Уровень 0 · материалов: 4
В кластер входят документы, описывающие методы кражи данных и перехвата сессий через уязвимости публичных Wi-Fi сетей, и не входят инструкции по технической расшифровке TLS-трафика в Wireshark.
Общие признаки: кража данных через открытый Wi-Fi, перехват сессий, кража SMS и паролей, атаки на незащищенные беспроводные сети
Группа выше: Безопасность Wi-Fi и публичных сетей
Смысл: The text demonstrates how lack of HTTPS encryption on a website allows attackers to steal session cookies and passwords in real-time from open WiFi networks using simple packet capture and filtering tools.
The author demonstrates how to hijack vk.com sessions in real-time by capturing unencrypted WiFi traffic with kismac and filtering cookies via grep.
Смысл: The main idea is to demonstrate how vulnerability in public Wi-Fi networks and session management allows a rooted Android device to steal active user sessions, enabling unauthorized access to social media and web accounts.
DroidSheep is an Android tool for rooted devices that lets users hijack active web sessions of others on the same Wi-Fi network by intercepting session identifiers.
Смысл: The main idea is that public Wi-Fi networks using MAC-address-based session tracking for SMS authorization are vulnerable to MAC spoofing, allowing unauthorized users to hijack the session of an already authenticated client.
The author demonstrates how to bypass public Wi-Fi SMS authentication by using aircrack-ng to capture and spoof the MAC address of an already authorized user.
Смысл: The text warns that using an iPhone with default root passwords on public Wi-Fi allows anyone with basic technical knowledge to steal all SMS messages via SSH.
Default root passwords on early iPhones allowed attackers on the same Wi-Fi network to easily steal all SMS messages via SSH.