+ All Categories
Home > Documents > Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf ·...

Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf ·...

Date post: 07-Aug-2020
Category:
Upload: others
View: 1 times
Download: 0 times
Share this document with a friend
14
Deception Firmware
Transcript
Page 1: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

Deception Firmware

Page 2: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

GettingStarted:Deception

TheDeceptionfirmwareallowsyoutouseyourdeviceasaportableWi-Fi Honeypot. The firmware has different captive portal splashpageswhichyoucanselectanddemoforsecurityawareness.

Page 3: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

DeceptionFirmware:Connecting

WewillbecommunicatingwiththedeviceusingitsserialportwhichisavailableovertheUSBinterface.WewillusetheSerialMonitorinthe Arduino IDE as it allows us to send and receive using a simpleinterface.We are assuming the device has already been flashedusingtheDeceptionfirmwaredownloadedfromourwebsite.

Step 1: Download and install Arduino IDE by following theinstructionsgivenbelow:

Windows:https://www.arduino.cc/en/Guide/Windows

Linux:https://www.arduino.cc/en/Guide/Linux

MacOSX:https://www.arduino.cc/en/Guide/MacOSX

Step 2: Connect the device to your laptop, start the Arduino IDE,make sure that the Port is selected correctly as per yourenvironmentandthenopentheSerialMonitor.

Page 4: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

Step3:IntheSerialMonitor,pleaseensurethatthebaudrateissetto115200.

YoushouldbeabletoviewthelogsfromWiNXDeceptionfirmware.IfyouareunabletoseeanythingthenresetthedeviceusingtheENbuttonatthebottom.Thiswillrestartthedeviceandyoushouldbeabletoseealogssimilartotheabove.

Page 5: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

DeceptionFirmware:Configuration

DefaultSettings:

Oncethedeviceboots,itwillshowyouahelpscreenwiththelistofsupported commands. You can access this anytime by using ?command.

The default SSID is Internet and the default splash page isHackerArsenal.

ChangingtheSSID:

TochangetheSSIDofthehoneypot,youcanusetheH<ssid_len>ssidcommand.Thismeans,HfollowedbylengthoftheSSIDandthentheSSID. For example the commandH13Free_Internetwill change thehoneypot SSID to Free_Internet (13 character long).ThemaximumallowedSSIDlengthis30characters.

Page 6: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

ChangingtheSplashPage:

The firmware comeswith five splash/loginpages. Inorder touseapage other than the default one, you will need to use theD<number> command. The <number> here is the number of thepageasshowninthehelp.Forexample,D4isforchoosingthePublicWi-Fisplashpage.

Page 7: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

ViewingCapturedLoginData:

Thesettingsarepersistentand retainedacross reboots.Thisallowsthedevicetorunonabatteryfordayswhilecollectingdata.

Toviewthecollecteddatalogs,connecttothedeviceandissuetheSEND command.This commandwill print logs to the serial consoleanddeletethelogsfromthedevice.

ResetDeviceConfiguration:

To reset the configuration, we can use FLUSH command. Thiscommandwilldeleteallconfigurationfilesanddevicewillbootwithdefaultconfiguration.

Page 8: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

DeceptionFirmware:InActionLetusnowlookatademo!WeareassumingthedeviceisconfiguredwithSSIDFree_InternetandthesplashpageisD4(PublicWiFi).

Step 1: The victim device connects toFree_Internet,an openWiFinetwork

Step2:Whenthevictimnowtriestoaccessanywebpage,heshouldbeautomaticallyredirectedtoourfakesplashpage.

Page 9: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

Step3:Anyinformationthatheentersintothefieldswillbelogged

Step 4: Nomatter what credentials are provided, an error page isshown.Thevictimmightendup tryingmultiplecombinationsallofwhicharelogged.

Step5:WewilluseSENDcommandtoviewthesestoredcredentials

Page 10: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

andotherlogs.

Page 11: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

DeceptionFirmware:SplashScreensThefollowingscreensareavailableforuseonyourdevice:

Screen1(default):HackerArsenalsplashpage

Screen2:Wi-Linkrouterloginpage

Page 12: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

Screen3:MyWiFirouterloginpage

Screen4:PublicWiFisplashpage

Page 13: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

Screen5:Coffeeshopinternetsplashpagescreen

Page 14: Deception Firmware - Amazon Web Serviceshackerarsenal.com.s3.amazonaws.com/deception-manual.pdf · with SSID Free_Internet and the splash page is D4 (Public WiFi). Step 1: The victim

Troubleshooting:

• If youdonot seeanyoutput thenpressand release the“EN”button on your device. This should reset the device and itshouldrestarttheprogram.

• Ifyoustillhaveproblemswithviewingtheoutputthenitmightbeagood idea todownload the firmwareagainand flash thedevice.


Recommended