Menu

Database

FakeAP

WVE ID: WVE-2005-0056

Type: Exploit

Status: Candidate

Classification:
Other

Description:
FakeAP is a tool that can be used to automatically spoof a large number of access points in order to confuse wardrivers.

Discussion:
FakeAP is a Perl script for Linux that utilizes cards compatible with the HostAP driver to create the illusion of many APs operating in the vicinity. It accomplishes this by putting a wireless card into Master mode which causes the card to function as an AP. FakeAP then cycles the card through varous MAC addresses and SSIDs. This will cause any 802.11 discovery tools being operated in the area to show many APs operating in the area.

By default FakeAP will randomly generate AP MAC addreses with the 00:00:0C, 00:00:CE, and 00:00:EF vendor prefixes along with the SSIDs "Access Point", "tsunami", "host", "airport", and "linksys". However, a list of vendor OUIs and words to use for SSIDs can be used.

In addition, FakeAP allows one to adjust the probably of it creating WEP encrypted networks. In order to evade detection through trilateration it also allows the output power of the card's radio to be varied within a user-supplied range.

It should be noted that an attacker can also modify FakeAP to generate AdHoc networks as well as fake stations.

Credits
Author: Stuart Stock (stuart@blackalchemy.to) : Black Alchemy Labs
Author: Ken Beames (ken@blackalchemy.to) : Black Alchemy Labs

References
URL: http://www.blackalchemy.to:8060/project/fakeap/index.php

Released: 2002-08-04

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Thu Dec 01 13:36:45 -0800 2005

Candidate Date: Thu Dec 01 13:37:29 -0800 2005


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...