Wireless Hacking Projects for Wi-Fi Enthusiasts.Pdf
Total Page:16
File Type:pdf, Size:1020Kb
308_WiFi_Hack_FM.qxd 10/1/04 10:37 AM Page i Register for Free Membership to [email protected] Over the last few years, Syngress has published many best-selling and critically acclaimed books, including Tom Shinder’s Configuring ISA Server 2000, Brian Caswell and Jay Beale’s Snort 2.0 Intrusion Detection, and Angela Orebaugh and Gilbert Ramirez’s Ethereal Packet Sniffing. One of the reasons for the success of these books has been our unique [email protected] program. Through this site, we’ve been able to provide readers a real time extension to the printed book. As a registered owner of this book, you will qualify for free access to our members-only [email protected] program. Once you have registered, you will enjoy several benefits, including: I Four downloadable e-booklets on topics related to the book. Each booklet is approximately 20-30 pages in Adobe PDF format. They have been selected by our editors from other best-selling Syngress books as providing topic coverage that is directly related to the coverage in this book. I A comprehensive FAQ page that consolidates all of the key points of this book into an easy to search web page, pro- viding you with the concise, easy to access data you need to perform your job. I A “From the Author” Forum that allows the authors of this book to post timely updates links to related sites, or addi- tional topic coverage that may have been requested by readers. Just visit us at www.syngress.com/solutions and follow the simple registration process. You will need to have this book with you when you register. Thank you for giving us the opportunity to serve your needs. And be sure to let us know if there is anything else we can do to make your job easier. 308_WiFi_Hack_FM.qxd 10/1/04 10:37 AM Page ii 308_WiFi_Hack_FM.qxd 10/1/04 10:37 AM Page iii WIRELESS HACKING Projects for Wi-Fi Enthusiasts By the SoCalFreeNet.org Wireless Users Group Lee Barken with Eric Bermel, John Eder, Matthew Fanady Michael Mee, Marc Palumbo, Alan Koebrick 308_WiFi_Hack_FM.qxd 10/1/04 10:37 AM Page iv Syngress Publishing, Inc., the author(s), and any person or firm involved in the writing, editing, or production (collectively “Makers”) of this book (“the Work”) do not guarantee or warrant the results to be obtained from the Work. There is no guarantee of any kind, expressed or implied, regarding the Work or its contents.The Work is sold AS IS and WITHOUT WARRANTY.You may have other legal rights, which vary from state to state. In no event will Makers be liable to you for damages, including any loss of profits, lost savings, or other incidental or conse- quential damages arising out from the Work or its contents. Because some states do not allow the exclusion or limitation of liability for consequential or incidental damages, the above limitation may not apply to you. You should always use reasonable care, including backup and other appropriate precautions, when working with computers, networks, data, and files. Syngress Media®, Syngress®,“Career Advancement Through Skill Enhancement®,”“Ask the Author UPDATE®,” and “Hack Proofing®,” are registered trademarks of Syngress Publishing, Inc.“Syngress:The Definition of a Serious Security Library”™, “Mission Critical™,” and “The Only Way to Stop a Hacker is to Think Like One™” are trademarks of Syngress Publishing, Inc. Brands and product names mentioned in this book are trademarks or service marks of their respective companies. KEY SERIAL NUMBER 001 HJCV184764 002 PO5FGHJ887 003 82JH26765V 004 VBHF43299M 005 C23NMVCXZ3 006 VB5T883E4F 007 HJJ3EBNBB6 008 2987GMKKMM 009 629JT5678N 010 IMWT6T3456 PUBLISHED BY Syngress Publishing, Inc. 800 Hingham Street Rockland, MA 02370 Wireless Hacking: Projects for Wi-Fi Enthusiasts Copyright © 2004 by Syngress Publishing, Inc.All rights reserved. Printed in the United States of America. Except as per- mitted under the Copyright Act of 1976, no part of this publication may be reproduced or distributed in any form or by any means, or stored in a database or retrieval system, without the prior written permission of the publisher, with the exception that the program listings may be entered, stored, and executed in a computer system, but they may not be reproduced for publication. Printed in the United States of America 1 2 3 4 5 6 7 8 9 0 ISBN: 1-931836-37-X Publisher:Andrew Williams Page Layout and Art: Patricia Lupien Acquisitions Editor: Christine Kloiber Copy Editor: Mike McGee Technical Editor: Lee Barken Indexer: Odessa&Cie Cover Designer: Michael Kavish Distributed by O’Reilly Media, Inc. in the United States and Canada. For information on rights and translations, contact Matt Pedersen, Director of Sales and Rights, at Syngress Publishing; email [email protected] or fax to 781-681-3585. 308_WiFi_Hack_FM.qxd 10/1/04 10:37 AM Page v Acknowledgments Syngress would like to acknowledge the following people for their kindness and support in making this book possible. Syngress books are now distributed in the United States and Canada by O’Reilly Media, Inc.The enthusiasm and work ethic at O’Reilly is incredible and we would like to thank everyone there for their time and efforts to bring Syngress books to market:Tim O’Reilly, Laura Baldwin, Mark Brokering, Mike Leonard, Donna Selenko, Bonnie Sheehan, Cindy Davis, Grant Kikkert, Opol Matsutaro, Steve Hazelwood, Mark Wilson, Rick Brown, Leslie Becker, Jill Lothrop,Tim Hinton, Kyle Hart, Sara Winge, C. J. Rayhill, Peter Pardo, Leslie Crandell, Valerie Dow, Regina Aggio, Pascal Honscher, Preston Paull, Susan Thompson, Bruce Stewart, Laura Schmier, Sue Willing, Mark Jacobsen, Betsy Waliszewski, Dawn Mann, Kathryn Barrett, John Chodacki, and Rob Bullington. The incredibly hard working team at Elsevier Science, including Jonathan Bunkell, Ian Seager, Duncan Enright, David Burton, Rosanna Ramacciotti, Robert Fairbrother, Miguel Sanchez, Klaus Beran, Emma Wyatt, Rosie Moss, Chris Hossack, Mark Hunt, and Krista Leppiko, for making certain that our vision remains worldwide in scope. David Buckland, Marie Chieng, Lucy Chong, Leslie Lim,Audrey Gan, Pang Ai Hua, and Joseph Chan of STP Distributors for the enthusiasm with which they receive our books. Kwon Sung June at Acorn Publishing for his support. David Scott,Tricia Wilden, Marilla Burgess, Annette Scott, Andrew Swaffer, Stephen O’Donoghue, Bec Lowe, and Mark Langley of Woodslane for distributing our books throughout Australia, New Zealand, Papua New Guinea, Fiji Tonga,Solomon Islands, and the Cook Islands. Winston Lim of Global Publishing for his help and support with distribution of Syngress books in the Philippines. v 308_WiFi_Hack_FM.qxd 10/1/04 10:37 AM Page vi 308_WiFi_Hack_FM.qxd 10/1/04 10:37 AM Page vii Technical Editor & Contributor Lee Barken CISSP,CCNA, MCP,CPA, is the co-director of the Strategic Technologies And Research (STAR) Center at San Diego State University (SDSU) and the President and co-founder of SoCalFreeNet.org, a non-profit community group dedicated to building public wireless networks. Prior to SDSU, he worked as an IT consultant and network security specialist for Ernst & Young’s Information Technology Risk Management (ITRM) practice and KPMG’s Risk and Advisory Services (RAS) practice. Lee is the technical editor for Mobile Business Advisor Magazine, and writes and speaks on the topic of wireless LAN technology and security. He is the author of How Secure Is Your Wireless Network? Safeguarding Your Wi-Fi LAN (ISBN 0131402064) and co-author of Hardware Hacking: Have Fun While Voiding Your Warranty (ISBN 1932266836). Lee is the author of Chapter 1 “A Brief Overview of the Wireless World,” Chapter 2 “SoCalFreeNet.org:An Example of Building Large Scale Community Wireless Networks,” Chapter 4 “Wireless Access Points,” Chapter 8 “Low-Cost Commercial Options,” and Appendix A “Wireless 802.11 Hacks.” “The most precious possession that ever comes to a man in this world is a woman’s heart.” —Josiah G. Holland To the love of my life, Stephanie: Thank you for your never-ending love and encouragement. vii 308_WiFi_Hack_FM.qxd 10/1/04 10:37 AM Page viii Contributors Eric Bermel is an RF Engineer and Deployment Specialist. He has many years of experience working for companies such as Graviton, Western US, Breezecom, Alvarion, and PCSI. Eric has extensive experience developing and implementing RF site surveys, installation and optimization plans for indoor and outdoor ISM and U-NII band systems. Eric is the author of Chapter 10 “Antennas.” John Eder (CISSP,CCNA) is a security expert with Experian. He currently pro- vides strategic and technical consulting on security policy and implementation. His specialties involve: risk profiling, wireless security, network security, encryption technologies, metrics development and deployment, and risk analysis. John’s back- ground includes a position as a consultant in the Systems and Technology Services (STS) practice at Ernst & Young,LLP. John holds a bachelor’s degree from San Diego State University. He actively participates in the security community, making presentations and writing numerous articles on wireless security. John is a proud member of SoCalFreeNet. John enjoys the support of his loving wife Lynda, a caring family (Gabriel, Lyn, and Genevieve), and a great friendship with his director, Michael Kurihara.The security information in this book was made possible through the help of the m0n0wall team, the Soekris Engineering team, the West Sonoma County Internet Cooperative Corporation, and the many members of SoCalFreeNet. John is the author of Chapter 3 “Securing Our Wireless Community.” Matthew Fanady is a gear-head turned networking and computer enthusiast, and has been wrenching on cars and building computers since he was 16 years old. He is currently employed designing and constructing electric vehicles for a small startup company in San Diego, and spends his free time troubleshooting computers and exploring new ways to incorporate the latest communications technologies into everyday life.