Wireless networking technologies present significant risks to an organization and highlight networking threats that have been ignored. Without a doubt, wireless technologies provide significant benefits over wired ones, but the security challenges incurred must be addressed. To try to help others understand and/or mitigate wireless security risks, I would like to list several of the tools I have found to be the most useful. If for nothing else, wireless security has been a lot of fun.
Papers
NIST Wireless Network Security
http://cs-www.ncsl.nist.gov/publications/nistpubs/800-48/NIST_SP_800-48.pdf
Cisco 802.11 Wireless LAN Security White Paper
http://www.cisco.com/warp/public/cc/pd/witc/ao1200ap/prodlit/wswpf_wp.pdf
Wireless Detection Tools
Kismet
http://www.kismetwireless.net
gKismet - GUI for Kismet
http://gkismet.sourceforge.net
Netstumbler
http://www.netstumbler.com
Wellenreiter
http://www.remote-exploit.org
Wireless Exploits
Airsnort
http://airsnort.shmoo.com
Void11
http://www.wlsec.net/void11
AirJack (wlan-jack, essid-jack, monkey-jack, kracker-jack)
http://802.11ninja.net
WepAttack
http://wepattack.sourceforge.net
Other Relevant Tools
Ethereal
http://www.ethereal.com
GPSDrive
http://gpsdrive.kraftvoll.at
Wireless Access Point Utilities for Linux
http://ap-utils.polesye.net/
Web Sites
Nutstumbler.com
http://www.netstumbler.com
Wigle.net
http://www.wigle.net
WiFiMaps.com
http://www.wifimaps.com
Drivers
Orinoco Patch for Monitor Mode
http://airsnort.shmoo.com/orinocoinfo.html
HostAP (Prism Drivers)
http://hostap.epitest.fi/
PCMCIA
http://pcmcia-cs.sourceforge.net/
Atheros ar5k 802.11a
http://team.vantronix.net/ar5k/
MadWiFi
http://sourceforge.net/projects/madwifi/
wlan-ng
http://www.linux-wlan.com/linux-wlan/
Antennas
Pringles Can Antenna (Antenna on the Cheap by Rob Flickenger)
http://www.oreillynet.com/cs/weblog/view/wlg/448
Yuban Antenna (The Essence of Community Wireless by Rob Flickenger)
http://www.oreillynet.com/pub/wlg/1124
Misc
World Wide War Drive
http://www.worldwidewardrive.org/
Blackhat Briefings
http://www.blackhat.com
没有评论:
发表评论