WhiteHat: Sydney's CBD a haven for Wardrivers

Security firm WhiteHat has found that out of 751 wireless networks discovered in Sydney's central business district, 75 percent were unencrypted.

Speaking at a hacking workshop in Sydney on Friday, WhiteHat's chief executive Jason Hart explained how he and a colleague drove around the CBD for 30 minutes on Thursday with a laptop to scan for wireless networks.

To conduct the 'Wardrive', Hart used a standard IBM laptop loaded with NetStumbler and Kismet -- both of which are freeware WLAN detection tools. Of the 751 wireless networks discovered, 75 percent were unencrypted and 35 percent were broadcasting their default station ID (SSID), which Hart said is a sign that they were 'rogue' access points unknown to administrators of the systems on which they resided.

Hart said he was not surprised by the results of the test: "No, it is not a surprise. But my concern is how many companies are aware that those access points are within their business? Probably in the majority of cases [administrators] do not know about them."

According to Hart, the test demonstrated that although companies spend millions of dollars buying security products to protect their business, far too many still 'leave the back door open'.

He advises administrators to 'sweep' their buildings for wireless networks at least once a month but preferably once a week.

"It should be part of somebody's job description to sweep the building. It doesn't cost anything except a bit of time -- and you are minimising risk within the business. Download NetStumbler and walk about your building," added Hart.

Advertisement

Talkback 2 comments

    Link layer encryption isn't everything Craig Ringer -- 12/11/05 (in reply to #120123145)

    I run an unencrypted business wireless network. Well, it looks unencrypted to someone driving by, anyway, and would be included in statistics such as this.

    If you attempt to connect to the network, you'll find that you get almost nowhere. The only service available from the outside world is DNS, and that's done via a local DNS server. Everything else requires you to use SSH tunnels to the server, or set up an IPSec VPN (using a certificate provided to you by the company).

    I can give a client who needs 'net access temporary use of the connection for Internet access by authorizing their MAC address. This doesn't permit them to see the internal network, as the wireless and core networks are on different segments connected only via the rather paranoid border gateway.

    Schemes like this, with varying degrees of complexity, are common. WEP is almost entirely useless, and WPA1 in pre-shared key mode almost as bad. Both degrade network performance, and arguably gain you little security. Worse, they introduce additional complexity and compatibility problems when joining a network. It's entirely reasonable for an administrator to forgo such link-layer schemes in favour of higher level, more secure VPN systems that can be standardized across services for wireless access, roaming users access, and user access from home.

    In summary, statistics like this are superficial hype. Without an investigation of what you can /do/ when you connect to an access point, they mean little.

    I agree Graeme Thorne -- 13/11/05 (in reply to #120123146)

    We need to move up the OSI stack and focus more on securing the application and its sessions.

    Network attacks are so passé in terms of improving your overall security and wardriving is just more hype of a problem that has been around for several years now. Next Generation Networks are really going to force businesses to think about their reliance on network controls forcing them to focus more on strong identity and access control at the application layer.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured