Wifi Pcap ๋ถ„์„

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

BSSID ํ™•์ธ

WireShark๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ฃผ๋œ ํŠธ๋ž˜ํ”ฝ์ด Wifi์ธ ์บก์ฒ˜๋ฅผ ์ˆ˜์‹ ํ•˜๋ฉด _Wireless โ€“> WLAN Traffic_์„ ํ†ตํ•ด ์บก์ฒ˜์˜ ๋ชจ๋“  SSID๋ฅผ ์กฐ์‚ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

๋ฌด์ฐจ๋ณ„ ๋Œ€์ž… ๊ณต๊ฒฉ

ํ•ด๋‹น ํ™”๋ฉด์˜ ์—ด ์ค‘ ํ•˜๋‚˜๋Š” pcap ๋‚ด์—์„œ ์ธ์ฆ์ด ๋ฐœ๊ฒฌ๋˜์—ˆ๋Š”์ง€ ์—ฌ๋ถ€๋ฅผ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ๋งŒ์•ฝ ๊ทธ๋ ‡๋‹ค๋ฉด aircrack-ng๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž… ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

aircrack-ng -w pwds-file.txt -b <BSSID> file.pcap

์˜ˆ๋ฅผ ๋“ค์–ด, PSK(์‚ฌ์ „ ๊ณต์œ  ํ‚ค)๋ฅผ ๋ณดํ˜ธํ•˜๋Š” WPA ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๊ฒ€์ƒ‰ํ•˜์—ฌ ๋‚˜์ค‘์— ํŠธ๋ž˜ํ”ฝ์„ ๋ณตํ˜ธํ™”ํ•˜๋Š” ๋ฐ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

๋น„์ฝ˜ / ์‚ฌ์ด๋“œ ์ฑ„๋„์˜ ๋ฐ์ดํ„ฐ

WiFi ๋„คํŠธ์›Œํฌ์˜ ๋น„์ฝ˜ ๋‚ด๋ถ€์—์„œ ๋ฐ์ดํ„ฐ๊ฐ€ ์œ ์ถœ๋˜๊ณ  ์žˆ๋‹ค๊ณ  ์˜์‹ฌ๋˜๋Š” ๊ฒฝ์šฐ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํ•„ํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋„คํŠธ์›Œํฌ์˜ ๋น„์ฝ˜์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: wlan contains <NAMEofNETWORK> ๋˜๋Š” wlan.ssid == "NAMEofNETWORK" ํ•„ํ„ฐ๋ง๋œ ํŒจํ‚ท ๋‚ด์—์„œ ์˜์‹ฌ์Šค๋Ÿฌ์šด ๋ฌธ์ž์—ด์„ ๊ฒ€์ƒ‰ํ•ฉ๋‹ˆ๋‹ค.

WiFi ๋„คํŠธ์›Œํฌ์—์„œ ์•Œ ์ˆ˜ ์—†๋Š” MAC ์ฃผ์†Œ ์ฐพ๊ธฐ

๋‹ค์Œ ๋งํฌ๋Š” WiFi ๋„คํŠธ์›Œํฌ ๋‚ด์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•˜๋Š” ๋จธ์‹ ์„ ์ฐพ๋Š” ๋ฐ ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค:

  • ((wlan.ta == e8:de:27:16:70:c9) && !(wlan.fc == 0x8000)) && !(wlan.fc.type_subtype == 0x0005) && !(wlan.fc.type_subtype ==0x0004) && !(wlan.addr==ff:ff:ff:ff:ff:ff) && wlan.fc.type==2

์ด๋ฏธ MAC ์ฃผ์†Œ๋ฅผ ์•Œ๊ณ  ์žˆ๋‹ค๋ฉด ์ถœ๋ ฅ์—์„œ ์ œ๊ฑฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ฒดํฌ๋ฅผ ์ถ”๊ฐ€ํ•˜์—ฌ: && !(wlan.addr==5c:51:88:31:a0:3b)

๋„คํŠธ์›Œํฌ ๋‚ด์—์„œ ํ†ต์‹ ํ•˜๋Š” ์•Œ ์ˆ˜ ์—†๋Š” MAC ์ฃผ์†Œ๋ฅผ ๊ฐ์ง€ํ•œ ํ›„์—๋Š” ํ•„ํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ํŠธ๋ž˜ํ”ฝ์„ ํ•„ํ„ฐ๋งํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: wlan.addr==<MAC address> && (ftp || http || ssh || telnet) ftp/http/ssh/telnet ํ•„ํ„ฐ๋Š” ํŠธ๋ž˜ํ”ฝ์„ ๋ณตํ˜ธํ™”ํ•œ ๊ฒฝ์šฐ์— ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค.

ํŠธ๋ž˜ํ”ฝ ๋ณตํ˜ธํ™”

Edit โ€“> Preferences โ€“> Protocols โ€“> IEEE 802.11โ€“> Edit

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ