Re: Re: Identification of non Cisco AP's

mox11_at_charter.net
Date: 07/27/05

  • Next message: Daniele Bellucci: "Some trouble with yersinia"
    To: Ian Gorrie <iag@locked.net>, Jonathan Gauntt <jon0966@yahoo.com>
    Date: Wed, 27 Jul 2005 17:37:15 -0400
    
    

    Here's a poor mans' fix

    Ping the broadcast address of your network.
    Most machines should reply.
    arp -an to determine MAC addresses or run PERL script (let me know if you need the code)
    The first 3 bits of the MAC will tell you the vendor
    http://standards.ieee.org/regauth/oui/index.shtml has most vendors available(OUI DB).
    I'd throw what you get into a database and filter everything but Cisco. Then run queries on the rest.
    There is a PERL script to automate some of this process if you like I'll post it.
    micro.
    >
    > From: Ian Gorrie <iag@locked.net>
    > Date: 2005/07/27 Wed AM 03:39:41 EDT
    > To: Jonathan Gauntt <jon0966@yahoo.com>
    > CC: security-management@securityfocus.com, pen-test@securityfocus.com
    > Subject: Re: Identification of non Cisco AP's
    >
    > On the wire detection is shoddy at best. Usually commercial scanners
    > will only detect default configurations.
    >
    > that being said, most products that I've looked at (such as Lumeta
    > IPSonar for instance) work by scanning for banners on webservers that
    > are running on the APs. If you use a product that scans 80 and 443 for
    > banners that match an APs, you might get somewhere.
    >
    > Not running an obvious banner, disabled, or not matching a signature?
    > You'll be out of luck unless you are tricky and can somehow determine
    > that it is a packet forwarding device.
    >
    > 802.11x on the network doesn't sound like such a bad idea now, does it? :)
    >
    > -i
    >
    > Jonathan Gauntt wrote:
    > > Hi,
    > >
    > > I have been tasked with the project of scanning and identifying all
    > > non Cisco wireless access points within the company?s network.
    > >
    > > We have about 800 /22 and /24 subnets, and because of the IP
    > > addressing scheme in place, might just be easier for me to scan the
    > > whole class A range of IP?s.
    > >
    > > I have access to Nessus and GFI Security Scanner. Since we over 8000
    > > IP?s in place, does anyone have any advice on the best way to
    > > identify these non Cisco AP?s such as Linksys and Netgear, etc.
    > >
    > > I wouldn?t want to have a report produced that is two miles long
    > > unless absolutely necessary.
    > >
    > > Thanks,
    > >
    > >
    > > Jonathan
    > >
    > >
    > >
    > >
    >


  • Next message: Daniele Bellucci: "Some trouble with yersinia"

    Relevant Pages

    • TidBITS#794/29-Aug-05
      ... This week's issue brings a potpourri of Mac news, ... Mark Anbinder looks briefly at Google Talk, ... Adding Tiger's AirPort Preferred Network List ...
      (comp.sys.mac.digest)
    • Apples new software may steal the show
      ... Steve Jobs, Apple Computer's co-founder and performer in chief, rarely shows any reluctance to sell -- or even over-sell -- his company's accomplishments. ... Jobs spent only about five minutes talking about what I see as the big news of the day: Apple's first software for using a home network through a television screen rather than a computer monitor. ... Apple's Mac OS X, the software running all its Macintosh computers, also has built-in features for easily connecting Macs in a network. ...
      (comp.sys.mac.advocacy)
    • Re: Wired security improvements
      ... I have a lot of experience with 802.1x in a wireless environment and it ... option than MAC Authentication via RADIUS as far as security is concerned, ... it can only provide a weak form of network authentication. ...
      (Security-Basics)
    • Re: OK first real Mac Complaint - Network Trouble
      ... changing the channel on my router has cleared up wireless issues on my ... have to reset it when the connection dies. ... to suck up a large amount of network bandwidth to do unnecessary screen ... It should at least help to identify what the Mac ...
      (comp.sys.mac.misc)
    • Re: About War Driving ..
      ... However, MAC filtering does not qualify as defense in depth, ... because the attacker can spoof a valid IP address. ... broadcasting the SSID doesn't hide a network, but just makes it show up ... machines in your building that you can control and check the MAC ...
      (Security-Basics)