LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-14-2006, 08:59 PM   #1
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Detecting Sniffers on Wireless


A friend of mine works at a bar where they're adding free wireless for customers. He, being the most computer-savvy person working there, has been asked to head this up. Good news for him: he's gonna get paid for a week to setup and test a wireless router. Bad news: he asked me to help him make it reasonable secure.

So, jointly, our question is this: is it possible to detect a packet sniffer on an open wireless network? Clearly we can't just look for unexpected MACs, but is there some 'signature' a packet sniffer puts out? As far as I know, they're very much passive devices, but I thought I'd ask.
 
Old 02-14-2006, 10:13 PM   #2
ilikejam
Senior Member
 
Registered: Aug 2003
Location: Glasgow
Distribution: Fedora / Solaris
Posts: 3,109

Rep: Reputation: 97
In short: no, you can't detect sniffers. Kismet, for example, is undetectable, as it never sends out packets.

Other (Windows) utilities may not be entirely invisible, but the point is moot, since you can't be sure that there isn't a cracker with a Linux laptop around somewhere.

Incidentally, MAC filtering is useless against Linux based systems anyway, as it's possible to sniff a MAC from the network and change the address on the card to match.

dave
 
Old 02-14-2006, 10:19 PM   #3
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Original Poster
Rep: Reputation: 128Reputation: 128
Notably, it's possible to change the MAC on many wireless cards under Windows as well. Thanks for the information that confirmed my initial suspicions.
 
Old 02-14-2006, 11:56 PM   #4
ilikejam
Senior Member
 
Registered: Aug 2003
Location: Glasgow
Distribution: Fedora / Solaris
Posts: 3,109

Rep: Reputation: 97
Windows MAC info noted. Shady characters with XP laptops will be watched with renewed suspicion.

Cheers.
 
Old 02-15-2006, 04:05 PM   #5
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
Quote:
Originally Posted by ilikejam
Incidentally, MAC filtering is useless against Linux based systems anyway, as it's possible to sniff a MAC from the network and change the address on the card to match.
dave
How do you change the MAC address of a NIC card on Linux?
 
Old 02-15-2006, 05:49 PM   #6
ilikejam
Senior Member
 
Registered: Aug 2003
Location: Glasgow
Distribution: Fedora / Solaris
Posts: 3,109

Rep: Reputation: 97
See 'man ifconfig' to achieve enlightenment.

Note that the MAC address is also known as the hardware address.

Dave
 
Old 02-15-2006, 08:42 PM   #7
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Original Poster
Rep: Reputation: 128Reputation: 128
As a summary, (though the man page should be sufficiently enlightening):

Code:
ifconfig <IFACE> hw ether <NEW MAC>
The new mac should be formatted just like the macs in the output of ifconfig: colon-separated hex bytes.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ethereal and Kismet wireless sniffers difference powah Linux - Wireless Networking 1 10-08-2005 07:19 AM
Ubuntu 5.04 Not Detecting Wireless Card TechSonic Linux - Wireless Networking 1 09-22-2005 01:03 AM
detecting wireless networking sherwood SUSE / openSUSE 2 04-18-2005 12:05 AM
detecting wireless network MiniMe001 Linux - Laptop and Netbook 13 11-28-2004 02:21 PM
Detecting Wireless Network Cards kharn Linux - Wireless Networking 0 07-16-2003 12:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:01 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration