WhiteHat: Sydney's CBD a haven for Wardrivers

Security firm WhiteHat has found that out of 751 wireless networks discovered in Sydney's central business district, 75 percent were unencrypted.

Speaking at a hacking workshop in Sydney on Friday, WhiteHat's chief executive Jason Hart explained how he and a colleague drove around the CBD for 30 minutes on Thursday with a laptop to scan for wireless networks.

To conduct the 'Wardrive', Hart used a standard IBM laptop loaded with NetStumbler and Kismet -- both of which are freeware WLAN detection tools. Of the 751 wireless networks discovered, 75 percent were unencrypted and 35 percent were broadcasting their default station ID (SSID), which Hart said is a sign that they were 'rogue' access points unknown to administrators of the systems on which they resided.

Hart said he was not surprised by the results of the test: "No, it is not a surprise. But my concern is how many companies are aware that those access points are within their business? Probably in the majority of cases [administrators] do not know about them."

According to Hart, the test demonstrated that although companies spend millions of dollars buying security products to protect their business, far too many still 'leave the back door open'.

He advises administrators to 'sweep' their buildings for wireless networks at least once a month but preferably once a week.

"It should be part of somebody's job description to sweep the building. It doesn't cost anything except a bit of time -- and you are minimising risk within the business. Download NetStumbler and walk about your building," added Hart.

Advertisement

Talkback 2 comments

    Link layer encryption isn't everything Craig Ringer -- 12/11/05 (in reply to #120123145)

    I run an unencrypted business wireless network. Well, it looks unencrypted to someone driving by, anyway, and would be included in statistics such as this.

    If you attempt to connect to the network, you'll find that you get almost nowhere. The only service available from the outside world is DNS, and that's done via a local DNS server. Everything else requires you to use SSH tunnels to the server, or set up an IPSec VPN (using a certificate provided to you by the company).

    I can give a client who needs 'net access temporary use of the connection for Internet access by authorizing their MAC address. This doesn't permit them to see the internal network, as the wireless and core networks are on different segments connected only via the rather paranoid border gateway.

    Schemes like this, with varying degrees of complexity, are common. WEP is almost entirely useless, and WPA1 in pre-shared key mode almost as bad. Both degrade network performance, and arguably gain you little security. Worse, they introduce additional complexity and compatibility problems when joining a network. It's entirely reasonable for an administrator to forgo such link-layer schemes in favour of higher level, more secure VPN systems that can be standardized across services for wireless access, roaming users access, and user access from home.

    In summary, statistics like this are superficial hype. Without an investigation of what you can /do/ when you connect to an access point, they mean little.

    I agree Graeme Thorne -- 13/11/05 (in reply to #120123146)

    We need to move up the OSI stack and focus more on securing the application and its sessions.

    Network attacks are so passé in terms of improving your overall security and wardriving is just more hype of a problem that has been around for several years now. Next Generation Networks are really going to force businesses to think about their reliance on network controls forcing them to focus more on strong identity and access control at the application layer.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Love me, tender
    Considering how expensive and drawn-out tender processes can be to solve problems that might be very immediate, it's little wonder that the Victorian Police IT department tried to work the tender exemptions system.
  • Array 2009 funding drought rolls on
    For Australian start-ups looking for venture capital, 2009 was a very bad year. 2010 may be no better.
  • Array Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • More blogs »

Tags

Back to top

Featured