NetStumbler.org Forums

Go Back   NetStumbler.org Forums > NetStumbler Community > NetStumbler
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 09-09-2001   #1 (permalink)
 
Posts: n/a
This was mentioned off the cuff at defcon, just quering to see if its still true

there was discussion that when scanning with netstumbler, it is sending out a very static preamble message when trying to detect the AP beacon signals.

somthing like:

SCANNING WITH NETSTUMBLER VER x.x.x

it was said that those sniffing the air, could pick up this traffic when in vegas and know that someone was scanning with nestumbler in the area.


any of you guys that are sniffing activly onw, can you confirm this?

it was rumoured a russian hacker had removed this, and had thus 'stealthed' his netstumbler scanning exploits. However im thinkig you would have had to get the source to do this and since the source isnt known, how could it happen?


A keen admin could setup a wireless workstation to pick up these types of transmissions just to see how many drive by's they were having....

would prove to be quite interesting i think.
  Reply With Quote
Old 09-09-2001   #2 (permalink)
 
Posts: n/a
...

Couldn't you check or remove said text using a hex editor? Shouldn't be holy difficult to check for. I would do it, but I don't have a hex editor and well, I hate downloading sh*t.


Anyone else think it would be slick to have a 4 sale forum on here for people to trade hardware? I can imagine that there's gotta be a few elite antenna builders out there willing to trade their pringle cans for cash...
  Reply With Quote
Old 09-09-2001   #3 (permalink)
 
Posts: n/a
Not sure about the hex editor, that may be the clue!


as for the pringle cans for cash, funny you should mention that, i got a friend who has several.... he just doesnt stop bulding them!!

bring him a pringle can and in about 20 mins he'll have you a working antenna.

interesting note on that, i have the hyperlinktech 14db 3 foot enclosed yaggi antenna, and his lil pringle cans are about 70% as effective!! probably around 10db of gain on it!

amazing stuff really. and all under 10 bucks worth of supplies!
  Reply With Quote
Old 09-09-2001   #4 (permalink)
 
Posts: n/a
New portal.

That's way cool. I just registered wirelesstrader.net and I'm going to put a bulletin board on there for buying/selling/trading wireless equipment. I personally don't like having to scour all of the various boards searching for wireless equipment, would be nice if there was one place to go. I'll have the page up as soon as the registration goes through. I'll let you all know when that is. I'll put up a link in the hardware section too.
  Reply With Quote
Old 09-10-2001   #5 (permalink)
 
Posts: n/a
The source does not have to be known in ordre to remove the preamble, if a hex-editor doesn't work, sice or windbg might work also...

stou
  Reply With Quote
Old 09-10-2001   #6 (permalink)
 
Posts: n/a
Ok, ok.

I got off my lazy ass, downloaded a hex editor and didn't find any questionable scanning strings. So I don't believe that it sends out that string... Perhaps earlier revisions had that string, but .3 does not, from what I can tell.
  Reply With Quote
Old 09-11-2001   #7 (permalink)
 
Posts: n/a
Here's what you need to know about this

If you have version 0.3.22 or later, you can disable this feature by unchecking the "Options -> Get AP Names" menu item.

When NS is sending these packets out, it is hoping for a response from the AP. Version 0.3.22 only sends out a limited number of these, and doesn't bother on APs from manufacturers that are known not to work (eg Cisco).

I know those guys (they were German, not Russian, I heard) wanted to prove how l33t they were, but they never bothered to ask me about it. When I want to change how NS works, I don't have to use a disassembler and hex editor, so it takes me a lot less time :-)
  Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 02:34 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.