Javascript must be enabled to continue!
Analisis Unauthorized Access Point Menggunakan Teknik Network Forensics
View through CrossRef
In this era, free access points are found available in various places. But this freedom comes with a price, and only a few users really understand the risk. In a recent survey, 70% of tablet owners and 53% of smartphone owners stated that they use public wifi hotspots. The biggest threat to public wifi security is how a hacker positions himself as a liaison between victims and Authorized Access Points. To do this the hacker creates an Unauthorized Access Point (Fake Access Point). We took a pentester/attacker POV in this artikel for educational purposes, so that users may know the stages of Fake Access Point attack based on Kali Linux, Fluxion. For the digital evidence analysis stage, we used the customized OSCAR (Obtain information, Strategies, Collect Evidence, Analyze and Report) methods, where attacking is the stage for preparation, determining which wifi Access Points is going to be the target of the attack, and carrying out attacks. While, analysis is the stage of analyzing the steps of attack and how to distinguish between AAP and UAP. The results of our research are that after determining the target, the pen tester/attacker will use aircrack-ng on Fluxion to get a handshake, create a fake web interface, then launch a deauth all attack, also known as DoS, to AAP so that the victim / client cannot connect with the AAP and switch to Fake Access Point. The fake web interface will then ask the victim to enter the password, where after the password is found, the pen tester/attacker can see it through Fluxion. As a precautionary measure, the difference between a Fake Access Point and an Authorized Access Point is found in the presence or absence of the padlock symbol (Android) or an exclamation point (Windows 10).Pada zaman ini, free access point telah tersedia di berbagai tempat. Namun, nyatanya kebebasan ini memiliki harga, dan hanya sedikit pengguna yang memahami benar risikonya. Ancaman terbesar terhadap kemanan wifi publik adalah bagaimana seorang hacker memposisikan dirinya sebagai penghubung antar korban dan Authorized Access Point. Untuk melakukan hal tersebut, hacker membuat Unauthorized Access Point (Fake Access Point). Dalam artikel ini pen tester/attacker diambil sudut pandang sebagai dengan tujuan edukasi, agar pengguna mengetahui tahapan serangan Fake Access Point dengan tool Fluxion berbasis OS Kali Linux. Tahapan analisis bukti digital menggunakan metode OSCAR (Obtain Information, Strategies, Collect Evidence, Analyze and Report) yang telah di kostumisasi, di mana attacking adalah tahapan untuk persiapan menentukan target wifi Access Point yang akan diserang serta menjalankan serangan. Analysis adalah tahapan menganalisa langkah penyerangan serta bagaimana cara membedakan Authorized Access Point dengan Unauthorized Access Point. Hasil penelitian yang dilakukan setelah menentukan target, pentester/attacker akan menggunakan Aircrack-ng pada Fluxion untuk mendapatkan handshake, membuat web interface palsu, kemudian melancarkan serangan Deauth all, dikenal DoS ke AAP, sehingga korban/client tidak dapat terkoneksi dan masuk ke Fake Access Point. Web interface palsu kemudian akan meminta korban untuk memasukkan password. Setelah password ditemukan, maka pen tester/attacker dapat melihatnya melalui Fluxion. Sebagai langkah pencegahan, perbedaan antara Fake Access Point dan yang Authorized Access Point ditemukan pada ada tidaknya simbol gembok (Android) atau tanda seru (Windows 10).
Yayasan Petra Harapan Bangsa
Title: Analisis Unauthorized Access Point Menggunakan Teknik Network Forensics
Description:
In this era, free access points are found available in various places.
But this freedom comes with a price, and only a few users really understand the risk.
In a recent survey, 70% of tablet owners and 53% of smartphone owners stated that they use public wifi hotspots.
The biggest threat to public wifi security is how a hacker positions himself as a liaison between victims and Authorized Access Points.
To do this the hacker creates an Unauthorized Access Point (Fake Access Point).
We took a pentester/attacker POV in this artikel for educational purposes, so that users may know the stages of Fake Access Point attack based on Kali Linux, Fluxion.
For the digital evidence analysis stage, we used the customized OSCAR (Obtain information, Strategies, Collect Evidence, Analyze and Report) methods, where attacking is the stage for preparation, determining which wifi Access Points is going to be the target of the attack, and carrying out attacks.
While, analysis is the stage of analyzing the steps of attack and how to distinguish between AAP and UAP.
The results of our research are that after determining the target, the pen tester/attacker will use aircrack-ng on Fluxion to get a handshake, create a fake web interface, then launch a deauth all attack, also known as DoS, to AAP so that the victim / client cannot connect with the AAP and switch to Fake Access Point.
The fake web interface will then ask the victim to enter the password, where after the password is found, the pen tester/attacker can see it through Fluxion.
As a precautionary measure, the difference between a Fake Access Point and an Authorized Access Point is found in the presence or absence of the padlock symbol (Android) or an exclamation point (Windows 10).
Pada zaman ini, free access point telah tersedia di berbagai tempat.
Namun, nyatanya kebebasan ini memiliki harga, dan hanya sedikit pengguna yang memahami benar risikonya.
Ancaman terbesar terhadap kemanan wifi publik adalah bagaimana seorang hacker memposisikan dirinya sebagai penghubung antar korban dan Authorized Access Point.
Untuk melakukan hal tersebut, hacker membuat Unauthorized Access Point (Fake Access Point).
Dalam artikel ini pen tester/attacker diambil sudut pandang sebagai dengan tujuan edukasi, agar pengguna mengetahui tahapan serangan Fake Access Point dengan tool Fluxion berbasis OS Kali Linux.
Tahapan analisis bukti digital menggunakan metode OSCAR (Obtain Information, Strategies, Collect Evidence, Analyze and Report) yang telah di kostumisasi, di mana attacking adalah tahapan untuk persiapan menentukan target wifi Access Point yang akan diserang serta menjalankan serangan.
Analysis adalah tahapan menganalisa langkah penyerangan serta bagaimana cara membedakan Authorized Access Point dengan Unauthorized Access Point.
Hasil penelitian yang dilakukan setelah menentukan target, pentester/attacker akan menggunakan Aircrack-ng pada Fluxion untuk mendapatkan handshake, membuat web interface palsu, kemudian melancarkan serangan Deauth all, dikenal DoS ke AAP, sehingga korban/client tidak dapat terkoneksi dan masuk ke Fake Access Point.
Web interface palsu kemudian akan meminta korban untuk memasukkan password.
Setelah password ditemukan, maka pen tester/attacker dapat melihatnya melalui Fluxion.
Sebagai langkah pencegahan, perbedaan antara Fake Access Point dan yang Authorized Access Point ditemukan pada ada tidaknya simbol gembok (Android) atau tanda seru (Windows 10).
Related Results
Steal More Wifi!
Steal More Wifi!
There has arisen a small litany of criminal prosecutions of nefarious dudes in long black trench coats that congregate outside coffee houses with their laptops, piggy backing on op...
A Novel Framework for Mobile Forensics Investigation Process
A Novel Framework for Mobile Forensics Investigation Process
Abstract
Investigating digital evidence by gathering, examining, and maintaining evidence that was stored in smartphones has attracted tremendous attention and become a key...
Potable Water Sources, Household Hygiene, and Sanitation Practices in Ikpoba Okha LGA, Edo State: Implications for Public Health and Sustainable Water Management
Omoregie, Andrew Edosa.1 Omoregie Abieyuwa Peace2 Okoro, Enyinnaya Okoro.3
1 College of Medi
Potable Water Sources, Household Hygiene, and Sanitation Practices in Ikpoba Okha LGA, Edo State: Implications for Public Health and Sustainable Water Management
Omoregie, Andrew Edosa.1 Omoregie Abieyuwa Peace2 Okoro, Enyinnaya Okoro.3
1 College of Medi
BACKGROUND
Access to potable drinking water and sufficient sanitation continues to be an urgent global concern, particularly in developing regions where con...
Unveiling the Dynamic Landscape of Digital Forensics: The Endless Pursuit
Unveiling the Dynamic Landscape of Digital Forensics: The Endless Pursuit
The invention of transistors in the 1940s marked the beginning of a technological revolution that has impacted every aspect of our lives. However, along with the positive advanceme...
A Cloud Forensics Framework to Identify, Gather, and Analyze Cloud Computing Incidents
A Cloud Forensics Framework to Identify, Gather, and Analyze Cloud Computing Incidents
The focus of cloud forensics is cyber-crime cases, no matter the object, the subject, or the environment involved. Each cloud computing environment has a variety of features that m...
IoT Forensics: Current Perspectives and Future Directions
IoT Forensics: Current Perspectives and Future Directions
The Internet of Things forensics is a specialised field within digital forensics that focuses on the identification of security incidents, as well as the collection and analysis of...
On the Relationship Between Traditional Criminalistics and Digital Forensics
On the Relationship Between Traditional Criminalistics and Digital Forensics
The article provides a comparative analysis of the structure, methodology and terminology of classical criminalistics as a humanitarian discipline and digital forensics as a techni...
Utilization of Digital Forensics in Proving the Crime of Disseminating Indecent Videos Through Facebook Social Media in the Legal Area of West Kalimantan Police
Utilization of Digital Forensics in Proving the Crime of Disseminating Indecent Videos Through Facebook Social Media in the Legal Area of West Kalimantan Police
The research entitled: "Utilization of Digital Forensics in Proving the Crime of Disseminating Indecent Videos Through Facebook Social Media in the KALBAR Police Legal Area" aims t...

