Security Basics mailing list archives

RE: Free Public WiFi Attempt At Social Engineering?


From: "Lee Hilt" <lhilt () mbc edu>
Date: Mon, 21 Jan 2008 14:02:06 -0500

 
here's a decent article on the phenomenon. Not sure about the credibility of
the site but: 

http://www.wlanbook.com/free-public-wifi-ssid/


to make sure that it is not any of your machines broadcasting the SSID, I
would suggest ensuring they are patched with KB917021 for windows xp
machines.

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On
Behalf Of absolutezero273c () gmail com
Sent: 2008-01-21 10:33
To: security-basics () securityfocus com
Subject: Free Public WiFi Attempt At Social Engineering?


Off and on through out the year, and multiple times a month, there is a
wireless access point/network that shows up on my windows machines. 
According to my "Wireless Network Connection" window it indicates it is a
computer to computer network with the name of Free Public WiFi with full
signal strength. 
Now based on the proximity of other buildings in our complex it would be
rather difficult to obtain a "full strength" signal from another business or
neighbor.   
I'd like to find out what type of network this is , where it is located and
who it belongs to, and consider it a security threat as I'm concerned that
an employee might find it "convenient" to use and would open our network up
to whoever is providing the Free Public WiFi. 
Should I be concerned that this is an attempt at social engineering a way
into my network? 
I've thought about configuring a linux laptop to gather information about
this wireless connection, without divulging information about my windows
network, but am not sure what tools I would need or how to go about it or
what to look for. 
I've found some tools, like net stumbler or chanalyzer but really don't know
what I'm looking for. 
Am I overly paranoid or do I need to be concerned?



Current thread: