Nytro Posted February 12, 2015 Report Posted February 12, 2015 WAIDPS – WIRELESS AUDITING AND IPS/IDSWAIDPS is an open source wireless swissknife written in Python and work on Linux environment. This is a multipurpose tools designed for audit (penetration testing) networks, detect wireless intrusion (WEP/WPA/WPS attacks) and also intrusion prevention (stopping station from associating to access point). Apart from these, it will harvest all WiFi information in the surrounding and store in databases. This will be useful when it comes to auditing a network if the access point is ‘MAC filtered’ or ‘hidden SSID’ and there isn’t any existing client at that moment.WAIDS may be useful to penetration testers, wireless trainers, law enforcement agencies and those who is interested to know more about wireless auditing and protection. The primarily purpose for this script is to detect intrusion. Once wireless detect is found, it display on screen and also log to file on the attack. Additional features are added to current script where previous WIDS does not have are :automatically save the attack packets into a fileinteractive mode where users are allow to perform many functionsallow user to analyse captured packetsload previously saved pcap file or any other pcap file to be examinecustomizing filterscustomize detection threshold (sensitivity of IDS in detection)At present, WAIDS is able to detect the following wireless attacks and will subsequently add other detection found in the previous WIDS.Association / Authentication floodingDetect mass deauthentication which may indicate a possible WPA attack for handshakeDetect possible WEP attack using the ARP request replay methodDetect possible WEP attack using chopchop methodDetect possible WPS pin bruteforce attack by Reaver, Bully, etc.Detection of Evil-TwinDetection of Rogue Access PointWAIDPS RequirementsNo special equipment is required to use this script as long as you have the following :Root access (admin)Wireless interface which is capable of monitoring and injectionPython 2.7 installedAircrack-NG suite installedTShark installedTCPDump installedMergecap installed (for joining pcap files)xterm installedDocumentation<span style="font-family: Rajdhani"><strong> Source && DownloadSursa: WAIDPS - Wireless Auditing and IPS/IDS Quote
GuyFawkes Posted February 15, 2015 Report Posted February 15, 2015 Pare mai bine structurat decât suita aircrack & co (cu tot cu Wifite). În plus, fata de aircrack & co vine cu partea de WIDS / WIPS care e absenta într-o forma cât de cât inteligibila în Kali. ( Variantele comerciale sunt pe foarte mul?i bani). Deci IMHO cred ca merita ?i de abia a?tept sa îl încerc. Quote
GuyFawkes Posted February 15, 2015 Report Posted February 15, 2015 Bineîn?eles ca nu am folosit niciodat? "suita aircrack-ng". Deci de abia a?tept sa îmi spui cu care dintre utilitarele din "suita aircrack-ng" faci WIDS adic? Wireless Intrusion Detection. Ca sa fiu mai specific m-ar interesa ni?te alerte la WPS PIN cracking, la Deauthentication attacks poate chiar la ni?te ARP request replay attacks, dac? nu sunt prea tehnic pentru cineva care nu prea a folosit "suita aircrack-ng".?i sa m? repet, nu e vorba de a face atacurile respective pe care ?i un pu?ti de 5 ani cu Wifite le poate face. E vorba e detec?ie ?i raportare. Acuma nu zic, e posibil sa îmi fi sc?pat, dar de folosit aircrack-ng, chiar am folosit. Cred. Quote