What Is Wardriving And How Can You Prevent It

Imagine a car equipped with nothing more than aare using a default SSID), cloaking is pointless. Due
laptop computer, a portable GPS receiver, and ato this, remember to change your SSID from the
wireless network card slowly strolls through yourfactory default. This is not a 100 percent
neighborhood. Unknown to any onlookers, this iseffective method to secure your network, but it
no ordinary vehicle; rather, it is a wardrivingis a good first line of defense.
machine. As the car strolls past homes andChange the default password. When you buy a
businesses, a wireless network card (available atrouter, a factory password is stored. People
any electronics store for as low as $25) scans forexperienced in working with routers know the
any wireless access points. Anyone with adefault passwords for different routers (and the
wireless network (and there are many out there)make of the router can be seen by wardriver
is vulnerable. The computer is looking for what issoftware such as netstumbler). It is important
called an SSID. An SSID is your wireless networkthat you secure your router with a good
name and it is being constantly transmitted bypassword.
your access point, letting computers know of itsEncrypt your wireless communication. I can't
presence. The wardriver uses software such asstress the importance of encrypting your wireless
Netstumbler (for windows) or Cismet (for linux)communication enough. Enable encryption and
to scan the airwaves for SSIDs. The program canenter a key. Most routers are only capable of
track various access points at once and monitorWEP encryption, but if they permit, use EAP
the signal strength. These programs can alsoencryption, it's more secure than WEP. Like
check to see if the network is encrypted. Thecloaking your SSID, encryption is not 100 percent
wardriver will generally configure his or hersecure. Given enough time and determination, if
software to log any strong unencrypted signals.someone wants to target you and access your
Using the GPS receiver, the coordinates of thenetwork, WEP encryption can be bypassed using
strong signal will be recorded. After thissoftware such as AirSnort.
preliminary drive, the wardriver can return to theFilter the MAC addresses that are allowed to
locations that were recorded, and connect to theconnect to your router. This would require that
access point. Once connected to an unencryptedyou enter your router configuration and input the
network, the wardriver can use the victim'sMAC address of each wireless card you have.
internet access, and can also explore computersThis will restrict access so that only your
on the network. If files are being shared withincomputers can connect to the router. You will
someone's private network, all of that informationneed to obtain the MAC address (which is the
is susceptible to a wardriver. Furthermore, once inindividual identification address of a network card
the network, a wardriver can sniff networkin the form a 12 digit hexadecimal number). If
traffic and can view any information such assomeone sniffs traffic and detects the MAC
passwords and credit card numbers you send outaddress of a computer wirelessly using your
to the internet - even SSL secured data. Wirelessnetwork, the wardriver could emulate that
network vulnerability is a major problem, and asaddress and connect to the router, but this takes
more and more households purchase wirelesstime.
technology, the problem of insecure networksIf you configure file sharing on your computers,
increases. Sound scary? Well this happens everymake sure it is password protected. You should
day, and it doesn't take an expert to pull off. Itnot share files on your networked computers
doesn't take an expert to protect against either,unless it requires an authenticated user to access.
however.Set up the same user accounts on your machines
Steps you can take to protect against wardrivers:so that your computers can share files.
There are a number of very simple steps youWith these relatively simple steps, wireless
can take to protect your wireless network. Fornetwork users can secure their networks from
many of these, you will have to access yourwardrivers. Wireless networks are inherently
router configuration utility (check your manual oninsecure, and these tips will merely help you
how to do this, you will generally need to type angreater secure your network. If someone is really
IP address into your browser such as 192.168.0.1determined to gain access to your network, given
or 192.168.1.1).enough time, a good hacker can get access.
Don't broadcast your SSID. If you areThese tips will deter the average wardriver from
broadcasting your SSID, this is the first thing againing access to your network, however.
program will pickup and recognize. If you configureAlthough these methods are not definite security
your router to not broadcast your SSID, it will bemeasures, they will change your network from
difficult to detect (but not impossible, for somebeing something that can be hacked in a matter
software can sniff wireless communication, so ifof seconds, to something that will take a
you are using your wireless network, the SSIDdetermined hacker days if not weeks of work, all
can be revealed). If you are not broadcastingof which will have to be done while in close
your SSID, but it can be guessed (such as if youproximity to your network.