Slashdot Mirror


Hot Sales In China For Wi-Fi Key-Cracking Kits

alphadogg writes "Dodgy salesmen in China are making money from long-known weaknesses in a Wi-Fi encryption standard, by selling network key-cracking kits for the average user. Wi-Fi USB adapters bundled with a Linux operating system, key-breaking software, and a detailed instruction book are being sold online and at China's bustling electronics bazaars. The kits, pitched as a way for users to surf the Web for free, have drawn enough buyers and attention that one Chinese auction site, Taobao.com, had to ban their sale last year. With one of the 'network-scrounging cards,' or 'ceng wang ka' in Chinese, a user with little technical knowledge can easily steal passwords to get online via Wi-Fi networks owned by other people. The kits are also cheap. A merchant in a Beijing bazaar sold one for 165 yuan ($24), a price that included setup help from a man at the other end of the sprawling, multistory building."

39 of 207 comments (clear)

  1. fp by Anonymous Coward · · Score: 4, Funny

    First post using my neighbor's wifi!

    1. Re:fp by sqldr · · Score: 2, Funny

      Damn you! I hate it when some wang ka leeches my next connection.

      --
      I wrote my first program at the age of six, and I still can't work out how this website works.
  2. Are these available in the states? by Locke2005 · · Score: 3, Funny

    My neighbors have all started encrypting their wireless routers :-(.

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
    1. Re:Are these available in the states? by blair1q · · Score: 4, Funny

      How are you going to steal my bytes when I don't pub my SSID?

    2. Re:Are these available in the states? by Annymouse+Cowherd · · Score: 5, Insightful

      By sniffing traffic to determine the existence of your network?

    3. Re:Are these available in the states? by Rijnzael · · Score: 2, Informative

      Sure are available DIY, for the price of a halfway decent wireless card (optimally supporting injection), a box running linux, and the requisite AirCrack (the latter for the total price of free).

    4. Re:Are these available in the states? by Rijnzael · · Score: 2, Insightful

      You have a fundamental misunderstanding of 802.11 and belligerence/holier-than-thou attitude to boot. An 802.11 access point will not respond to a probe with its actual SSID if it's configured to not broadcast SSID. If it were not heeding this directive, you'd still see the access point using a Windows station. This condition is the express purpose of the "don't broadcast SSID" directive.

      You can verify your incorrectness by disabling SSID broadcast on an AP with proper firmware, actually saving the setting, ifconfig interface down/ifconfig interface up and attempting iwlist again. If you see an ESSID other than an empty string in your output, then you'll see the access point on Windows too, provided the band is supported by your Windows wireless hardware as well. Any other result is you doing it wrong or just plain trolling.

      The only time you'll see the actual SSID of these types of APs are clients setting the ESSID field in packets they send to the AP, which would require you to sniff.

      People like you are a significant contributing factor in the slow adoption of Linux, so thanks for that.

    5. Re:Are these available in the states? by Locke2005 · · Score: 4, Funny

      ...making it easier to browse their pr0n collection. My neighbors are all devout Christians, meaning I'm not interested in their pr0n collections -- that shit is WAY too kinky for me!

      --
      I've abandoned my search for truth; now I'm just looking for some useful delusions.
    6. Re:Are these available in the states? by Tiger4 · · Score: 4, Funny

      See that's where I fool 'em. I don't encrypt my traffic. They'll search all day and never find the key!

      --
      Behold, this dreamer cometh. Come now, and let us slay him... and we shall see what will become of his dreams.
    7. Re:Are these available in the states? by GillyGuthrie · · Score: 3, Insightful

      and it makes it simple for my wife to let others on.

      It seems simpler to configure WPA/WPA2 and just type in a password than to manually configure the router to allow a specific MAC address...

    8. Re:Are these available in the states? by mlts · · Score: 4, Interesting

      On a side subject, it would be nice for a wireless AP to have the ability to use multiple (like up to 255+) WPA2-PSK keys, one individual key per machine. Yes, this encroaches on WPA-Enterprise, but this would provide the ability to lock out a compromised machine off the network just by zapping its key, as opposed to having to rekey every single box on the wireless segment.

    9. Re:Are these available in the states? by geekoid · · Score: 3, Informative

      There are several tools you can use to get the SSID from a "Non broadcasting" device.

      Linux:
      http://www.kismetwireless.net/,
      Airjack,
      Many others...

      Windows:
      AirMagnet
      AirSnort

      I just listed the most common for the particular OS. I do know they can be compiled onto other systems.

      If you take a minute to step away from your knee jerk reaction to correcting people and think about it, you would realize* that at some point it has to broadcast the SSID or know one could ever maintain connection.

      http://tech.blorge.com/Structure:%20/2008/04/21/wi-fi-mythbuster-do-not-hide-your-ssid/

      So it is trivial to get an SSID from one that is hidden.

      * Against all evidence. I'm assuming your not actually an idiot

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    10. Re:Are these available in the states? by h4rr4r · · Score: 2

      Oh and learn how to take a joke you stick in the mud.

    11. Re:Are these available in the states? by bbk · · Score: 2, Interesting

      There are certain AP's and firmware that have a built-in RADIUS server for WPA/WPA2 Enterprise.

    12. Re:Are these available in the states? by geekoid · · Score: 2, Interesting

      Except he is wrong. So I'm glad you don't have mod point to help this yahoo make people think a system is hidden just by hiding the SSID.

      SSID is trivial to get.

      People like him are a significant factor in the slow adoption or proper security procedures. So thank him for that.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    13. Re:Are these available in the states? by Ethanol-fueled · · Score: 2, Funny

      I bet you could write a custom driver that simply XORs all wireless traffic,

      Even better, a custom driver that XOR's the traffic twice for double the protection.

    14. Re:Are these available in the states? by socceroos · · Score: 5, Funny

      Commentator 1: And in the blue corner we have seasoned slashdotter and daisy-cutter h4rr4r. His opponent today is the unheard-of Rijnzael...
      Commentator 2: Yeah, Bob - rumour has it that this Rijnzael dude is a cryptographer wannabe...
      Commentator 1: Indeed! Round one is about to begin...
      DING!
      Commentator 1: We're off! Both contestants start jostling.
      KABAM!!!
      Commentator 1: Wow! h4rr4r has just run to the side of the ring and flattened a member of the crowd who started shouting out about something to do with hidden SSIDs. That was unexpected!!
      THUD!!
      Commentator 1: Ouch! And with h4rr4r's back turned, Rijnzael has snuck in from behind and layed a stiff elbow into the back of h4rr4r's head! He's reeling off something about the legitimacy of hidden SSIDs.
      Commentator 2: It's all happening here, Bob. h4rr4r looks stunned... Rijnzael has bounced back to the middle of the ring - he almost looks surprised that he was able to land that blow. h4rr4r is turning around to face him...
      BIFF!!! BOP!!!
      Commentator 1: Thats gotta hurt! h4rr4r lays a couple of punches on Rijnzael!
      Commentator 2: h4rr4r really likes that iwlist+luser combo doesn't he! Rijnzael stumbles backward. He's composing himself now...
      DING DING DING!!
      Commentator 1: Oooooh! And with that the round ends! Rijnzael looks upset, he was getting all fired up for his next attack! Look at the anger in that bloke's eyes will ya!
      Commentator 2: Agreed. Rijnzael is itching to get back out there! h4rr4r is looking around the crowd... Ok, we're about to start round 2.
      DING!
      Commentator 1: And we're back into it. Rijnzael is bouncing like a kangaroo, he's pumped! Oh! He's moving in...
      BAP!! PUNT!! THUD!!
      Commentator 1: WOOOOOWW! What a combo! Rijnzael has hit h4rr4r squarely on the nose here! h4rr4r stumbles backwards and hits the ropes, arms splayed!
      POW!!! KABIFF!!!
      Commentator 2: Oh wow! "Fundamental Misunderstanding", "Belligerence", "Verifiable Incorrectness" - Rijnzael is throwing everything and the kitchen sink at h4rr4r!
      KABLOOIE!
      Commentator 1: An explosive hit! Rijnzael just landed a "slow adoption of Linux" blow on h4rr4r!
      Commentator 2: My goodness, Bob! You don't do that to a seasoned slashdotter! h4rr4r has gritted his teeth now, boy he looks in pain! What a grimace!
      *CROWD ROARING*
      Commentator 2: Here we go! h4rr4r's senior, geekoid, has just jumped into the ring!! Talk about uneven now!
      Commentator 1: Whats going on?! Looks like he got annoyed at the Linux reference! This is starting to look like a WWE match now!
      BOP! POW! BAP! BIFF!!
      **CARRIER LOST

      I'd better get back to RL and start working.
      'twas fun boys.

    15. Re:Are these available in the states? by rtb61 · · Score: 2, Informative

      Of course these kits can be used far more destructively than just for free browsing. By penetrating a secure and encrypted connection, the legal holder of that connection is far more likely to be held criminally liable for the activity on their network.

      Guilty until proven innocent for child porn, threats of violence against politicians and, terrorist related speech, these kits are quite dangerous. In China of course their version of the three worst things to do on the internet are speaking out for freedom, democracy and an end to government corruption, of course those is a far more risky activities to do in China.

      Any political candidates out there, don't be cheap, wire up you homes because wireless could be the end of your career.

      --
      Chaos - everything, everywhere, everywhen
    16. Re:Are these available in the states? by h00manist · · Score: 2, Informative

      Aircrack is, curiously, one of the few tools that cannot be ported to windows, and which actually manages to attract people to run linux, just for this app. It's a "killer app", as they call it, which carries it's platform. Makes me think, sometimes, more open source software should be circulated without any windows ports or binaries at all, to keep people on open source platforms... of course, it goes against the whole idea of open...

      --
      Build your own energy sources from scratch. http://otherpower.com/
    17. Re:Are these available in the states? by rtb61 · · Score: 3, Insightful

      For those crimes being accused is sufficient to destroy your life, especially when it often takes a considerable period of time to clear things up, months and often years. The 'other side' is law enforcement and they have no problem tracking accessing you via your ISP. As for selectively breaking into a connection to target a specific person, simple proximity and monitoring over a short time will be sufficient to identify the specific target, upon whom you wish to piggy back questionable traffic.

      Not long ago a person was presumed guilty by the RIAA and a civil court a fined hundreds of thousands of dollars, with no physical evidence just the ISP records, with the persons claim that someone broke into their network not being accepted as a defence with out "PROOF OF BREAK IN" ie they were required to prove themselves innocent. Of course that is civil versus criminal but the point can be mute if it is equally punishing at the end of the day.

      Oddly enough legally speaking having a completely insecure and open wireless network would be safer than a secured and encrypted network ie on the unsecured one you do not have to prove someone else accessed it.

      PS the first step of breaking into people's computers is breaking into their network especially their internal network versus secured beyond the firewall internet connection (well, hopefully at least that). In charged political times and under social economic stresses, these destructive attacks become more prevalent, the real point is innocent until proven guilty needs to be at the forefront of all computer and network based crimes, especially when it comes to confiscation of technological devices for forensic analysis until the investigation is completed months or years later.

      --
      Chaos - everything, everywhere, everywhen
    18. Re:Are these available in the states? by fsulawndart · · Score: 2, Insightful

      All the Cisco APs have built-in RADIUS servers.

    19. Re:Are these available in the states? by Maarx · · Score: 5, Informative

      Aircrack is, curiously, one of the few tools that cannot be ported to windows, and which actually manages to attract people to run linux, just for this app. It's a "killer app", as they call it, which carries it's platform. Makes me think, sometimes, more open source software should be circulated without any windows ports or binaries at all, to keep people on open source platforms... of course, it goes against the whole idea of open...

      While I cannot debate it's status as a "killer app", the reason it works is not that the code for Aircrack cannot be ported, but instead because Windows does not possess the underlying DLL's to support it. In fact, the fork project, Aircrack-ng, has a port for Windows, with a giant alt-text disclaimer on the download link that says it doesn't work without DLL's that they do not provide (i.e., they do not believe exist). The result is the same, but it's inaccurate to speak of it as an inability to translate the program "source".

  3. WEP not secure, use WPA with random key by Anonymous Coward · · Score: 5, Informative

    Free Wifi cracking kit: Download here and use with brain 1.0 and any USB wireless dongle.

  4. How hard? by Elitist_Phoenix · · Score: 2, Informative

    Seriously. Usb Wifi Dongle + Rainbow Tables DVD + Backtrack = Win?!

    --
    "I'm going to f***ing bury that guy, I have done it before, and I will do it again. I'm going to f***ing kill Google"
    1. Re:How hard? by fl_litig8r · · Score: 2, Informative

      No. Fail as long as AP is using WPA or WPA2 and a decent non-dictionary passphrase. Rainbow tables don't work on all passwords. Usually they just pre-calculate PSKs using large dictionaries with some minor mangling applied. Also, because the SSID of the AP is hashed into PSK, you need a rainbow table for the specific SSID you are trying to hack. So while some common SSID's like "linksys" or "attwifi" (Google church of the renderlab for most common ssids with pre-made tables) may be more vulnerable, if their passphrase is a 20-character, non-dictionary mix of alphanumeric, upper/lower case and special characters, you won't be cracking it in your lifetime using today's best hardware. For some impressive cracking of WPA/2 (after you capture the 4-way handshake), check out Pyrit, which uses GPU computing to blow away programs like aircrack or cowpatty. Using a radeon 4850, I can calculate over 20,000 PSKs/sec for any given SSID using a wordlist, john the ripper, crunch, or any other dictionary tool. But just to give you an idea of how futile this can be, I've calculated over 5 billion PSKs for a neighbor's WPA2-PSK router (it has a non-standard SSID) and I've only gone through 2% of an incomplete wordlist which is being mangled with john the ripper. Note: this is not for malicious intent. I have 2 neighbors using WEP that I cracked in about 10 mins and I haven't used their wifi -- just new to backtrack and playing around. To sum up: I doubt I'll ever crack my neighbor's WPA2, even if I were calculating 100,000 PSKs/sec. There are just too many possibilities once you leave the dictionary. So my advice: Use a non-standard SSID, and WPA2-PSK (radius is even better, obviously) with a non-dictionary password of 12 or more characters. Most hackers will give up on you and move on. This junk they're selling in China just sounds like WEP cracking stuff, which any slashdotter could learn in about an hour or less from the aircrack-ng site.

  5. Video in action by DNS-and-BIND · · Score: 5, Informative

    Video of cengwang ka in action here. Someone whose mandarin is better than mine will have to provide a translation. "Mee-ma" means password. Heck, I might get one just to use it in airports and other places where jerks charge for internet. Evidently they are illegal as taobao.com (the Chinese ebay) doesn't list them while a simple google search turns up dozens of vendors. I'll have to check on these next time I go to the computer market.

    Another notable aspect of this story is that it's actually accurate. China is a blank slate to most Westerners and I have seen journalists fabricate the most outrageous lies simply because it "fits the narrative" (narrative=preconceived ideas). No surprise the guy who wrote this was in Beijing, it's like the world ends for journalists outside the fifth ring road.

    --
    Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    1. Re:Video in action by Anonymous Coward · · Score: 2, Informative

      If you want actual news about China from Chinese folks, try ChinaSMACK. They cover whatever Chinese internet users are talking about. Half of it is tabloid type crap, but it's more authentic than what you get in most newspapers.

    2. Re:Video in action by Zarel · · Score: 4, Informative

      You Slashdotters haven't been very nice when talking about my country recently. :( But I'll forgive you. Here's a translation:

      woman: "[incoherent] Wi-Fi key cracking kits are an extremely important threat to the safety of the Internet"

      woman: "Here, we simply follow these instructions, and then use the CD drive [sic] to access the password cracking software, and five seconds later, it indeed shows us five Wi-Fi access points. Clicking one, the computer starts to automatically crack the password, and after a while, it displays a string of numbers."

      man: "[incoherent] Looking at this, does this say that it's done yet?"

      other man: "Yeah, it says it's successful; it's connected to the Internet now."

      man: "So you can go and browse the web now?"

      other man: "Yep, you can, using its [the key cracker's] connection."

      other man: "Here, you can see four wireless signals, and the connections are pretty nice, at a speed of [incoherent]."

      woman: "Continuing our explanation, these key cracking kits are a type of external Wi-Fi card, but their ability to search for access points is stronger. What's scarier is that it comes with black-hat hacking software, that can let you hack into others' router administration panels. If this kind of tool falls into the wrong hands, it could have serious consequences, such as disruption of service."

      other man: "This software is very powerful. This one can crack passwords, and see here, I'm copying this guy's files - copying them to my own computer."

      woman: "[some organization I didn't catch the name of] says that Internet hacking incidents are steadily increasing. In actuality, securing a computer is not difficult, and modern OSes have mechanisms to limit how many people can connect, and who has permission to connect."

      other man: "Here, they've disabled DHCP and I'm connected, but I can't browse the Web since I don't have an IP address."

      woman: "To clarify, Wi-Fi cracking happens overseas as well. Several countries have already enacted laws preventing it; [incoherent] and Singapore, for instance, have made Wi-Fi cracking crimes. England has not only made it illegal, but are actively hunting infringers. However, China still hasn't passed laws regarding it."

      caller: "There are two sides to every issue. One one hand, it's password cracking, which is clearly wrong. But on the other hand, it's accessing the Internet for free, which should really be controlled by the owner of the access point and definitely [interrupted]"

      --
      Want a high quality FOSS RTS game? Try Warzone 2100!
  6. I have a question. by 3seas · · Score: 2, Interesting

    Why is china or the people of, so interested in causing problems on the internet?

    IS this just a way of rebelling that is safe for them from their government (the party they would really like to rebel against.)

    1. Re:I have a question. by timeOday · · Score: 4, Informative

      The summary says what the motive is: to make $24 selling the kits.

    2. Re:I have a question. by DigiShaman · · Score: 2, Informative

      Without question, China is on fantastic road to recovery. Each year I go over there, I'm blown away at the level of progress going on. But make no mistake about it, going the capitalist road was rather self-serving of the CCP. The amount of kickbacks and bribery that goes on dwarf that of our American politicians. That's saying a lot.

      --
      Life is not for the lazy.
  7. Re:backtrack? aircrack-ng? by SomeJoel · · Score: 4, Informative
    Yeah, hey, look at TFS FFS you SOB:

    a user with little technical knowledge can easily steal passwords

    Note the lack of an article between "with" and "little".

    --
    <Complete your profile by adding a signature!>
  8. Backtrack 4 on ebay by kaptink · · Score: 3, Informative

    Out of curiousity I put backtrack in to ebay and what do you know, theres half a dozen backtrack 4 dvds for sale as Hacking Operating System.

    But no rerturns accepted!

    --
    Those who can, do. Those who cannot, sue.
  9. That's for WEP ... by Agarax · · Score: 4, Informative

    You don't NEED packet injection, you just need it if you want to break into the network anytime soon. Sitting and listening to normal traffic will eventually get you enough packets to attempt to break it.

    For WPA you don't even need packet injection, just deauth a client that is connected, collect their reconnection packets, and then run a dictionary/brute force attack against the handshake.

    --
    Remember folks, slashdot doesn't have a -1 "disagree" moderation!
  10. They should totally market it as... by Anonymous Coward · · Score: 2, Funny

    ...Kuang Grade Mark Eleven

  11. Re:backtrack? aircrack-ng? by h4rr4r · · Score: 2, Informative

    Indeed. I treasure my gmail account as I treasure the time I spend plundering your mothers anus.

  12. Re:this is why my network is "unsecured". by Fnord666 · · Score: 2, Informative

    My wireless router filters devices by mac address.. if I understand it correctly, there's no way for it to be cracked into so long as the filters in my router are enabled. It recognizes my netbook, a skype phone, and an ipod that I own. All other devices will "see" the network but will not be able to access it.. if I understand the way it works correctly anyway. :)

    If someone wants to use your network, they will capture packets so that they can see what MACs are authorized. They then alter the MAC address of their wireless card to be one of the authorized values and bob's your uncle.

    --
    'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
  13. Re:this is why my network is "unsecured". by X0563511 · · Score: 2, Informative

    MACs can be sniffed, and spoofed.

    The trick is to not use it while the "true" device is (you'll just cause problems)

    --
    For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
  14. TRANSLATION by vampire_baozi · · Score: 2, Informative

    Quick translation, since I'm kinda in a hurry (though, c'mon, DNS-and-Bind, you've lived there for 7 years? if I remember from a previous post, and you can't speak fluent mandarin now, plus a few dialects? What have you been doing with your time?)

    Anchorwoman: We will now explore the background behind these (Wifi Keys) and the hidden danger they present to internet security.
    The journalist installed the Wifi Cracking kit according to the instructions, and then used the Cd-rom to open the password cracking software. After 5 seconds, the computer monitor correctly displayed 5 wireless network signals. Click on any of the networks and the computer will automatically start cracking the password. After 4 minutes, a series of numbers appears on the display.
    I'm just going to freeform this bit, I'm translating background chatter, not just the subtitles. Mostly Mr. Hu and the reporter talking, I won't note who is who, but it should be kind of obvious...also, there's stuff that isn't in the subtitles, so it should flow better
    Guy1: oh, this is the password (background)
    Guy1: AAAAA....
    Reporter: His password is 8 A's (this is the subtitle guy number 1)
    Guy1: What an idiot!
    Reporter: Take a look at it now, did it work?
    Mr. Hu (Hu something-ying, the middle character is too low resolution), network expert at a Wuhan Guangtong Computer Technology Development company: It succeeded, we're already online.
    Reporter: So we can get online directly?
    Mr. Hu: Yes, we're online through his network(thanks to the key)
    Here we have 4 signals, this signal isn't bad! 18megabit speeds.
    Anchorwoman: The computer expert explains, the Wifi Cracking kit is essentially a just wireless card, but its ability to search out wireless networks is much stronger than normal wireless cards. What's scarier, is that it's combined with a "hacker" software program that can easily hack into other people's host machine (host computer), if this apparatus is used for nefarious purposes, it could result in computer files being accessed, privacy leaks, etc., with serious consequences.
    Mr. Hu: This is a serious threat to internet security. It can reveal secrets, and interferes with security. Look, I can directly make copies of his files, copy it directly to my own computer.Anchorwoman: Wuhan network expert Mr. Hu of the XYZ company IT dept. says that reports of successful network intrusion attempts are skyrocketing. He also explains that protecting yourself is not difficult, by setting the number of user accounts or adjusting the router settings.
    Mr. Hu: Turn off the DHCP on the router, then even if you access the network, you can't get online,since there's no IP address. The important thing is to do it from the router.
    Anchorwoman: The phenomenon of Wifi password cracking is common outside China, regardless of the nation. Singapore considers it to be a crime, and the UK considers it illegal and you can be arrested. In China, however, there are no laws about Wifi password cracking.
    Phone caller, from Hubei, works with communications related company: This thing presents two main problems. The first is password cracking. This is a security/safety problem. The other is using other people's Wifi connections for free, this is a problem of stealing access. If you check and can find evidence of.....(is cut off)

    I may have cut a few corners, but that's the gist. I don't do much technical translation, but this one was light on the technical terms anyway, so if you have questions or need other stuff translated, let me know.