Penetration Testing mailing list archives

RE: Identification of non Cisco AP's


From: "Jonathan Gauntt" <jon0966 () yahoo com>
Date: Thu, 28 Jul 2005 00:33:23 -0500

Hi, I am running SuperScan on the Class A, I will let you know the results
in a few days, thank you.


Jonathan

-----Original Message-----
From: Peter Wood [mailto:peterw () firstbase co uk] 
Sent: Wednesday, July 27, 2005 2:40 AM
To: Jonathan Gauntt
Cc: security-management () securityfocus com; pen-test () securityfocus com
Subject: Re: Identification of non Cisco AP's

Hi Jonathan

We have had considerable success in locating default APs by simply 
identifying their banners (on TCP 80). SuperScan will do this very well.

regards
Pete

At 20:22 26/07/2005 -0500, Jonathan Gauntt wrote:
Hi,

I have been tasked with the project of scanning and identifying all non
Cisco wireless access points within the company's network.

We have about 800 /22 and /24 subnets, and because of the IP addressing
scheme in place, might just be easier for me to scan the whole class A
range
of IP's.

I have access to Nessus and GFI Security Scanner.  Since we over 8000 IP's
in place, does anyone have any advice on the best way to identify these
non
Cisco AP's such as Linksys and Netgear, etc.

I wouldn't want to have a report produced that is two miles long unless
absolutely necessary.

Thanks,


Jonathan

--------------------------------------------------------------------
Peter Wood FBCS CITP MIEEE MIMIS CISSP
Chief of Operations
First Base Technologies
+44 (0)1273 454525
www.fbtechies.co.uk
www.white-hats.co.uk




Current thread: