Penetration Testing mailing list archives

Re: Identify rogue adsl modems routers in the network


From: Dave McCormick <mccormic () xecu net>
Date: Tue, 27 May 2008 15:56:40 -0400 (EDT)


He said he wanted to check for modems from the LAN side of the house rather than from the telco side.

One of the things we were looking at some time back was using WMI to check for modems installed on remote windoze systems. we had no problems finding modems using WMI, there were plenty. The challenge we ran into was finding which of the installed modems were actually getting a dial tone.

If your management wants you to go ahead and disable all of the modems you find then I suppose that finding a dial tone doesn't really matter. Of course that was not the case for us.

We couldnt figure out how to remotely detect a dial tone so we wound up going to all the PBX's instead and pulling all the DID's and ranges. Then we did what kevin said to do. We used phonesweep.

Fortuntately phonesweep has an API that you can use to automate the sweeps as well as update the numbers in the phonesweep databases.

Maybe someone on the list has some info on approaching this from the LAN side. I'd be interested to hear if anyone has a way to connect to a remote workstation over the LAN and check to see if the installed modem has a dial tone.

Dave

"Leave the gun.  Take the canolis"

-The Godfather

On Mon, 26 May 2008, kevin horvath wrote:

use a wardialer such as phonesweep.  Sweep the phone numbers that are
allocated to you and if you get a carier signal then you need to check
it out.  Good luck.

Kevin

On Mon, May 26, 2008 at 12:25 PM, t35tman <t35tman () gmail com> wrote:
Hi all,

Had a weired requirement recently.
I was wondering if there is any way to detect an adsl modem/router connected
to a phone line.

The scenario being able to trace the adsl modem/router internally from
within the corporate network or externally from the ISP network.

The only option I see is to check with the ISP ... any suggestions ?

Thanks and Regards



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes in Securing Web Applications  Find out now! Get
Webinar Recording and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes
in Securing Web Applications
Find out now! Get Webinar Recording and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes in Securing Web Applications Find out now! Get Webinar Recording and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------


Current thread: