wireless router security question

This is a discussion on wireless router security question within the Linux Security forums, part of the System Security and Security Related category; I have a Netgear MR 314 wireless router, but for various reasons we are not at the moment using the ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-16-2004
Richard Kimber
 
Posts: n/a
Default wireless router security question

I have a Netgear MR 314 wireless router, but for various reasons we are
not at the moment using the wireless facility, but are using it as a
hard-wired router.

About every two minutes the wireless activity light is illuminated. Is
this just the router checking whether there are any nearby wireless
stations, or could it be someone trying to access the system? I can't see
any info on this in the manual, other than a statement that implies that
when the light goes on a connection is made.

- Richard.

--
Richard Kimber
http://www.psr.keele.ac.uk/

Reply With Quote
  #2 (permalink)  
Old 07-16-2004
Alexander Harsch
 
Posts: n/a
Default Re: wireless router security question

Richard Kimber wrote:

> I have a Netgear MR 314 wireless router, but for various reasons we are
> not at the moment using the wireless facility, but are using it as a
> hard-wired router.
>
> About every two minutes the wireless activity light is illuminated. Is
> this just the router checking whether there are any nearby wireless
> stations, or could it be someone trying to access the system? I can't see
> any info on this in the manual, other than a statement that implies that
> when the light goes on a connection is made.
>
> - Richard.
>

Hi,

is this a linux router? If so, use tcpdump. Besides, if you haven't shut the
interface down explicitly, AFAIK it sends discovery packets from time to
time. You can usually configure the intervall length of these discovery
packets.

Alex
Reply With Quote
  #3 (permalink)  
Old 07-17-2004
Richard Kimber
 
Posts: n/a
Default Re: wireless router security question

On Fri, 16 Jul 2004 17:37:40 +0200, Alexander Harsch wrote:

> Richard Kimber wrote:
>
>> I have a Netgear MR 314 wireless router, but for various reasons we are
>> not at the moment using the wireless facility, but are using it as a
>> hard-wired router.
>>
>> About every two minutes the wireless activity light is illuminated. Is
>> this just the router checking whether there are any nearby wireless
>> stations, or could it be someone trying to access the system? I can't
>> see any info on this in the manual, other than a statement that implies
>> that when the light goes on a connection is made.
>>
>> - Richard.
>>

> Hi,
>
> is this a linux router? If so, use tcpdump. Besides, if you haven't shut
> the interface down explicitly, AFAIK it sends discovery packets from
> time to time. You can usually configure the intervall length of these
> discovery packets.


Thanks. tcpdump seems to point to it being the router if I interpret this
correctly.:-

12:19:37.521345 IP 192.168.0.1 > ALL-SYSTEMS.MCAST.NET: igmp query v2
12:19:37.522467 IP 192.168.0.1 > DHCP-AGENTS.MCAST.NET: igmp v2 report
DHCP-AGENTS.MCAST.NET

I don't think there's a way of switching off the wireless function.

--
Richard Kimber
http://www.psr.keele.ac.uk/

Reply With Quote
  #4 (permalink)  
Old 07-17-2004
Alexander Harsch
 
Posts: n/a
Default Re: wireless router security question

Richard Kimber wrote:

> On Fri, 16 Jul 2004 17:37:40 +0200, Alexander Harsch wrote:
>
>> Richard Kimber wrote:
>>
>>> I have a Netgear MR 314 wireless router, but for various reasons we are
>>> not at the moment using the wireless facility, but are using it as a
>>> hard-wired router.
>>>
>>> About every two minutes the wireless activity light is illuminated. Is
>>> this just the router checking whether there are any nearby wireless
>>> stations, or could it be someone trying to access the system? I can't
>>> see any info on this in the manual, other than a statement that implies
>>> that when the light goes on a connection is made.
>>>
>>> - Richard.
>>>

>> Hi,
>>
>> is this a linux router? If so, use tcpdump. Besides, if you haven't shut
>> the interface down explicitly, AFAIK it sends discovery packets from
>> time to time. You can usually configure the intervall length of these
>> discovery packets.

>
> Thanks. tcpdump seems to point to it being the router if I interpret this
> correctly.:-
>
> 12:19:37.521345 IP 192.168.0.1 > ALL-SYSTEMS.MCAST.NET: igmp query v2
> 12:19:37.522467 IP 192.168.0.1 > DHCP-AGENTS.MCAST.NET: igmp v2 report
> DHCP-AGENTS.MCAST.NET
>
> I don't think there's a way of switching off the wireless function.
>

So, what does ifdown ethx do? Just to make sure, you can use iptables to
block everything incoming and everything outgoing. Regards, Alex
Reply With Quote
  #5 (permalink)  
Old 07-18-2004
Richard Kimber
 
Posts: n/a
Default Re: wireless router security question

On Sat, 17 Jul 2004 17:08:09 +0200, Alexander Harsch wrote:


>>>> About every two minutes the wireless activity light is illuminated. Is
>>>> this just the router checking whether there are any nearby wireless
>>>> stations, or could it be someone trying to access the system? I can't
>>>> see any info on this in the manual, other than a statement that implies
>>>> that when the light goes on a connection is made.


>> Thanks. tcpdump seems to point to it being the router if I interpret this
>> correctly.:-
>>
>> 12:19:37.521345 IP 192.168.0.1 > ALL-SYSTEMS.MCAST.NET: igmp query v2
>> 12:19:37.522467 IP 192.168.0.1 > DHCP-AGENTS.MCAST.NET: igmp v2 report
>> DHCP-AGENTS.MCAST.NET
>>
>> I don't think there's a way of switching off the wireless function.
>>

> So, what does ifdown ethx do? Just to make sure, you can use iptables to
> block everything incoming and everything outgoing. Regards, Alex


It closes my internet connection.

As I understand it, the router blocks all attempts to connect from the
outside (I haven't opened any ports) and the Suse iptables firewall on my
machine only allows pop3 connection from a second (Windows) machine on
the internal side of the router's firewall.

--
Richard Kimber
http://www.psr.keele.ac.uk/

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 02:14 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0