Re: Tool for Identifying Rogue Linksys Routers

From: Mike Kershaw (dragorn_at_kismetwireless.net)
Date: 08/27/05

  • Next message: Mandriva Security Team: "MDKSA-2005:153 - Updated gnumeric packages fix integer overflow vulnerability"
    Date: Fri, 26 Aug 2005 19:37:48 -0400
    To: bugtraq@securityfocus.com
    
    
    

    > > Is there a scanning tool out there that can determine if there are
    > > unauthorized Linksys (type) routers in a specific VLAN?
    >
    > Try pinging all hosts using nmap:
    >
    > Then find MAC addresses that are from Linksys's space. I know macchanger
    > [1] has a list of what addresses belong to which vendors.

    Except, of course, that most Linksys units allow mac cloning through the
    web interface.

    This won't find anyone who is deliberately avoiding the scan, nor anyone
    who messed with the config out of boredom.

    -m

    -- 
    Mike Kershaw/Dragorn <dragorn@kismetwireless.net>
    GPG Fingerprint: 3546 89DF 3C9D ED80 3381  A661 D7B2 8822 738B BDB1
    Bus Error at 008BE426 while reading byte from DEADBEEF in User data space
    
    



  • Next message: Mandriva Security Team: "MDKSA-2005:153 - Updated gnumeric packages fix integer overflow vulnerability"

    Relevant Pages

    • Re: Tracing computers via AOL?
      ... > of the laptop, ... the CPU serial number enabled in their BIOS? ... The MAC probably cannot be seen past the user's intranet so it probably ... but that's only for hosts on my intranet. ...
      (alt.computer.security)
    • Re: Any reasons to filter ARP packets?
      ... this means other hosts do have ... a way to get to know the MAC address of my network device, ... I've been observing further how these settings influence operation and ...
      (comp.os.linux.security)
    • Re: Huge Arp Cache - Neighbour Table Overflow on IPCOP
      ... An ARP cache that huge is ludicrous. ... to "translate" MAC addresses to IPs at the 'link' level. ... (Requirements for Internet Hosts - Communication Layers) ... the presence of "remote internet-hosts" in the ARP cache might be ...
      (comp.security.firewalls)
    • Re: strange routing problem
      ... invisible to either the router or the Mac. ... 1122 Requirements for Internet Hosts - Communication Layers. ... Section 2.3.2 requires unused ARP entries to time out, ... The Mac has 10.0.0.200 manually set. ...
      (comp.os.linux.networking)
    • Re: Accessing NFS from OS X. Was: NFS how to
      ... >>with Unix underneath these days NFS should work better on Mac OS X ... While to a user Mac OS X appears to be Unix, to an Administrator, there are ... # nidump hosts> hosts.txt ...
      (comp.os.vms)