Security Basics mailing list archives
RE: Wireless blocking
From: "Beauford, Jason" <jbeauford () EightInOnePet com>
Date: Wed, 5 Oct 2005 15:16:23 -0400
My thought is that this Wireless device, MUST be pretty close to a
switch of some sort. I doubt Joe Hacker is going to try to run Cat5
cable througout your building. More likely he/she probably ran a short
store-bought cable behind a cabinet or in the ceiling directly above
some available cubicle port or switch. Once you connect to the device
via Netstumbler or Kismet, you can simply get its MAC address, then
(provided your switch is managed) look at the MAC table on your switch.
Identify the port and trace it or unplug it, or even better...leave it
in place, Tap the port and capture all the traffic going through the
wireless and ultimately your switch. This will give you a better idea
as to who is your insider hacker.
-JMB
| -----Original Message-----
| From: Tom Van de Wiele [mailto:tom.vandewiele () gmail com]
| Sent: Wednesday, October 05, 2005 12:30 PM
| To: Hayes, Ian
| Cc: security-basics () securityfocus com
| Subject: Re: Wireless blocking
|
| You could try and find out its location with kismet
| and judging from the signal strength more or less
| guess its location. Far from waterproof though,
| especially if you have large objects that might
| bounce the signal (like walls :). If you don't
| have something like airdefense/aruba you can use
| void11 or aircrack to send deauthentication frames
| to stop the rogue AP from interferring with your network.
|
| Tom
|
|
|
| On 10/5/05, Hayes, Ian <Ian.Hayes () wynnlasvegas com> wrote:
| > > -----Original Message-----
| > > From: Daryl Davis [mailto:daryl () ultbingo com]
| > > Sent: Tuesday, October 04, 2005 9:56 AM
| > > To: security-basics () securityfocus com
| > > Subject: Wireless blocking
| > >
| > > I believe I have an unauthorized wireless
| router on my network. I
| > have
| > > been
| > > unable to physically find it as of yet.
| > >
| > > Does anyone know how to find the hidden SSID
| and then Jam it?
| >
| > Hard to find the SSID until a device connects to
| it. Then something
| > like a laptop running Kismet or NetStumbler will
| reveal what the SSID
| > is. If you want to get fancy, an AirMagnet is a
| really neat tool and
| > you can find the rogue by following the signal strength.
| >
| > As for jamming, it's a bit more difficult to do.
| If you have an Aruba
| > or Airtight network, they would not only pick up
| the rogue and degrade
| > it to the point of uselessness, they can also
| give you a rough
| > indication of where the rogue is placed.
| >
| >
| >
| > Ian Hayes | Senior Systems Engineer
| > Wynn Las Vegas
| > 3131 South Las Vegas Blvd, Las Vegas, NV 89109 Ph
| (702) 770-3252 |
| > Cell (702) 266-6002 Ian.hayes () wynnlasvegas com
| >
| >
| >
|
Current thread:
- RE: Wireless blocking, (continued)
- RE: Wireless blocking Hayes, Ian (Oct 05)
- Re: Wireless blocking Tom Van de Wiele (Oct 05)
- Re: Wireless blocking xyberpix (Oct 06)
- Re: Wireless blocking Kevin white (Oct 06)
- RE: Wireless blocking Patton Roub (Oct 05)
- RE: Wireless blocking Charles Hammett (Oct 05)
- RE: Wireless blocking Bryan McAninch (Oct 05)
- Re: Wireless blocking lists (Oct 05)
- RE: Wireless blocking Joshua Berry (Oct 06)
- FW: Wireless blocking Charles Hammett (Oct 06)
- RE: Wireless blocking Beauford, Jason (Oct 06)
- Re: Wireless blocking Steve.Cummings (Oct 06)
- RE: Wireless blocking Steve McLaughlin (Oct 11)
- RE: Wireless blocking Dean De Beer (Oct 11)
- RE: Wireless blocking Gross Barry D. (Oct 11)
- Re: Wireless blocking Alex S. Harasic (Oct 11)
- Re: Wireless blocking Dragos Ruiu (Oct 12)
- Wireless Blocking Daryl Davis (Oct 14)
- RE: Wireless Blocking Alex S. Harasic (Oct 17)
- Wireless blocking Daryl Davis (Oct 24)
- RE: Wireless blocking Hayes, Ian (Oct 05)
