{"id":1864,"date":"2009-05-24T20:22:28","date_gmt":"2009-05-25T00:22:28","guid":{"rendered":"http:\/\/blogs.n1zyy.com\/n1zyy\/?p=1864"},"modified":"2009-05-24T20:22:28","modified_gmt":"2009-05-25T00:22:28","slug":"wireless-security-audit","status":"publish","type":"post","link":"https:\/\/blogs.n1zyy.com\/n1zyy\/2009\/05\/24\/wireless-security-audit\/","title":{"rendered":"Wireless Security Audit"},"content":{"rendered":"<p>I found myself sitting in the back seat of a car today, toying with Chess on the Mac. (And being defeated in ways I didn&#8217;t even understand. Quite discouraging.)<\/p>\n<p>Tired of the endless losses, I started up <a href=\"http:\/\/kismac.de\/\">KisMAC<\/a> to show the wireless APs that I passed. Between Margarita&#8217;s in Nashua and my home, I found 232 access points.<\/p>\n<p>As if doing that wasn&#8217;t enough to make me a nerdy loser, I went on to generate some statistics. 32% of the access points were open. (No encryption.) The remaining two-thirds were encrypted; 48% of the access points used WEP, and 21% used WPA. WEP is old an insecure; someone with some targeted utilities can spend about 15 minutes watching network traffic and crack the key to gain entry to your network.<\/p>\n<p>It&#8217;s probably not surprising that the majority of the unsecured networks had names like &#8220;linksys&#8221; and &#8220;belkin54g.&#8221;<\/p>\n<p>&#8220;Wireless Nashua&#8221; is an open access point in downtown Nashua. Stopped at a light I connected, and was taken to a captive portal splash page explaining that it&#8217;s free wifi for people at local businesses. Neat. A handful of other businesses had open access, too.<\/p>\n<p>A few access points were named &#8220;hpsetup.&#8221; I&#8217;m not sure what this is; this is the only access point that was at the car dealership when I brought my car in for service. Connecting gave me a generic &#8220;not actually connected&#8221; fake IP, and there was no gateway, and a quick scan of the netblock suggested that there was nothing on it. I have no idea why this is my theory, but I think it might be connected to HP printers that have WiFi capability.<\/p>\n<p>Driving by the hotel between the Bud Plant and the old McDonald&#8217;s in Merrimack, I noticed a network called Marriott (open), plus five GoldenTree open APs. I wasn&#8217;t aware that the hotel was a Marriott, nor do I know what GoldenTree means. (Ah-ha: GoldenTree is also known as Guest Tek, and provides tech solutions to hotels.)<\/p>\n<p>The highlight, though, was an access point named &#8220;Cisco Sys. Security.&#8221; It sounds like something that would be set up by a CCNA, and you&#8217;d think it&#8217;d be locked down with WPA and pass through an ASA firewall before connecting to the rest of the network. All I know is that it was an actually an open AP.<\/p>","protected":false},"excerpt":{"rendered":"<p>I found myself sitting in the back seat of a car today, toying with Chess on the Mac. (And being defeated in ways I didn&#8217;t even understand. Quite discouraging.) Tired of the endless losses, I started up KisMAC to show &hellip; <a href=\"https:\/\/blogs.n1zyy.com\/n1zyy\/2009\/05\/24\/wireless-security-audit\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1864","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/posts\/1864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/comments?post=1864"}],"version-history":[{"count":0,"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/posts\/1864\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/media?parent=1864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/categories?post=1864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/tags?post=1864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}