Security Basics mailing list archives

Re: About War Driving ..


From: Paul daSilva <pdasilva () polr org>
Date: Mon, 04 Dec 2006 10:54:51 -0500

Gaurav,

First, I recommend that you implement more security on your WLAN. All comments previously provided on this topic are valid options. Personally, the most logical option is an upgrade to WPA/WPA2, which will make it more difficult to crack (though not impossible). But that assumes all wireless end-points on your network are WPA capable.

Second, try Googling "Wireless Positioning" - there are various products available that will cater to this need. However, I only recommend this route if you have the budget to spend, and if you are chasing an intruder for legal reasons. Otherwise, it's more or less impractical - you are better served by securing your network and perhaps taking a few calculated walks around the building (looking for suspicious laptop users in cars, closets, etc).

You may have a rogue access point enabled within proximity to your wireless network. In which case, I recommend you perform a test "war drive" of the immediate area, eliminating known/good access points and investigating the remainder.

Lastly, if your organization has the money to spend, I highly recommend some form of Wireless Intrusion Detection and/or Prevention (WIDS/WIPS), which will alert you when it finds rogue users and access points, along with any other breach attempts. You may even find "Wireless Positioning" and "WIDS or WIPS" in the same software product.

Some products that caught my eye:

http://www.navizon.com/
http://www.skyhookwireless.com/
http://www.ekahau.com/


Cheers,

Paul daSilva



gaurav saha wrote:
Hi , I was wondering if it is possible to locate and catch
a guy who is connecting to our wep wireless network
and downloading stuff from torrents and using up our
bandwidth .. I checked up with arp scan and found 2 unknown IPs 192.168.1.246 and 247 Is there anyway of locating the guy in a building of 7
floors and how to stop this ..I have tried changing
the Wep keys so . he is cracking the wep key.
Any Suggestion People ?
---gaurav


____________________________________________________________________________________
Do you Yahoo!?
Everyone is raving about the all-new Yahoo! Mail beta.
http://new.mail.yahoo.com


Current thread: