wifi sniffing

Feb 27, 2009 1 Replies

I have been having a bit of fun snooping my wifi network. Its easy since I know the WPA key, I poison the targets arp, then I can sniff all transported passwords, and even more fun, I can hijack the SSL certificate, present my own to the target and capture the should be encrypted passwords in clear text. All good stuff..



however sitting on my desktop pc, which doesn't even have a wireless card in it I can also see my passwords transported on the laptop running the sniffer (which has no wired connection only wireless).



I don't understand how that can work. My PC is on a different subnet than the wireless LAN. My PC is also behind a hardware firewall with no connection to the wireless router.



The wireless/adsl router is a cheap DLINk unit, but are they trying to tell me this whole time even my wired connections are being broadcast out the radio?? To me that is a huge security issue..



Anyone seen the same behavior before? what can i do to stop this? chuck the dlink?



Flamer.


What you are seeing is not uncommon with home network devices. What you can do to limit that is create separate networks for wired and wireless (i.e. 192.x.x.x for wireless and 10.x.x.x for wired) and don't allow routing between those networks (if that device supports all of that). You can get a cheap ($150) Cisco PIX or ASA if you really want to filter properly. You might even be able to do the same with a linksys that has been reflashed with something like OpenWRT.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required