Closed poser closed 10 years ago
Where does the initial channel parameter come from? Is it even necessary?
It is unnecessary for the WLAN probes demo, and probably unnecessary for the mDNS demo on an unencrypted WLAN. On an encrypted WLAN, however, in which we have to decrypt each WiFi network individually, it may be necessary (or at least helpful), as it stops the adapter from channel-hopping. So, to clarify, for this particular demo it was a typo.
Moving content to wiki and deleting
Uses monitor mode to sniff wireless network traffic and correlates each associated device with a set of wireless network names (ESSIDs) to which that device has previously connected. This is possible because, in the interest of reducing the time required to obtain a working Internet connection, devices are often quite aggressive about broadcasting WLAN probes that contain the ESSIDs of the networks they have used in the past. With this information, combined with the output of the who's in the room demo described above, it would be relatively easy for an attacker to correlate human beings with IP addresses.
Demo script:
Shutdown: