[TOOL] Hotspotter - a Wireless Honeypot

From: SecuriTeam (support_at_securiteam.com)
Date: 10/04/04

  • Next message: SecuriTeam: "[NEWS] Znif PLS Buffer Overflow"
    To: list@securiteam.com
    Date: 4 Oct 2004 15:45:44 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Hotspotter - a Wireless Honeypot
    ------------------------------------------------------------------------

    SUMMARY

    DETAILS

    Hotspotter passively monitors the network for probe request frames to
    identify the preferred networks of Windows XP clients, and will compare it
    to a supplied list of common hotspot network names. If the probed network
    name matches a common hotspot name, Hotspotter will act as an access point
    to allow the client to authenticate and associate. Once associated,
    Hotspotter can be configured to run a command, possibly a script to kick
    off a DHCP daemon and other scanning against the new victim.

    ADDITIONAL INFORMATION

    The information has been provided by Max Moser, Joshua Wright.
    The original article can be found at:
    <http://www.remote-exploit.org/?page=hotspotter>
    http://www.remote-exploit.org/?page=hotspotter

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NEWS] Znif PLS Buffer Overflow"

    Relevant Pages