Arsenale · Wireless & IoT
WiFi, Bluetooth, RFID/NFC, radio (SDR) e dispositivi IoT. Tutorial WiFi: WiFi Cracking.
Trasmettere/interferire su frequenze o reti altrui è illegale. Usa la tua rete, hardware di test, o range/lab autorizzati.
WiFi (802.11)
| Tecnica | Come funziona | Tool / comando |
| Monitor mode + discovery | Ascolta reti e client vicini | airodump-ng |
| Channel hopping | Scansiona tutti i canali | airodump auto |
| Deauthentication attack | Disconnette i client (DoS o per handshake) | aireplay-ng --deauth |
| WPA/WPA2 handshake capture | Cattura il 4-way handshake | airodump-ng -w |
| WPA2 offline crack | Cracki l'handshake con wordlist | aircrack-ng/hashcat -m 22000 |
| PMKID attack | Cattura senza client, dal solo AP | hcxdumptool |
| WPS PIN brute (online) | Indovina il PIN WPS | reaver |
| WPS Pixie Dust (offline) | Rompe WPS sfruttando entropia debole | bully/reaver |
| WPS null PIN | Alcuni AP accettano PIN vuoto | reaver |
| Evil Twin AP | AP gemello per far connettere le vittime | airgeddon · hostapd |
| Captive portal phishing | Portale falso ruba la password WiFi | wifiphisher |
| Karma/known beacon | Rispondi alle probe request dei client | mana-toolkit |
| WEP cracking | IV deboli → chiave (reti legacy) | aircrack-ng |
| WEP fake auth / ARP replay | Genera traffico per raccogliere IV | aireplay-ng |
| WPA3 downgrade/Dragonblood | Forza fallback o sfrutta SAE debole | PoC |
| KRACK (WPA2 handshake) | Reinstallazione chiave nonce | PoC |
| 802.1X/EAP attacks | Cattura/relay credenziali enterprise | eaphammer |
| PEAP relay / GTC downgrade | Ruba credenziali enterprise | eaphammer |
| Beacon flooding | Spam di SSID falsi | mdk4 |
| Auth/assoc flood (DoS) | Sovraccarica l'AP | mdk4 |
| Client deauth flood (DoS) | Nega servizio a tutta la rete | mdk4 d |
| Hidden SSID reveal | Deduci l'SSID nascosto dalle probe | airodump |
| MAC filter bypass | Cloni un MAC autorizzato | macchanger |
| Rogue AP detection bypass | MAC/SSID clone per sembrare legittimo | hostapd |
| Probe request tracking | Traccia dispositivi dai probe | probemon |
Bluetooth / BLE
| Tecnica | Come funziona | Tool / comando |
| Device discovery | Scopre dispositivi BT/BLE vicini | hcitool · bluetoothctl |
| BLE enumeration | Servizi/caratteristiche GATT | gatttool · bettercap |
| BLE sniffing | Cattura pacchetti BLE | Ubertooth · nRF sniffer |
| BLE replay/write | Riinvii comandi a caratteristiche scrivibili | gatttool |
| Bluejacking | Invio messaggi non richiesti | legacy |
| Bluesnarfing | Furto dati via OBEX su BT vulnerabili | legacy |
| Bluebugging | Controllo del dispositivo BT | legacy |
| KNOB attack | Forza chiave di cifratura BT corta | PoC |
| BIAS attack | Impersonation nel pairing BT | PoC |
| BLE pairing MITM | Intercetti il pairing debole | btlejack |
| BlueBorne | RCE via stack Bluetooth vulnerabile | PoC |
RFID / NFC
| Tecnica | Come funziona | Tool / comando |
| Card cloning (LF 125kHz) | Copia badge di prossimità | Proxmark3 |
| MIFARE Classic crack | Rompe le chiavi (nested/darkside) | mfoc · mfcuk |
| MIFARE default keys | Prova chiavi note | mfclassic |
| NFC read/emulate | Leggi/emuli tag NFC | libnfc · Flipper Zero |
| Relay attack (contactless) | Estendi il raggio tra carta e lettore | hardware relay |
| Badge replay | Riinvii il codice di un badge letto | Proxmark3 |
| HID Prox cloning | Clona badge HID aziendali | Proxmark3 |
| NFC payment analysis | Studio protocolli EMV contactless | — |
Radio / SDR
| Tecnica | Come funziona | Tool / comando |
| Spectrum analysis | Osservi/identifichi segnali radio | gqrx · SDR# |
| Capture & replay (433/315MHz) | Registri e ritrasmetti comandi (telecomandi) | rtl_433 · HackRF |
| Rolling code analysis | Studio codici rolling (auto/garage) | SDR |
| RollJam-style (teoria) | Cattura+blocca+replay di rolling code | — |
| GPS spoofing | Segnali GPS falsi ingannano la posizione | HackRF + gps-sdr-sim |
| ADS-B/AIS analysis | Decodifica traffico aereo/navale | dump1090 |
| Pager (POCSAG) decode | Decodifica messaggi cercapersone | multimon-ng |
| Jamming (illegale) | Disturbo di frequenza — solo teoria/lab schermato | — |
| Zigbee attacks | Sniff/replay reti domotiche | KillerBee |
| Z-Wave analysis | Studio rete Z-Wave | Z-Wave sniffer |
| LoRa/LoRaWAN analysis | Sniff/replay reti LoRa | SDR |
IoT / embedded
| Tecnica | Come funziona | Tool / comando |
| Firmware extraction | Estrai e analizzi il firmware | binwalk |
| Firmware analysis | Cerchi credenziali/backdoor nel FS | firmwalker |
| Firmware emulation | Esegui il firmware per testarlo | firmadyne · QEMU |
| UART/serial console | Accesso console via pin seriali | USB-TTL · screen |
| JTAG debugging | Dump/controllo a basso livello | OpenOCD |
| SPI flash dump | Leggi la memoria flash direttamente | flashrom · clip |
| I2C/glitching | Fault injection sull'hardware | ChipWhisperer |
| Default/hardcoded creds | Password di fabbrica note | liste |
| Telnet/UPnP esposti | Servizi insicuri di default | nmap |
| MQTT abuse | Broker senza auth: leggi/pubblica topic | mosquitto_sub |
| CoAP abuse | Protocollo IoT senza auth | coap-client |
| Camera/DVR exploit | CVE note su webcam/DVR | searchsploit |
| Router web exploit | Command injection nei pannelli router | manuale |
| Smart home hub abuse | API locali non autenticate | manuale |