Menu

Database

KARMA

WVE ID: WVE-2006-0032

Type: Exploit

Status: Candidate

Classification:
Authentication Management
Hijacking
Infrastructure

Description:
KARMA is a set of tools for assessing the security of wireless clients at multiple layers. It listens to all client probe requests and becomes a fake AP for any requested network while emulating a production network environment.

Discussion:
Wireless sniffing tools discover clients and their preferred network list by passively listening for 802.11 Probe Request frames. From there, individual clients can be targeted by creating a Rogue AP for one of their probed networks (which they may join automatically) or using a custom driver that responds to probes and association requests for any SSID. Higher-level fake services can then capture credentials or exploit client-side vulnerabilities on the host.

The tool provides an exploit framework known as BYOX (Bring Your Own Exploits). A number of client-side exploits have been written, tested and demonstrated within this framework.

Credits
Author: Dino A. Dai Zovi : None
Author: Shane Macaulay : None

References
URL: http://theta44.org/karma/index.html

Released: 2006-01-24

Submitter
Raul Siles (raul.siles@hp.com) : HP

Submitted: Tue Apr 11 10:44:18 -0700 2006

Candidate Date: Wed Apr 12 06:34:52 -0700 2006


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...