![]() |
|
|
#1 (permalink) |
|
Registered Member
Join Date: Aug 2006
Posts: 5
|
Security ?
Here is my setup...
Cisco 350 AP Windows 2003 AD Domain All wireless devices must authenticate using WEP and be authenticated against AD using P-eap. I have setup my certificate authority on the AD Domain, DHCP is running, the clients that need wireless access are in a security group on the domain and have dial-in permission. The authenticated clients are not the problem... my problem is someone outside of my network is trying to gain access, of course they can't so far because they need a cert., group membership, dial-in access... I have their mac address, what other kind of information can I get from this device and how would I do that? Basically I am trying to get information on a rouge client. Does this make sense? Any thoughts, ideas or suggestions would greatly be appreciated. Thanks, Paul |
|
|
|
|
|
#2 (permalink) |
|
Psychic Amish Stumbler
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,239
|
AirSnare or Airsnort will both gather more information about what that particular Luser is attempting against your system.
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary. |
|
|
|
|
|
#3 (permalink) |
|
Alien Paranoid Stumbler
Join Date: May 2003
Location: WI
Posts: 2,688
|
A 12 gauge is usually a pretty good deterrent. Wakes up the sleepers in the cubicle next to you pretty well also.
__________________
"Yeah," said a voice from under the table, "you go to pieces so fast people get hit by the shrapnel." |
|
|
|
|
|
#5 (permalink) |
|
Psychic Amish Stumbler
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,239
|
Keep in mind, that during your investigation you may find it's just a machine that's just trying to connect, because someone attempted it once and it may not actualy be a real attempt.
Have you checked your logs to show that they're actually trying to authenticate agains your AD? If they've gotten that far, then they've already cracked your WEP.
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary. |
|
|
|
|
|
#7 (permalink) | |
|
Psychic Amish Stumbler
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,239
|
Quote:
And you've checked the MAC against the list of MAC's that are actually allowed on your network, so that it isn't a machine that can't connect because someone erased the WEP key? After all, a good Network Admin knows the MAC's of every single device that's allowed to be on the network.
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary. |
|
|
|
|
|
|
#9 (permalink) | |
|
Psychic Amish Stumbler
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,239
|
Quote:
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary. |
|
|
|
|
|
|
#12 (permalink) | |
|
Psychic Amish Stumbler
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,239
|
Quote:
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary. |
|
|
|
|
|
|
#13 (permalink) | |
|
Free Public Wifi
Join Date: Aug 2003
Posts: 4,992
|
Quote:
__________________
┌──────────────────────────────┐ ╞ NS Icons Explained|et hoc genus omne ╡ └──────────────────────────────┘ Creating yesterday's future, Today! |
|
|
|
|
|
|
#14 (permalink) | |
|
Psychic Amish Stumbler
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,239
|
Quote:
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary. |
|
|
|
|
|
|
#15 (permalink) | |
|
Registered User
Join Date: Oct 2004
Posts: 98
|
Quote:
|
|
|
|
|