Stumble across rogue wireless access points

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS
The explosion of wireless technology into the hands of end users is one of the biggest challenges facing security officers and network administrators. With their transparent bridging, today's wireless access points are easy to set up, but they're even easier to misconfigure, leaving your network vulnerable to hackers. You need a way to detect any unauthorised wireless access points on your network. In this Daily Drill Down, I'll show you how to search for and identify rogue access points using NetStumbler on a laptop and the associated Pocket PC program MiniStumbler. I'll also show you how to map the results using a GPS receiver and a mapping program like MapPoint. Location mechanisms
There are two basic approaches for locating rogue access points: beaconing -- or requesting a beacon -- and network sniffing -- or looking for packets in the air. These methods use different features of the IEEE's 802.11b wireless standard as an exploit to discover weaknesses and access points on your network. Let's look at each in a little detail. Requesting a beacon
The IEEE's 802.11b standard is designed to enable a wireless device to see the SSIDs (Service Set Identifiers) used by nearby wireless access points. When the wireless device sees the SSID, it can configure itself to connect to the wireless network. To make this work, an 802.11b-compliant network card transmits a packet -- a beacon -- that causes all of the access points in the vicinity to announce their availability. This is an effective method because it doesn't require any current traffic. The problem with this mechanism is that the access point must be configured to respond to these beacon requests. Most "enterprise class" access points let you turn this setting off. Because of this, the beaconing mechanism isn't completely effective at finding all wireless access points. However, some users may not be aware that they should disable this feature when they deploy their wireless access points. Likewise, inexpensive wireless access points intended for home use don't normally allow you to disable the beaconing mechanism. Unfortunately, because they're inexpensive, they are the type of device most likely to be smuggled in and connected to your network without your knowledge. Sniffing the air
"Sniffing" is another mechanism for detecting a wireless network's presence. It involves turning on the receiver on the wireless card and allowing the receiver to passively capture packets out of the air. When the receiver finds information that looks like a packet, it can record the information, allowing the hacker to deconstruct the packets. Using the deconstructed information, the hacker can find a way to access your network. The problem with the sniffing mechanism is that currently you must select a specific channel to monitor. Given that 802.11b can operate on 12 channels, it's difficult to constantly switch between channels to monitor packets. So it's technically feasible to detect an access point by sniffing traffic, but it's impractical at present. Another problem with sniffing is that there must be traffic on the network for this method to work. If no one is using the rogue access point, there's no traffic to monitor. The access point could be right next to you, but if it's not in use, your monitor will never find it. Beyond these limitations, sniffing wireless packets is a useful way to determine who's using the wireless access point after it's been identified. The process used by NetStumbler and MiniStumbler, requesting beacons, will return the channel information that you can use later to sniff the network. The biggest threat
For the purposes of this article, I'll focus on requesting that the access point transmit a beacon frame. You can use this method whether or not there is active traffic on the network. This means you can make your sweep through a building or a campus during a weekend, when users of rogue access points are less likely to be present. Intruders are likely to use this same method because it lets them look for access points when no one is around. So requesting beacons gives you the added benefit of evaluating your network's security using the same tactics as a potential attacker. Choose your weapon
Two very useful tools for finding rogue wireless access points are NetStumbler and MiniStumbler. To run NetStumbler, you'll need at least a notebook and a wireless LAN card that the software supports. There's a list of supported cards available at the NetStumbler Web site. You'll also need a GPS capable of connecting to the notebook if you want to log and map your results. Alternatively, you can run a smaller version of NetStumbler called MiniStumbler. MiniStumbler runs on a Microsoft Pocket PC device, such as the Compaq iPAQ. All you need is a Pocket PC device and a wireless LAN card that is supported by MiniStumbler. As with NetStumbler, if you want to log the signal's location, you'll need a GPS that you can connect to your Pocket PC. MiniStumbler is much more useful than NetStumbler for zooming in on rogue access points. Because a Pocket PC can fit in the palm of your hand, it has a natural advantage over a bulky notebook. You can use the signal strength displayed on the Pocket PC, just like a minesweeper might use a metal detector, to home in on rogue ports.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

45 minutes ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

8 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

10 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

10 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

12 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

12 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

13 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

14 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

14 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

15 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

15 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

15 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

15 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

15 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

18 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

20 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

20 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

21 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

22 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule