Ok, So I was reading up about this abit, I seen that you can use
Nessus with plugin ID #11026 to detect wireless. But from what I see
is that you can only find enterprise WAP's.
Now the thing is this, What happends if a user uses his wireless card,
put it into adhoc mode and use it as a wireless AP. Nessus will pick
up well known WAP devices, but what about picking up someone that
added a new type of WAP into his machine or putting his LAPtops card
into AP mode ???
I see that you can use something like arpwatch to check out a switch
and make sure that only one MAC is sending though a port, but what
happends if you have a switch with a hub connected to it.
Is there ANY software out there that you can use to scan for Rogue
AP's from the WIRED network ??
Thanks a ton
|