Weaponizing the Nokia N900 – Part 3.6 – Portable Rogue AP Point

by on Feb.26, 2011, under Code, Posts

With continuing the series of weaponizing the N900 and hoping that Infosec Island will continue with their series as well, I have successfully setup my N900 as a rogue AP point.

Firstly, to effectively deploy it you want to make sure your cell phone service (3G for the N900) is quite strong. You may even want to try pinging google or the like and see what the delay is. With a good connection, it will very for me between 70 and 90 milliseconds.

Second, you want to survey the site you’re going to deploy your portable rogue ap point. Luckily, you can run kismet on the N900. Once you have surveyed the site for other AP points, take note of the MAC addresses of each AP point that is specific to the area and also take note of the names of the AP points. With this mac address you can spoof your wlan0 interface to something that is very similar:

ifconfig wlan0 hw ether 00:XX:XX:XX:XX:XX

You will need to have the extra repos enabled to install an application called mobilehotspot. You will also need prior to this, to install the custom kernel for the N900. You will also need ettercap and sslstrip to carry out this attack. See my earlier post for notes on the two: http://zitstif.no-ip.org/?p=451

1.) Get sslstrip up and running, and make sure you have iptables. For steps on using sslstrip check out:
http://www.thoughtcrime.org/software/sslstrip

2.) Spoof your wlan0 hardware address to what is appropriate for the site.

3.) Run the mobilehotspot application.

4.) Wait for a few seconds

5.) Run ettercap by doing so (modify as needed):
ettercap -i wlan0 -q -T -p -u // //

The reason why we don’t have ettercap forward packets, is because the kernel is already doing so due to the mobilehotspot application.

That is pretty much it. You could also do dnsspoofing to send your victims to a server under your control to do drive by attacks.

:, , , , , , , , , , , , , , , , , , , , , , , , ,

5 Comments for this entry

  • G mustafa taj

    In thе Nokia Research аnԁ Enhancement Centers (Nokia R & D) іѕ already working οn a 3D multi-touch UI, whісh іѕ based οn a capacitive touch screen аnԁ sensors.

  • zitstif

    That is interesting, however I’m sure this new device is going to be Windows based… 🙁

  • zerocool

    i have a quetion but do you know if theres another way of creating a rogueAP with out using 3g …

  • zitstif

    Not to the best of my knowledge. If you’re referring to not using the cell phone network as a means of connecting to the internet, the only other way I can think of is if you can get your Nokia N900 in host mode and be able to hook up a usb wireless adapter through the micro usb connection. A problem you’d likely run into is having working drivers for the USB wireless device..

    I hope this at least gives you some ideas and thanks for your question.

  • zerocool

    thanks very much for reply i will look into it love the site some very usfull posts well done cant wait for more N900 related stuff ..

1 Trackback or Pingback for this entry

Leave a Reply

Please leave these two fields as-is:

Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!