|
Warwalking
27/02/03 I'm now living out in Greenwich and fighting an
increasingly frustrating battle with BT to get my ADSL connection back. Last
night, out of frustration, I fired up the Zaurus to see if anybody was running
a WLAN nearby that I could get access to. I picked up 4 or 5 networks, only
one of which seemed 'open' in any way. Looking at the packets I could see that
somebody was making repetetive FTP transfers. I figured out what was going on
a few seconds later. There's a website called Camvista that have a number of
webcams dotted around London, and one of them is located just across the road
from my flat in the
Greenwich
Millennium Village. The FTP sessions were transferring a file called
'gmvl01.jpg', which is the name of the webcam's image file. The station was
using a BSSID of '00:02:2D:07:6C:26' and an ESSID of '0 OR-1000_00UT42250150',
so if you see something similar, it's probably another Camvista webcam.
I've also logged some WLAN activity at Waterloo station - 3 APs with ESSID
'1nf0P01n2C0nc0ur3e'. I'm not entirely sure why they decided to go with
semi-l33t IDs, unless the installer had a sense of humour. There were about 12
or so clients associated with the APs but network traffic was very light -
only about 10 packets a minute when I was looking (around 7.30am). The traffic
was encrypted - I'm guessing with a l33t key ;-)
25/01/03 I've been a bit busy looking at flats recently to
waste my time looking for WLANs, but I was out in the docklands this afternoon
and had arranged to meet a Letting Agent at a well known burger bar adjacent to
Blackwall DLR station. Since I had the Zaurus with me and a few minutes to kill
I thought I'd fire up Kismet to see what was about. Does anybody know why said
burger bar would be running an encrypted AP? For the "drive-through"? Looking
back at previous logs I see I've picked up other APs using the same ESSID
(hint: the ESSIDs begin with 3 letters you may associate with burger bars), but
I just never made the connection before. On a similar note, if you ever go to
a Wagamama "Japanese" restaurant in London, the staff there all have Ipaqs
with 802.11b cards that talk to an AP to process food orders. Kindaneat.
Yeah, I admit it - I'm a sad geek who actually goes out looking for wireless
LANs in London when I have nothing better to do.
I use my U1 with a Xircom (Cisco) CWE1120 card or,
preferably, my Zaurus with a
Netgear MA701
card. I say preferably because the Zaurus is far more usable for this kind of
thing, it starts instantly (near enough) and slips into my pocket .. it's also
a lot more practical to use while walking than the Vaio. The only downside to
using the Zaurus is that I can't connect my GPS receiver to it to automatically
log the location of discovered networks, but I can live with that so long as
I can remember where I was during that capture session.
No matter which machine I use, the software is the same -
Kismet. The Kismet
download
page has links to the latest source code and pre-compiled binaries for the
Zaurus.
I have an old and kind of useless script to display old and kind of useless
Kismet data here.
OK, so what do I actually find? Well, all sorts - from home based networks
up to corporate LANs, and the majority don't have WEP enabled, many don't even
bother to change the default SSID. I have sat opposite a shop on Tottenham
Court Road that uses PCs for tills that are connected via a WLAN and seen
plain text network messages being exchanged. I didn't actually see any credit
card numbers go by, but I suspect that was simply because nobody was using any
of the tills at the time. Kind of worrying.
Here are the results from a fairly average stroll along Tottenham Court Road
in London, I've left out the GPS data (where available) so as not to identify
the actual physical addresses with the networks.
| BSSID |
ESSID |
IP range |
WEP |
| 00:01:03:79:77:BB |
BTA-W1P.0LA |
|
No |
| 00:02:2D:05:EA:74 |
Apple Network 05ea74 |
|
No |
| 00:02:2D:36:3D:5A |
<No ssid > |
|
No |
| 00:02:2D:38:7F:7C |
j29hCAMBERWELL7m2f |
|
Yes |
| 00:02:2D:41:D1:2D |
0703CCGROUP |
192.168.168.0 |
No |
| 00:02:2D:45:85:71 |
<No ssid > |
|
No |
| 00:02:2D:45:85:77 |
<No ssid > |
|
No |
| 00:02:2D:46:CA:84 |
<No ssid > |
|
No |
| 00:02:2D:56:17:81 |
ELSA |
|
No |
| 00:02:2D:56:D3:7C |
<No ssid > |
|
No |
| 00:02:2D:57:83:D2 |
<No ssid > |
|
No |
| 00:02:2D:58:21:E6 |
Non-specified SSID !! |
|
No |
| 00:02:2D:5A:B7:58 |
MSHORNY |
|
Yes |
| 00:02:2D:5B:14:40 |
<No ssid > |
|
No |
| 00:02:2D:5B:19:9F |
<No ssid > |
|
No |
| 00:02:2D:5B:66:81 |
work |
|
No |
| 00:02:2D:5B:66:9E |
<No ssid > |
|
No |
| 00:02:2D:5C:33:7B |
<No ssid > |
|
No |
| 00:02:2D:5C:33:7C |
<No ssid > |
|
No |
| 00:02:2D:5C:33:EE |
101 |
|
No |
| 00:02:2D:69:18:8C |
<No ssid > |
|
No |
| 00:02:2D:69:3A:A7 |
toshiba |
|
No |
| 00:02:2D:6A:28:A0 |
<No ssid > |
|
No |
| 00:02:2D:6E:CB:7E |
<No ssid > |
|
No |
| 00:02:2D:6E:CF:A3 |
SOOONY |
|
Yes |
| 00:02:2D:6F:03:87 |
101 |
|
No |
| 00:02:2D:6F:04:DD |
<No ssid > |
|
No |
| 00:02:2D:6F:05:DA |
<No ssid > |
|
No |
| 00:02:2D:6F:B2:75 |
hitz |
|
No |
| 00:02:2D:6F:E7:8E |
<No ssid > |
|
No |
| 00:02:2D:6F:E9:0F |
<No ssid > |
|
No |
| 00:02:2D:73:C8:D9 |
IGF |
|
Yes |
| 00:02:B3:AE:AA:E0 |
101 |
|
No |
| 00:02:B3:BA:B7:30 |
101 |
|
No |
| 00:04:75:63:75:2E |
db |
|
Yes |
| 00:04:E2:1B:3A:E5 |
WLAN |
|
No |
| 00:05:3C:04:8E:30 |
<No ssid > |
|
No |
| 00:20:E0:89:6B:98 |
hitz |
|
No |
| 00:20:E0:8D:05:E3 |
dino |
|
Yes |
| 00:20:E0:8E:1E:47 |
hitz |
|
No |
| 00:20:E0:8E:3C:44 |
ELSA |
|
No |
| 00:30:65:03:DF:0F |
<No ssid > |
|
No |
| 00:30:65:1D:59:2A |
base22 |
|
Yes |
| 00:30:65:1D:59:4E |
FraserCRE Server End Airport |
|
Yes |
| 00:30:65:1D:82:3C |
FraserCRE Trading Floor Airport |
|
Yes |
| 00:30:AB:0A:EE:3C |
Wireless |
|
No |
| 00:30:AB:0C:3B:1F |
PUK |
|
No |
| 00:30:AB:1A:3B:01 |
Wireless |
|
No |
| 00:30:AB:1C:69:0F |
Wireless |
|
No |
| 00:40:96:3A:6C:08 |
RFNetwork |
192.10.120.0 |
No |
| 00:40:96:42:03:16 |
RFNetwork |
|
No |
| 00:50:DA:93:8A:2B |
101 |
|
Yes |
| 00:50:DA:94:36:94 |
BTA-W1P.0LA |
|
Yes |
| 00:50:DA:96:49:F8 |
BTA-W1P.0LA |
|
Yes |
| 00:60:1D:22:0A:78 |
PARESH |
192.168.0.0 |
No |
| 00:60:1D:22:0A:EE |
PARESH |
192.168.0.0 |
No |
| 00:60:1D:22:0B:B6 |
PARESH |
|
No |
| 00:60:1D:22:0C:62 |
ELSA |
|
No |
| 00:60:1D:F0:7B:C5 |
<No ssid > |
|
Yes |
| 00:60:1D:F6:98:55 |
<No ssid > |
|
Yes |
| 00:A0:F8:43:EB:08 |
CEDSAP |
|
No |
| 00:D0:59:BD:37:B6 |
<No ssid > |
|
No |
| 00:D0:59:BD:43:EB |
<No ssid > |
|
No |
| 00:D0:59:BD:43:FE |
ELSA |
|
No |
| 00:D0:59:BD:45:48 |
<No ssid > |
|
No |
| 00:D0:59:BD:51:08 |
IGF |
|
Yes |
| 00:D0:59:BD:55:46 |
<No ssid > |
|
No |
| 00:D0:59:BD:9C:0F |
<No ssid > |
|
No |
| 02:02:2D:58:21:E6 |
Non-specified SSID !! |
|
No |
| 02:02:2D:5C:33:EE |
101 |
|
No |
| 02:02:2D:69:3A:A7 |
toshiba |
|
No |
| 02:20:5F:80:05:E3 |
dino |
|
No |
| |
| And here are some stations picked up on Regent Street,
New Bond Street, around The City and along Piccadilly. You'll notice that
Hamleys the toy shop and the Montblanc store appear to be more concerned with
security than certain financial institutions. |
| |
| BSSID |
ESSID |
IP range |
WEP |
| 00:00:AA:BB:CC:0D |
PFA Wireless |
|
Yes |
| 00:01:24:F1:35:C7 |
WLAN |
192.168.1.0 |
No |
| 00:01:F4:EE:90:E9 |
<No ssid> |
|
Yes |
| 00:02:2D:07:29:48 |
<No ssid> |
|
Yes |
| 00:02:2D:0A:20:81 |
AirPort |
|
Yes |
| 00:02:2D:0E:22:E8 |
UK-LON |
192.168.10.75 |
No |
| 00:02:2D:21:8C:6C |
000000Raindrop |
|
No |
| 00:02:2D:22:65:AF |
<No ssid> |
|
No |
| 00:02:2D:2B:68:23 |
WaveLAN Network |
|
No |
| 00:02:2D:2B:68:65 |
WaveLAN Network |
192.168.61.28 |
No |
| 00:02:2D:2B:7C:F9 |
<No ssid> |
|
Yes |
| 00:02:2D:2B:7D:02 |
<No ssid> |
|
Yes |
| 00:02:2D:2C:E2:14 |
MPEGLA |
|
Yes |
| 00:02:2D:2C:E5:D1 |
9WESTBOURNEPARK7 |
|
No |
| 00:02:2D:32:67:46 |
Precision |
|
Yes |
| 00:02:2D:38:55:C9 |
j29hCAMBERWELL7n2f |
|
No |
| 00:02:2D:38:55:D9 |
j29hCAMBERWELL7n2f |
|
No |
| 00:02:2D:38:56:45 |
j29hCAMBERWELL7n2f |
|
No |
| 00:02:2D:3F:B0:D0 |
Apple Network 3fb0d0 |
|
No |
| 00:02:2D:5E:22:9D |
<No ssid> |
|
No |
| 00:02:2D:65:7B:93 |
<No ssid> |
|
Yes |
| 00:02:B3:05:AC:A3 |
Tokio Marine 6631 |
|
No |
| 00:04:76:A5:DD:9F |
3Com |
|
No |
| 00:04:E2:1B:3A:D8 |
WLAN |
|
No |
| 00:04:E2:1B:3A:F1 |
WLAN |
|
No |
| 00:05:5D:D6:C8:14 |
b2Lateral |
|
No |
| 00:06:25:5D:7D:4F |
fworld |
|
Yes |
| 00:06:25:60:12:ED |
linksys |
|
No |
| 00:30:65:17:91:5A |
DSE London 1 |
|
Yes |
| 00:30:65:1D:24:26 |
TMLEWIN |
|
No |
| 00:30:AB:0A:EC:6A |
albany01 |
|
Yes |
| 00:30:AB:0A:F0:B7 |
Wireless |
|
No |
| 00:30:AB:0E:DC:41 |
HamleysWireless |
|
Yes |
| 00:30:AB:0F:B1:48 |
Wireless |
|
Yes |
| 00:30:AB:16:6B:85 |
Wireless |
|
No |
| 00:30:AB:1B:A5:16 |
Atlasventure |
|
No |
| 00:30:AB:1C:04:AA |
Wireless |
|
No |
| 00:30:AB:1F:49:EC |
Wireless |
|
No |
| 00:40:05:C4:BC:2F |
loftnet |
|
Yes |
| 00:40:96:29:75:D2 |
tsunami |
|
No |
| 00:40:96:40:06:8C |
tsunami |
|
No |
| 00:40:96:40:9F:DF |
Montblanc |
|
Yes |
| 00:40:96:42:39:E6 |
lonlab_ap1 |
|
No |
| 00:40:96:43:9B:B5 |
tsunami |
|
No |
| 00:40:96:47:65:9E |
tsunami |
|
No |
| 00:40:96:48:18:2C |
<No ssid> |
|
No |
| 00:40:96:49:C2:00 |
tsunami |
|
Yes |
| 00:40:96:56:21:F5 |
1ns1ghtv01ce |
|
Yes |
| 00:40:96:56:44:C6 |
1ns1ghtv01ce |
|
Yes |
| 00:40:96:56:C1:44 |
tsunami |
|
Yes |
| 00:40:96:57:4F:6A |
t-mobile |
|
No |
| 00:50:DA:01:74:08 |
101 |
|
Yes |
| 00:50:DA:01:F4:E1 |
101 |
|
No |
| 00:50:DA:92:B1:34 |
101 |
|
No |
| 00:50:DA:95:00:35 |
101 |
|
No |
| 00:60:1D:1C:A2:58 |
88036ANB_1 |
|
Yes |
| 00:60:1D:21:9E:D7 |
WaveLAN Network |
|
No |
| 00:60:1D:21:E7:FD |
WaveLAN Network |
|
No |
| 00:60:1D:22:10:00 |
wtgdom |
|
No |
| 00:60:1D:22:28:D7 |
<No ssid> |
|
Yes |
| 00:90:96:16:76:C8 |
ELSA |
|
No |
| 00:A0:F8:3A:63:37 |
CEDSAP |
|
No |
| 00:A0:F8:3A:BC:AE |
CEDSAP |
|
No |
| 00:A0:F8:3A:BC:B2 |
CEDSAP |
|
No |
| 00:A0:F8:3B:BC:D7 |
Iukwap01 |
|
Yes |
| 00:A0:F8:46:41:7B |
8113 |
192.7.1.249 |
No |
| 00:A0:F8:46:41:A4 |
8113 |
|
No |
| 00:A0:F8:4C:C9:1A |
8113 |
|
No |
| 00:A0:F8:4C:C9:39 |
8113 |
|
No |
|