THIS IS A TEST INSTANCE. Feel free to ask and answer questions, but take care to avoid triggering too many notifications.
0

How to identify Rogue Access Point?

Is it possible to identify Rogue Access Point with Wireshark?

Thank You.

vladinko0's avatar
7
vladinko0
asked 2020-03-05 12:45:41 +0000
edit flag offensive 0 remove flag close merge delete

Comments

add a comment see more comments

1 Answer

0

In theory, yes, you can use Wireshark to find rogue APs. With a quality over-the-air (OTA) capture, you can see the various devices in the environment around you. If an AP is behaving in a way that you consider rogue, you would then have identified it.

Note that digging though millions (could be 100s of millions) of frames in an OTA capture can be tedious and there would be limitations: you can only analyze what the OTA capture can see at a given point in time. Large facilities could have 1000+ access points and/or spread over relatively large areas so could be like finding a needle in a haystack. High end wifi systems can often tell you this information directly, or perhaps a specialized tool would be better served here.

Bob Jones's avatar
1.5k
Bob Jones
answered 2020-03-05 13:21:10 +0000
edit flag offensive 0 remove flag delete link

Comments

Are there any criteria, when AP can be considered as a Rogue AP?

vladinko0's avatar vladinko0 (2020-03-05 13:41:07 +0000) edit

Here are some criteria:

https://en.wikipedia.org/wiki/Rogue_access_point

At the frame level, I would like for BSSIDs from APs that I don't know about but are using my ESSID(s), i.e. network names.

Bob Jones's avatar Bob Jones (2020-03-05 14:57:44 +0000) edit
add a comment see more comments

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account. This space is reserved only for answers. If you would like to engage in a discussion, please instead post a comment under the question or an answer that you would like to discuss.

Add Answer