tabelle inscope_AP, inscope_proberequests e inscope_proberesponses. Per visualizzare un riepilogo di tutti gli SSID inscope esegui il comando SSID_Info.
I moduli possono essere usati per analizzare i dati contenuti nei workspace o per eseguire attacchi wireless offensivi usando il comando use <nome modulo>. Per alcuni moduli potrebbero essere necessarie variabili aggiuntive. Possono essere impostate usando il comando set set <nome variabile> <valore variabile>:
>> [demo]# show modules
Available Modules
=================
[+] Auto EAP - Automated Brute-Force Login Attack Against EAP Networks
[+] Auto PSK - Automated Brute-Force Passphrase Attack Against PSK Networks
[+] AP Hunter - Discover Access Point Within a Certain Range Using a Specific Type of Encrpytion
[+] Captive Portal - Web Based Login Portal to Capture User Entered Credentials (Runs as an OPEN Network)
[+] Certificate Generator - Generates a Certificate Used by Evil Twin Attacks
[+] Exporter - Exports Data Stored in a Workspace to a CSV File
[+] Evil Twin - Creates a Fake Access Point, Clients Connect to Divulging MSCHAP Hashes or Cleartext Passwords
[+] Handshaker - Parses Database or .pcapdump Files Extracting the Pre-Shared Handshake for Password Guessing (Hashcat or JTR Format)
[+] Mac Changer - Changes The Mac Address of an Interface
[+] Probe Packet - Sends Out Deauth Packets Targeting SSID(s)
[+] Proof Packet - Parses Database or .pcapdump Files Extracting all Packets Related to the Inscope SSDIS
[+] Hidden SSID - Discovers the Names of HIDDEN SSIDS
[+] Suspicious AP - Looks for Access Points that: Is On Different Channel, use a Different Vendor or Encrpytion Type Then the Rest of The Network
[+] Wigle Search SSID - Queries wigle for SSID (i.e. Bob's wifi)
[+] Wigle Search MAC - Queries wigle for all observations of a single mac address
>> [demo]#
>> [demo]# use Captive Portal
>> [demo][Captive Portal]# info
Globally Set Varibles
=====================
Module: Captive Portal
Interface:
SSID:
Channel:
Template: Cisco (More to be added soon)
>> [demo][Captive Portal]# set Interface wlan0
>> [demo][Captive Portal]# set SSID demo
>> [demo][Captive Portal]# set Channel 1
>> [demo][Captive Portal]# info
Globally Set Varibles
=====================
Module: Captive Portal
Interface: wlan0
SSID: demo
Channel: 1
Template: Cisco (More to be added soon)
>> [demo][Captive Portal]#
Una volta impostate tutte le variabili, esegui il comando exploit o run per avviare l'attacco desiderato.
Per esportare tutte le informazioni memorizzate nelle tabelle di un workspace utilizza il modulo Exporter e imposta il percorso desiderato.
Sniffiar contiene lavoro dai seguenti repository: