Lock in $30 Savings on PRO—Offer Ends Soon! ⏳
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Wi-Fiによるモダン ネットストーキング
Search
Akira KUMAGAI
August 24, 2013
Technology
0
1.9k
Wi-Fiによるモダン ネットストーキング
Akira KUMAGAI
August 24, 2013
Tweet
Share
More Decks by Akira KUMAGAI
See All by Akira KUMAGAI
Wi-Fiの混雑に向き合う基本的知識とオフィスWi-Fi提供時の課題
tinbotu
0
120
JANOG39会場ネットワークの裏話
tinbotu
0
380
Wi-Fi再入門〜見えない電波を知識で見抜く
tinbotu
71
160k
Other Decks in Technology
See All in Technology
Active Directory 勉強会 第 6 回目 Active Directory セキュリティについて学ぶ回
eurekaberry
16
5.9k
事業部のプロジェクト進行と開発チームの改善の “時間軸" のすり合わせ
konifar
9
2.8k
その設計、 本当に価値を生んでますか?
shimomura
2
180
モバイルゲーム開発におけるエージェント技術活用への試行錯誤 ~開発効率化へのアプローチの紹介と未来に向けた展望~
qualiarts
0
280
形式手法特論:CEGAR を用いたモデル検査の状態空間削減 #kernelvm / Kernel VM Study Hokuriku Part 8
ytaka23
1
140
なぜフロントエンド技術を追うのか?なぜカンファレンスに参加するのか?
sakito
9
1.9k
All About Sansan – for New Global Engineers
sansan33
PRO
1
1.3k
手動から自動へ、そしてその先へ
moritamasami
0
180
日本Rubyの会の構造と実行とあと何か / hokurikurk01
takahashim
2
400
AI/MLのマルチテナント基盤を支えるコンテナ技術
pfn
PRO
5
720
ML PM Talk #1 - ML PMの分類に関する考察
lycorptech_jp
PRO
1
490
Master Dataグループ紹介資料
sansan33
PRO
1
4k
Featured
See All Featured
VelocityConf: Rendering Performance Case Studies
addyosmani
333
24k
Put a Button on it: Removing Barriers to Going Fast.
kastner
60
4.1k
Why Our Code Smells
bkeepers
PRO
340
57k
Speed Design
sergeychernyshev
33
1.4k
Mobile First: as difficult as doing things right
swwweet
225
10k
Statistics for Hackers
jakevdp
799
230k
Creating an realtime collaboration tool: Agile Flush - .NET Oxford
marcduiker
35
2.3k
XXLCSS - How to scale CSS and keep your sanity
sugarenia
249
1.3M
GraphQLの誤解/rethinking-graphql
sonatard
73
11k
Imperfection Machines: The Place of Print at Facebook
scottboms
269
13k
Done Done
chrislema
186
16k
Fashionably flexible responsive web design (full day workshop)
malarkey
407
66k
Transcript
8J'JʹΑΔ Ϟμϯ ωοτετʔΩϯά Akira KUMAGAI @tinbotu 2013ՆٳΈࣗ༝ݚڀ
͋ͱͰσϞΛ͠·͢ • ݸਓΛಛఆՄೳͳใ͋Γ·ͤΜ • ؒతʹಛఆͷࡐྉʹͳΓಘΔ͔ • ಉҙ͍͚ͨͩͳ͍߹ WiFi σόΠεͷ ిݯΛ͍ͬͯͩ͘͞
σϞͷରʹͳΔΑ
WiFi ͷ͘͠Έ 1.ΫϥΠΞϯτ(ࢠػ) ͕ AP(ػ) Λ୳͢ 2.ΫϥΠΞϯτ͕ AP ͷҰཡΛදࣔ 3.Ϣʔβ͕
AP Λબ 4.ೝূ 5.ଓྃ
APҰཡΛදࣔ
Ϣʔβ͕APΛબ
ύεϫʔυೖྗ
ύεϫʔυೖྗ ॳճ͚ͩͩΖ
WiFi ͷ͘͠Έ(2) 1.ΫϥΠΞϯτ(ࢠػ) ͕ AP(ػ) Λ୳͢ 2.هԱ͍ͯ͠Δ AP͕͋Ε 3.هԱ͍ͯ͠ΔύεϫʔυͰೝূ 4.ଓྃ
WiFi ͷ͘͠Έ(2) 1.ΫϥΠΞϯτʢࢠػʣ͕ AP Λ୳͢ 2.هԱ͍ͯ͠ΔAP͕͋Ε 3.هԱ͍ͯ͠ΔύεϫʔυͰೝূ 4.ଓྃ શࣗಈ
͏গ͠ৄ͘͠
ػ͕ͳ͍ͱ ଓͰ͖ͳ͍
͕AP(ػ)ͷଘࡏΛΔํ๏2ͭ • AP͕ఆظ์ૹ͍ͯ͠ΔϏʔίϯ*1 • ΞΫςΟϒͳݕग़ཁٻ*2 *1 IEEE802.11 00/1000 Beacon Frame,
MAC(APͷBSSID), SSID, Capability, BI, TIM ͳͲΛಛఆͷνϟωϧʹͯ௨ৗ20ʙ500msִؒͰૹ৴ *2 IEEE802.11 00/0100 Probe Request, MAC(ͷMACΞυϨε), SSID(ۭͳΒϒϩʔυΩϟετ) ɹ IEEE802.11 00/0101 Probe Response, େମϏʔίϯͱಉ͡ใྔΛಛఆͷԠ
AP௨৴͕ͳ͍ͱ͖ ࣗͷSSIDͳͲΛఆظతʹ์ૹ͍ͯ͠Δ ͜ΕΛBeacon(Ϗʔίϯ) ͱݺͼ·͢
ݕग़ཁٻΛੵۃతʹૹ৴͠ɺAP͔ΒͷԠ ͕͋Ε AP ΛೝࣝͰ͖Δ IEEE802.11 Probe Request
ݕग़ཁٻΛੵۃతʹૹ৴͠ɺAP͔ΒͷԠ ͕͋Ε AP ΛೝࣝͰ͖Δ AP ݕग़ཁٻ (Probe Request) ʮAP ୭͔͍·͔͢ʯ
IEEE802.11 Probe Request
ݕग़ཁٻΛੵۃతʹૹ৴͠ɺAP͔ΒͷԠ ͕͋Ε AP ΛೝࣝͰ͖Δ AP ݕग़ཁٻ (Probe Request) ʮAP ୭͔͍·͔͢ʯ
AP ݕग़Ԡ (Probe Response) ʮ͍ɹԶͷ໊”MyHomeBuffalo”ʯ IEEE802.11 Probe Request
None
(ࢠػ)ϏʔίϯΛड৴͢Δ͔ɺ·ͨ ݕग़ཁٻΛੵۃతʹૹ৴͠ɺAP͔ΒͷԠ ͕͋Ε AP ΛೝࣝͰ͖Δ
(ࢠػ)ϏʔίϯΛड৴͢Δ͔ɺ·ͨ ݕग़ཁٻΛੵۃతʹૹ৴͠ɺAP͔ΒͷԠ ͕͋Ε AP ΛೝࣝͰ͖Δ ·ͨʁ
(ࢠػ)ϏʔίϯΛड৴͢Δ͔ɺ·ͨ ݕग़ཁٻΛੵۃతʹૹ৴͠ɺAP͔ΒͷԠ ͕͋Ε AP ΛೝࣝͰ͖Δ ݕग़ཁٻ(Probe Request)ͬͯԿΑ AP͕Ϗʔίϯग़ͯ͠Εଘࡏ͕Θ͔Δ͡ΌΜ ͍Βͳ͍ͷͰɻ ·ͨʁ
ݕग़ཁٻ͕ඞཁ!
ݕग़ཁٻ͕ඞཁ! • ܨ͍͗ͨSSID͕طʹΘ͔ͬͯΔͳΒɺͦͷ SSIDΛ໊ࢦ͠Ͱݕग़ཁٻͨ͠΄͏͕ᴴ͔ʹ ͍(ೋճҎ߱ͷଓͱ͔)
ݕग़ཁٻ͕ඞཁ! • ܨ͍͗ͨSSID͕طʹΘ͔ͬͯΔͳΒɺͦͷ SSIDΛ໊ࢦ͠Ͱݕग़ཁٻͨ͠΄͏͕ᴴ͔ʹ ͍(ೋճҎ߱ͷଓͱ͔) • WiFi νϟωϧ͕͍ͬͺ͍͋Δ͠ɺλΠ ϛϯά͕ѱ͍ͱϏʔίϯΛड৴Ͱ͖ͳ͍
ݕग़ཁٻ͕ඞཁ! • ܨ͍͗ͨSSID͕طʹΘ͔ͬͯΔͳΒɺͦͷ SSIDΛ໊ࢦ͠Ͱݕग़ཁٻͨ͠΄͏͕ᴴ͔ʹ ͍(ೋճҎ߱ͷଓͱ͔) • WiFi νϟωϧ͕͍ͬͺ͍͋Δ͠ɺλΠ ϛϯά͕ѱ͍ͱϏʔίϯΛड৴Ͱ͖ͳ͍ •
SSIDΛӅͯ͠ΔAPͦͦݟ͑ͳ͍
ݕग़ཁٻ͕ඞཁ! • ܨ͍͗ͨSSID͕طʹΘ͔ͬͯΔͳΒɺͦͷ SSIDΛ໊ࢦ͠Ͱݕग़ཁٻͨ͠΄͏͕ᴴ͔ʹ ͍(ೋճҎ߱ͷଓͱ͔) • WiFi νϟωϧ͕͍ͬͺ͍͋Δ͠ɺλΠ ϛϯά͕ѱ͍ͱϏʔίϯΛड৴Ͱ͖ͳ͍ •
SSIDΛӅͯ͠ΔAPͦͦݟ͑ͳ͍
SSID ໊ࢦ͠Ͱݕग़ཁٻ
SSID ໊ࢦ͠Ͱݕग़ཁٻ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ
SSID ໊ࢦ͠Ͱݕग़ཁٻ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़Ԡ (Probe
Response) ʮ͍ʯ
SSID ໊ࢦ͠Ͱݕग़ཁٻ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़Ԡ (Probe
Response) ʮ͍ʯ ͍
SSID ໊ࢦ͠Ͱݕग़ཁٻ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़Ԡ (Probe
Response) ʮ͍ʯ ͍ ݕग़ϛεͳ͍
͍͚Ͳ
• ࢠػࣗͷډॴ͕Θ͔ͬͯͳ͍. AP͕ແ͍ͣͷॴͰ Probe Request ͢Δ
• ࢠػࣗͷډॴ͕Θ͔ͬͯͳ͍. AP͕ແ͍ͣͷॴͰ Probe Request ͢Δ • ҰଓهԱͤͨ͞Β͠Β͘ͷؒ Probe Request
Λૹग़͠ଓ͚Δ(࣮ґଘ)
ͨͱ͑౦ژʙതଟΛҠಈ͠·͢
ͨͱ͑౦ژʙതଟΛҠಈ͠·͢ ࣗͷAPʹର͢Δݕग़ཁٻ ՈΛग़ͨॠ͔ؒΒͯ͢ແବܸͪ ʢిͱ͔ͷແବ·͋ࠣͳʣ
SSID ໊ࢦ͠Ͱݕग़ཁٻ
SSID ໊ࢦ͠Ͱݕग़ཁٻ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ
SSID ໊ࢦ͠Ͱݕग़ཁٻ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़ཁٻ (Probe
Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ
SSID ໊ࢦ͠Ͱݕग़ཁٻ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़ཁٻ (Probe
Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ
SSID ໊ࢦ͠Ͱݕग़ཁٻ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़ཁٻ (Probe
Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़ཁٻ (Probe Request)
SSID ໊ࢦ͠Ͱݕग़ཁٻ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़ཁٻ (Probe
Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़ཁٻ (Probe Request) ʮ“MyHomeBuffalo”͞Μ͍·͔͢ʯ AP ݕग़ཁٻ (Probe Request) ͜ͷiPhone͕͋ΒΏΔग़ઌͰ “MyHomeBuffalo”ͬͯͷΛཁٻͯ͠ΔΑ͏ͩ
࣮ࡍʹݟͯΈΑ͏
None
ࣗͷϊʔτPC(b8:f6:b1:14:fc:1b)͕ iis-visitor ͬͯͷΛ୳͍ͯ͠Δ
iis-visitor Ͳ͔͜ͷήετ༻WiFiͬΆ͍
iis-visitor Ͳ͔͜ͷήετ༻WiFiͬΆ͍ ଓ֮ͨ͑͋͠Δ
Probe Request ʹؚ·ΕΔ༰
Probe Request ʹؚ·ΕΔ༰ • ͷMACΞυϨε • ͕ଓͨ͜͠ͱͷ͋Δ AP ͷ ESSID
ʢෳ͔ʣ • APͷBSSID(MACΞυϨε)ؚ·Εͳ͍
None
None
͜ͷ"QQMFͷॴ༗ऀΪʔਫʹߦͬͨ͜ͱ ͕͋ͬͯTIJCVIPVTFʹߦͬͨ͜ͱ͕͋ͬͯ TJOBQʹߦͬͨ͜ͱ͕͋ͬͯUBLBOP͞Μͱ ໘͕ࣝ͋ΔͩΖ͏ɻ
͍
ετʔΩϯάͷԠ༻
ετʔΩϯάͷԠ༻ • શʹडಈ(passive)ͳετʔΩϯάͳͷͰɺ ଆͰ߈ܸݕ͕ෆՄೳ
ετʔΩϯάͷԠ༻ • શʹडಈ(passive)ͳετʔΩϯάͳͷͰɺ ଆͰ߈ܸݕ͕ෆՄೳ • WiFi ͕ಧ͘ൣғʹߦ͘ඞཁ͕͋ͬͯɺ ݫີʹωοτετʔΩϯά͡Όͳ͍
ετʔΩϯάͷԠ༻ • શʹडಈ(passive)ͳετʔΩϯάͳͷͰɺ ଆͰ߈ܸݕ͕ෆՄೳ • WiFi ͕ಧ͘ൣғʹߦ͘ඞཁ͕͋ͬͯɺ ݫີʹωοτετʔΩϯά͡Όͳ͍ • λʔήοτͷͷMACΞυϨε͕Θ͔Β
ͳ͍ͱ୭͕୭͔ͩΘ͔Βͳ͍
MACΞυϨεΛΔํ๏
MACΞυϨεΛΔํ๏ λʔήοτͷʹ৮͢Δඞཁ͕͋Δ… ͦΕ͕ແཧͳΒਪଌ͢ΔͷΈ
σϞ
None
ଞͷωλ • BSSID(MAC) ͔ΒҐஔใΛҾ͚ΔAPI • ESSID ͔Β BSSID Λਪଌ͠ Probe
Request ͔ΒͷաڈͷҐஔใΛਪ ଌ
๏తͳ • ి๏ ୈ59ʢൿີͷอޢʣ • Կਓ๏ʹผஈͷఆΊ͕͋Δ߹Λআ͘΄͔ɺಛఆͷ૬खํʹର͠ ͯߦΘΕΔແઢ௨৴ʢిؾ௨৴ࣄۀ๏ୈ4ୈ1߲ຢୈ164ୈ2߲ͷ ௨৴Ͱ͋ ΔͷΛআ͘ɻୈ109ฒͼʹୈ109ͷ2ୈ2߲ٴͼୈ3߲ʹ͓ ͍ͯಉ͡ɻʣΛडͯͦ͠ͷଘࡏए͘͠༰Λ࿙Β͠ɺຢ͜ΕΛ
༻ͯ͠ͳΒͳ͍ɻ
__END__