mirror of
https://github.com/jokob-sk/NetAlertX.git
synced 2026-10-02 02:35:05 -04:00
DOCS: skill updates, WIFICANARY updates
This commit is contained in:
1 parent
591b1fadbe
commit
28eced2a25
9 files changed
+27
-9
No files matched your search
@@ -21,17 +21,24 @@ Runs a periodic passive WiFi scan (`iw scan`, no monitor mode) and flags rogue A
|
||||
|
||||
- Vendor names for a rogue device do show up in the GUI, but not from this plugin - a `Devices` row it creates gets its `Vendor` field filled in by core's own `VNDRPDT` (vendor_update) plugin on its next run, same as any other device. That lookup is a local OUI-database match, not a network call, so it's deliberately kept out of the scan step itself.
|
||||
- The duplicate-SSID/different-vendor check only looks at SSIDs you've listed in `WIFICANARY_trusted_aps` - an untracked network's own AP diversity (e.g. a cafe chain) is never flagged. For a tracked SSID, every explicitly-trusted BSSID's OUI is whitelisted (see the range-extender note above) - only an OUI that matches *none* of them gets flagged. "Vendor" here means OUI (BSSID's first 3 octets) compared directly between the APs sharing an SSID, not a vendor-name lookup.
|
||||
- `WIFICANARY_TRUSTED_SECURITY` is multi-select. An observed encryption exactly matching any selected value is always accepted; otherwise it's flagged if it's weaker than the *strongest* value you selected - deliberately, not a typo: comparing against the weakest would make selecting more than one value pointless (anything at or above the weakest would silently pass either way, making the rest of the selection meaningless). Worked example for `wep` + `wpa2` selected:
|
||||
- `WIFICANARY_TRUSTED_SECURITY` is multi-select. An observed encryption exactly matching any selected value is always accepted; otherwise it's flagged if it's weaker than the *strongest* value you selected - deliberately, not a typo: comparing against the weakest would make selecting more than one value pointless (anything at or above the weakest would silently pass either way, making the rest of the selection meaningless).
|
||||
|
||||
| Observed | Result |
|
||||
|---|---|
|
||||
| `wep` | OK (listed) |
|
||||
| `wpa2` | OK (listed) |
|
||||
| `wpa` | **Alert** - not listed, and weaker than `wpa2` |
|
||||
| `open` | **Alert** - weaker than everything |
|
||||
Worked example for `wep` + `wpa2` selected:
|
||||
|
||||
| Observed | Result |
|
||||
|---|---|
|
||||
| `wep` | OK (listed) |
|
||||
| `wpa2` | OK (listed) |
|
||||
| `wpa` | **Alert** - not listed, and weaker than `wpa2` |
|
||||
| `open` | **Alert** - weaker than everything |
|
||||
|
||||
Select `open` here only for a network you intend to run unencrypted on purpose (e.g. a guest SSID) - otherwise leave it out so an unexpected open clone or downgrade still trips an alert.
|
||||
|
||||
Select `open` here only for a network you intend to run unencrypted on purpose (e.g. a guest SSID) - otherwise leave it out so an unexpected open clone or downgrade still trips an alert.
|
||||
- Encryption is classified from the `iw scan` IEs into `open` / `wep` / `wpa` / `wpa2` / `wpa3`. A `Privacy`-flagged AP with neither an `RSN` nor a `WPA` information element is reported as `wep` - the closest reasonable guess for that combination, not a certainty.
|
||||
- See the [WIFICANARY addendum on issue #1789](https://github.com/netalertx/NetAlertX/issues/1789#issuecomment-5777023835) for the reasoning behind creating a device for never-associated attacker BSSIDs, and for the "known device turned rogue" idea. The implemented version above only covers the BSSID-identity angle (is the radio itself a device you already trust?) - the addendum's original, richer version (cross-referencing the *source MAC of attack traffic* like deauth/probe floods) still needs monitor-mode data this plugin doesn't have.
|
||||
|
||||
- Author: `mauricio-camayo`
|
||||
## Other info
|
||||
|
||||
- Version: 1.0.0
|
||||
- Author: [mauricio-camayo](https://github.com/mauricio-camayo/)
|
||||
- Release Date: `2026-09-26`
|
||||
Reference in new issue
Block a user