Re: Wired detection of rogue access points



johnnywkm@xxxxxxxxx wrote:
Can anyone point me to a wired LAN scanner/sniffer that detects wireless access points connected to the LAN?


I don't believe you can identify an AP just by sniffing. The problem is that AP acts as a L2 switch so there is not necessarily a signature.

The only way I can think of doing something like that is polling your switches (through SNMP) for connected MAC addresses and running a wireless sniffer like Kismet and cross referencing mac addresses that Kismet sees vs. what you see on your wired switches. That has been on my to-do list and I have a project that does switch polling for MAC addresses I just haven't added the Kismet portion yet :-(.

Vladimir

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more.
------------------------------------------------------------------------



Relevant Pages

  • RE: Exploit code for IP Smart Spoofing
    ... If there is a MAC violation, this is logged and the port is ... traffic of one other host on the switch. ... but there is no way to protect against ...
    (Bugtraq)
  • Re: Network scanning
    ... > level before the switch will enable that port... ... > new MAC and disable the port. ... >> informieren Sie bitte sofort den Absender und vernichten ... Wenn Sie nicht der richtige Adressat sind oder diese E-Mail irrtümlich ...
    (Security-Basics)
  • Re: Leopard market share???
    ... only), MacBook Pro C2Duo connecting wirelessly, Mac Pro directly connected to switch. ... Airport Extreme connected to switch and to cable modem. ... Ethernet configured automatically (If the MP is set to a large MTU it can no longer administer the Airport Extreme!) ... I have been working with networking for over 15 years. ...
    (comp.sys.mac.advocacy)
  • Re: Leopard market share???
    ... GreyCloud wrote: ... another Mac. ... Airport Extreme connected to switch and to ... I've been into networking since the early 80s. ...
    (comp.sys.mac.advocacy)
  • RE: Caching a sniffer
    ... I can think of at least four behaviors, each of which would give different ... Dump the entire MAC table. ... Switch acts as if power on reset just ... Shutdown port - assume hostile intent and stop forwarding traffic. ...
    (Security-Basics)