RE: How to track down a wireless hacker



Just examples of how calling the cops about a strange car packed outside has
nabbed people. Just something to consider in the big picture, nothing more.

--cg

-----Original Message-----
From: janheisterkamp@xxxxxx [mailto:janheisterkamp@xxxxxx]
Sent: Sunday, November 11, 2007 3:14 PM
To: ep
Cc: pen-test@xxxxxxxxxxxxxxxxx
Subject: Re: How to track down a wireless hacker

What tells me/us this reply?
ep schrieb:

http://www.dailywireless.org/2004/06/07/wifi-hacker-busted/
http://www.infoworld.com/article/07/08/23/London-man-arrested-for-stea
ling-W
i-Fi_1.html
http://www.theinquirer.net/en/inquirer/news/2006/03/24/wi-fi-user-fine
d-for-
battening-off-hotspit

http://www.infoworld.com/article/05/08/08/HNwifi_1.html?source=rss&url=http:
//www.infoworld.com/article/05/08/08/HNwifi_1.html

src
http://www.wardriving.com/




-----Original Message-----
From: janheisterkamp@xxxxxx [mailto:janheisterkamp@xxxxxx]
Sent: Sunday, November 11, 2007 5:55 AM
To: ep
Cc: 'Craig Wright'; pen-test@xxxxxxxxxxxxxxxxx
Subject: Re: How to track down a wireless hacker

I lost who started this thread.
Of course you can track a wireless attacker due the fact that he is
broadcasting a trackable signal and you can do it pretty accurate. But
he question behind is "And then?"

What will you do?
1.
If the attacker is in house you might have to close all the doors,
call the security stuff and confiscate all the laptops running
wireless. The attacker goes arested and the rest of the user will take
their case to the court, sueing you for damages.
2.
If the attacker is, let us say in a car in the street and you have
tracked and localized him what are you able to do?
You can't touch him, neither arrest him, you have no legal right to do
so; probably you will se the attackers golden finger he hits the road.

The energy you are wilt to afford to track this freak down you had
better spent before in securing your Network.
It's a fact, that you messed it up and not he.
I guess there is waiting some homework for you...

Regards
Jan









--
Grupo Ampersand S.A.
IT-Security Consultants & Auditors
Apdo. 924 Escazu 1250
Costa Rica C.A.
Phone: (506)588-0432
ceo_at_ampersanded.com [corp.]
janheisterkamp_at_web.de [priv.]




------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • [NT] Buffer Overrun in Windows Help and Support Center Could Lead to System Compromise (MS03-044)
    ... Get your security news from a reliable source. ... A security vulnerability exists in the Help and Support Center function ... *Microsoft Windows Millennium Edition ... An attacker could exploit the vulnerability by constructing a URL that, ...
    (Securiteam)
  • [UNIX] Security Analysis of VTun
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... An attacker can modify ... Packet forwarding: ... password) as encryption key. ...
    (Securiteam)
  • [REVS] Security Considerations for Web-based Applications
    ... Get your security news from a reliable source. ... consequences of this ranges from the erosion of customer confidence in the ... of poorly implemented host naming procedures or web-application URL ... The attacker may choose to inject ...
    (Securiteam)
  • [NT] Windows Media Player Directory Traversal Vulnerability (WMZ)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... When Media Player 7 or 8 is installed, ... As most other Internet Explorer vulnerabilities, ... cannot be guessed by a potential attacker. ...
    (Securiteam)
  • [NT] MHTML vulnerability in Outlook Express
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A vulnerability in Outlook Express allows an attacker to run code of the ... If an attacker were to host a malicious website that contained an MHTML ...
    (Securiteam)