[TOOL] Hotspotter - a Wireless Honeypot

From: SecuriTeam (support_at_securiteam.com)
Date: 10/04/04

  • Next message: SecuriTeam: "[NEWS] Znif PLS Buffer Overflow"
    To: list@securiteam.com
    Date: 4 Oct 2004 15:45:44 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Hotspotter - a Wireless Honeypot
    ------------------------------------------------------------------------

    SUMMARY

    DETAILS

    Hotspotter passively monitors the network for probe request frames to
    identify the preferred networks of Windows XP clients, and will compare it
    to a supplied list of common hotspot network names. If the probed network
    name matches a common hotspot name, Hotspotter will act as an access point
    to allow the client to authenticate and associate. Once associated,
    Hotspotter can be configured to run a command, possibly a script to kick
    off a DHCP daemon and other scanning against the new victim.

    ADDITIONAL INFORMATION

    The information has been provided by Max Moser, Joshua Wright.
    The original article can be found at:
    <http://www.remote-exploit.org/?page=hotspotter>
    http://www.remote-exploit.org/?page=hotspotter

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NEWS] Znif PLS Buffer Overflow"

    Relevant Pages

    • [TOOL] Network Utilities from Bindshell
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... * massresolve - This program performs reverse dns lookups for network ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [TOOL] N-View - Network Monitor
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... N-View is a network monitor for small and medium-sized networks. ... ICMP responses from all hosts, signaling of timeouts and delays in the GUI ... o graphic display of traffic load for selected network interfaces, ...
      (Securiteam)
    • [REVS] Remote Rogue Network Detection
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Remote Rogue Network Detection ... The techniques listed in this document will not be able to find all rogue ...
      (Securiteam)
    • [REVS] GPRS Wireless Security: Not Ready For Prime Time
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Mobile GPRS devices contain built-in support for Internet Protocol ... Network operators installing next generation equipment often ...
      (Securiteam)
    • [NEWS] Check Point VPN-1 ASN.1 Decoding Remote Compromise
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... "an integrated VPN-1 and FireWall-1 gateway, offers management capability, ... Internet while securing critical network resources against unauthorized ... it is possible for an attacker to trigger a buffer overflow ...
      (Securiteam)