Locating wireless c...
 
Notifications
Clear all

Locating wireless clients

16 Posts
9 Users
0 Reactions
2,183 Views
erowe
(@erowe)
Estimable Member
Joined: 18 years ago
Posts: 144
Topic starter  

I was wondering if anyone had any experience or suggestions with regard to techniques or tools to use to locate clients that are connected to wireless access points.

I have a situation where someone in or near an apartment building is accessing an open WAP to do "bad" things. We have his MAC and can tell when he is logged on, but we want to locate him physically.

Any suggestions?


   
Quote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

-AirMagnet WiFi Analyzer PRO.

AirMagnet Analyzer’s Find Tool locks onto an unauthorized/rogue or policy violating AP or station and guides the user to its physical location.

- Yellowjacket BANG

When equipped with a BVS DF (Direction Finding) antenna, Yellowjacket® B/A/N/G locates and pinpoints rogue APs and STAs and even detects interference from sources such as microwave ovens and cordless phones. Powerful packet analysis features such as Multipath (Ec/Io), SNR (Signal-to-Noise Ratio), Delay Spread, Channel Frequency Response (CFR), SSID and Received Signal Strength Indicator (RSSI) give Yellowjacket® B/A/N/G the distinction of being the only true handheld RF spectrum protocol analysis and direction finding tool accurate to within +1 dB.


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Also
http//www.wi-fiplanet.com/tutorials/article.php/3590551

http//www.netstumbler.com/downloads/

jaclaz


   
ReplyQuote
erowe
(@erowe)
Estimable Member
Joined: 18 years ago
Posts: 144
Topic starter  

Thanks for the info.

The Yellowjacket looks like what might be the most useful for what I need to do. I've just emailed the supplier to see what the cost of the equipment is.

As for NetStumbler, I don't think it will allow me to locate rogue clients, only APs. I've also used Kismet to see clients logged on to APs, but unfortunately it isn't a lot of use in locating them (e.g. with a directional antenna).

Anyway, thanks again for the input.


   
ReplyQuote
markg43
(@markg43)
Trusted Member
Joined: 18 years ago
Posts: 77
 

Cost is around 5-6k.
I've used the Yellowjacket on a job before. Works great, need a boss willing to buy one.

For a cheaper alternative, you could try hacking up a war driving outfit with a customized directional antenna and then try Kismet, perhaps even all setup with Backtrack boot CD. You need to be able to detect the beaconing from the Wifi NICs not just APs.

Antenna stores
http//www.l-com.com/category.aspx?id=2073
http//www.pacwireless.com/products/MD24-12.shtml

or even a can-tenna
http//www.wirelessgardenstore.com/SearchResults.asp?Cat=3 (commercial)
http//www.oreillynet.com/cs/weblog/view/wlg/448 (homemade)

Other antenna goodness
http//www.seattlewireless.net/AntennaHowTo#TypesofAntennas
http//www.radiolabs.com/Articles/wifi-antenna.html

Info on detection using Kismet.
http//articles.techrepublic.com.com/5100-10878_11-5054412.html

Good luck and Google is your friend.

\M


   
ReplyQuote
erowe
(@erowe)
Estimable Member
Joined: 18 years ago
Posts: 144
Topic starter  

Just got a price estimate on the yellowjacket - way beyond my budget…

At the moment I'm trying Kismet (BackTrack4) with a cantenna to get some directionality but I'm not getting any strength readings on the client, just on the AP. I probably just need to configure it properly.

A colleague using airodump-ng seems to be getting nice signal strength readings for the client on the other hand.

Not a terribly elegant solution, but at least it seems to be working.

If I find anything better I'll re-post.


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

Just got a price estimate on the yellowjacket - way beyond my budget…

I only get to use the Yellowjacket at one of my DoD clients. Not really in my budget either, but it works.

I will be interested in what works in a budget approach. Please keep us posted on your results.


   
ReplyQuote
jhup
 jhup
(@jhup)
Noble Member
Joined: 16 years ago
Posts: 1442
 

In combo with your open source tracking, look for "hamster" "wifi" and "cookie". There was a WiFi write up here somewhere on it.

hamster dumps HTTP traffic, including cookie details, IM chats, other relevant information. It is highly possible the user will dump various data that can locate the individual.


   
ReplyQuote
erowe
(@erowe)
Estimable Member
Joined: 18 years ago
Posts: 144
Topic starter  

In combo with your open source tracking, look for "hamster" "wifi" and "cookie". There was a WiFi write up here somewhere on it.

hamster dumps HTTP traffic, including cookie details, IM chats, other relevant information. It is highly possible the user will dump various data that can locate the individual.

Thanks jhup, sniffing the user's traffic is being considered however the officer doing the investigation was hoping to avoid a part 6 warrant (i.e. intercept warrant). The ISP would also charge him $$$ to collect the data.

One person that I talked to pointed out that an intercept warrant might not be needed however as there should be no expectation of privacy when you are using a system illicitly. But then that's more of a question for the Law forum.

We're hoping to come up with a low/medium budget easy to implement solution that we can share with others. Maybe an iPhone app. lol


   
ReplyQuote
jhup
 jhup
(@jhup)
Noble Member
Joined: 16 years ago
Posts: 1442
 

Triangulation with your cantenna?


   
ReplyQuote
Page 1 / 2
Share: