๐ก Hierarchy Wireless โ Hierarki Spektrum Nirkabel
Peta hierarki kemampuan wireless security dari level konsumen/off-the-shelf (WiFi rumah, BLE, NFC) hingga tactical-grade (SDR, IMSI catcher, satellite downlink). Pelengkap hierarchy-osint-rf yang fokus ke RF emission; catatan ini lebih luas: protokol nirkabel, attack surface, dan tooling.
Daftar Isi
- Sheet 1 โ Wireless Consumer / Off-the-Shelf
- Sheet 2 โ Wireless Pro / Pentester Standard
- Sheet 3 โ Wireless Tactical / SDR-Grade
- Plot Twist โ Tiga Vektor Lateral di Wireless Attack
- Koneksi ke Vault
Sheet 1 โ Wireless Consumer / Off-the-Shelf
Spektrum kemampuan yang umumnya tersedia tanpa clearance โ beli di toko, tidak butuh lisensi khusus. Cocok untuk homelab pentest, learning, audit internal SME.
| Level & Tools | Teknik & Sweet Spot | Tembok & Batasan | Use Case Nyata |
|---|---|---|---|
| Level 0 โ WiFi WPS & Default Password (aireplay-ng, Reaver, Wash, Wifite) | Serangan WPS PIN bruteforce di router yang belum patched. Reaver crack PIN router dalam 4-10 jam. | Mayoritas router modern disable WPS by default. Patch 2011 sudah adopted. | Mendeteksi router konsumen yang masih allow WPS (laporan audit internal) |
| Level 1 โ WPA2 Handshake Capture (aircrack-ng, hcxtools, hashcat) | Capture 4-way handshake dengan deauth, crack offline via hashcat + wordlist rockyou. GPU-accelerated. | WPA3 sudah menggantikan WPA2-Personal di pasar baru. PMKID attack masih mungkin di WPA2. | Audit password WiFi corporate yang masih lemah (wordlist-based) |
| Level 2 โ WPA3 Dragonblood & SAE Attacks (Dragonslayer, hostap-mt) | Exploit implementation flaw di WPA3-SAE. Timing side-channel di transition mode. Waktu patching bervariasi per vendor. | Mayoritas produksi modern sudah patched WPA3-SAE. Tinggal eksploitasi device lama. | Riset akademik, validasi apakah firmware router kantor punya CVE Dragonblood |
| Level 3 โ Evil Twin & Captive Portal (hostapd-mana, Wifiphisher, eaphammer) | Rogue AP dengan nama SSID mirip legitimate (e.g. Starbucks_Free di kafe). Capture creds atau push malware. | HTTPS HSTS + certificate pinning bisa mitigate captive portal MITM. User harus sadar untuk notice SSID aneh. | Pentest social engineering, demo security awareness |
| Level 4 โ Bluetooth Low Energy (BLE) & HID Injection (nRF Connect, gattacker, bleah) | Sniff & inject GATT characteristic di BLE peripheral. BadUSB via HID (mouse/keyboard spoofing) di BLE HID. | BLE 5+ randomized address mempersulit tracking permanen kecuali pair persistent. | Pentest IoT device, kontrol smart-lock/lampu paksa, BYOD keyboard injection |
| Level 5 โ NFC / RFID Cloning (proxmark3, ACR122U, libnfc) | Read UID dari Mifare Classic โ clone ke magic card. Read credit-card NFC (EMV) untuk research. | NFC payment terenkripsi (Apple Pay/Google Pay pakai tokenization โ tidak langsung expose PAN). | Riset access control kartu, audit badge karyawan, eksplorasi transit card |
| Level 6 โ Zigbee / Z-Wave IoT (Z-Stack sniff, Z3us, razbermon) | Sniff & replay Zigbee traffic. Eksploitasi pairing. Banyak smart-home device belum punya secure pairing. | Zigbee 3.0 dengan Touchlink/Install Code menambah barrier. Matter/Thread menyatukan layer. | Pentest smart-home, audit gedung otomatis (lighting, HVAC controller) |
Sheet 2 โ Wireless Pro / Pentester Standard
Tooling standar untuk pentester profesional. Umumnya butuh dedicated hardware USB dongle ($25-300). Tool ini juga dipakai red team enterprise.
| Level & Tools | Teknik & Sweet Spot | Tembok & Batasan | Use Case Nyata |
|---|---|---|---|
| Level 7 โ WiFi Enterprise (802.1X / EAP) (eaphammer, hostapd-wpe, wpa_supplicant_eap_peap_crack) | Evil twinๆปๅป 802.1X dengan negosiasi EAP ke weaker method (PEAP-MSCHAPv2 โ crack via asleap). RADIUS mis-config. | 802.1X dengan EAP-TLS + per-user cert membuat attack ini jauh lebih sulit. | Audit RADIUS-Server enterprise, validasi penerapan EAP-TLS |
| Level 8 โ 5G / LTE IMSI Catchers (Stingray-class) (IMSI-catcher, rayhunter) | Rogue base station yang memaksa handset turun ke 2G/3G (no mutual auth). Tangkap IMSI, TMSI, lokasi perangkat. Rate-limit enforcement di 4G/LTE. | Di 5G SA deployments, IMSI protection mandatory. Device juga ada IMSI-catcher detector (Android 12+). | Forensic saat ada indikasi targeted surveillance, riset 5G security posture |
| Level 9 โ Cellular Base-Station (BTS) Sandbox (OpenBTS, OsmoBTS, OsmoSGSN, OsmoMGW) | Bangun BTS sendiri (mini GSM/UMTS) dengan SDR. Asumsikan SIM Anda. Lihat handset Anda connect ke BTS rogue. | Regulasi telekomunikasi ketat (running BTS tanpa ijin = ilegal di mayoritas negara). Legal only in lab. | Lab riset cellular security, edukasi, simulasi cellular-protocol man-in-the-middle |
| Level 10 โ GPS Spoofing & Jamming (GPS-SDR-SIM, HackRF One) | Broadcast fake GPS signal yang membuat receiver berpikir di lokasi lain. Jamming dengan broad-spectrum noise (illegal civilian). | Anti-spoofing (Galileo OS-NMA, GPS M-code). Regulasi penggunaan frequency (ITU-R + local regulator). | Riset di GPS-equipped drone, autonomous vehicle di sandbox environment |
| Level 11 โ WiFi & BLE Continuous Monitor (Kismet, Wireshark+wifi, BearTrap) | 24/7 sensor detection rogue AP/Evil Twin di enterprise. Integration ke SIEM (Loki/Splunk). | False positive bisa tinggi di dense area (apartment buildings). Perlu tuning baseline. | SOC enterprise, monitoring gedung multi-tenant, audit compliance |
Sheet 3 โ Wireless Tactical / SDR-Grade
Spektrum research-grade / nation-state. Butuh SDR hardware (USRP, LimeSDR, HackRF) mulai 10k, ditambah technical expertise khusus. Banyak komponen ini.subject riset legal/akademik, atau dipakai oleh intelijen.
| Level & Tools | Teknik & Sweet Spot | Tembok & Batasan | Use Case Nyata |
|---|---|---|---|
| Level 12 โ Wide-Band SDR Capture (LimeSDR, USRP B200/B210, GNU Radio) | Capture full band (1 MHz โ 6 GHz) sekaligus. Decode protokol proprietary (LoRa, sub-GHz IoT). | Butuh storage besar (TB untuk capture panjang). Processing CPU/GPU heavy. | Reverse engineering IoT proprietary, riset waveform baru |
| Level 13 โ Protocol Reverse Engineering (Universal Radio Hacker, inspectrum, SigBerkeley swooping) | Capture demodulated baseband โ manual decode. Identifikasi preamble, sync, payload, CRC. Eliminasi layer proprietary. | Butuh waktu signifikan (minggu untuk protokol sederhana). Beberapa protokol pakai encryption โ tidak bisa decode tanpa key. | Riset IoT proprietary (smart-meter, industrial sensor), academic wireless research |
| Level 14 โ Satellite Downlink Intercept (SatNOGS, NOAA weather satellites, Inmarsat / Iridium) | Receive downlink sinyal dari LEO/MEO/GEO satellite. Decoder demodulator built atop open source. NOAA APT, LRPT, HRPT. | Regulasi ITU โ menerima downlink tidak selalu illegal, tapi decode & redistribute bisa. Bird-feed S-band butuh izin. | Meteorologi, maritim tracking, riset orbital |
| Level 15 โ RF Side-Channel & TEMPEST (TEMPEST font, Van Eck phreaking demo) | Capture EM emanation dari monitor/kabel (VGA, HDMI, USB). Rekonstruksi display dari sincangan EM yang tertangkap. | Sangat specialized: butuh shielded room, broadband antenna, software FFT dengan timing resolution ms. | Riset TEMPEST (akademik CS), validasi emanation compliance produk (perisai TEMPEST-level) |
| Level 16 โ Nation-State SIGINT & Quantum Cryptanalysis (XKEYSCORE, NSA ANT, GCHQ) โ close-source) | Tap ke fiber backbone / antenna farm (per xkeyscore). Kuantum computer untuk RSA/ECC. | Klasifikasi. Akses negara-bangsa. Quantum cryptanalysis butuh $100M+ infrastructure (Google Willow, IBM Heron). | Mass surveillance (legally regulated), cryptographic backdooring, foreign intelligence |
| Level 17 โ Quantum Radar & LPI / LPD (DARPA HRTI, Spread-spectrum, OFDM, chaotic) | Waveform dengan low probability of intercept/detect (LPI/LPD). Quantum illumination untuk deteksi stealth aircraft. | Sangat classified. Militer-only. Riset publik terlambat 5-15 tahun dari capability aktual. | Anti-stealth defense, electronic warfare kontra-emersi (limited Tier-1 country) |
Plot Twist โ Tiga Vektor Lateral di Wireless Attack
Yang jarang dibahas di literatur standar tapiๅฎๆ relevan:
Twist 1 โ Bluetooth Mesh Hijack via GATT Injection
Device A (sniffer, valid pair)
โ
โ BLE GATT read char_value
โผ
Device B (victim โ e.g. insulin pump, smart-lock)
โ
โ Inject update firmware via GATT
โผ
Command sent โ physical device compromised
Risk: banyak medical IoT (insulin pump, pacemaker legacy) tidak menggunakan secure pairing.
Twist 2 โ WiFi Deauth sebagai Smokescreen + Channel Switch Reconnaissance
Attacker sends 50 deauth/sec on ch 6
โ
โผ
Target AP trigger channel-switch announcement (CSA)
โ
โผ
Legitimate clients pindah ke ch 1 (attacker-controlled)
โ
โผ
Attacker inspect original ch 6 secara stealth
(exposes hidden SSID, paket management-only, dsb)
Advanced reconnaissance yang jarang ditangkep SOC tradisional. Lihat referensi: CSA Injection paper.
Twist 3 โ Hybrid Cellular + WiFi Handoff untuk Persistent C2
[Persistent command & control architecture]
โโ Cell 1 (Tower A) โ MikroTik disrupts โ fail-over โโ
โโ Cell 2 (Tower B) โ fallback via SIM#2 โโโโโโโโโโโโค
โโ WiFi captive portal (rogue AP) โ fallback โโโโโโโโโค
โโ LoRa 868 MHz ad-hoc mesh โ long-range fallback โโโ
Berlaku di APT-targeting: kalau adversary tahu target sering travel (konsuler, jurnalis), multi-channel C2 jadi resilient. Lihat apt-c2-infrastructure.
Koneksi ke Vault
Catatan Materi Wireless
- wireless-security-deepdive โ Deep dive sister untuk hierarchy ini
- hierarchy-osint-rf โ Hierarki OSINT & RF signal paralel
- hierarchy-search โ Hierarki informasi (surface โ Five Eyes SIGINT)
Hardware & Offense Tools
- imsi-catcher โ IMSI catcher hardware
- oscor โ OSOR spectrum analyzer (legal Intercept)
- hack5-suite โ Hak5 payload & implant ecosystem
- victoria-hdd โ Storage forensics
Defense & Detection
- blueteam-detection-matrix โ Detection matrix untuk rogue AP/Evil Twin
- covert-channel-encyclopedia โ Sub-GHz & UWB covert channel
- cgnat-attribution-deepdive โ Attribution pasca-WiFi-capture-correlation
- dns-tunneling-deepdive โ Covert exfil via RF-channel (LoRa, ISM)
SIGINT Lintas Domain
- siginter โ Siginter architecture
- upstream-and-tempora โ Upstream collection (NSA/CNE)
- xkeyscore โ Indexing tool dari Five Eyes partnership
- military-sigint-deepdive โ Military SIGINT mendalam
- siginter-quantum โ Quantum-based SIGINT (cryptographically relevant)
Catatan etika & hukum: Mayoritas Level โฅ 8 butuh lisensi regulator lokal (Kominfo di Indonesia, FCC di US, dst.). Jalankan hanya di lab terisolasi dengan spektrum analyzer untuk monitor unintentional emission. Lihat digital-privacy-anonymity & isp-surveillance-privacy-deepdive untuk konteks legal surveillance.