![]() |
|
|||||||
| Register | Search | Today's Posts | Mark Forums Read |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
Registered Member
Join Date: May 2003
Location: UK
Posts: 91
|
Unauthorised AP Intrusion??
I've tried a search but couldn't find anything relating to my problem.
I have reason to believe that someone has hacked in to my AP although it's WEPd. I live in a residential area where I know there are 1 or 2 other wireless users and my AP is on the top floor with good coverage. Apart from, 1) reducing my area of coverage and 2) MAC addressing the AP, is there any hardware/software available that can scan/monitor if there are local 802.11b signals? I'm using a Senao 2511 CD+ card with a T-DSL 130 AP. Appreciate any help... |
|
|
|
|
|
#2 (permalink) | |
|
I amuse you?
Join Date: Dec 2003
Posts: 9,141
|
Quote:
Last edited by wrzwaldo : 05-23-2004 at 12:44 PM. |
|
|
|
|
|
|
#3 (permalink) |
|
Registered Member
Join Date: May 2003
Location: UK
Posts: 91
|
Absolutely perfect - many thanks. It works great and have found an unfriendly MAC address, so I'll continue to monitor.
I change my WEP about once a month but I understand that you only need a few minutes to hack the key if you have the right software?? Appreciate your help.... ![]() |
|
|
|
|
|
#4 (permalink) | |
|
Country Boy.
Join Date: Aug 2002
Location: Deep in the Woods.
Posts: 1,963
|
Quote:
__________________
audit Blackberry Outage Mail List. Be the one of first people to know about RIM outages. |
|
|
|
|
|
|
#5 (permalink) | |
|
Bad as Can
Join Date: Jul 2002
Posts: 1,141
|
Quote:
Or generating your key from a dictionary word.
__________________
perl -e 'print pack(c5, (41*2), sqrt(7056), (unpack(c,H)-2), oct(115), 10)' |
|
|
|
|
|
|
#6 (permalink) |
|
Tropical Stumbler
Join Date: Apr 2002
Posts: 575
|
My guess is that if you have someone with the know how to crack WEP, MAC filtering is not going to keep him out for long.
You need to be aware that AirSnare will also detect wired MACs - in fact - I picked up a couple of unknown MAC addresses on my network using both a wireless sniffer AND AirSnare that had me convinced I had an intrusion problem. I eventually tracked them down to multicast packets coming in through the DSL - the local telco had some misconfigured equipment. What led you to thinking that there was an intrusion? |
|
|
|
|
|
#7 (permalink) | |
|
PeaceDriver
Join Date: Apr 2002
Location: Dos Palabras, Mandoras
Posts: 2,920
|
Quote:
I'd suggest using a sniffer to determine what's going on. Are you worried someone is accessing your LAN or the internet? -edit- where in the UK are you at?
__________________
all good ends all ?u=273
|
|
|
|
|
|
|
#8 (permalink) | ||
|
Registered Member
Join Date: May 2003
Location: UK
Posts: 91
|
Quote:
Quote:
Last edited by mopsie : 05-24-2004 at 08:25 AM. |
||
|
|
|
|
|
#9 (permalink) | |
|
Did you do the math?
Join Date: Apr 2002
Location: Villa Straylight
Posts: 10,351
|
Quote:
__________________
Thorn "Read Altas Shrugged. Compare it to today. Repeat as necessary" |
|
|
|
|
|
|
#10 (permalink) | |
|
Registered Member
Join Date: May 2003
Location: UK
Posts: 91
|
Quote:
And I've just discovered from my ISP activity log that access started to occur at 3am this morning - I know where I was then and it wasn't anything to do with computers!! Any suggestions what to do next??..... |
|
|
|
|
|
|
#11 (permalink) |
|
Asshole Emeritus
Join Date: May 2003
Location: Goomba's Booty Boardwalk
Posts: 6,121
|
Try spoofing your own MAC's and see if the activity has stopped. Maybe someone grabbed one of your MAC's...just a thought.
__________________
"My mind is aglow with whirling, transient nodes of thought careening through a cosmic vapor of invention." Sons of Confederate Veterans |
|
|
|
|
|
#12 (permalink) | |
|
Tropical Stumbler
Join Date: Apr 2002
Posts: 575
|
Quote:
How much data did you transfer over the connection in the time span between changing the WEP key and the resumption of suspect activity? As Audit pointed out an intruder would need to capture a few Gb of data before cracking the key - I don't think that's normal in the space of a couple of hours with the typical residential network. Leave AirSnare running overnight with your AP disconnected and see if AirSnare detects anything. |
|
|
|
|
|
|
#14 (permalink) | |
|
Bad as Can
Join Date: Jul 2002
Posts: 1,141
|
Quote:
That is not entirely true. If you use a dictionary, or easily guessable word to auto-gen your WEP key, wepattack will crack it in about 15 mintues or less. I would change my key again and auto-gen using a combination of upper/lowercase letters, numbers, and special chars to generate the key. Then see if you still note the same activity.
__________________
perl -e 'print pack(c5, (41*2), sqrt(7056), (unpack(c,H)-2), oct(115), 10)' |
|
|
|
|
|
|
#15 (permalink) | |
|
Tropical Stumbler
Join Date: Apr 2002
Posts: 575
|
Quote:
|
|
|
|
|