Franck Veysset and Laurent Butti: Wi-Fi Advanced Stealth

Published: June 4, 2006, 11:10 p.m.

b'Wireless stealth was somewhat expensive some years ago as we were required to use proprietary radios and so on\\u2026 Thanks to increasingly flexible low-cost 802.11 chipsets we are now able to encode any MAC layer proprietary protocol over 2.4 GHz/5 GHz bands! This could mean stealth to everybody at low-cost!\\n\\t\\n\\tThis presentation will focus on two techniques to achieve a good level of stealth:\\n\\t\\n\\t * a userland technique exploiting a covert channel over valid 802.11 frames;\\n\\t * a driverland technique exploiting some 802.11 protocol tweaks. \\n\\t\\n\\tThese techniques are somewhat weird! That\\u2019s one reason they resist the action of scanners and wireless IDS!\\n\\t\\n\\tThe tools that will be released are proof-of-concepts and may be improved both in terms of features and code cleanups!"'