ottaky@ottaky.com
 
HTML OK
CSS OK
 
WiFi
 
ottaky.com supports..
ORG
no2id

Warwalking

27/02/03 I'm now living out in Greenwich and fighting an increasingly frustrating battle with BT to get my ADSL connection back. Last night, out of frustration, I fired up the Zaurus to see if anybody was running a WLAN nearby that I could get access to. I picked up 4 or 5 networks, only one of which seemed 'open' in any way. Looking at the packets I could see that somebody was making repetetive FTP transfers. I figured out what was going on a few seconds later. There's a website called Camvista that have a number of webcams dotted around London, and one of them is located just across the road from my flat in the Greenwich Millennium Village. The FTP sessions were transferring a file called 'gmvl01.jpg', which is the name of the webcam's image file. The station was using a BSSID of '00:02:2D:07:6C:26' and an ESSID of '0 OR-1000_00UT42250150', so if you see something similar, it's probably another Camvista webcam.

I've also logged some WLAN activity at Waterloo station - 3 APs with ESSID '1nf0P01n2C0nc0ur3e'. I'm not entirely sure why they decided to go with semi-l33t IDs, unless the installer had a sense of humour. There were about 12 or so clients associated with the APs but network traffic was very light - only about 10 packets a minute when I was looking (around 7.30am). The traffic was encrypted - I'm guessing with a l33t key ;-)

25/01/03 I've been a bit busy looking at flats recently to waste my time looking for WLANs, but I was out in the docklands this afternoon and had arranged to meet a Letting Agent at a well known burger bar adjacent to Blackwall DLR station. Since I had the Zaurus with me and a few minutes to kill I thought I'd fire up Kismet to see what was about. Does anybody know why said burger bar would be running an encrypted AP? For the "drive-through"? Looking back at previous logs I see I've picked up other APs using the same ESSID (hint: the ESSIDs begin with 3 letters you may associate with burger bars), but I just never made the connection before. On a similar note, if you ever go to a Wagamama "Japanese" restaurant in London, the staff there all have Ipaqs with 802.11b cards that talk to an AP to process food orders. Kindaneat.


Yeah, I admit it - I'm a sad geek who actually goes out looking for wireless LANs in London when I have nothing better to do.

I use my U1 with a Xircom (Cisco) CWE1120 card or, preferably, my Zaurus with a Netgear MA701 card. I say preferably because the Zaurus is far more usable for this kind of thing, it starts instantly (near enough) and slips into my pocket .. it's also a lot more practical to use while walking than the Vaio. The only downside to using the Zaurus is that I can't connect my GPS receiver to it to automatically log the location of discovered networks, but I can live with that so long as I can remember where I was during that capture session.

No matter which machine I use, the software is the same - Kismet. The Kismet download page has links to the latest source code and pre-compiled binaries for the Zaurus.

I have an old and kind of useless script to display old and kind of useless Kismet data here.

OK, so what do I actually find? Well, all sorts - from home based networks up to corporate LANs, and the majority don't have WEP enabled, many don't even bother to change the default SSID. I have sat opposite a shop on Tottenham Court Road that uses PCs for tills that are connected via a WLAN and seen plain text network messages being exchanged. I didn't actually see any credit card numbers go by, but I suspect that was simply because nobody was using any of the tills at the time. Kind of worrying.

Here are the results from a fairly average stroll along Tottenham Court Road in London, I've left out the GPS data (where available) so as not to identify the actual physical addresses with the networks.

BSSID ESSID IP range WEP
00:01:03:79:77:BB BTA-W1P.0LA   No
00:02:2D:05:EA:74 Apple Network 05ea74   No
00:02:2D:36:3D:5A <No ssid >   No
00:02:2D:38:7F:7C j29hCAMBERWELL7m2f   Yes
00:02:2D:41:D1:2D 0703CCGROUP 192.168.168.0 No
00:02:2D:45:85:71 <No ssid >   No
00:02:2D:45:85:77 <No ssid >   No
00:02:2D:46:CA:84 <No ssid >   No
00:02:2D:56:17:81 ELSA   No
00:02:2D:56:D3:7C <No ssid >   No
00:02:2D:57:83:D2 <No ssid >   No
00:02:2D:58:21:E6 Non-specified SSID !!   No
00:02:2D:5A:B7:58 MSHORNY   Yes
00:02:2D:5B:14:40 <No ssid >   No
00:02:2D:5B:19:9F <No ssid >   No
00:02:2D:5B:66:81 work   No
00:02:2D:5B:66:9E <No ssid >   No
00:02:2D:5C:33:7B <No ssid >   No
00:02:2D:5C:33:7C <No ssid >   No
00:02:2D:5C:33:EE 101   No
00:02:2D:69:18:8C <No ssid >   No
00:02:2D:69:3A:A7 toshiba   No
00:02:2D:6A:28:A0 <No ssid >   No
00:02:2D:6E:CB:7E <No ssid >   No
00:02:2D:6E:CF:A3 SOOONY   Yes
00:02:2D:6F:03:87 101   No
00:02:2D:6F:04:DD <No ssid >   No
00:02:2D:6F:05:DA <No ssid >   No
00:02:2D:6F:B2:75 hitz   No
00:02:2D:6F:E7:8E <No ssid >   No
00:02:2D:6F:E9:0F <No ssid >   No
00:02:2D:73:C8:D9 IGF   Yes
00:02:B3:AE:AA:E0 101   No
00:02:B3:BA:B7:30 101   No
00:04:75:63:75:2E db   Yes
00:04:E2:1B:3A:E5 WLAN   No
00:05:3C:04:8E:30 <No ssid >   No
00:20:E0:89:6B:98 hitz   No
00:20:E0:8D:05:E3 dino   Yes
00:20:E0:8E:1E:47 hitz   No
00:20:E0:8E:3C:44 ELSA   No
00:30:65:03:DF:0F <No ssid >   No
00:30:65:1D:59:2A base22   Yes
00:30:65:1D:59:4E FraserCRE Server End Airport   Yes
00:30:65:1D:82:3C FraserCRE Trading Floor Airport   Yes
00:30:AB:0A:EE:3C Wireless   No
00:30:AB:0C:3B:1F PUK   No
00:30:AB:1A:3B:01 Wireless   No
00:30:AB:1C:69:0F Wireless   No
00:40:96:3A:6C:08 RFNetwork 192.10.120.0 No
00:40:96:42:03:16 RFNetwork   No
00:50:DA:93:8A:2B 101   Yes
00:50:DA:94:36:94 BTA-W1P.0LA   Yes
00:50:DA:96:49:F8 BTA-W1P.0LA   Yes
00:60:1D:22:0A:78 PARESH 192.168.0.0 No
00:60:1D:22:0A:EE PARESH 192.168.0.0 No
00:60:1D:22:0B:B6 PARESH   No
00:60:1D:22:0C:62 ELSA   No
00:60:1D:F0:7B:C5 <No ssid >   Yes
00:60:1D:F6:98:55 <No ssid >   Yes
00:A0:F8:43:EB:08 CEDSAP   No
00:D0:59:BD:37:B6 <No ssid >   No
00:D0:59:BD:43:EB <No ssid >   No
00:D0:59:BD:43:FE ELSA   No
00:D0:59:BD:45:48 <No ssid >   No
00:D0:59:BD:51:08 IGF   Yes
00:D0:59:BD:55:46 <No ssid >   No
00:D0:59:BD:9C:0F <No ssid >   No
02:02:2D:58:21:E6 Non-specified SSID !!   No
02:02:2D:5C:33:EE 101   No
02:02:2D:69:3A:A7 toshiba   No
02:20:5F:80:05:E3 dino   No
 
And here are some stations picked up on Regent Street, New Bond Street, around The City and along Piccadilly. You'll notice that Hamleys the toy shop and the Montblanc store appear to be more concerned with security than certain financial institutions.
 
BSSID ESSID IP range WEP
00:00:AA:BB:CC:0D PFA Wireless   Yes
00:01:24:F1:35:C7 WLAN 192.168.1.0 No
00:01:F4:EE:90:E9 <No ssid>   Yes
00:02:2D:07:29:48 <No ssid>   Yes
00:02:2D:0A:20:81 AirPort   Yes
00:02:2D:0E:22:E8 UK-LON 192.168.10.75 No
00:02:2D:21:8C:6C 000000Raindrop   No
00:02:2D:22:65:AF <No ssid>   No
00:02:2D:2B:68:23 WaveLAN Network   No
00:02:2D:2B:68:65 WaveLAN Network 192.168.61.28 No
00:02:2D:2B:7C:F9 <No ssid>   Yes
00:02:2D:2B:7D:02 <No ssid>   Yes
00:02:2D:2C:E2:14 MPEGLA   Yes
00:02:2D:2C:E5:D1 9WESTBOURNEPARK7   No
00:02:2D:32:67:46 Precision   Yes
00:02:2D:38:55:C9 j29hCAMBERWELL7n2f   No
00:02:2D:38:55:D9 j29hCAMBERWELL7n2f   No
00:02:2D:38:56:45 j29hCAMBERWELL7n2f   No
00:02:2D:3F:B0:D0 Apple Network 3fb0d0   No
00:02:2D:5E:22:9D <No ssid>   No
00:02:2D:65:7B:93 <No ssid>   Yes
00:02:B3:05:AC:A3 Tokio Marine 6631   No
00:04:76:A5:DD:9F 3Com   No
00:04:E2:1B:3A:D8 WLAN   No
00:04:E2:1B:3A:F1 WLAN   No
00:05:5D:D6:C8:14 b2Lateral   No
00:06:25:5D:7D:4F fworld   Yes
00:06:25:60:12:ED linksys   No
00:30:65:17:91:5A DSE London 1   Yes
00:30:65:1D:24:26 TMLEWIN   No
00:30:AB:0A:EC:6A albany01   Yes
00:30:AB:0A:F0:B7 Wireless   No
00:30:AB:0E:DC:41 HamleysWireless   Yes
00:30:AB:0F:B1:48 Wireless   Yes
00:30:AB:16:6B:85 Wireless   No
00:30:AB:1B:A5:16 Atlasventure   No
00:30:AB:1C:04:AA Wireless   No
00:30:AB:1F:49:EC Wireless   No
00:40:05:C4:BC:2F loftnet   Yes
00:40:96:29:75:D2 tsunami   No
00:40:96:40:06:8C tsunami   No
00:40:96:40:9F:DF Montblanc   Yes
00:40:96:42:39:E6 lonlab_ap1   No
00:40:96:43:9B:B5 tsunami   No
00:40:96:47:65:9E tsunami   No
00:40:96:48:18:2C <No ssid>   No
00:40:96:49:C2:00 tsunami   Yes
00:40:96:56:21:F5 1ns1ghtv01ce   Yes
00:40:96:56:44:C6 1ns1ghtv01ce   Yes
00:40:96:56:C1:44 tsunami   Yes
00:40:96:57:4F:6A t-mobile   No
00:50:DA:01:74:08 101   Yes
00:50:DA:01:F4:E1 101   No
00:50:DA:92:B1:34 101   No
00:50:DA:95:00:35 101   No
00:60:1D:1C:A2:58 88036ANB_1   Yes
00:60:1D:21:9E:D7 WaveLAN Network   No
00:60:1D:21:E7:FD WaveLAN Network   No
00:60:1D:22:10:00 wtgdom   No
00:60:1D:22:28:D7 <No ssid>   Yes
00:90:96:16:76:C8 ELSA   No
00:A0:F8:3A:63:37 CEDSAP   No
00:A0:F8:3A:BC:AE CEDSAP   No
00:A0:F8:3A:BC:B2 CEDSAP   No
00:A0:F8:3B:BC:D7 Iukwap01   Yes
00:A0:F8:46:41:7B 8113 192.7.1.249 No
00:A0:F8:46:41:A4 8113   No
00:A0:F8:4C:C9:1A 8113   No
00:A0:F8:4C:C9:39 8113   No