802.11 scanner:
- : a passive 802.11 wireless network sniffer and intrusion detection system. THE reference for all other wireless scanners.
- : a Kismet wardriving map generator for locations outside the USA, by Raul Siles
- : parses Kismet .xml output files and generates html web pages for analysis.
- : free (but closed source) windows based wireless lan scanner
- : a tool to detect wireless lans
- : wireless lan discovery and auditing tool written in GTK/Perl. The new version WellenreiterII is completely re-coded in C++.
- : a wireless access point sniffer for Prism 2 chipsets
- : a wireless scanner for prism2 and Cisco Aironet cards
- : a top-notch wireless scanner for MAC OS X systems
Bluetooth tools:
- : a bluetooth pentest toolset for Linux and FreeBSD
- @stake released a new proof-of-concept tool called "Redfang - The Bluetooth Hunter". Redfang detects non-discoverable bluetooth devices. Unfortunately, @stake seems no longer to support much of their free security tools. So, use instead the alternativ download link above.
- : a bluetooth war-walking tool. Based on the paper from Ollie Whitehouse. The new version 2 is a complete rewrite ov version 1.0.
- : a curses based gui for redfang
- : a free windows-based bluetooth vulnerability assessment tool from NetworkChemistry
- : a free windows-based bluetooth device scanner from AirMagnet
- : a tool for "communicating" with Bluetooth carkits.
tools:
- : a tool for reading and writing RFID tags (RFID Reader required)
WEP attack tools:
- : a wireless LAN tool which recovers WEP encryption keys. Uses the well-known FMS attack.
- : the new version of the famous aircrack tool after Christine Devine quit the aircrack development. A very fast/advanced WEP cracking program. The included aireplay tool allows to reinject traffic (similar to reinj for *BSD from h1kari). Aircrack now also implements the very efficient statistical attack from KoreK.
- : a WLAN open source Linux tool for breaking 802.11 WEP keys with a dictionary attack. Supports different modes for ASCII mapping and hashed password generation in APs.
- : a tool to review the security of WEP encryption in wireless networks. Implements many different attacks like FMS, improved FMS and the new statistical KoreK attack.
Injection tools:
- : a toolkit for determining 802.11 WEP keystreams and injecting traffic with known keystreams
- : a tool for 802.11 frame injection which uses the driver. A paper about libwlan is available
- : a platform for injection of application layer data on a 802.11b network
- : a Linux device driver API for 802.11 cards which supports raw 802.11 traffic injection. This currently only works with linux kernels 2.4. The Wi-Foo Team the driver for Linux Kernel 2.6
LEAP attack tools:
- : a cisco leap attack tool released by Joshua Wright
- : a toolset to break the NTChallengeResponse encryption technique e.g. used by Cisco Wireless LEAP Authentication
- anwrap: a Dictionary Attack script against LEAP
WPA attacks:
- by Joshua Wright
by TinyPEAP-Team
Keep in mind with both tools the relatively slow speed due to the 4096 HMAC-SHA1 iterations required per password. WPA Cracker checks 16-18 passwords/second on a 1.4GHz notebook, cowpatty 70 passwords/second on a high end PC with 3.8 GHz.
: a set of tools for assessing the security of wireless clients
: a toolset for 802.11 auditing with a scanner (dstumbler), a WEP cracker (dwepcrack) and a handfull of helper tools. Only available for *BSD.
A for dwepcrack (the WEP cracker tool from bsd-airtools) has been ported by Per von Zweigbergk.
: an OpenSource implementation of IEEE 802.1x
: a FreeBSD 5.0 based wireless "network auditing kit" on a boot CD
: A linux boot CD distribution for Wardrivers (seems to be quite old)
: a Linux driver for 802.11 cards based on Prism 2, 2.5 and 3 chipsets. Its HostAP mode allows to operate your wireless card as a full Access Point.
: How to flash a 802.11 Access Point with Linux
: simulates up to 53.000 fake APs. Useful as part of a honeypot or as part of a "security by obscurity" strategy. Currently only works with Intersil Prism cards.
: A curses-based Wireless 802.11(b) Network Analyzer with a VERY broad feature set
: an automated penetration tool against wireless clients. It impersonates a valid access point and tricks the client to associate with it.
: a system for cooperative position detection in wireless lans
: a WEP key attack tool, based on
: a collection of 802.11 tools