Open WLANs the early results of WarDriving. Peter Shipley

Similar documents
Wireless Attacks and Countermeasures

Lure10: Exploiting Windows Automatic Wireless Association Algorithm

Wireless LAN, WLAN Security, and VPN

Risks & Rewards of WiFi and WiMax

What is a Wireless LAN? The wireless telegraph is not difficult to understand. The ordinary telegraph is like a very long cat. You pull the tail in Ne

Wednesday, May 16, 2018

Digital Entertainment. Networking Made Easy

WPA SECURITY (Wi-Fi Protected Access) Presentation. Douglas Cheathem (csc Spring 2007)

ScreenBeam Wireless display over LAN

Wireless LAN Security (RM12/2002)

Wi-Net Window and Rogue Access Points

PRODUCT GUIDE Wireless Intrusion Prevention Systems

Wireless Network Defensive Strategies

Wireless Networking. Dennis Rex SCALE 3X

Outline : Wireless Networks Lecture 10: Management. Management and Control Services : Infrastructure Reminder.

Karthik Pinnamaneni COEN 150 Wireless Network Security Dr. Joan Holliday 5/21/03

Chapter 11: Networks

Complying with RBI Guidelines for Wi-Fi Vulnerabilities

What is Eavedropping?

Mobile Security Fall 2013

Wireless Security Protocol Analysis and Design. Artoré & Bizollon : Wireless Security Protocol Analysis and Design

Learn How to Configure EnGenius Wi-Fi Products for Popular Applications

Chapter 16: Advanced Security

Exam Questions CWSP-205

Install Your Own Wireless Network

Table of Contents 1 WLAN Service Configuration 1-1

Wireless 11n Smart Repeater AP (1T1R)

D-Link AirPlus G DWL-G700AP

GCIA. GIAC Certified Intrusion Analyst.

SMART CAMPUS, BUILDING AND VENUES

Chapter 11: It s a Network. Introduction to Networking

Secure Mobility Challenges. Fat APs, Decentralized Risk. Physical Access. Business Requirements

300Mbps Long Range Wireless N Ceiling Mount AP Model : N10+

How Insecure is Wireless LAN?

Multi-Layered Security Framework for Metro-Scale Wi-Fi Networks

Cyber Security Guidelines for Public Wi-Fi Networks

WLAN Security. Dr. Siwaruk Siwamogsatham. ThaiCERT, NECTEC

Using GIS in Designing and Deploying Wireless Network in City Plans

On completing this chapter, you will be able to Explain the different WLAN configurations Explain how WLANs work Describe the risks of open wireless

Fix Home Network. Thousands of satisfied users! Easy steps to setup Wireless router with Cable or DSL internet service provider.

SECURITY ON PUBLIC WI-FI New Zealand. A guide to help you stay safe online while using public Wi-Fi

Expected Outcomes Able to design the network security for the entire network Able to develop and suggest the security plan and policy

WhatsUp Gold Wireless v16.4

Wireless Network Security

Department of Public Health O F S A N F R A N C I S C O

Attacking Networks. Joshua Wright LightReading LIVE! October 1, 2003

Implementing a network operations centre management console: Netmates

DMK 11A & 11A GPS Owners Manual

CYBER ATTACKS EXPLAINED: WIRELESS ATTACKS

WhatsUp Gold v16.0 Wireless User Guide

WNRT-627. Data Sheet. Europe/ ETSI: 2.412~2.472GHz (13 Channels) Japan/ TELEC: 2.412~2.484GHz (14 Channels) RF Power.

WRE6505 v2. User s Guide. Quick Start Guide. Wireless AC750 Range Extender. Default Login Details. Version 1.00 Edition 1, 10/2016

FAQ on Cisco Aironet Wireless Security

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

BeeKeeper Manual Version 1.5

NWD2705. User s Guide. Quick Start Guide. Dual-Band Wireless N450 USB Adapter. Version 1.00 Edition 1, 09/2012

D. The bank s web server is using an X.509 certificate that is not signed by a root CA, causing the user ID and password to be sent unencrypted.

AIRPLAY AND AIRPRINT ON CAMPUS NETWORKS AN ARUBA AIRGROUP SOLUTION GUIDE

Securing Wireless Networks by By Joe Klemencic Mon. Apr

Mohammad Hossein Manshaei 1393

How to connect to a Wi-Fi or Wireless Network

WRE2206. User s Guide. Quick Start Guide. Wireless N300 Range Extender. Default Details. Version 1.00 Edition 1, 01/2015

MESH TECHNOLOGY PRIMER

802.11ac Wireless Access Point Model WAC104

PCI Compliance. What is it? Who uses it? Why is it important?

A Division of Cisco Systems, Inc. GHz 2, g. Wireless-G. User Guide. Access Point WIRELESS WAP54G (EU/LA/UK) Model No.

Networking Basics. Crystal Printer Network Installation Guidelines

1. Press "Speed Test" to find out your actual uplink and downlink speed.

WLAN Troubleshooting Using AirCheck Wi-Fi Tester

TestsDumps. Latest Test Dumps for IT Exam Certification

PMS 138 C Moto Black spine width spine width 100% 100%

How Secure is Wireless?

Content. Chapter 1 Product Introduction Package Contents Product Features Product Usage... 2

Alarms and Events. Using the Alarm Summary CHAPTER

IMW-C910W. User Manuel

Wireless# Guide to Wireless Communications. Objectives

CCNA 3 (v v6.0) Chapter 4 Exam Answers % Full

CSMC 417. Computer Networks Prof. Ashok K Agrawala Ashok Agrawala. Fall 2018 CMSC417 Set 1 1

Brian S. Dennis Director Cyber Security Center for Small Business Kansas Small Business Development Center

NT1210 Introduction to Networking. Unit 6: Chapter 6, Wireless LANs

High Power Wireless N. 600mW Smart Repeater LP 9698SR

Wireless network security: A how-to guide for SMBs

300Mbps Wireless N Gigabit Ceilling Mount Access Point

Motorola AirDefense Retail Solutions Wireless Security Solutions For Retail

GETTING THE MOST OUT OF EVIL TWIN

IT220 Network Standards & Protocols. Unit 6: Chapter 6 Wireless LANs

Table of Contents. Your ZTE PEEL. i How to Use This Guide

Welcome to Cogeco UltraFibre Internet. UltraFibre Internet User Guide

تاثیرفناوری اطالعات برسازمان ومدیریت جلسه هشتم و نهم

Procedure: You can find the problem sheet on the Desktop of the lab PCs.

WL-5420AP. User s Guide

QUICK START GUIDE. Pepwave Express. Quick Start Guide. Pepwave Express. Nov Pepwave

Children s Health System. Remote User Policy

AirCheck Wi-Fi Tester Evaluation Guide

AiM User Manual. Wi-Fi Configuration. Release 1.01

Exam : PW Title : Certified wireless security professional(cwsp) Version : DEMO

Guide to Networking Essentials, 6 th Edition. Chapter 7: Network Hardware in Depth

Securing Your Airspace with WatchGuard s Wireless Intrusion Prevention (WIPS)

Aruba Instant in AirWave 7.7

AC1350 Wireless Dual Band Router

Transcription:

Open WLANs the early results of WarDriving Peter Shipley shipley@dis.org

The Project The purpose of my project is to raise the awareness of the security ramifications arising from the use of wireless Lans (WLAN) in the home and office community. Presented here are the early results of a 18 month effort that started in fall of 2000.

Network Security and Wireless Lans The convenience and low cost of WLANs has resulted in their deployment at a feverish rate. This is very similar to the Web race a several years ago. Sadly this deployment has brought security back ten years.

Hardware low end Laptop with FreeBSD stable or Windows 98 External Antenna (>5db) GPS (Garmin emap) Lucent /Aironet 802.11 (Wi-Fi) card

Software wi-scan perl script for FreeBSD Netstumbler a Windows App. dstumbler A FreeBSD App. (beta) The native drivers for cards can also be used although the operation will not be as automated.

Detection Methods Currently the WLANs are being detected with a 802.11 feature called broadcast SSID or Null SSID. The Lucent card supports this feature that when you to set your SSID to (null) or ANY the card will detects a AP s beacon and automatically associate with it.

Detection Methods Currently I run a script that resets then polls the card every three to five seconds. When a new WLAN is detected the script notes the SSID, Mac address, signal strength, channel, location (via. GPS) and security configuration.

Detection Methods Currently we can drive at speeds of up to fifty-five miles a hour and successfully locate and identify wireless networks.

Long Distance? Some security officers feel that if AP is distanced from the street or on a high floor of a building they will be safe from network trespassers. Experiments show that we are able to successfully make a network connection twenty-five miles away from hilltops and high-rise buildings.

The view from a hilltop in Berkeley.

Hardware Connecting to WLANs networks from across the bay. 24db dish connecting to a network on the horizon!

Hardware 15 db Yaggi Laptop Portable power Amp Wyatt

Other Methods Other methods include sniffing 802.11 frame this will all for more efferent and faster detection including more information about the Lan. Sniffing can be done with most WLAN cards and the right software.

Detection Methods Anyone can do this with a Windows based laptop and Wi-Fi card.

Detection Methods Run the Client Manager software and set your SSID to ANY or (null). Next from the Advanced menu of Client Manager and select Site Monitor a window should open listing all the local WLANs that are available from where you are standing.

Six networks detected from a single street corner in downtown San Francisco.

Detection Methods The previous slide was taken from a street corner in downtown San Francisco. Note that you have your choice of six networks open for access!

Statistics We are still in the process in distilling the data Currently we have located over 9000 APs. 60 % of APs are run in their default configuration. Majority are connected to a internal backbone network (not a DMZ).

Statistics A majority of these (85% or more) do not utilize WEP. Of those running WEP, near half utilize a default WEP/encryption key (7%).

Statistics Top SSIDs: 13% tsunami 11% AirWave 10% WaveLAN Network 8% WLAN 5% linksys 2% default 2% TEKLOGIX

Statistics Based on SSIDs and IP address it appears that over 60% of AP are running with a default configuration.

Risks Not just personal and corporate LANs are going wireless: Banks Hospitals Legal firms Police Stations/Jails City hall/municipal

Risks This places people personal information at risk.

Home Networks The risks to home users are greater then simple bandwidth theft. Violations of Term of Use: SPAMing Hacking Anonymous threats Violations can result in loss/disconnection of service

Corporate Networks Failure to protect your network can result in costly headaches SPAMing Hacking providing a starting point Unrestricted internal access. Theft of corporate information Lawsuits Failing to protect stockholders interests

What is Free There are are growing number of free networks in parks, coffee shops and libraries. How can you tell if a network is free?

Accidental Trespassing If you are at a coffee shop that offers free wireless internet access it is possible for your client to drift and associate with a corporate LAN. Making *you* unknowingly guilty of cyber trespassing.

Accidental Trespassing There are already documented cases where to neighboring businesses with wireless had employees unknowingly using each others networks. What is these companies were unfriendly competitors?

What can be done? Place APs in a DMZ Place Access Points on a dedicated subnet. Block unauthorized internal and external access. WEP Stops accidental trespassing. Some cards will not associate with out the correct key.

What can be done? IPSec WEP will not protect your data. Require clients to authenticate with the DMZ firewall/router. Arpwatch Discovers new MAC addresses on your network. 802.1x New protocol, not well supported / tested.

What can be done? Locking your AP to known MAC addresses This only slows the attacker (a few seconds) Stop accidental trespassing Even with WEP the MAC address can still unencrypted. Turn off broadcast SSID This will stop you network from being discovered with simple probes. Your network will still be visible to sniffers and protocol analyzers.

Credit due Matt Peterson -Hardware questions Aaron Peterson (no relation) - Data processing scripts Cal -Linux support Wyatt -Misc. hardware fabrication Bay Area Wireless Users Group DoC: Dis Org Crew

Maps Here are some maps of the data we have collected on the open networks.

Downtown San Francisco

Downtown San Francisco

San Francisco & East Bay

Sunnyvale & Mnt. View

References Bay Area Wireless Users Group www.bawug.org Dis.Org Crew info files www.dis.org/filez NetStumbler.com: www.netstumbler.com wireless news and references IEEE : www.ieee.org 802.11 standards Arrl: www.arrl.org antenna design info.

Peter Shipley +1 510 849 2203 Shipley@dis.org