RE: How to track down a wireless hacker



Bah, I'm talking wan IP and service not Lan IP and service, thought I was
clear on that.

What we want is to track the cookie, this MIGHT lead to some mistakes on the
intruders part. Yes, the intruder/s will most likely use someone else's
internet drop to use those identifiable credentials, but what if it's a
internet café? A school library? Another victim? Not only is it fun and
educational to track this info, it's also a possible benefit for others.
Open up the door, give them a cookie and track it's use. Ummm, seems like
there's gonna be some feedback there eh? And bet I would give it a chance to
out weigh any given effort and time. Maybe we need more effort and time?

I have no idea of the resources of the original poster. Besides, the initial
investment is very small. The crux is the tracking of the cookie once it has
been snatched, at it's simplest it's monitoring a log file of the service.
Honestly, this is a small project. Initial setup is under one hour and
checking for the credential use in a log file is automated with a little
bash skill set.

Have fun,
cg




-----Original Message-----
From: Nicholas Chapel [mailto:nicholas.chapel@xxxxxxxxx]
Sent: Wednesday, November 07, 2007 1:42 PM
To: ep
Cc: jond; pen-test@xxxxxxxxxxxxxxxxx
Subject: Re: How to track down a wireless hacker

On 11/7/07, ep <captgoodnight@xxxxxxxxxxx> wrote:
So setup a duplicate of the previously vulnerable wireless
configuration and from a secure linux laptop (only thing on the
segment) simply every 15 minutes pass some unique clear text working
credentials to a internet facing service you can monitor, like a ftp
server or pop3 account. Wait for the connection/authentication and log
the ip, then get law enforcement and the what I think will be a local ISP
involved.

We are talking about wireless, right? Because in such a scenario, logging
the IP address won't make much of a difference since any IP that the
intruder has would be *one that your DHCP server leased to him*. There is
no ISP to involve here. Unless of course the intruder accesses the
FTP/POP3/whatever server from a different connection, in which case he may
very well be on someone *else's* WLAN and you'll end up expending a great
deal of effort and time (both yours and others') and be no closer to knowing
the identity of your malefactor than you were before.

Yeah, I think hoping that the intruder would be daft enough to access his
Hotmail account is about the best you can hope for here.

--Nick


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: error code 0x80072EFD
    ... [CallerId = AutomaticUpdates] ... cookie, reporting URL = ... the server with hr = 80072efd. ...
    (microsoft.public.windowsupdate)
  • Re: Login for access to certain pages or parts?
    ... I know roughly what an .htaccess file is and I have access to more than this on my own server, but not more on commercial servers that host various sites I have made or maintain. ... The successful login routine sets the cookie by testing to see if the password the user has entered matches the one in your database for that user. ... For pages that can be accessed by multiple groups, your authorize function could be passed a comma-delimited list of allowable groups for that page. ... // Authorizes user based on group, redirects if necessary. ...
    (alt.php)
  • Chicken and egg issue with Cookie based login?
    ... I have few questions I hope someone can clear up for me with the cookie ... private web server. ... It also says this about the secret key: ... Second, would be an example of the "Session ID" or more general, what is an ...
    (comp.security.misc)
  • RE: Proof of Concept Tool on Web Application Security
    ... You are misreading the script fragment that you quoted. ... What that is intended to do is fetch an image from a server under your own ... and reacting when it sees a new cookie. ... But this require interaction of victim, ...
    (Pen-Test)
  • Re: Getting 12209 error on isa when server tries to connect to cookie enabled site. Xp workstation w
    ... What leads you to a conclusion that this problem is an ISA server related? ... We try to access a certain site which sets cookies by sending cookie ... 2.The conclusion is that when Cookie header is sent from the server to ...
    (microsoft.public.isa)