2016-08-06

DEFCON 24: Wi-Fi Sheep Hunt Contest Brief

WI-FI SHEEP HUNT 2016
Wall of Sheep (WOS)
Packet Hacking Village (PHV)

MISSION BRIEF:

WELCOME to WI-FI SHEEP HUNT 2016. Your mission, if you choose to accept it, is to hunt and herd our lost SHEEPS. Clues will be broadcasted in the PHV airwaves – near, far and wide. You’ll need your strongest and fastest wireless “Kung-Fu” to collect the clues and decipher the codes. Accumulate points by playing one or all the challenges.

1:\> NFC SHEEP HUNT
2:\> RF SHEEP HUNT
3:\> WEP/WPA SHEEP HUNT


WARNING: If the “airwaves” smell rotten, that’s probably not us. This is DEF CON, don’t say we didn’t warn you...

REGISTRATION:

1. In person at PHV Info Booth.
2. Online at https://t.co/WFI9TLVt4j - CLOSED 08/06/2016

MISSION DETAILS:

1. NFC SHEEP HUNT: There are NFC tags hidden all around the PHV. Use your handheld device (iPhone, Android…etc.) to sniff them out, retrieve and decipher the codes. Points are awarded for every tag you find, extra points for every code you decipher.

2. RF SHEEP HUNT: Locate RF beacons, then decipher the codes to earn points.  We have military grade radio detection gear for you to use. Registration and gear reservation is required. Go to the PHV Info Booth for details.

1. WEP/WPA SHEEP HUNT: Find the correct WEP/WPA APs and crack the key. Every key (WEP/WPA) you crack & submit earns you points.

WEP? really?! But how strong is your wireless kung-fu?! These APs are dynamic and can change its security settings. Move fast when you spot them ---> crack the key and grab a sheep before it disappears.  NOTE: Point value decreases the longer you take to crack it.

EXTRA POINTS: Grab SHEEPS (files) from WEP, move them to the WPA.  Once you’re inside the network, sniff around and hunt for SHEEPS (files)… yes, you’ll need both keys to move the files from one wireless network to the other.

NEED HELP TO JOIN THE FUN?
Come by the Wi-Fi Sheep Hunt desk and we’ll help you to get started. No laptop or gear? No problem, we have some you can use for a limited time. Registration and gear reservation is at the PHV Info Booth.

FOR TIPS/CLUES:  Follow the @WallofSheep on Twitter
Hashtag: #WOS #WIFISH #SHEEPHUNT

Aircrack Basics for Wi-Fi Sheep Hunters

AIRCRACK BASICS
By: @donds https://hackvault.blogspot.com

The instructions below are strictly for research and educational purposes only.  Please setup a test lab, it is illegal to hack an AP without permission.

The steps below might not work, but it does work most of the time. It works very well when a client is connected to the AP, but of course you can fake that also.

TIPS: Change your monitoring interface's MAC address for anonymity and to make is easy to remember: Example 11:22:33:44:55:66  - Use MACCHANGER.

Let’s start AirCrackin’

PHASE 1
-OPEN A TERMINAL WINDOW (Terminal 1)
1. Set the interface to monitor mode:
 airmon-ng start [interface]
2. To recon the airwaves use airodump-ng:
 airodump-ng [interface] 
3. Select a victim and take note of the SSID, channel and mac address.
4. Stop airodump-ng, then restart it with the write option to start catching the IVs.  
airodump-ng -c [channel] -w [filename] [interface]
-LEAVE Terminal 1 PROCESS RUNNING

PHASE 2
-OPEN A SECOND TERMINAL WINDOW (Terminal 2)
5. Inject some "care packages" to generate IV's. Get creative! Take your pick.

NOTE: To test the subjects' ability for packet injection, use the following code.  You are looking for a 100% injection result.  aireplay-ng -9 -e [vic ssid] -a [vic mac] [interface]

Fake Associations for the victim AP
            aireplay-ng -1 0 -e [vic ssid] -a [vic mac] -h [your mac] [interface]
OR use this for picky Access Points 
            aireplay-ng -1 6000 -o 1 -q 10 e [vic ssid] -a [vic mac] -h [your mac] [interface]

You have to get a successful association before you can continue. Your ARP request replay packets will not generate any initialization vectors (IVs) if you are not associated with the AP.

Send out ARP request replay modes
            aireplay-ng -3 -b [vic mac] -h [your mac] [interface]

-LEAVE Terminal 2 PROCESS RUNNING

PHASE 3
-OPEN A THIRD TERMINAL WINDOW (Terminal 3)
6. Start cracking -aircrack-ng [filename] pick the vic SSID then go.  You can also use the FMS/Korek method by adding -K on the code above. 

You will need approx. 250,000 IV's for a 64 bit key, 1.5M IVs for a 128 bit key.

For the PTW method, you'll need 20,000 packets for 64bit and 40,000 packets for 128bits.