Re: Wireless Honeypots
So in the context of the original message at
http://www.incident-response.org/WISE.htm
honeypot=sniffer=nothing new.
As opposed to honeypot=tarpit=still nothing new.
Seems to me that placing the WAP in front of an authentication firewall server would go a long way toward letting authenticated clients in and keeping unauthenticated clients out.
Wep the Wap (oh, Wep me baby! wep it good...) at the hardware level, add an encrypted tunnel at the software level and it seems to me that you've layered yourself a reasonably secure solution without needing to worry if your AP is being hijacked or not.
(or am I oversimplifying?)
Cheers,
Mo