Thoughts Media.com

 





Go Back   Thoughts Media Forums > Thoughts Media Off Topic

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-19-2004, 01:21 AM
Pontificator
Join Date: Feb 2004
Posts: 1,423
Default HELP! Finding a rogue wifi AP on a corp LAN

(Mods: I decided to post in OT instead of Wireless because this doesn't relate to PPCs and more people visit this area.)

I work in a large school district's IT department, and we have about 30 schools/buildings that we support. One of the High Schools has an unauthorized Wireless Access Point in it called "TheSecretAccessPoint". We NEED to find it before school starts and remove it from our network. Sounds easy? Keep reading! :wink:

THE FACTS:
Pocket WiNc, a WAP sniffer, has found the network with a 40%-50% several times, but the signal only lasts for a few seconds and then it just disappears for a random amount of time!!

No WEP encryption, DHCP is enabled, SSID is broadcasting.

I have the MAC address but when we told our HP Procurve Switches to search for that MAC they couldn't find it.

It has internet access, but we can't stay connected long enough to run an IPCONFIG or check our leased IP.

The auditorium is very big and is in the middle of the building. Walking around the whole school yields no other signals. Rule out multipath or a directional wifi shoot, methinks.

It might be getting it's web access from a DSL or cable line.

This was set up by a high school geek (probably), so they won't have a EE degree or anything.

I'd really appreciate any help you can offer. I've spent a few hours already wandering all over the area looking for any CAT5 cables or hardware.

Thank you! Looking forward to creative ideas and links. :way to go:
__________________
The One Nerd Band
www.davidprahl.com
 
Reply With Quote
  #2 (permalink)  
Old 08-19-2004, 04:52 AM
Swami
Join Date: Jun 2007
Posts: 4,593

It start by getting a directional antenna. Either a cantenna, or a parabolic sort. There are lots of cheap ways to make these.

Have two receivers set up, one with the omni and one with the directional. When the signal pops up, swivel the omni around to maximise the signal and that will give you a better direction ot search in. Would be great if you could have several receivers with directional antennas, to triangulate an area on one pop-up.

Is the network distributed with switches? with activity lights? When it pops up you could start a ping from your host to the server or router address and look for that activity on the switch activity lights. that would tell you what cat 5 cable the thing is on.

Are you sure this thing isn't moving? School still closed? If so, how is someone turning it on and off. I know this could be done from the network, but who has access.
 
Reply With Quote
  #3 (permalink)  
Old 08-19-2004, 12:20 PM
News Editor
Darius Wey's Avatar
Join Date: Aug 2006
Posts: 12,553

Totally OT, but this seems like a case in CSI! 8)
__________________
Want the latest news, views, rants and raves? Visit our portal. Wish to contact me? Send me a private message or e-mail.
 
Reply With Quote
  #4 (permalink)  
Old 08-19-2004, 03:29 PM
Swami
Join Date: Jun 2007
Posts: 4,593

Quick other thought. You could do an IP sweep of your subnet and see what you can't account for. If the AP is permanently connected to the network and the perp is turning the radio on an off via the cabled side, the IP it has will be seen. I have used SuperScan just to audit a network, but there are many things like this.
 
Reply With Quote
  #5 (permalink)  
Old 08-19-2004, 05:09 PM
Pontificator
Join Date: Feb 2004
Posts: 1,423

Thanks for the ideas and quick response! We're having a department LAN party in two days and are going to look for this WAP just beforehand.

School is currently out of session, so students cannot get physical access to it. I also have a hard time believing that a student would be sitting at his home PC all summer randomly turning it on and off for kicks.

I don't see how it would be moving, either. Only office, custodial, and IT staff should be in the building. Security is tight.

Yes, the switches have status lights and management software. We're the second largest WAN in the state, so we have some nice gear. :wink:
__________________
The One Nerd Band
www.davidprahl.com
 
Reply With Quote
  #6 (permalink)  
Old 09-07-2004, 08:07 PM
Thinker
Join Date: Jul 2003
Posts: 420

So, did you ever find it?
 
Reply With Quote
  #7 (permalink)  
Old 09-07-2004, 09:27 PM
Pontificator
Join Date: Feb 2004
Posts: 1,423

No, we didn't. :cry:

My boss, who came along for this last attempt, thinks that the huge attenna on the roof of the school is absorbing a point-to-point wireless shoot and radiating it downward. A little far fetched, but it's the only solution we've thought of.

There's always next year... :wink:
__________________
The One Nerd Band
www.davidprahl.com
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +1. The time now is 10:54 PM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC7
Copyright Thoughts Media Inc. 2007