Slashdot Mirror


Wireless Camouflage?

Anonymous Coward writes "Black Alchemy's Fake AP generates thousands of counterfeit 802.11b access points. Hide in plain sight amongst Fake AP's cacophony of beacon frames. As part of a honeypot or as an instrument of your site security plan, Fake AP confuses Wardrivers, NetStumblers, Script Kiddies, and other undesirables. Fake AP is a proof of concept released under the GPL."

174 comments

  1. Security through Obscurity by FalconRed · · Score: 2, Insightful

    Perhaps the author of this tool forgot to read this:

    http://slashdot.org/features/980720/0819202.shtm l

    1. Re:Security through Obscurity by Anonymous Coward · · Score: 0

      True, but if no network is 100% secure doing this causes 9/10 cracker/script kiddies/netsumblers to give up then it is an improvement of security.

    2. Re:Security through Obscurity by mindstrm · · Score: 2

      No.. it won't.
      It's not about using up bandwidth.. it's simply the data packets that announce other APs as present.
      A very small amount of traffic, actually.

    3. Re:Security through Obscurity by Otter · · Score: 3, Insightful
      "Security through obscurity doesn't work" is an aphorism, not a law of thermodynamics. It's foolish to rely on obscurity, but there's no reason why it can't add an extra layer of protection.

      Same for Brooks' law, for all the people who love to invoke that one. It's not a formal proof that adding a developer will necessarily delay a project.

    4. Re:Security through Obscurity by schon · · Score: 2

      It's foolish to rely on obscurity, but there's no reason why it can't add an extra layer of protection.

      If you can't rely on it, why are you wasting your time doing it in the first place?

      Security through obscurity is never "protection" because you're not really doing anything - because people who believe it's useful do rely on it.

      That being said, I disagree that this is obscurity - like a honeypot, nothing is being hidden; I see it more as a way to waste a potential hacker's time.. if they try a few that are bogus, they'll give up and go elsewhere.

    5. Re:Security through Obscurity by zapfie · · Score: 2

      Would you consider passwords to be security through obscurity? Security through obscurity isn't a bad thing- it just shouldn't be what your security relies on.

      --
      slashdot!=valid HTML
    6. Re:Security through Obscurity by King+of+the+World · · Score: 2, Insightful
      If you can't rely on it, why are you wasting your time doing it in the first place?
      Because security isn't binary, good security is about lowering the odds of a break-in. Obscurity achieves this, and it can often be a very quick way of lowering the odds of intrusion.
    7. Re:Security through Obscurity by Anonymous Coward · · Score: 0

      Hint: This is the same as salting crypted passwords... adding about 2^17 work to "crack" a network, since you have to find a valid AP THEN begin trying to get in. 2^17 in encryption is trivial, 2^17 in a protocol is a nice bit of padding. Especially if there's no easy way to sift
      through the false APs

    8. Re:Security through Obscurity by i.r.id10t · · Score: 1

      I would never rely on just a single system for security anyway. And something like this that is relatively inexspensive, and can get rid of a good amount of the undesireables is worth doing. Good example is leaving a radio on and lights on when you aren't at home - anyone that watches the house for more than a few hours will realize you aren't home anyway, but for a good percentage of (would-be) thieves, that is something that is just too close to work so they move on and hit your neighbor.

      --
      Don't blame me, I voted for Kodos
    9. Re:Security through Obscurity by RallyNick · · Score: 2, Insightful
      I don't think this has anything to do with Security through Obscurity. StO means you keep the flaws secret, while a fake AP flooding is an entirely different matter.

      Not saying it's bulletproof, but if it makes it harder to get in and the cost is small then there's no reason not to do it.

    10. Re:Security through Obscurity by vrmlknight · · Score: 1

      thats exactly why you should leave your win32 admin accounts as administrator and your *uix's superuser as root

      --
      This must be Thursday, I never could get the hang of Thursdays.
    11. Re:Security through Obscurity by somniculosus · · Score: 1

      2^16 are the odds of you drowning (in the US per year) what can I say: trivial! gl-gl-gll..

    12. Re:Security through Obscurity by Mr+Z · · Score: 2, Informative

      This is security by obscurity in the same way that chaff released to confuse a radar system is. You obscure a target so that attacking it with your primary mode of attack is no longer profitable.

      In other words, as many others have said, it's another layer of protection. I certainly wouldn't leave my network unsecured behind such a fuzz curtain.

      Just think of this as a form of radar jammer. It doesn't stop you from looking for the target. It just makes one of the easier ways of doing so hard.

      --Joe
    13. Re:Security through Obscurity by Anonymous Coward · · Score: 0

      Security through obscurity is never "protection" because you're not really doing anything

      How do you figure that? If I create an encryption algorithm, and don't release the code for the world to analyze, this is utilizing security through obscurity. You can't claim I'm not doing anything, and there's no proof that my algorithm RELIES on obscurity, only that I happen to make use of it. Someone who doesn't even have the foggiest clue how a random stream of bits was encrypted is going to have a much harder time even starting to decrypt it.

      FWIW, I fully agree that open analysis of any encryption scheme is the best way to find problems with it. It's just that too many people have a stupid notion that "SECURITY THROUGH OBSCURITY IS BAD FULL STOP (that means 'period' for Usonians ;)".

      It's not the case. Security ONLY by obscurity is bad, because that's only the one layer of protection, and once the obscurity is out of the way, you're screwed.

    14. Re:Security through Obscurity by Anonymous Coward · · Score: 0

      Passwords are not typically thought of as security through obscurity. Neither is crypto. But both ARE guessable. However, the odds of that guess are usually considered slim to near nonexistent (as we understand them currently).

      56,000 points is a decent amount of access points. It reduces the odds. If you are going to characterize this as security though obscurity, then nearly every accepted security method today is that as well.

  2. Won't this kill available bandwidth? by Anonymous Coward · · Score: 2, Interesting

    Won't this kill available bandwidth?

    1. Re:Won't this kill available bandwidth? by Anonymous Coward · · Score: 1, Funny

      This is 802.11b.
      There is no bandwidth anyhow :P

    2. Re:Won't this kill available bandwidth? by HotNeedleOfInquiry · · Score: 1

      Are you stupid or just trying to be funny? I get 1.2mbps actual ftp transfer speed all day long over a 1600 foot 802.11b link.

      --
      "Eve of Destruction", it's not just for old hippies anymore...
    3. Re:Won't this kill available bandwidth? by ICA · · Score: 1

      I would pose the first sentence of your post back to you...

      On a related note, you won't mind if I bring in 20 access points, or a few microwave ovens and place them in range of your network right?

      Since you have invincible bandwidth and all.

    4. Re:Won't this kill available bandwidth? by HotNeedleOfInquiry · · Score: 1

      The link has high gain antennas on both ends plus significant elevation above ground. It's been as solid as copper for several months.

      --
      "Eve of Destruction", it's not just for old hippies anymore...
    5. Re:Won't this kill available bandwidth? by Anonymous Coward · · Score: 0

      maybe not but it'll kill the available bandwidth on their webserver.

    6. Re:Won't this kill available bandwidth? by Anonymous Coward · · Score: 0

      Uhm, I can't get more than 400kilobyte/s trough my 1m link with no high-gain antennas... Tops arround 600kB/s. 802.11b is half-duplex, so no 1.2MB/s for you, I'm afraid

  3. FP by Anonymous Coward · · Score: 0

    FP, but this is smart. Too bad companies probably won't have the know how and intelligence to put this into affect.

    Hed23

  4. What's next? by WIAKywbfatw · · Score: 4, Funny

    Fake breasts?

    --

    "Accept that some days you are the pigeon, and some days you are the statue." - David Brent, Wernham Hogg
  5. Cacophany! by utdpenguin · · Score: 1, Funny
    I always admire a man who can use that word in a sentence.
    Kudos!!


    * bows to anonymous coward *

    --
    In Soviet Russia you dant have to put up with these crappy jokes
    1. Re:Cacophany! by Anonymous Coward · · Score: 0

      ...except that the article poster spelled it correctly, and you didn't.

      It has the "phone" root, meaning sound... cacophOny.

    2. Re:Cacophany! by utdpenguin · · Score: 0

      I never said I admired a man who can speel it correctly. Thats a piddling little acheivment. :)

      --
      In Soviet Russia you dant have to put up with these crappy jokes
    3. Re:Cacophany! by Anonymous Coward · · Score: 0
      I can speel oranges with my speedy orange peeler.

      And when I ache, an intravenous treatment is the best acheivment for it.

    4. Re:Cacophany! by mangu · · Score: 1

      "cacophany" actually means something that's ugly but transparent. So, yes, even the misspelling makes sense in some way, the "phanos" root may be appropriate when talking about wireless systems.

  6. So how do your wireless devices know what's real? by hackwrench · · Score: 1

    So you set up one of these things... How do your devices know what's real?

  7. DOS application? by eander315 · · Score: 2, Insightful

    Couldn't this software also be used to confuse actual end-user's wireless cards that try to find the legitimate AP? Seems like most wireless cards/software would have a hard time finding the real AP if there are 53,000 fake ones to choose from.

    1. Re:DOS application? by cscx · · Score: 2

      Not if you know the correct SSID, which was gives to you via a secure channel (e.g., paper).

    2. Re:DOS application? by Anonymous Coward · · Score: 1, Informative

      No, since you are manually setting your card to a specific network name you and your AP will be able to talk. If you are trying to passively sniff a network for available network names you will have a hard time since lots of phoney ones are received (or at least that seems to be the idea behind this).

    3. Re:DOS application? by funky+womble · · Score: 2
      Well, only if they don't already know the SSID.

      It'll probably stop Steve and Bill from stealing your service, though :-)

  8. Imagine . . . by Anonymous Coward · · Score: 1, Funny
    A beowulf cluster of these!


    hehehehe. THat joke never gets old.


    well not to me anyway.

  9. Why... by gatesh8r · · Score: 2

    You take the red pill!

    --
    Karma whorin' since 1999
  10. Peripheral damage by RollingThunder · · Score: 2

    Correct me if I'm wrong, but a quick scan through the README doesn't seem to imply it'll do anything more than scream at the top of it's digital lungs with ever-changing AP SSID's.

    Isn't that going to completely slaughter your actual AP?

    1. Re:Peripheral damage by dragorn · · Score: 1

      This is still trivial to see past - look at the number of data packets, and you have your real network. End of problem.

      As for bandwidth usage - 802.11 is collision-based shared media just like unswitched wired ethernet. If you keep flooding the airwaves with junk packets you increase the chances of there being a collision and decrease the available bandwidth. Actually securing the network is a better course of action.

      -m

  11. DMCA by greymond · · Score: 1

    how long before the DMCA starts saying that "counterfit 802.11b hot spots" is like DoS atacks on the WiFi community? I'm sure they'll find somethign wrong with this - even though I think it would be great considering I use an 802.11b wireless connection that sometimes seems to drop its speed when a lot of people are nearby - hhmmm.....

    1. Re:DMCA by Anonymous Coward · · Score: 0

      DMCA starts saying ... they'll find somethign wrong

      The DMCA is a law, not a "they".

    2. Re:DMCA by SN74S181 · · Score: 1

      He was using DMCA as shorthand, not meaning the specific law. DMCA means 'the bogeyman' here on Slashdot. Didn't you know?

  12. Re:So how do your wireless devices know what's rea by extra88 · · Score: 2, Informative

    The have the correct SSID entered in their settings.

  13. So who's going by RebelTycoon · · Score: 1

    to port it to Windows?

    I'm not being a prick... But there are a lot of users out there who use WinDoze and this would be another tool in protecting us from those crazy script kiddies...

    Oh to be young and under 18 again...

    1. Re:So who's going by laserjet · · Score: 3, Funny

      Our you could just secure your system(s). There are better ways to protect yourself than this. This is just obscurity. It is like trying to avoid sexually transmitted diseases by dressing as a transvestite. Sure, it may work, but there are much better solutions.

      --
      Moon Macrosystems. Sun's biggest competitor.
    2. Re:So who's going by analog_line · · Score: 4, Insightful

      It's not security through obscurity, it's creating a forest around your tree. While I may be able to secure the machines on my network, use a VPN for all transactions over the wireless network, there's no real way to secure my access point. WEP is a joke, plain and simple. If someone gets on my wireless network unauthorized by me, I'm liable for whatever shit they might pull through my internet connection, so I don't see the supposed stupidity in making it alot harder for someone to find the real access point. I have my doubts that this software is as effective at what it's trying to do as it's author(s) claim, but even so, it narrows the potential abusers of my network down to the determined, patient, and lucky. No security is perfect. You just have to run faster than the slowest guy to avoid getting eaten by the lion, you know?

      And a better analogy would be trying to avoid venereal disease by dumping condoms all over the place so it's a veritable certainty that you'll be within reach of one wherever you happen to find yourself doing the nasty.

      A better

    3. Re:So who's going by Anonymous Coward · · Score: 0

      On the other hand, such a tool as described here fits very nicely into the average windows user/box. Since this is the exact philosophy that William Gates is dicating.

    4. Re:So who's going by elphkotm · · Score: 1

      or... having sex with thousands of people and saying that makes each instance of sex have a lower likeliness to cause an STD.

      --

      <Amanda`> I just went out to the parking lot in my bathrobe to exchange warez CDs.
    5. Re:So who's going by Anonymous Coward · · Score: 0

      Sorry, waaayyyy of topic.
      You just have to run faster than the slowest guy to avoid getting eaten by the lion, you know?

      I was at a beach in Hawaii with some military friends. I noticed one of my friends yelling shark and running in from knee deep water. The lifeguard started using the megaphone to alert everyone in the water. I said dude, I didn't know sharks swam in water that shallow, he said it wasn't, he saw him about 50 feet futher out and the shark was between him and land but he didn't say anything until he new he could get out of the water. I image being a little smarter AND faster then someone else increses your chances even more.

    6. Re:So who's going by Anonymous Coward · · Score: 0

      Actually, this is more like filling the bar with actors who distract everybody else so nobody will bother you and the person who you want to talk to.

    7. Re:So who's going by Anonymous Coward · · Score: 0
      No, Gates wants to lock out untrusted users, those who are outside the verifiably trusted chain.

      Which brings us to the IE/Outlook certificate flaws, which allow making fake links in the chain of trust...

  14. Doesn't this just slow down the wardriving a bit? by westfirst · · Score: 4, Insightful

    So I get a list of hundreds of access points. My trusty computer can be programmed to check them all one by one. Only the legit one will respond. I realize this is a bit slower, but I think the number of fake APs needs to be huge to hurt the war drivers.

    In fact, I think that the problem with this solution is the amount of effort expended in defense is equal to the amount of effort for the war driver. You've got to have a PC pumping out fake APs constantly. Both radio modems are putting out the same bandwidth. This isn't a good equation for most of us.

    Good encryption, on the other hand, takes only a few cycles to do but a gazillion cycles to undo. That's a great ratio of defense to offense.

    Plus, don't the fake APs still end up jamming the channel. If you're faking an AP, someone else can't use the channel on that micro second. Given that wardrivers come only occasionally, but the jamming goes on constantly, I think that the legitmate users will pay a big price in network access for something that would only slow war drivers down a bit.

    But I may be wrong.

  15. Dumb. by Fat+Casper · · Score: 4, Informative
    Um... Why not secure the damn network instead?

    --
    I spent a year in Iraq looking for WMD and all I found was this lousy sig.
    1. Re:Dumb. by s0l0m0n · · Score: 1

      Agree'd..

      Security through obscurity is not the best solution.

      It seems to me that if this solution is commonly used, the tools will also rapidly adapt.

    2. Re:Dumb. by Surak · · Score: 2

      Yeah, this sounds an AWFUL LOT like STO. There's really no substitute for good security practices...

      I mean, you wouldn't dream of hiding the door to your home with bushes and leaving it unlocked because after all nobody can see the door for all the bushes. If I suggested that was a good idea, you'd probably laugh at me.

      (Hell, you probably already are. :-P)

    3. Re:Dumb. by dattaway · · Score: 2

      Um... Why not secure the damn network instead?

      Heh, this sounds like the best way to secure a network. Along with the usual firewalls and other gems of obscurity, this is like a minefield that stands to catch 99.99% of the wannabee intruders. If you place lucrative triggers of deception everywhere, a newbie to your network is guaranteed to set off an alarm.

      This is just the final touch for security. Its more beautiful than the venus fly trap. Imagine an intruder blindly walking off the edge of a cliff. The death penalty won't protect you from pests, but this will!

  16. Uhm, huh? by Qwerpafw · · Score: 2, Interesting
    I really don't understand how this works. I perused their website for a bit, and even downloaded the binary, but it still bewilders me.

    So this program creates a whole host of fictional access points? Well, a few points I don't get

    How do *you* the correct user, find out which AP is correct?

    What keeps the wardriver from doing that?

    How does this affect performance?

    how does this affect range?

    If it doesn't affect either of the two above, then how does it work? It requires, apparently, only one 802.11b card...

    Of course, I only run a small wireless network, and I am really not the most technically skilled of people. However, I use whatever security I have (the relatively weak WEP, with a well generated key), and would love having a bit more assurance of network safety.

    Anyone who understands this willing to come forwards?
    (And not just understanding in principle, i understand their whole schpiel about hiding in plain sight, like an apple in a barrel of apples.)

    1. Re:Uhm, huh? by utdpenguin · · Score: 0
      (And not just understanding in principle, i understand their whole schpiel about hiding in plain sight, like an apple in a barrel of apples.)


      Or Michael Jackson in a barrel of monkeys

      --
      In Soviet Russia you dant have to put up with these crappy jokes
    2. Re:Uhm, huh? by The+Turd+Report · · Score: 2, Informative
      How do *you* the correct user, find out which AP is correct?
      You should know what your SSID is. That is how your device knows which AP it should use.

      What keeps the wardriver from doing that?
      Don't tell the wardrivers your SSID. :)

      How does this affect performance? how does this affect range?
      Minimal. The packets that announce APs are a small fraction of your outgoing packets.

    3. Re:Uhm, huh? by great_flaming_foo · · Score: 1

      The software basicly turns you Wan card in to a compulsive liar. It keeps saying it is diffrent accesss points but it will only respond to its real name. You as a legit user know the real name because the person who set it up told you the real name. In that way it kinda works like a password, but the AP is broadcasting possible passwords all the time. It seems to me the person who wrote the software doesn't quite get the consept of "just because we can, doesn't mean we should"

    4. Re:Uhm, huh? by Anonymous Coward · · Score: 0
      How do *you* the correct user, find out which AP is correct?
      Because *you*, the correct user, know the real AP's SSID.

      What keeps the wardriver from doing that?
      Because, in theory, they don't know the correct SSID.

      How does this affect performance?
      802.11b is spread-spectrum, so not much at all. Just on that wireless card.

      how does this affect range?
      ...why would it?

      If it doesn't affect either of the two above, then how does it work?
      Magic.
    5. Re:Uhm, huh? by tchdab1 · · Score: 1

      >>How do *you* the correct user, find out which AP is correct?

      Just check the warchalk on the sidewalk outside. ;-)

    6. Re:Uhm, huh? by Anonymous Coward · · Score: 0

      So it lies. But at some point, the access point is going to transmit real data, real legit packets from someone on the network. What keeps a hacker from sniffing that ride and hijacking it?

  17. Script kiddies are people too by Dunhausen · · Score: 2, Insightful

    Is there really such a problem with people mooching off wireless networks?

    I mean come on. Is the big problem in todays work environment really that before all the staff can play Quake III on the company LAN someone has to go out and scatter all the hooligans with laptops?

    This is cool, don't get me wrong. But if encryption isn't enough, go with the cat5 cable.

    --
    Anyone who cannot cope with mathematics is not fully human. At best he is a tolerable subhuman who has learned to we
    1. Re:Script kiddies are people too by The+Turd+Report · · Score: 1

      Is there really such a problem with people mooching off wireless networks?
      Right now? I'd guess not. But, as soon as Joe Average-user figures it out...

    2. Re:Script kiddies are people too by Anonymous Coward · · Score: 0

      I mooch! hehehe.... Why pay when I am surrounded by twenty idiots who broadcast unencrypted, dhcp enabled wireless connections?

  18. Nice site... by bhsx · · Score: 2

    Pretty much everything on the site is included in the submission. Fairly amusing... anyone tried this? How about a full report on it's usage in a heavy wardriven area like downtown Chicago or San Francisco?

    --
    put the what in the where?
    1. Re:Nice site... by SEWilco · · Score: 1
      "How about a full report on it's usage in a heavy wardriven area like downtown Chicago or San Francisco?"

      How would you measure the effect on wardrivers?
      Videotape the street and watch for people who stop suddenly, then their hopeful expressions change just before they leave?

  19. Open source Innovates! by MrWinkey · · Score: 1, Redundant

    That has got to be one of the coolest things I've seen. The article is a lil short on details but this reminds of the article on LeBrea. the software to mire the MS worms....

    This is pretty innovative.....sorry just my 2 cents.

    --
    Vote early. Vote often. Vote CowboyNeal.
    1. Re:Open source Innovates! by scosol · · Score: 1

      Innovative? not really...

      The idea of hiding a gold nugget in a sea of crap is nothing new.

      Except here you can just erase all that crap by just sniffing for TCP on 80-
      Well gee- now what you gonna do?
      Fake a slew of web requests so someone sniffing can't see the real ones?

      yeesh...

      --
      I browse at +5 Flamebait- moderation for all or moderation for none.
  20. Won't Work by Ken@WearableTech · · Score: 1

    It won't work! Of the 50,000 AP's you just need to find the one called tsunami.

  21. A much simpler solution... by ihowson · · Score: 3, Interesting

    that doesn't eat up bandwidth on your network, is to simply disable beacons on your AP. Having thousands of beacons sent makes it fairly obvious that there's an actual AP somewhere in the area, and there are other ways to determine the real network name.

    Admittedly, not all AP's allow beacons to be disabled. But then, Kismet doesn't need them at all to detect networks.

    1. Re:A much simpler solution... by lommer · · Score: 1

      What if you disabled the actual beacon, but then enabled all of these bogus ones?

      That should throw one more wrench into the intruder's machinery...

  22. Physical security by trentfoley · · Score: 4, Funny

    Let's hope that this concept is never applied to physical security. Imagine working in an office/cubicle with 32 keyboards and 64 mice, rj45 and rj11 jacks everwhere, throw in some extra pc cases to fill every inch under your desk -- with only one of each that actually works

    1. Re:Physical security by zrodney · · Score: 5, Funny

      ... Imagine working in an office/cubicle with 32 keyboards and 64 mice, rj45 and rj11 jacks everwhere, throw in some extra pc cases to fill every inch under your desk -- with only one of each that actually works


      You must know the guy who set up our office network

    2. Re:Physical security by Anonymous Coward · · Score: 0

      I miss the fact that at my old company I had three switches, five computers, two 24 port patch panels, and a chit load of cable coming out of everywhere. True security through obscurity.

      (yes, I was really really really^pi bored)

    3. Re:Physical security by CSG_SurferDude · · Score: 2

      That sounds like the offices of most Senior System Administrators that I know. (Myself included). ;-)

    4. Re:Physical security by Anonymous Coward · · Score: 0

      Having an obscurity of plugs can lead to real security, if you sneak big, Chunky voltage into the wrong ones. You probably should have an "In case of Hacker" fire extinguisher, just in case.

  23. What a day... by Dannon · · Score: 4, Funny

    First, uncloaking networks. Then, invisible cloaks. Now, cloaking networks.

    Next thing you know, we'll see a post about the invention of visible cloaks.

    --
    Good judgment comes from experience.
    Experience comes from bad judgment.
  24. I ask that question... by fm6 · · Score: 2

    ...every time somebody goes on a silly hackers witchhunt. Been asking for a long time!

  25. Why this is a bad thing by Anonymous Coward · · Score: 0

    Not everyone accessing wireless networks is bad. Nor is everyone even doing it intentionally. I, for one, having accidently coming across an insecure wireless LAN, will do everything in my power to attempt to notify the owner and tell him to secure it. Given fake access points, this will only create more insecure wireless LANs because nobody will want to report insecure ones to the owners.

  26. Not much help unless your network is unused.. by funky+womble · · Score: 5, Insightful

    This won't do anything to hide an active network, people will just look at the data traffic instead of the beacons.

    1. Re:Not much help unless your network is unused.. by Anonymous Coward · · Score: 4, Funny
      This won't do anything to hide an active network, people will just look at the data traffic instead of the beacons.

      No, I'm a hacker, and I can tell you, this has us beat. Trust me on this one: this will work. I promise.

      Also, run your telnet daemon on port 123. That will stump us as well.

    2. Re:Not much help unless your network is unused.. by Anonymous Coward · · Score: 0

      As a wardriver, I'd have to disagree with you. This application would not in any way hinder our passtime. As you see, this would only cause problems for legit users in the wlan. For ppl like us, we'd just park our cars and weed out throug the signals till we find the right one. This is just pure lameness. I would now suggest someone make a a real wardialler for us :)

    3. Re:Not much help unless your network is unused.. by zod1025 · · Score: 0

      OMG, are you dense? Or have I been trolled?

      --

      -ZOD-
    4. Re:Not much help unless your network is unused.. by zoombat · · Score: 2
      This won't do anything to hide an active network, people will just look at the data traffic instead of the beacons.

      I'd say the effectiveness of this is not to hide a real AP amongst bogus AP's, but to hide real networks amongst bogus networks. So don't set this up in your office building... set it up in places there aren't currently wireless networks so wardrivers waste their time trying to break into something that can't be broken into. This isn't security through obscurity, it's a honeypot designed to lure people away from the real target.

  27. uhhhh, OK. by wowbagger · · Score: 1

    So, we have a story submitted by an AC, linking to a site with very little information on it. Mayhaps the AC was the site operator?

    Now, how does this generate all the frames? Does it require the 802.11 interface to be on the Linux box, or does it manage to send the data to the interface as normal packets. In other words, if I am using one of the Linksys router/802.11 boxes, can I run this on my normal Linux box, or do I need to hack the Linksys to run Linux?

    And what is the effect on throughput? Any time the system is sending a fake frame, that is time it cannot be sending real data.

  28. Security through obscurity by KILNA · · Score: 1, Redundant

    This is like painting your house the same color as the hill behind it, or better yet, using mirrors to create a bunch of fake reflections of houses. Not using encryption over wireless is akin to having no key-lock on the front door. Obscuring your house does little to keep someone from taking your precious collection of Atari 2600 cartridges.

    --
    Error: PANTS NOT FOUND. Press <F1> to continue.
  29. No. by The+Turd+Report · · Score: 1

    Because you *should* know what your SSID is. Your correctly configured device will have no problem making a connection, but some 3viL Hax0r will have a hell of a time connecting.

    1. Re:No. by RollingThunder · · Score: 2

      Sure, but there's still going to be assloads of superfluous chatter on the channels in the area. That can't be impact-free.

    2. Re:No. by The+Turd+Report · · Score: 1

      Well, it certainly isn't impact-free. I'd call it impact-lite. It is just that the packets that announce APs are a small fraction of the outgoing packets.

    3. Re:No. by Real+World+Stuff · · Score: 0, Flamebait

      TTR is currently fucking your mother. If this is legit; then HELLL yeah. Go kill yourself now fag and consider what "legit" means to you. AKA as groupthink and slashbotting.

      --
      If we don't fight for ourselves no one will.
  30. I thought that the by Anonymous Coward · · Score: 1

    party line for all of us was to mock security-through-obscurity. Did I miss a memo?

    Oh, I see. It runs on Linux. Never mind. Carry on and sing praises to it.

    1. Re:I thought that the by Anonymous Coward · · Score: 0

      There is a difference between relying on security through obscurity and using it as another layer of protection.

      Of course, you can't grasp that.

  31. Re:Doesn't this just slow down the wardriving a bi by The+Turd+Report · · Score: 1

    The packets that announce an AP consume a tiny fraction of your available bandwidth. There should not be a noticable drop in bandwidth.

  32. From the trenches.. by Render_Man · · Score: 5, Insightful

    As a wardriver, I think that this would definatly confuse and annoy anyone driving around.

    However I've noticed that companies with wireless AP's tend to be in clusters in close vicinity to each other. I'm just wondering what the effects on the persons neighboor would be. I could just see someone running this and just confusing the hell out of his neighboors. It would be even worse if the fake broadcasts were on different channels, then there would be real chaos with legit users.

    Fun to play with, but not practical for production since a determined attacker would wade through the data to get your real SSID

    Just my $0.02

    --
    Where are we going, and why are we in this hand cart?
    1. Re:From the trenches.. by Anonymous Coward · · Score: 0

      "Words to the wise."

      I don't mean to be a troll, but do wish to include the paranoia of security and the technology that watches the workplace. The employees are almost always contracted out, but services are performed onsite with excellent technology which costs that exceeds the salary of those performing the monitoring. If you know the quality of the X10 cameras that spam your browsing, these cameras are the best that deal with low light conditions. Be aware of theat when you enter a parking lot.

      As someone who has close ties to the security working in a company, I can tell you cameras are rarely, sometimes, or often recorded and sometimes the time elapsed video tapes are rotated. The distribution wharehouse where I work at has nearly 100 cameras, mostly in the wharehouse, but do cover the perimeter, do have excellent resolution.

      If you do enjoy the passion of "wardriving," get to know the security staff of at least one company to know the culture. You see, security staff are geeks too, in their own way. Think paranoia.
      While they may not have an excessive amount of incidents regarding communications related trespassing, they have been aware of these interesting opportunities.

      You are on their radar scope. If you are genuinely interested in security and finding out how your competition defends their networks, get tired of your lawyer defending you, have a partner to drive and use a yagi antenna.

      That is all for now. Sorry for the brief interruption. Please carry on.

    2. Re:From the trenches.. by bigfatlamer · · Score: 1

      Fun to play with, but not practical for production since a determined attacker would wade through the data to get your real SSID

      Congratulations, you seem to be the only one who has gotten it (or bothered to read the actual page cited in the article). This is merely a proof of concept. They've simply written a proggy that allows you to hide your real AP among a bunch of fake ones. I don't see where he's claiming this is the be-all-end-all of wireless security, simply that it would make life more difficult for the random dork surfing for APs.

      E

      --
      There's one thing computing teaches you, and that's that there's no point to remembering everything.
      --Doug Copland
  33. OT: microsoft class action suit to proceed by Anonymous Coward · · Score: 0
  34. MAC filter always worked for me by nowt · · Score: 3, Informative
    I have a 3com Airconnect AP (one of the earliest AP's available). It has MAC filtering for nics. For the odd time I have a new nic I want to use, I need to add the MAC addr to it to even get a signal.


    It seems to work very well and would foil would-be wardrivers.

    --
    A strange game. The only winning move is not to play. How about a nice game of chess? - Joshua (Wargames)
    1. Re:MAC filter always worked for me by NetJunkie · · Score: 2

      You can change the MAC address on wireless cards easily now. MAC filters are about useless these days.

    2. Re:MAC filter always worked for me by ICA · · Score: 2, Insightful

      Why would this foil them exactly?

      You're most likely right, since they are likely doing this for sport, not hacking. If you are using this simply as a deterrent, not security, then you are correct.

      However, any hacker who actually wanted in your network could do so in seconds:

      1. Listen for a unicast frame to determine a valid MAC address on the network.
      2. Change MAC address on his/her card to be one of the MAC addresses.
      3. Pillage the network of the person sitting dumb, fat, and happy on their unsecured net.

      The short and sweet of this is that it is not hard to spoof MAC addresses. Therefore, Access Control Lists (ACL) can not be the only level of security.

    3. Re:MAC filter always worked for me by Anonymous Coward · · Score: 0

      ..except that I can change the MAC address of my wireless nic. So, all's I have to do is wait for you to broadcast with your MAC addy, record it, change my MAC addy and wait for you to go to bed.

      Oops :-P

    4. Re:MAC filter always worked for me by SCHecklerX · · Score: 2
      However, any hacker who actually wanted in your network could do so in seconds: 1. Listen for a unicast frame to determine a valid MAC address on the network.

      Ummm...how, exactly, are they going to do this without being on the network? Mac filtering will keep them off the network unless they are an incredibly lucky guesser or have a lot of spare time on their hands.

    5. Re:MAC filter always worked for me by cronik · · Score: 1

      Have you ever heard of monitor mode, promiscuous mode, or packet analyzers, these methods don't auth with your AP, they just look at the packets in the ether.

      --
      Information wants to be free like speech wants to be free, not like we want beer to be free.
    6. Re:MAC filter always worked for me by commodoresloat · · Score: 2

      point is, you have to know the network is there to analyze it. The filter won't work against a determined attacker who targets your network knowing it is there. But unless they're monitoring your airspace 24/7, or you're broadcasting 24/7, this kind of filtering greatly diminishes the chance of someone randomly happening upon the network and deciding to mess with it.

  35. This is not security by Anonymous Coward · · Score: 0

    This is absolute retardness. I mean it.

    If you can't secure your own network, why are you being a pest to other networks around you? This tool would hinder other legit network users of other networks close to this. This is a nightmare... the tool itself could be classified as virus or worse.

  36. that explains the asshole... by Hooya · · Score: 0, Troll

    ... fake pussy!!

  37. Security through obscurity? by Anonymous Coward · · Score: 0

    How's this different from security through obscurity? Why's everybody finding it so cool?

  38. Contaminated Coffee. by perlyking · · Score: 4, Interesting

    Am I the only one who saw this and thought of Starbucks?
    :-)

    --
    no sig.
  39. Re: wouldn't improperly encrypted pkts be better by hburch · · Score: 2

    This sounds more interesting to me. I have no closely looked at the exploitation of WEP to see if introduces a low level (~1%) of improperly encrypted packets would cause problems or not. My guess is that it would, although you would have to be careful that the false encryptions were subtly wrong. What I do not know if how much harder it would make it. Perhaps more important, I do not know how possible it is to do with commercial cards.

    Of course, the much better solution would be if encryption was used properly by wireless networks. If you add a good key management system, it might even be usable (a globally shared key is just not a good idea). Many people are working on these, of course. Of course, it does not matter how good your encryption is if people do not use it.

  40. Re:FP? by ICA · · Score: 1

    Ummm, no.

  41. Yes. Re:Doesn't this just slow down the wardriving by WolfWithoutAClause · · Score: 4, Insightful
    The packets that announce an AP consume a tiny fraction of your available bandwidth. There should not be a noticable drop in bandwidth.

    That's probably its achilles heal. If you measure which AP point has the most traffic, you've blown past any illusion of security this gives you.

    --

    -WolfWithoutAClause

    "Gravity is only a theory, not a fact!"
  42. This seems easy to circumnvent by TechyImmigrant · · Score: 2, Interesting

    The messaging of WEP security associations within the 802.11 mac spec is performed in the clear by passing challenge texts and responses around.

    So just compile a list of all the APs you see and listen out for a good security association. From this you can devine the real AP.

    With the proposed enhanced security mechanisms (TKIP & AES) the encryption similarly is not turned on until a security association (based on 802.1x) is completed. You can see this happen on the air and you can see which AP is being communicated with.

    For this to work well you might need to also fake lots of good security associations to all the fake APs that are beaconing.

    I see this is a poor mechanism. It is security through obscurity. It can be circumvented and the beacons suck away bandwith.

    TKIP is the way to go.

    --
    I should use this sig to advertise my book ISBN-13 : 978-1501515132.
  43. It may confuse wardrivers... by Anonymous Coward · · Score: 0

    but where there is smoke, there is fire.

    This will just prove that there is, in fact, an AP to look for but it will require some work.

    If this becomes popular look for wardialers for wardrivers.

  44. SSID def, by kingkade · · Score: 1

    For anyone who doesnt know: http://www.webopedia.com/TERM/S/SSID.html

    You still need a secure authentication b/c the ssid can be sniffed. What solutions are there for this prob?

  45. Very effective @ DCX by kwj8fty1 · · Score: 2, Interesting

    While I was at defconX, I fired up kismet at one point, and started see lots of APs. It turns out that the folks sitting behind me had been from Black Alchemy, playing with this neato tool. I personally saw about 600 APs/minute with this tool under kismet, and they had lots of dumb windows clients trying to associate with them. With some tuning, I'm sure they could get the number of APs per second to increase (They may have done this by the time of release).

    It was good stuff, and I ended up getting my name in the credits. :)

    1. Re:Very effective @ DCX by Anonymous Coward · · Score: 0

      What's your name? We don't recall ever giving credit to anyone attending defcon. Why should we? Who are you anyway?

    2. Re:Very effective @ DCX by BeBoxer · · Score: 3, Informative

      and they had lots of dumb windows clients trying to associate with them

      Which is exactly why this is a bad idea. The software doesn't just send beacons. It requires to you install a driver which contains full AP functionality, and then starts configuring it with random MAC address and common, well known SSID's, every quarter second. Which means that anybody within range who happens to have "linksys", or "tsunami", or any of a handful of common SSID's is going to be out of luck when their laptop connects to whomever is running this Alchemy "tool". People who set up broken AP's with liberal (i.e. wide open) security are assholes. And that's exactly what this. software does.

    3. Re:Very effective @ DCX by Anonymous Coward · · Score: 0

      Very good. You managed to discover the point. Good job for not cutting and pasting from the readme file. :)

  46. Re:FP? by Neurodyne · · Score: 0

    Whadda mean no?

    This was my first post to Slashdot (I've been a lurker for years). And it was the first post (Ooo... wow =P)! So feh!

    Anywho, I was just joking around in the first place. Just as I am now. =)

    And how'd I get a Troll mod? What am I trolling for?

    Caio baby!

  47. Wireless DOS attacks? by Sarin · · Score: 2

    It made me think, say you have an "evil enemy" company, or wait.. a corporation (it sounds more evil somehow) which is stealing all your hard earned profits. All you have to do is get a car with a couple of nice antennas (if you want to do it nice, but perhaps you won't even need it) and a couple of laptops and park it close to their office. Then you intercept the channel and ssid of their wlan, and you start to flood it with a lot of random packets using their channel and ssid. That's going to be more than a little annoying then, perhaps to the point that some people would even call it a DOS attack right?

    Now, I don't think such a thing is illegal or is it?

    1. Re:Wireless DOS attacks? by chris_mahan · · Score: 1

      But the fun thing would be that if they hadset up their system to be wireless only and had used VoIP, then they wouldn't be able to call the cops on ya.

      --

      "Piter, too, is dead."

    2. Re:Wireless DOS attacks? by Sarin · · Score: 2

      Why, I mean the 2.4ghz band is a public one, they can't force you to change ssid or channel?
      What if they had a default network, ssid 101 or airport on channel 1 or something like that, if you're not on their territory and having a lan party with a couple of laptops sitting in your car with the same default settings, they can't accuse you of dos'ing right?

    3. Re:Wireless DOS attacks? by chris_mahan · · Score: 1

      Of course not. And the judge will agree completely with you, but since the corporate lawyers would be out in force, they would find some obscure law and the judge would go along with them, and at best they would just take your laptops to make sure you "hadn't" in fact been stealing company secrets. Which of course you weren't, but then the laptops would be retuned to you, and there woould be no telling what those bozos had done to them, so it's: reformat, resintall, change all your password dance...

      Anyway.

      --

      "Piter, too, is dead."

  48. Wait a minute... by EvilTwinSkippy · · Score: 2
    Why not spray paint on the side of the building "Hey there's an 802.11 access point in here!"

    Come on! They idea is for them not to notice, and set up a barrier if they do. Not for you to set up a red light district.

    --
    "Learning is not compulsory... neither is survival."
    --Dr.W.Edwards Deming
    1. Re:Wait a minute... by GlassUser · · Score: 2

      48.5
      )(
      forgetit

  49. ...and even if your network IS unused... by Anonymous Coward · · Score: 0
    Funky Womble makes an interesting point in a previous comment -- FakeAP is generally useless when legit network traffic exists.

    One point that has been missed thus far is this: FakeAP generates random ESSIDs at a default rate of 0.25 second. All one would have to do is watch for the beacon from a solid ESSID that comes in at a regular interval -- can we say simple perl/bash scripting?

    The only way FakeAP can do any good is to give it a static ESSID, and a time interval equal to that of the real AP -- and even then, it would take one instance of FakeAP in it's current form to imitate one real AP.

    With some modifications FakeAP may be slightly useful in preventing unwanted/unmitigated access to wireless APs, but only when it can masquerade undetected to the would-be "hacker."

    -- dw
    1. Re:...and even if your network IS unused... by Anonymous Coward · · Score: 0

      May I ask why this post has not been modded up from a 0? It contains information not mentioned in any other post. It speaks to why FakeAP will not work (well) in it's current implementation. It even goes so far as to give suggestions of enhancements that could improve this tool.

    2. Re:...and even if your network IS unused... by bblgoose · · Score: 1

      that'd be because you posted as AC....AC=0.

  50. fine, then sniff for probe packets by LWolenczak · · Score: 2

    Fine, We will sniff for probe packets then.

  51. Re:So how do your wireless devices know what's rea by SCHecklerX · · Score: 2

    Which makes this whole thing pretty pointless. If you don't want people to 'netstumble' you, don't beacon and pick some obscure (non dictionary) name for your ssid. Sheesh.

  52. Linux radius by Op911 · · Score: 1

    If you're smart enough and technically inclined enough to have a RedHat linux box to run this program on why not just run FreeRadius instead? It would seem to me that it would be better just to have a good authentication protocol and real security rather than just splatter crap all over the radio instead.

  53. SSID this... by Anonymous Coward · · Score: 0

    Someone living near me uses his (her?) last name followed by "ssid" as they ssid.

    Which means I now know(to a high degree), without even checking signal levels which house has the UNENCRYPTED access point.

  54. This "tool" is a remarkably bad idea by BeBoxer · · Score: 2

    If you actually download it and look at it, you'll realize it's just a Perl script. Basically what it does is configure your laptop to be a real, functioning, access point. Every quarter second it reconfigures the card with a random MAC address and one of a handful of well-known SSID's such a "tsunami" and "linksys". Which means if you run this near any poor sap who happened to leave his card in it's default configuration, they'll be screwed as they continuously associate with your non-functioning access point.

    Basically, I can't imagine this being effective at all against war-driving. But I can imagine it being quite effective as a DoS tool. Imagine setting it up with the SSID that Starbucks uses and walking into one of their shops with this. You could have half the customers futily trying to connect to the legitimate service but getting your non-connected and continously resetting "AP" instead. It would be easy enough for this "tool" to configure the card so that clients couldn't accidentally connect to it, by enabling WEP or MAC filtering or whatever. But it doesn't do that, or even try to. I understand it's version 0.2, but at this point I think it should be filed under "trojan horse" or "skript kiddie" given that it'll easily screw up legitimate users while doing basically nothing to protect you from any crackers around.

  55. "hack me, I am special" by Anonymous Coward · · Score: 0

    As others have pointed out, war driving gets old quick.

    But anyone who goes to the trouble of trying to obfuscate their AP? Why, they are interesting!

    They will get tracked down and potentially messed with. If for no other reason than "who's the Linux dude in my neighborhood".

    I still think it is a neat hack.

    How about streaming banner adds to the war drivers via the SSID? "EAT AT JOES. WWW.. BIG.. PORN.. NET.. MAKE.. MONEY.. FAST.. GREENCARD.. LAWYER.."

  56. Re:So how do your wireless devices know what's rea by efaust93 · · Score: 2, Informative

    You configure it to talk to your WAP.

    This product works a lot like a flare that is used to distract missiles or other military ECM. It's meant more as a distraction. I am surprised someone didn't come up with this idea before now.

    I think the point is that it will waste the potential intruder's time - not that it will totally secure your network. If the potential intruder WANTS to get in, he/she will get in eventually. This is to confuse someone trying to just do a drive by hit.

    Then again, there is no stopping luck - what if the person hits on the right access point the first time?

    I haven't seen any studies on wireless where people are finding Wireless AP's with the "Broadcast SSID" turned off (NetStumber can't find WAP's if you have the "Broadcast SSID" turned off)and MAC security enabled (you can clone a MAC address but you have to have a card that can do this function). If you are going to run a Wireless AP, why would you let any MAC hook into your system and why would you broadcast your wireless AP? Ok, you might have some clueless users who don't know how to configure their laptops and yes, it is a pain in the ass to have to distribute the SSID and the encryption Network key to everyone but why would you make it that much easier for an intruder?

    If you have a WAP that doesn't let you turn off the broadcasting of the SSID, why don't you research into either flashing the firmware to enable this feature or buying one that does let you do that? They aren't that expensive anymore.

    --
    e. Faust
  57. Illegal under FCC Part 15? by name_already_taken · · Score: 1

    I thought 802.11b was covered under Part 15 of the FCC rules. Doesn't this violate them by purposely generating interference?

    --
    Putting moderation advice in your .sig lowers your karma!
  58. the BEST way to stop wardrivers... by Anonymous Coward · · Score: 0

    is with one of these: Barrett

  59. Re:Micheal, PLS INVESTIGATE by Anonymous Coward · · Score: 0

    Good luck... Michael will never admit he's wrong.

  60. Knowing the MAC address by Anonymous Coward · · Score: 0

    All 802.11b devices are constantly scanning the airwaves broadcasting clutter like this anyways. All it would take to stop the netstumblers is to filter out all of the nonsense ever-changing signals being generated by this program. I would guess if this thing only changes the SSID it would not stop the wardriver from picking out the rogue MAC address and ignoring everything coming from that MAC address, thus defeating the entire purpose of this program. Surely the author doesn't change the MAC address of his Prism card every single time he changes the SSID or WAP name...

  61. Really Terrible Idea by adb · · Score: 1

    If you don't want people using your network, require authentication. This doesn't protect you from a genuine "intrusion attempt" at all, and will stomp on the community wireless networks around you. I operate open access points at home and at work. Both my employer and my ISP (speakeasy.net) approve. I would be mightily pissed off if some asshole decided to fill the local SSID space with noise just to obfuscate his insecure network instead of closing it properly.

  62. Are slashdotters really this stupid? by Spackler · · Score: 2

    Ok, a flaimbait subject, but get off your horse. It is a tool for FUN. Personally, I plan on using it to cause wardrivers to drive off 128 as their laptop goes bonkers in the front seat (128 is a main commuter parking lot around Boston for those not lucky enough to live there). Should be FUN!

  63. Re:Yes. Re:Doesn't this just slow down the wardriv by Anonymous Coward · · Score: 0

    that would be a "heel". Heal being the opposite of the intent of the term.

  64. Signals Intelligence and Noise Reduction. by SEWilco · · Score: 1
    Obviously changing or obscuring the MAC address is a possibility. Or have the real AP broadcasting junk. Or change the junker's MAC to match the real AP.

    As for using the real traffic, now you're shifting from electronic countermeasures to signal intelligence. The standard way to hide valid signal traffic is to send lots of fake signal traffic. So someone will add a fake-traffic-generator to the mix.

    Also note that if the purpose is to block outsiders from listening in, the noise might be transmitted from an outside antenna. So the camouflage traffic might not be heard well inside the building, while an outsider would have to deal with that obvious distraction.

    There could also be an inside fake AP with different behavior -- it might even allow connections and sound an alarm or do other IDS functions. The outer shield would help reduce inner intrusions, which makes odd behavior in the work area of more interest than otherwise.

  65. Re: wouldn't improperly encrypted pkts be better by Anonymous Coward · · Score: 0

    Heh.. A honeypot could also broadcast with the real AP but respond to wrong WEPs. So finding the right AP is not enough, you also have to use the right WEP key to connect to the real AP. The fake AP needs an antenna away from the real one so real clients won't try to connect to the wrong one... for that matter, fake client traffic can be provided...

  66. It's cool by Anonymous Coward · · Score: 0

    I installed it and have it running. It's pretty cool and I can see how it can confuse wardrivers. Tomorrow I'm going to setup a few more of these at work and set them on the 24th floor of our building in downtown Chicago. hehehe

    Oh, and it does work with WEP. iwconfig is nice ;)

  67. random SSIDs right? by dkc · · Score: 1

    so each 'time period' the AP is sending out the one real SSID, and a whole bunch of random SSIDs. So after a few time periods you can build up a collection of different SSIDs - one of which will be seen significantly more than all the rest: this is the real SSID.

    mm

  68. Not much more than a diversion by AnnaBlack · · Score: 2, Insightful

    As has been pointed out in other replies to this story:

    it's easy to sniff for data traffic and thus ignore the fake access points,

    this is a useful DoS tool more than a way of securing networks.

    Seems to me that as long as network admins, users or Jo-average-computer-at-home-user keeps thinking of 802.11 kit as a "alternative to wires", we'll be stuck with all the security problems. Wireless = broadcast. That will inevitably involve sending your data out to anyone who cares to set up an antenna and kit to recieve it. You trade the convenience of not having to run wires for the insecurity of broadcasting your bits to the world. Anyway, given that this unpleasantly insecure technology is spreading worldwide, it's interesting to see this article at CNet about small, cheap 802.11 chipsets destined for set-top boxes. I contentedly predict that in a couple of years there'll be scares about wardrivers sniffing what people are watching on their wireless TVs :) Anna B

  69. Another analogy... by Burning1 · · Score: 2

    ...Would be trying to avoid venereal disease by dumping condoms all over the place hoping that one of them will land on your penis. ...Or mabie not. I don't think STDs and wireless networking can be directly compared... -_-

  70. An even weirder scenario. by Anonymous Coward · · Score: 0

    A user of this tool sits in an airport, closes his laptop in such a way that it runs when the laptop is closed. Suddenly nobody has wireless access.

    Sounds like a terrorist activity if you ask me.

  71. Re:So how do your wireless devices know what's rea by arivanov · · Score: 2

    At which point you start loving some of the wireless vendors who do not have this setting easily available. You love the older linux Prism drivers even more. The only love that shines greater is the love to driver authors who always scan for all APs before offering you a choice and overflow a fixed limit in the dialogs (there is one like that out there).

    To be continued ad naseum... Grghh....

    --
    Baker's Law: Misery no longer loves company. Nowadays it insists on it
    http://www.sigsegv.cx/
  72. Use IPSec by karlm · · Score: 2

    You can use IPSec on your gateway to prevent random people from using your gateway. Real security also has all kinds of side benefits, such as actually having reasonable assurances of security.

    --
    Copyright Violation:"theft, piracy"::Anti-Trust Violation:"thermonuclear price terrorism"<-Overly dramatic language.
    1. Re:Use IPSec by analog_line · · Score: 2

      You can use IPSec on your gateway to prevent random people from using your gateway.

      The above is a content-free statement that wishes it was a rebuttal. What gateway? My gateway to the internet? What, do you actually think I've got a Cisco with an IPSec module lying around that I can use merely for authenticating outbound web browsing? Are you clinically thick? Do you mean the wireless access point? How many consumer 802.11b access points do you think have an integrated VPN server built into them? None that I've found. Sure if you're an enterprise and have the cash to spend, and the need for wireless networking on a a large and secure scale, you can get a Colubris Access Controller, but I, and most of the other people fielding wireless access points for their homes, can't afford it. And even if they could, setting up a VPN securely is not a trivial task that just anyone can do. Neither is using a spare Intel box to run a xBSD or Linux-based VPN server, not to mention the issues involved in securing the VPN server itself, that many well paid system administrators and security professionals can't seem to do correctly.

      Real security also has all kinds of side benefits, such as actually having reasonable assurances of security.

      I dare you to find the right access point out of 53000 others WITHOUT having to come up with a story behind why you're inching around with a Pringles can trying to figure out which access point my computers are using. ANY security measure can be socially engineered into uselessness. All your "resonable assurance of security" buys you is a false sense of invulnerability, and the good feeling you get from spouting industry buzzwords.

  73. Why don't we try this for open relays? by HerringFlavoredFowl · · Score: 2

    This might slow down wireless intruders, but not stop them ... ... Now if we where to come up with a package that makes a computer pretend it was an open relay we would be set.

    Imagine a BeoWolf cluster of these ;-) A spammer finds what he thinks is a open relay and all it does is send his junk to /dev/null.

    If everyone did this, we would raise the cost of spamming. It will not stop spammers, but it will make them have to check if the relay is actually working by spamming themselves. Nice little breadcrumb trail, no more bulk sending blind ...

    --
    TastesLikeHerringFlavoredChicken
  74. Issues by Martin+Spamer · · Score: 2


    We should stop this attitude in its tracks, it is a selfish and irresponsible waste of bandwidth.

    1) WarChalking &| WarDriving are not crimes, the bands used by 802.11 are *public airspace* they belong to *everyone* not *anyone*.

    2) The vast majority of 802.11 access points are still expermental and like the early days of the Web are *supposed* to be *free* to use by responsible early adopters.

    3) If your AP is not intended for public use, it is it's owners responsibility to secure it.

  75. Public doesn't mean unregulated by Jim+McCoy · · Score: 3, Interesting
    1) WarChalking &| WarDriving are not crimes, the bands used by 802.11 are *public airspace* they belong to *everyone* not *anyone*.


    Just because something is public does not mean that rules do not apply to this public space. A park is a public space but there are rules about how you can use it, the unlicensed spectrum used by 802.11b is available for anyone to use but you are still required to follow FCC regulations regarding how you operate within this spectrum. There are rules that dictate how your wireless card operates, how much power it can put into it's signal, etc.


    In fact, it might be wise of you to consider this in terms of another user of this particular segment of the spectrum -- cordless phones operating at 2.4 GHz. The signal goes out over the same unlicensed spectrum band, but if you were to create a base station which prevented your neighbors from using their cordless phone handsets (even if it was accidental) you could be fined for violating the FCC rules regarding this slice of the spectrum. If you were to monitor and record a transmission between the base station and remote node you would be breaking the law. If you created a phone handset that masqueraded as your neighbors handset and used his phone base station (and phone line) for your calls you would be breaking the law. Both offenses can bring stiff fines and jail terms, something that aggressive wardrivers and 802.11b access point "borrowers" might want to keep in mind...

  76. Area DOS attack by Martin+Spamer · · Score: 2


    This tool is essentially conducting an Area DOS attack against peer 802.11 services.

  77. WarChalking doesn't mean Cracking by Martin+Spamer · · Score: 2


    You seem to be missunderstanding my position. I am AGAINST this tool.

    You also seem to be making incorrect assumptions about what WarChalking &| WarDriving are about, it is no more about cracking than hacking is. The majority of people doing these are the very people trying to develop invovative uses of the technology.

    I suggest your persue this site: http://www.wardrivingisnotacrime.com/

    spectrum used by 802.11b is available for anyone to use but you are still required to follow FCC regulations regarding how you operate within this spectrum

    I agree. Though the author of this tool clearly does not. It is essentially an area denial of service attack for 802.11, filling the spectrum with invalid SSID's. This is akin to seeding local DNS servers with invalid domains, are worse hijacking popular domains. I am sure that the FCC would consider that abuse. I know the UK's Radio Communication Agency would.

    but if you were to create a base station which prevented your neighbors from using [...]

    I am not doing that, though anybody using this tool would be.

  78. Opinions are like...... by Anonymous Coward · · Score: 0

    I like reading all the opinions written by people on /. who have no clue about anything other than video games and who comment about software they have never used.

    Fake AP does not DOS anyone. I'm using it on one machine with three instances of Fake AP running using three WMP11 cards and it does not interfere with my real wireless lan.

    I think most of the comments here are from wardrivers who are upset that someone has finally done something about their activity.

    Before you try to form an opinion about software try using it first so that you will understand how it works. Once you know what it does and what it does not do then your /. opinion would be worth something.