Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

  Cisco sell a Wireless LAN controller, which can 
  send disconnect packets to "rogue" APs [...] 
  this would help to encourage the other AP 
  providers to turn their boxes off.
Perhaps I should make a product that detects controllers sending fake deauth packets, and does the same thing in return.

This would help "encourage" people who buy the Cisco product to turn that feature off :)



Not defending Marriott, but the primary use case for rogue AP mitigation is not fueled by corporate greed. I recommend it to clients to keep employees from standing up insecure AP's on their internal network, which is a serious security concern. I encourage you to write the tool, though!


[deleted]


Many consumer routers have a clone MAC feature to address exactly this issue. A person puts their computer behind the new wifi router and clones the MAC address so it can get on the network.


Cisco makes the product that does the detection, too. So does Aruba, Motorola, and probably Meru.

The first main use case for the deauth packets is when someone is broadcasting your SSID but they're not actually part of your network. The second use case is when a client that you actually own (corporate laptop) connects to an access point it's not supposed to. And nobody will really mind if you do those.

This anti-competitive use case is another matter.


I mind. You can't own an SSID and they are not uniquely set. Just because you have the same SSID as me what gives you the right to deauth my router?


What is the use case for using an SSID that is already taken? Especially in a business or corporate environment.


The use-case doesn't really matter; it's against the regulations for that radio band to interfere with other people's usage. Even if you think they're attempting to commit fraud.


Right about radio but the thread was talking about Cisco sending deauth packets to rouge APs.


... as was I! Just because you consider an AP to be rogue doesn't mean it's legal for you do something about it.


Right! because who decides if it is a rogue AP. In this cause Marriott has decided that all AP's that don't belong to them are rogue.


And I would argue that as it is their building they can decide what is legal and what is not, no?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: