Security Basics mailing list archives

Re: About War Driving ..


From: Joel W Pauling <joel () catalyst net nz>
Date: Fri, 1 Dec 2006 11:27:07 +1300

On Thursday 30 November 2006 06:17, gaurav saha wrote:
Hi ,
I was wondering if it is possible to locate and catch
a guy who is connecting to our wep wireless network
and downloading stuff from torrents and using up our
bandwidth ..
I checked up with arp scan and found 2 unknown IPs
192.168.1.246 and 247
Is there anyway of locating the guy in a building of 7
floors and how to stop this ..I have tried changing
the Wep keys so . he is cracking the wep key.
Any Suggestion People ?
---gaurav


a) You should not be using wep. 
b) Try mac filter list before doing anything else. He can always spoof a valid 
mac... but it might stop him. 
c) Use a vpn on top of  your wireless network (http://openvpn.sf.net), disable 
wep, and setup your wireless to be open with mac filtering (optional). And 
have the open network only allow stuff to goto your vpn server.

Location awareness via wifi is not an easy task. There are a number of 
approaches to doing it, none of which are very satisfactory. Your best bet is 
to just setup your wireless network in a nicer way.

Using a userland VPN over web/wpa is my prefered solution, in that it won't 
hurt your performance over wifi. Getting users to install and configure the 
vpn software is not difficult, you just setup a simple webserver with captive 
portal where the various vpn binaries can be grabbed from. 


Kind regards

JoelW

Attachment: _bin
Description:


Current thread: