Jump to content
Nytro

WAIDPS – WIRELESS AUDITING AND IPS/IDS

Recommended Posts

Posted

WAIDPS – WIRELESS AUDITING AND IPS/IDS

WAIDPS-main-1000x621.png

WAIDPS is an open source wireless swissknife written in Python and work on Linux environment. This is a multipurpose tools designed for audit (penetration testing) networks, detect wireless intrusion (WEP/WPA/WPS attacks) and also intrusion prevention (stopping station from associating to access point). Apart from these, it will harvest all WiFi information in the surrounding and store in databases. This will be useful when it comes to auditing a network if the access point is ‘MAC filtered’ or ‘hidden SSID’ and there isn’t any existing client at that moment.

WAIDPS.png

WAIDS may be useful to penetration testers, wireless trainers, law enforcement agencies and those who is interested to know more about wireless auditing and protection. The primarily purpose for this script is to detect intrusion. Once wireless detect is found, it display on screen and also log to file on the attack. Additional features are added to current script where previous WIDS does not have are :

  • automatically save the attack packets into a file
  • interactive mode where users are allow to perform many functions
  • allow user to analyse captured packets
  • load previously saved pcap file or any other pcap file to be examine
  • customizing filters
  • customize detection threshold (sensitivity of IDS in detection)

At present, WAIDS is able to detect the following wireless attacks and will subsequently add other detection found in the previous WIDS.

  • Association / Authentication flooding
  • Detect mass deauthentication which may indicate a possible WPA attack for handshake
  • Detect possible WEP attack using the ARP request replay method
  • Detect possible WEP attack using chopchop method
  • Detect possible WPS pin bruteforce attack by Reaver, Bully, etc.
  • Detection of Evil-Twin
  • Detection of Rogue Access Point

WAIDPS Requirements

No special equipment is required to use this script as long as you have the following :

  1. Root access (admin)
  2. Wireless interface which is capable of monitoring and injection
  3. Python 2.7 installed
  4. Aircrack-NG suite installed
  5. TShark installed
  6. TCPDump installed
  7. Mergecap installed (for joining pcap files)
  8. xterm installed

Documentation

<span style="font-family: Rajdhani"><strong>

docum.png

waidps2-934x1024.png

Source && Download

download-1024x154.jpg

Sursa: WAIDPS - Wireless Auditing and IPS/IDS

Posted

Pare mai bine structurat decât suita aircrack & co (cu tot cu Wifite).

În plus, fata de aircrack & co vine cu partea de WIDS / WIPS care e absenta într-o forma cât de cât inteligibila în Kali.

( Variantele comerciale sunt pe foarte mul?i bani). Deci IMHO cred ca merita ?i de abia a?tept sa îl încerc.

Posted

Bineîn?eles ca nu am folosit niciodat? "suita aircrack-ng". Deci de abia a?tept sa îmi spui cu care dintre utilitarele din "suita aircrack-ng" faci WIDS adic? Wireless Intrusion Detection.

Ca sa fiu mai specific m-ar interesa ni?te alerte la WPS PIN cracking, la Deauthentication attacks poate chiar la ni?te ARP request replay attacks, dac? nu sunt prea tehnic pentru cineva care nu prea a folosit "suita aircrack-ng".

?i sa m? repet, nu e vorba de a face atacurile respective pe care ?i un pu?ti de 5 ani cu Wifite le poate face. E vorba e detec?ie ?i raportare.

Acuma nu zic, e posibil sa îmi fi sc?pat, dar de folosit aircrack-ng, chiar am folosit. Cred.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...