Networking Forums

Networking Forums > Computer Networking > Linux Networking > Wireless sniffing

Reply
Thread Tools Display Modes

Wireless sniffing

 
 
Matt
Guest
Posts: n/a

 
      04-20-2005, 01:15 AM
I have a question about sniffing on networks. I know that it is possible to
sniff on a wired network, even without an IP address, and i know it is
possible to sniff on an unencrypted or encrypted wireless network, but is it
possible for someone to have cracked my WEP key, sit on my network and sniff
or communicate on my network w/o an IP address? Using a wireless IDS
(kismet), i can see that my access point has packets going through the air,
even though my laptop is turned off. I checked in my linksys web-based
management page and there are no other MAC addresses assigned. someone
could be using a static IP, but can they be listening or communicating w/o
an IP address?

Thanks!
-matt


 
Reply With Quote
 
 
 
 
James Knott
Guest
Posts: n/a

 
      04-20-2005, 01:59 AM
Matt wrote:

> I have a question about sniffing on networks. I know that it is possible
> to sniff on a wired network, even without an IP address, and i know it is
> possible to sniff on an unencrypted or encrypted wireless network, but is
> it possible for someone to have cracked my WEP key, sit on my network and
> sniff
> or communicate on my network w/o an IP address? Using a wireless IDS
> (kismet), i can see that my access point has packets going through the
> air,
> even though my laptop is turned off. I checked in my linksys web-based
> management page and there are no other MAC addresses assigned. someone
> could be using a static IP, but can they be listening or communicating w/o
> an IP address?


Yes, it is possible for someone to intercept your signal, without you
knowing about it and it's also possible to break WEP.

 
Reply With Quote
 
=?ISO-8859-15?Q?Thomas_Kr=FCger?=
Guest
Posts: n/a

 
      04-20-2005, 07:24 AM
Matt schrieb:
> I have a question about sniffing on networks. I know that it is possible to
> sniff on a wired network, even without an IP address, and i know it is
> possible to sniff on an unencrypted or encrypted wireless network, but is it
> possible for someone to have cracked my WEP key, sit on my network and sniff
> or communicate on my network w/o an IP address? Using a wireless IDS
> (kismet), i can see that my access point has packets going through the air,
> even though my laptop is turned off. I checked in my linksys web-based
> management page and there are no other MAC addresses assigned. someone
> could be using a static IP, but can they be listening or communicating w/o
> an IP address?


At first, a wep key can be cracked after sniffing about 500.000
enmcrypted packets with unique IVs. You can see the kismet information
page on a WLAN to see some datails
If you have less packets it will take some time to crack the key.

The AP is constantly sending out broadcast packets like beacon frames.
They are not encrypted and so they don't help in decrypting the key.

Thomas
 
Reply With Quote
 
Coenraad Loubser
Guest
Posts: n/a

 
      04-20-2005, 12:16 PM
Matt wrote:
> I have a question about sniffing on networks. I know that it is possible to
> sniff on a wired network, even without an IP address, and i know it is
> possible to sniff on an unencrypted or encrypted wireless network, but is it
> possible for someone to have cracked my WEP key, sit on my network and sniff
> or communicate on my network w/o an IP address? Using a wireless IDS
> (kismet), i can see that my access point has packets going through the air,
> even though my laptop is turned off. I checked in my linksys web-based
> management page and there are no other MAC addresses assigned. someone
> could be using a static IP, but can they be listening or communicating w/o
> an IP address?
>
> Thanks!
> -matt
>
>


Wep is useless and can be cracked in 2 hours on a moderately used
network by a 10 year old with open source software.

Also, have you heard of a radio tower than can detect how many radios
are tuned into it?

 
Reply With Quote
 
Matt
Guest
Posts: n/a

 
      04-20-2005, 04:30 PM
"Coenraad Loubser" <(E-Mail Removed)> wrote in message
news:d45h5o$ca1$(E-Mail Removed)...
> Matt wrote:
>> I have a question about sniffing on networks. I know that it is possible
>> to sniff on a wired network, even without an IP address, and i know it is
>> possible to sniff on an unencrypted or encrypted wireless network, but is
>> it possible for someone to have cracked my WEP key, sit on my network and
>> sniff or communicate on my network w/o an IP address? Using a wireless
>> IDS (kismet), i can see that my access point has packets going through
>> the air, even though my laptop is turned off. I checked in my linksys
>> web-based management page and there are no other MAC addresses assigned.
>> someone could be using a static IP, but can they be listening or
>> communicating w/o an IP address?
>>
>> Thanks!
>> -matt

>
> Wep is useless and can be cracked in 2 hours on a moderately used network
> by a 10 year old with open source software.
>
> Also, have you heard of a radio tower than can detect how many radios are
> tuned into it?
>


I wouldn't say useless, but not as useful as i had thought. Basically, i
cracked my own WEP and because enough data went through the air to do this,
i want to know if anyone else cracked it.

Just curious, if its so useless, what would you use?

No i haven't heard of radio towers. I'm not sure how that's possible since
it's A) analog data B) nothing is sent from the radio, but enlighten me....

-matt


 
Reply With Quote
 
Coenraad Loubser
Guest
Posts: n/a

 
      04-20-2005, 05:39 PM
Matt wrote:
> "Coenraad Loubser" <(E-Mail Removed)> wrote in message
> news:d45h5o$ca1$(E-Mail Removed)...
>
>>Matt wrote:
>>
>>>I have a question about sniffing on networks. I know that it is possible
>>>to sniff on a wired network, even without an IP address, and i know it is
>>>possible to sniff on an unencrypted or encrypted wireless network, but is
>>>it possible for someone to have cracked my WEP key, sit on my network and
>>>sniff or communicate on my network w/o an IP address? Using a wireless
>>>IDS (kismet), i can see that my access point has packets going through
>>>the air, even though my laptop is turned off. I checked in my linksys
>>>web-based management page and there are no other MAC addresses assigned.
>>>someone could be using a static IP, but can they be listening or
>>>communicating w/o an IP address?
>>>
>>>Thanks!
>>>-matt

>>
>>Wep is useless and can be cracked in 2 hours on a moderately used network
>>by a 10 year old with open source software.
>>
>>Also, have you heard of a radio tower than can detect how many radios are
>>tuned into it?
>>

>
>
> I wouldn't say useless, but not as useful as i had thought. Basically, i
> cracked my own WEP and because enough data went through the air to do this,
> i want to know if anyone else cracked it.
>
> Just curious, if its so useless, what would you use?
>
> No i haven't heard of radio towers. I'm not sure how that's possible since
> it's A) analog data B) nothing is sent from the radio, but enlighten me....
>
> -matt
>
>

Heh heh heh, I was just emphasising the point that anyone with a normal
lan packet sniffer and an 802.11b/g client adapter can receive all the
packets sent out by any of the adapters on your lan, without
"associating" or "connecting" to any of them

sure, wep is enough to hold of amateurs

The better access points implement TKIP and 802.11X, which has a key
that changes rapidly and possiblity of an authentication server on the lan.


I hope that answers your questions.

So yes, it is possible for anyone to decode any traffic.

I would use ZIP files with long passwords to send sensitive information,
as a quick fix.

And ssl connections for pop and smtp, https for web

Actually, I do use that!
 
Reply With Quote
 
Michael Heiming
Guest
Posts: n/a

 
      04-20-2005, 06:16 PM
In comp.os.linux.networking Matt <(E-Mail Removed)>:
> "Coenraad Loubser" <(E-Mail Removed)> wrote in message
> news:d45h5o$ca1$(E-Mail Removed)...
>> Matt wrote:
>>> I have a question about sniffing on networks. I know that it is possible


[ standard wlan security is just a joke ]

> I wouldn't say useless, but not as useful as i had thought. Basically, i
> cracked my own WEP and because enough data went through the air to do this,
> i want to know if anyone else cracked it.


> Just curious, if its so useless, what would you use?


Just use it and tunnel anything through a ssh (2), only allow ssh
on the wireless lan (iptables), nothing else, force key
authentication only. There shouldn't be much left for crackers
and they'll probably look out soon for some other wlan.

[..]

--
Michael Heiming (X-PGP-Sig > GPG-Key ID: EDD27B94)
mail: echo (E-Mail Removed) | perl -pe 'y/a-z/n-za-m/'
#bofh excuse 52: Smell from unhygienic janitorial staff wrecked
the tape heads
 
Reply With Quote
 
James Knott
Guest
Posts: n/a

 
      04-20-2005, 11:05 PM
Matt wrote:

> "Coenraad Loubser" <(E-Mail Removed)> wrote in message
> news:d45h5o$ca1$(E-Mail Removed)...
>> Matt wrote:
>>> I have a question about sniffing on networks. I know that it is
>>> possible to sniff on a wired network, even without an IP address, and i
>>> know it is possible to sniff on an unencrypted or encrypted wireless
>>> network, but is it possible for someone to have cracked my WEP key, sit
>>> on my network and
>>> sniff or communicate on my network w/o an IP address? Using a wireless
>>> IDS (kismet), i can see that my access point has packets going through
>>> the air, even though my laptop is turned off. I checked in my linksys
>>> web-based management page and there are no other MAC addresses assigned.
>>> someone could be using a static IP, but can they be listening or
>>> communicating w/o an IP address?
>>>
>>> Thanks!
>>> -matt

>>
>> Wep is useless and can be cracked in 2 hours on a moderately used network
>> by a 10 year old with open source software.
>>
>> Also, have you heard of a radio tower than can detect how many radios are
>> tuned into it?
>>

>
> I wouldn't say useless, but not as useful as i had thought. Basically, i
> cracked my own WEP and because enough data went through the air to do
> this, i want to know if anyone else cracked it.


Perhaps you should be asking, if there's anyone who hasn't cracked it. ;-)

>
> Just curious, if its so useless, what would you use?


I keeps out the casual intruder.
>
> No i haven't heard of radio towers. I'm not sure how that's possible
> since it's A) analog data B) nothing is sent from the radio, but enlighten
> me....


Analog/digital has nothing to do with it. If it's sent by radio, anyone
within range can receive the signal and analyze it.



 
Reply With Quote
 
James Knott
Guest
Posts: n/a

 
      04-20-2005, 11:06 PM
Coenraad Loubser wrote:

> The better access points implement TKIP and 802.11X, which has a key
> that changes rapidly and possiblity of an authentication server on the
> lan.
>


While I use WEP, it's outside my firewall, which requires ssh or vpn to get
through.

 
Reply With Quote
 
James Knott
Guest
Posts: n/a

 
      04-20-2005, 11:06 PM
Michael Heiming wrote:

> Just use it and tunnel anything through a ssh (2), only allow ssh
> on the wireless lan (iptables), nothing else


Or vpn.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Tips on wireless sniffing Aaron Leonard Wireless Internet 4 11-29-2011 04:57 PM
Wireless networking sniffing seandoe51@yahoo.com Linux Networking 1 09-23-2011 09:53 AM
Wireless sniffing Matt Wireless Internet 12 04-20-2005 11:06 PM
Which wireless card for sniffing? Sumit Birla Linux Networking 5 01-20-2005 11:48 PM
best card to use for wireless sniffing on PDA s n u f f y Wireless Internet 6 06-27-2003 02:43 PM



1 2 3 4 5 6 7 8 9 10 11