
You've heard of
black hat hackers and
white hat hackers, but what about leather hat hackers? Meet the first: Kyle Williams. This creative genius has built the ultimate network hacking PC, the "Janus Project," which can focus its eight WiFi cards to break your standard
WEP encryption in under five minutes. Beyond that, it can sniff 300
WiFi networks simultaneously, store and continuously encrypt all the data with AES 256-bit keys. In addition, the Janus Project has an instant off switch, which requires a USB key that has a 2000-bit passkey and a separate password to regain access. What's under the hood? Williams packed an
Ubuntu Linux machine running on a 1.5GHz VIA C7 processor with an Acer 17-inch screen into that snazzy little rugged yellow box. Oh, and the closed case is waterproof too, in case you need to transport Janus Project on a whitewater raft to your next hacking hotspot. We don't doubt someone will.
[Via
The Raw Feed]
You wanna be's need to know that a "real" hacker doesn't do anything illegal. People that do things with their computers for illegal purposes are NOT considered to be "real" hackers in the technology world. If I remember correctly, then I believe "real" hackers call the illegal fellas "crackers". "Real" hackers use their powers for good and not evil.
that.. is.. AWESOME!
i WANT! NOW MOMMY, NOW! ;]
Oh to have those sweet computer hacking skills.
i made one of those ages ago
i want 1
Seen this box close up, it's pretty wel built IMO. He had it at DEFCON and was freely giving details as well as peeks at the innards. I cannot recall exactly what was under the hood but it was pretty tightly packed and not his first effort at this either. I'd liek more details on the WEP break in "5mins" claim though as simply having more antennas isn't going to make that happen faster. I'm aware you can tweak a network to create weak packets blah blah but 5mins seems awful fast. Once you have the data though it takes only seconds to whack it :-)
So what does all of this wireless firepower provide?
Thats a nice keyboard. Anyone got any ideas on what it is? Looks like an apple but I haven't seen one before
I am 99% certain that keyboard is a White I-Rocks X-SLIM Computer Keyboard
http://www.directron.com/ir6810mwh.html
That's awesome. He looks kinda like the kid from Growing Pains.
Now THAT is a hacking project worthy of recognition!
Nice Mountain Dew product placement :- )
[re:Tob3z] speedlink crystal keyboard
Janus was the nickname of the decryption box in the movie Sneakers...FYI
@Rick,
That's probably what it was named for, but Janus was also the two headed god in Roman mythology.
http://en.wikipedia.org/wiki/Janus_%28mythology%29
"We don't doubt someone will."
Exactly! Like James Bond! Except his would be disguised as, like, his tie or something.
is'nt hacking illegal
re: Thats a nice keyboard. Anyone got any ideas on what it is? Looks like an apple but I haven't seen one before
[re:Tob3z] speedlink crystal keyboard
I believe its a Kensington for mac. we have black ones at work for pc. they have low tactile feel...
http://us.kensington.com/html/5463.html
"in case you need to transport Janus Project on a whitewater raft to your next hacking hotspot"
Sure, as if anybody interested in 1337 custom-built WiFi hacking hardware spends any time outdoors.
yo i just totally hacked into your moms computer and found pictures of you sleeping with your girlfriend. aren't you totally creeped out?
He has a bright future working as a snoop for the government.
8 wifi cards... I was afraid to get cancer from one.
wow... I could leech off any one of my neightbors anytime I want to with something like this soooo cool :-)
have that Linux distro.. :O although dont have the skills to do that though... :(
I'm going to build my next computer in a pelican caese.
We're not worthy. Kyle, if you ever read this, seriously I'm jealous. Good job.
The case looks like an Otterbox 3500.
http://www.otterbox.com/products/otterbox/3500/index.htm
The case looks like an Otterbox 3500.
http://www.otterbox.com/products/otterbox/3500/index.htm
8"x4"x3.5"
with a 17" lcd?
NOT
BLOODY
LIKELY
Wasn't Janus also the name of the cloning project in JUDGE DREDD?
Its a Peli case
this is underwhelming to say the least. congratulations, you built a case around a PC to do something people have been doing for years. nice k-fed look btw.
hey, that's my friend in real life! haha!
I bet you could hack the Gibson with that.
The link to the original article:
http://www.tgdaily.com/2006/08/30/defcon2006_janus_project/
The case is a Pelican. They keyboard is whatever was on sale for around $10 that day (the box is gone so I don't know who made it). I know what the project was named for, but I'll let you discuss it among yourselves. It's more entertaining that way.
How do I know all this? I'm married to one of the co-creators.
the feds cracked 128bit WEP in 3 minutes at ISSA last year with publically available tools and a couple laptops. they said 5-10 minutes is common.
http://www.tomsnetworking.com/2005/03/31/the_feds_can_own_your_wlan_too/
VIA C7 EN15000G mainboard, two routerboard PCI to 4xminiPCI adapters, 8 x CM9 atheros abg radios, 2 x teletronics 1W 2.4Ghz amplifiers.
http://s103.photobucket.com/albums/m127/coderman42/?action=view¤t=janusbox.jpg&refPage=&imgAnch=imgAnch3
http://s103.photobucket.com/albums/m127/coderman42/?action=view¤t=janusbox-dev.jpg&refPage=&imgAnch=imgAnch2
Tob3z, its an ITWorks KC-6130W keyboard, im typing on it now. £20 from comet
Man, he has used Ubuntu to get 8 Wifi cards running and do this. I still can't get my one to work in Ubuntu! Fairplay though, this must be of interest to CID, MI5 the FBI and every other bloody 3 lettered acronym for someone who likes to snoop in other people businessm, surely they'll cough up to get him to help them make one of these or at least bundle him into the back of a car, steal if off him and replace his memory with that of a chicken.
I'd just like to see a mid to high end system built into the smallest available Zero Halliberton (www.zerohalliburton.com) alluminum breif case. It should also come with wireless keyboard, mouse, bluetooth headset with Voip, with the lid being being the screen and the bottom half after takeing out the kB, Mouse & headset being a graphics tablet.. or even better a second screen and have the 2nd one be a touchscreen. Also the very top of the lid on the inside above the screen should have a web cam and microphone setup. And last of all have the base of the Halliburton Case when closed & standing upright have a hole drilled in it the right size for a projector lens. That way when it's laying on a desk with the lid open or closed you could have a built in projector. Of course the lens should have an metal iris type powered cover that closes when you turn off the projector. All in all the unit should have a minumum run time of 12 hours on the battery (like some of the Panasonic sub-note's claim) and should be under 3lbs total weight. These are just the base spec's.... if anyone want's to do a qoute for me on this I get them more details on some of the more complex things needed in it. ;-) LOL I wish I could get a unit like that.
looks like a Pelican 1520 case. great cases
http://www.pelican.com/cases_detail.php?Case=1520
The death penalty for hacking? Are you some kind of psycho? How do you think the government spies on people (for example Bush's illegal wire tapping)? Wire taps are essentially phone hacks. For starters, what makes hacking an offense punishable by death? Computers aren't secure, and if anyone has anything they want to keep safe they shouldn't keep it on a computer that's possibly going to be connected to the Internet at some point in time. The Internet is about as safe as a back alley abortion clinic. But wait... Most people who believe in the death penalty these days are also pro-life. If you don't feel safe with hackers running around then simply don't use the Internet. I promise you that just like terrorists, you're never going to catch enough hackers to make a difference without screwing things up for everyone else.
i only need two words:
kick & ass
"...you're never going to catch enough hackers to make a difference without screwing things up for everyone else....
I dunno. Tell us where you are, and we've caught you!
It's a start.
Hackers should die.
Killer.
I knew there was a reason I never trusted wireless. Improve wireless :)
Or a banks ATM and have it spit money into the street.
8 wireless cards, hope you mailed in all the rebates
well, encript that WiFi on wep+mac limitation and try again to crack-it :) lost hopes + try never to use as a key first one, set 4 up and swich on them o regular bases, makes that kind of hacking a time waist to wit's end :)
Serioulsy I need to build this thing
This creative genius has built the ultimate network hacking PC...
Ultimate? So there will be no more after this one?
Nice box, anyway!
@Rick
Dude, you obviously haven't watched Sneakers enough. The little black box is only called just that: "little black box." It's creator, Dr. Gunter Janek, has a name that sounds kind of like Janus, except not.
I have two words also...
So so...
This really isn't that special. You are hard pressed to ever be in range of 50 wireless networks at any given time, and 300? Please! By the time the world reaches the point of being that densly packed with wireless networks i'm sure they will have developed wireless cards with 8, 16 or 32 cores built in. Don't they already have some that use dual core to speed up existing 802.11b/g? Why do people get accolades for using existing technology as it was intended? If he had gotten those wireless network card to do something new that would be different.
I will give him some kudos on the case mod. It's pretty sweet!
Keyboard I-Rocks KR-6810
Can break WEP keys in under 5 minutes?!? WOW!
Ok, so what if I have MAC-based access as well...?
Unless you can access into my ap (of which you would have to have an allowed MAC address), find the MAC access list, spoof your MAC for one of the allowed MACs... which you would need to access my ap (of which you would have to have an allowed MAC address)...
See a problem here?
[re: James Bishop]
It would be nice if people would learn that all hackers are not evil! I hack but I do not do it for nefarious reason and never to steal anything, only to learn; no different then a shade-tree mechanic with toolbox and his car.
So the "genius" part is? I mean its a really cool hackjob but it doesn't sound like he has done anything remarkable. If they actually said anything about how he set it up it would be another thing entirely but from the blurb it sounds like he just put together off the shelf code. Am I missing something really cool?
Haven't seen this one yet, but wasn't JANUS the name of the villanous organization in "Goldeneye" for N64?
@bpc
Dude, thanks for that - I was about to chime in on the Sneakers mis-quote.
@Wes -
No one would have to have access to your router - the mac address of your nic can be sniffed out by the same tools that are used to break the WEP key - then it can simply be spoofed. This is extremely easy for someone who knows how to break a wep key to do. The only way to truely secure it would be to use some other sort of encryption, i.e. WPA, WPA2, etc. etc.
Mad filtering is easy to get around.. Use Kismet to sniff the network and it will show you the mac addresses of the systems attached to the network... then all you have to do is use a mac address changer and voila.. you are on the network. Wep will only protect you for 5-10 min past that.. Best bet ... turn the wireless off and make like Glade and "plug it in ... plug it in" *grin*
@Wes
Why do I need to get into your AP for the MAC exactly? The MAC broadcasts freely in the clear anytime you talk to your AP and it's possible to pull it from the traffic and clone it, no biggie. Yes, there would be a duplicate MAC on the network but if one has more power than the other the stronger one wins - gotta love directional antennas. MAC access filtering doesn't slow down an attacker using Linux tools which tend to be ALOT more flexible than Windows.
The 5min claim is what seems a bit farfetched. I know how to break WEP as I've done it myself with my own paws, not watched some demonstration on a stage. In my experience it takes a bit longer than 5mins which is why I questioned it in the first place. If you simply accumulate traffic yourself then it will take ALOT longer even on a really busy network - I did mine while downloading Torrents and it took a good half hour. If you use a second NIC it's possible to cause the target network to spew traffic in response and you can build up a pile of packets much more quickly but no, not 5mins in my experience and it's ALOT noisier since it's not passive. When you've got enough packets though it only takes SECONDS to get the key even if it's a lengthy HEX key created randomly. Kind of fun to watch it break actually :-)
Rolling the key works, you can change it faster than the attacker can accumulate traffic to crack it. Terrific! Now do it across hundreds of clients :-) Not going to happen with WEP, at least not the preshared key stuff you run at home with even a handful of clients. WPA does something like this although depending upon the version of WPA that too has some vulnerabilities during the initial client association. I understand WPA alot less and there's still alot of hardware out there that won't support it too.
It *is* possible to secure wireless, it's just not so easy that it can be done without some thought. Some of the protocols have been pretty flawed but it's better than nothing.
Me? I run 128bit WEP. I know it can be broken but it's a clear No Tresspassing sign so if I do catch someone on my network I can hunt them down and have a clear legal case. I wouldn't even bother with MAC filtering, not worth the added hassle for you and not a significant detterant to the attacker...
WPA2 with MAC filtering and signal power dropped to a 25 foot range. I challenge you to get into my network. Because you would have to park in my driveway to be close enough to get signal. And if you were in my driveway, I would shoot you. I live in Vermont, we are crazy bastards up here. And yes, it is legal to shoot trespassers.
Everyone should check out WiCrawl , a project that aims to do a very similar task. It is in alpha release at the moment and should be available to the public very soon. The applilcation aims to be the next step in wifi scanning.
You can find wicrawl here, its now publicly available:
http://midnightresearch.com/projects/wicrawl/
Actually it looks more like a Storm Case, http://www.stormcase.com/.
Nice box the guy built.
The thing is that it probably still couldn't break WPA2(AES)-PSK with a strong password or WPA2-Enterprise with something like EAP-TLS on a radius server, because he'd have to break the key, not just sniff out a few WEP packets. Eight radios makes it fast to sniff out packets but does not nessesarily mean he can crack a well configured WPA setup.
Maybe he could though...
I am DUMB, I wish I were that brilliant.
that's.....so bad ass.
*drool*