RE: MORE: Tools for Detecting Wireless APs - from the wire side.

From: R. DuFresne (dufresne@sysinfo.com)
Date: 06/13/02


Date: Wed, 12 Jun 2002 23:13:14 -0400 (EDT)
From: "R. DuFresne" <dufresne@sysinfo.com>
To: John Adams <jadams@inktomi.com>

On Tue, 11 Jun 2002, John Adams wrote:

> On Tue, 11 Jun 2002, ed d wrote:
>
> > depending on how the clients in your network get their ip addresses, you
> > might be able to search through your dhcp logs and pull all of the ap mac
> > addresses.
> >
> > this discounts rogue aps with statics, but if i was to drop a rogue ap into
> > a network, i would probably turn on dhcp, then let it go.
>
> Ahh, but this is useless if the AP DHCPs an address and then NATs everyone
> on wireless.
>
> > a good site for mac address/vendor coorelation is:
> > http://standards.ieee.org/regauth/oui/oui.txt
>
> I disagree with the entire "find them by Vendor MAC prefix to find APs"
> approach. Many vendors are assigned blocks of MAC prefixes (look at Cisco,
> for example) and share these blocks between disparate devices, both wired
> and wireless.
>

Actually, I believe they are assigned a number of MAC blocks over time,
thus a search of 3Com MAC's should produce a number of MAC blocks.

http://www.codito.de/manufactor_hash

http://coffer.com/mac_find/

   00068C 3Com Corporation
   000A04 3Com Europe Ltd
   00104B 3com corporation
   00105A 3com corporation
   0020AF 3COM Corporation
   00301E 3COM Europe Ltd.
   005004 3COM CORPORATION
   005099 3com europe, ltd.
   0050DA 3COM CORPORATION
   006008 3com corporation
   00608C 3Com (1990 onwards)
   006097 3Com
   009004 3com europe ltd.
   00A024 3com Corporation
   00D096 3com Europe Ltd.
   00D0D8 3Com Corporation (was: Nomadic Technologies)
   026060 3COM
   02608C 3COM IBM PC; Imagen; Valid; Cisco; Macintosh; Apple
   02C08C 3com corporation
   080002 Bridge (was: 3Com)
   08004E 3com europe ltd.
   3C0000 3Com dual function (V.34 modem + Ethernet) card

Thanks,

Ron DuFrense

-- 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        admin & senior security consultant:  sysinfo.com
                        http://sysinfo.com

"Cutting the space budget really restores my faith in humanity. It eliminates dreams, goals, and ideals and lets us get straight to the business of hate, debauchery, and self-annihilation." -- Johnny Hart

testing, only testing, and damn good at it too!

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • Re: the exploit that wasnt
    ... The other Mac Book Pro? ... brought Microsoft into a security discussion about Mac OS X. ... The number of security patches, ... if you were to scan random machines on the internet for a week, ...
    (comp.sys.mac.advocacy)
  • Re: 13 MASSIVE holes found in Safari...
    ... And yet Apple releases monthly security updates. ... But most malware use the normal http port, ... that it's OK because he's on a Mac and Macs are 100% safe). ...
    (comp.sys.mac.advocacy)
  • Re: The Myth of the secure Mac
    ... >> yes, it's in Tiger, perhaps you didn't read the Security Brief as you ... the real reason is they can't break a mac. ... Plug your Mac into Linux box acting as DHCP server ...
    (comp.sys.mac.advocacy)
  • Re: [Full-Disclosure] Anti-MS drivel
    ... News ... Apple released Security Update 2003-12-19 described to offer numerious ... Apple released 10.3.2 accessable via the software update pane in Mac OS X. ...
    (Full-Disclosure)
  • Re: Mac OS X hacked under 30 minutes
    ... a Swedish Mac fan posted a web site that challenged all ... updated it to Mac OS X 10.4.5 and fixed some security issues. ... As there was no cash prize associated with the contest, ... The hacker, known only as "gwerdna," explained what he ...
    (comp.sys.mac.advocacy)