Re: Tool for Identifying Rogue Linksys Routers

From: Dave Hull (ireadit_at_gmail.com)
Date: 08/26/05

  • Next message: list_at_rem0te.com: "Sophos Antivirus Library Remote Heap Overflow"
    Date: Fri, 26 Aug 2005 14:29:11 -0500
    To: Martin Mkrtchian <dotsecure@gmail.com>
    
    

    If the Linksys devices are DHCP clients themselves, you might be able
    to use DHCPFingerprint to locate them when they renew their leases.

    You may want to contact the folks at http://www.packetfence.org. They
    may have a more comprehensive list of signatures.

    Also, nmap may work, see
    http://seclists.org/lists/nmap-dev/2003/Apr-Jun/0010.html for more
    details.

    Examining TTLs of packets coming from edge devices may also give you
    some indication of who's sitting behind an extra hop, though some
    folks may be savvy enough to tweak this on their workstations to avoid
    detection.

    Good luck.

    On 8/25/05, Martin Mkrtchian <dotsecure@gmail.com> wrote:
    > Dear Group Members
    >
    > We are migrating from Lucent QIP to MetaIP for DHCP services and so
    > far we have had two issues when MetaIP has been implemented for VLAN
    > that has an unauthorized Linksys router giving out IP addresses.
    >
    > Is there a scanning tool out there that can determine if there are
    > unauthorized Linksys (type) routers in a specific VLAN?
    >
    > Your input is appreciated
    >
    > Thank You
    >
    > Martin M
    > http://dotsecure.blogspot.com
    >

    -- 
    Dave Hull
    ireadit@gmail.com
    

  • Next message: list_at_rem0te.com: "Sophos Antivirus Library Remote Heap Overflow"

    Relevant Pages

    • Re: Prevent determined intrusion attacks ?
      ... The Linksys devices have a clean and efficient web interface that gives ... Linksys is a subsidiary of Cisco Systems, ... >>this further prevents connections as they will not be able to connect to ... $>whoami: Carl Holtje ...
      (comp.security.misc)
    • Re: Wireless setup help please
      ... > I am conecting to a Linksys 54G wireless router ... Now you can try asking the Linksys to allocate an ip address.... ... Two common DHCP clients are pump and dhclient. ... has dhclient installed but not pump. ...
      (comp.os.linux.hardware)
    • Re: Access points on wheels
      ... until I put Sveasoft Talisman firmware on them. ... Linksys is a completely different beast. ... When set up as a repeater, Aironet needs to associate with a root, and ... I can't use Linksys devices due to environmental and management ...
      (comp.dcom.sys.cisco)
    • Re: Linksys: IE only?
      ... Ken Dere wrote: ... > I have finally gotten a wireless network running that includes a Linksys ... > linksys devices is with Internet Explorer. ...
      (comp.os.linux.networking)