Click to See Complete Forum and Search --> : Search for AP's on wired network


e654562
08-03-2007, 02:28 PM
I am looking for a tool to search for WIFI AP's on my corporate network. we have had some issues with people just popping a linksys or dlink type device on the network. Does anyone have a way to search for these.. I would do it wirelessly but most of our sites do not have corporate wireless networks..

Thanks in advance

golfnut
08-03-2007, 07:56 PM
Try this. It's free...

http://www.networkchemistry.com/products/roguescanner.php

Greg

Andrej Komarov
01-10-2008, 03:12 PM
You can use any active or passive tools. The most popular:
active: netstumbler
passive: tcpdump on wi-fi interface with IEEE802_11 flag

M/Q
01-12-2008, 08:43 AM
Hello Greg,

Have you worked with that application? It looks interesting, I was wondering how accurate it was when trying to guess what the unknown device was??

golfnut
01-14-2008, 08:51 PM
Hey M/Q - haven't work with it extensively...

Andrej Komarov
01-23-2008, 09:07 AM
Have you worked with that application? It looks interesting, I was wondering how accurate it was when trying to guess what the unknown device was??

First of all, you enumerate legitimate devices. Then the programm search for all new hotspots with the same SSID's like yours (Rogue) or other new SSID's. If it is, it will alert the admin about it.

Wifi-Guru
04-23-2009, 03:58 PM
There are tools out there that can easily do this but they are not cheap. Look into a WIPS system if you want real time protection.

IMO, adjust the company security policy to ban doing this and fire the first person that does it, I am sure it will be the LAST person to do it.

If you think / know someone already has one plugged into the corp network, walk around with netstumbler and watch the signal strengths. OR Start a ping to the broadcast address or your network and walk with a wireless sniffer looking for that packet to pop out into the air.

OR enable 802.1x on your network switches!

~K

mr black
08-30-2009, 10:44 PM
I think he means when someone puts an AP on the corporate network.

802.1x can fix, also you can limit the MAC`s on the switch portsto 1 or 2.

Also look at the router table and switch. look up MAC address that come
from DLINK,LINKSYS etc . [usually cheap AP`s]

I have found many this way. RF scanning is a waste of time and effort unless
its a really small business or you have millions to spend !


Mr black
CCNOT