Saturday, November 8, 2008

Active AP 802.11 Fingerprinting

Toorcon recently seems to have had a presentation on Fingerprinting APs to see if they are ones you should trust. (Click on the Title to see it)

Some interesting tests by tweaking flags sent and doing clock skew tests. Looks like it may have also been presented at Blackhat and ShmooCon also this year.

The presentation material for Toorcon seems to be a little longer than the ShmooCon one, though ShmooCon's seems to have a few different slides in it. Didn't go looking for it at Blackhat.

Makes me think I should work on getting Satori to be able to use my AirPCap adapter and start working at breaking down those 802.11 packets!

