From: Anonymous
Subject: Anecdote about "open" WaveLAN networks.
I found my first "open" WaveLAN (IEEE 802.11)
network by accident. I had
a WaveLAN card in my laptop when I visited the
California office of the
company I work for. My first reaction to getting a
working dhcp lease was
"Great, I won't have to fiddle with cables. But I think I
need to talk to
the local sysadmin if he has thought about security."
My happiness
quickly changed into annoyance when I felt how slow
the network was and
the annoyance changed into surprise when while
debugging the network I
realized that XXX.com wasn't the domain name of the
company I work for (as
a side note: XXX sells crypto hardware). I reported
the incident to the
local sysadmin and forgot about it.
When I got back to Sweden, I told about the stupidity
of XXX to a few
friends at a restaurant in downtown Stockholm. Some
time before the food
arrived we started to discuss WaveLAN and somehow
a laptop showed up on
the table and voila! We were inside YYYinternal.com.
We knew a guy
working at YYY, told him about this, he told his
sysadmin, the sysadmin
responded "I'll have to talk to the firewall guy." (I
didn't know that
firewalls had TEMPEST protection in their default
configuration.) AFAIK
the network has been shut off.
Another month or two passed. I was riding the bus
around downtown
Stockholm to get home after a pretty late evening and
I was too tired to
read. I fired up my laptop and started to detect
networks. I found six
or seven (one could have been a duplicate) during 30
minutes.
A week later a friend from Canada visited us. He
stayed at a hotel in
central Stockholm. He had a working network in
some spots in his room.
Apparently it belonged to a law firm. On the square
outside the hotel the
networks didn't work, simply because there were three
of them fighting
with each other. When we walked around 10 blocks
in central Stockholm we
found 5 to 15 networks.
And so on...
Many of the networks we found gave us DHCP leases
and good routing out to
the internet. Most of them were behind a firewall, but
the firewall was
"aimed" in the wrong direction; the WaveLAN was a
part of the internal
network. We were inside private networks of telcos,
law firms, investment
companies, consulting companies, you name it.
generated by msg2page 0.06 on Jul 21, 2006 at 19:04:56