Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 04-11-2007, 04:53 PM
aljuhani
Guest
 
Posts: n/a
Default MAC address and Wifi DDoS

Hello Group,

I have a linksys WAG54gX2 SRX200 and decided lately and in addition to
WPA encryption to apply MAC address filtering which would allow only
my 1 x Wireless Desktop and 1 x Laptop.

But now and looking to my /var/log/messages, I see the following Mac
Address trying to gain access which is normal when someone is trying
to connect to my wifi.

Due to the number of consecutive error messages below and time frame
in between, I thought may be the attacker is applying some sort of
Denial of service attack that would may be disable such filtering, I
do not know but just thought to ask the experts here.

Thanks in advance.

-aljuhani

Below my /var/log/messages.

Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 8)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 9)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 10)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 11)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 12)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 13)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 14)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 15)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 4)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 5)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 6)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:58 - aniWsmLimRecvMsgs.c:1115 Station (0, 7)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 8)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 9)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 10)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 11)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 12)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 13)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 14)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 15)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 4)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 5)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:48:59 - aniWsmLimRecvMsgs.c:1115 Station (0, 6)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 9)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 10)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 11)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 12)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 13)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 14)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 15)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 4)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 5)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 6)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 7)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:49:10 - aniWsmLimRecvMsgs.c:1115 Station (0, 8)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:12 - aniWsmLimRecvMsgs.c:1115 Station (0, 9)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:12 - aniWsmLimRecvMsgs.c:1115 Station (0, 10)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:12 - aniWsmLimRecvMsgs.c:1115 Station (0, 11)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:12 - aniWsmLimRecvMsgs.c:1115 Station (0, 12)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:12 - aniWsmLimRecvMsgs.c:1115 Station (0, 13)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:12 - aniWsmLimRecvMsgs.c:1115 Station (0, 14)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:12 - aniWsmLimRecvMsgs.c:1115 Station (0, 15)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:13 - aniWsmLimRecvMsgs.c:1115 Station (0, 4)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:13 - aniWsmLimRecvMsgs.c:1115 Station (0, 5)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:13 - aniWsmLimRecvMsgs.c:1115 Station (0, 6)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:13 - aniWsmLimRecvMsgs.c:1115 Station (0, 7)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON
Wed, 2007-04-11 18:50:13 - aniWsmLimRecvMsgs.c:1115 Station (0, 8)
00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON


Reply With Quote
  #2 (permalink)  
Old 04-11-2007, 05:07 PM
John Navas
Guest
 
Posts: n/a
Default Re: MAC address and Wifi DDoS

On 11 Apr 2007 09:53:33 -0700, "aljuhani" <private.mailbox@gmail.com>
wrote in <1176310413.169362.63560@n59g2000hsh.googlegroups. com>:

>I have a linksys WAG54gX2 SRX200 and decided lately and in addition to
>WPA encryption to apply MAC address filtering which would allow only
>my 1 x Wireless Desktop and 1 x Laptop.


MAC addresses are too easily spoofed for MAC address filtering to be of
any real value; i.e., it's not worth the trouble. WPA with a strong
passphrase is all you really need.

>But now and looking to my /var/log/messages, I see the following Mac
>Address trying to gain access which is normal when someone is trying
>to connect to my wifi.
>
>Due to the number of consecutive error messages below and time frame
>in between, I thought may be the attacker is applying some sort of
>Denial of service attack that would may be disable such filtering, I
>do not know but just thought to ask the experts here.


Probably not a DoS attack. Might even be a device of your own. Anyone
worth worrying about will be spoofing in any event.

--
Best regards, FAQ for Wireless Internet: <http://Wireless.wikia.com>
John Navas FAQ for Wi-Fi: <http://wireless.wikia.com/wiki/Wi-Fi>
Wi-Fi How To: <http://wireless.wikia.com/wiki/Wi-Fi_HowTo>
Fixes to Wi-Fi Problems: <http://wireless.wikia.com/wiki/Wi-Fi_Fixes>

Reply With Quote
  #3 (permalink)  
Old 04-11-2007, 05:21 PM
Jeff Liebermann
Guest
 
Posts: n/a
Default Re: MAC address and Wifi DDoS

"aljuhani" <private.mailbox@gmail.com> hath wroth:

>I have a linksys WAG54gX2 SRX200 and decided lately and in addition to
>WPA encryption to apply MAC address filtering which would allow only
>my 1 x Wireless Desktop and 1 x Laptop.
>
>But now and looking to my /var/log/messages, I see the following Mac
>Address trying to gain access which is normal when someone is trying
>to connect to my wifi.


00:16:6f:3c:9e:cf is an Intel client device. Does your wireless
desktop or laptop use an Intel wireless chipset? Do you own any other
wireless device that uses an Intel chipset? Any game machines with
Wi-Fi?

>Due to the number of consecutive error messages below and time frame
>in between, I thought may be the attacker is applying some sort of
>Denial of service attack that would may be disable such filtering, I
>do not know but just thought to ask the experts here.


>Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 8)
>00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON


My guess(tm) is that someone has their wireless client set to connect
to your access point by default. Note that "connect" here means the
initial wireless "association", before any negotiated encryption key,
authentication, or login. Without finishing the actual connection
ordeal and getting past your Access Control List, I can't tell whether
this is an attacker, misconfigured wireless device, or overly
aggressive wireless client. It doesn't look like Kismet or
NetStumbler probes (but I'm not sure).

It would be really tempting to allow them to connect and then sniff
the traffic to see what they try to do. If it's a computer with open
shares, snooping around their computer is usually sufficient to
identify them.

You can also determine if they're using 802.11b or 802.11g to help
identify the culprit. Just set your SRX200 to "802.11b only" or
"802.11g only" to see which one works. That might help identify the
culprit.

If you just want them to go away, you might try changing the SSID on
the SRX200. (Changing the channel will do nothing). If they are set
to connect to your specific SSID, they won't follow the change.
However, if they have their wireless client set to "connect to any
available network", they will follow the change. If it's an attacker,
it may not initially follow the change in SSID, but might follow when
they realize what happened.

--
Jeff Liebermann jeffl@comix.santa-cruz.ca.us
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558

Reply With Quote
  #4 (permalink)  
Old 04-11-2007, 06:59 PM
aljuhani
Guest
 
Posts: n/a
Default Re: MAC address and Wifi DDoS

Jeff Liebermann wrote:
>
> 00:16:6f:3c:9e:cf is an Intel client device. Does your wireless
> desktop or laptop use an Intel wireless chipset? Do you own any other
> wireless device that uses an Intel chipset? Any game machines with
> Wi-Fi?


no not anything I own.

> >Wed, 2007-04-11 18:48:16 - aniWsmLimRecvMsgs.c:1115 Station (0, 8)
> >00:16:6f:3c:9e:cf, MAC-ACL lookup failed, ssId HOTWANCON

>
> My guess(tm) is that someone has their wireless client set to connect
> to your access point by default. Note that "connect" here means the
> initial wireless "association", before any negotiated encryption key,
> authentication, or login. Without finishing the actual connection
> ordeal and getting past your Access Control List, I can't tell whether
> this is an attacker, misconfigured wireless device, or overly
> aggressive wireless client. It doesn't look like Kismet or
> NetStumbler probes (but I'm not sure).
>
> It would be really tempting to allow them to connect and then sniff
> the traffic to see what they try to do. If it's a computer with open
> shares, snooping around their computer is usually sufficient to
> identify them.
>
> You can also determine if they're using 802.11b or 802.11g to help
> identify the culprit. Just set your SRX200 to "802.11b only" or
> "802.11g only" to see which one works. That might help identify the
> culprit.
>
> If you just want them to go away, you might try changing the SSID on
> the SRX200. (Changing the channel will do nothing). If they are set
> to connect to your specific SSID, they won't follow the change.
> However, if they have their wireless client set to "connect to any
> available network", they will follow the change. If it's an attacker,
> it may not initially follow the change in SSID, but might follow when
> they realize what happened.


Well I have actually changed the SSID and the logs provided is after
changing so it appears to be deliberate attempts and is continuing
upto now.

Will give him the access as you have suggested to be able at least
identify him or if I am lucky enough he will check a pop3 email
account and give me the pleasure disclosing his data.

Thanks for the input Jeff.

Rgds.
-aljuhani


Reply With Quote
  #5 (permalink)  
Old 04-11-2007, 07:54 PM
John Navas
Guest
 
Posts: n/a
Default Re: MAC address and Wifi DDoS

On 11 Apr 2007 11:59:21 -0700, "aljuhani" <private.mailbox@gmail.com>
wrote in <1176317961.149446.276570@b75g2000hsg.googlegroups .com>:

>Jeff Liebermann wrote:


>> If you just want them to go away, you might try changing the SSID on
>> the SRX200. (Changing the channel will do nothing). If they are set
>> to connect to your specific SSID, they won't follow the change.
>> However, if they have their wireless client set to "connect to any
>> available network", they will follow the change. If it's an attacker,
>> it may not initially follow the change in SSID, but might follow when
>> they realize what happened.

>
>Well I have actually changed the SSID and the logs provided is after
>changing so it appears to be deliberate attempts and is continuing
>upto now.


Not necessarily -- many wireless clients are configured to try to
connect to any available access point, often by accident.

--
Best regards, FAQ for Wireless Internet: <http://Wireless.wikia.com>
John Navas FAQ for Wi-Fi: <http://wireless.wikia.com/wiki/Wi-Fi>
Wi-Fi How To: <http://wireless.wikia.com/wiki/Wi-Fi_HowTo>
Fixes to Wi-Fi Problems: <http://wireless.wikia.com/wiki/Wi-Fi_Fixes>

Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Asus P5B WiFi woes acb alt.internet.wireless 3 12-15-2007 02:18 PM
Wifi horribly slow on MSI RG60G, very fast with an ethernet cable deepdark@onvol.net alt.internet.wireless 10 01-18-2007 04:34 PM
Linksys wrt54g-wet54g-wap54g incompatable Bob & Geri alt.internet.wireless 6 09-28-2006 01:07 AM
Changing my IP address for wifi radio Canada Bob alt.internet.wireless 0 08-27-2006 04:27 AM
Theoretical Discussion: Hotel WiFi Hack logankriete@gmail.com alt.internet.wireless 23 08-13-2006 02:28 PM


All times are GMT. The time now is 09:42 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45