<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>patrick charles &#187; security</title>
	<atom:link href="http://pchuck.net/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://pchuck.net</link>
	<description>on software, photography, finance and motorsport</description>
	<lastBuildDate>Sun, 20 Nov 2011 04:53:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Downtown Denver Wi-Fi Survey</title>
		<link>http://pchuck.net/security/downtown-denver-wi-fi-survey/</link>
		<comments>http://pchuck.net/security/downtown-denver-wi-fi-survey/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 16:36:58 +0000</pubDate>
		<dc:creator>pchuck</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://pchuck.net/?p=187</guid>
		<description><![CDATA[On July 27th, we carried out a thorough scan of 802.11 networks in downtown Denver. A Columbus V-900 tracking device was used to log location and path, validating that all streets and alleys were traversed. Meanwhile, an iPhone 3G and Wififofum were used to detect and log detected networks, their location, and attributes. The area [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_189" class="wp-caption alignleft" style="width: 310px"><a href="http://pchuck.net/wp-content/uploads/2009/07/downtown_combined_drive.jpg"><img class="size-medium wp-image-189" title="downtown_combined_drive" src="http://pchuck.net/wp-content/uploads/2009/07/downtown_combined_drive-300x252.jpg" alt="Downtown Denver Driving Route" width="300" height="252" /></a><p class="wp-caption-text">Downtown Denver Driving Route</p></div>
<p>On July 27th, we carried out a thorough scan of 802.11 networks in downtown Denver. A Columbus V-900 tracking device was used to log location and path, validating that all streets and alleys were traversed. Meanwhile, an iPhone 3G and Wififofum were used to detect and log detected networks, their location, and attributes.</p>
<p>The area bounded by Speer Blvd to the SW, Broadway to the East, and 20th Avenue to the NE were covered. Total area traversed was approximately 1.4 square miles and 125 square blocks.</p>
<p>9,522 networks were detected in ~200 minutes.</p>
<div id="attachment_194" class="wp-caption alignright" style="width: 310px"><a href="http://pchuck.net/wp-content/uploads/2009/07/downtown_combined_scan.jpg"><img src="http://pchuck.net/wp-content/uploads/2009/07/downtown_combined_scan-300x251.jpg" alt="Downtown Denver&#039;s 9,522 Wifi Networks" title="downtown_combined_scan" width="300" height="251" class="size-medium wp-image-194" /></a><p class="wp-caption-text">Downtown Denver's 9,522 Wifi Networks</p></div>
<h4>Security</h4>
<p>Strong (45%)</p>
<ul>
<li> WPA2: 2418 (25.3%)</li>
<li> WPA: 1843 (19.4%)</li>
</ul>
<p>Weak (55%)</p>
<ul>
<li>WEP: 3294 (34.6%)</li>
<li>None: 1967 (20.7%)</li>
</ul>
<p>11.8% of the networks observed were hiding their ESSID, 88.2% were broadcasting.</p>
<p>On average, a new wifi network was discovered every 1.3s during the scan.</p>
<p>Number of wireless networks per…</p>
<ul>
<li>square mile: 6,800</li>
<li>city block: 75</li>
<li>acre: 11</li>
</ul>
<p>Total population of the scan area is not known. A portion of the area, though, known as the <a href="http://en.wikipedia.org/wiki/Golden_Triangle,_Denver">Golden Triangle</a>, has a population of 630 residents. In that neighborhood, 1506 networks were detected, for a total of 2.4 access points per person.</p>
<p><a href="http://pchuck.net/kml/golden_triangle_wfffLog_a831ad202de66a8eeaaefabec3e723551957e5f5_270449290.165097_1506.kml">Downtown, pass 0 KML, Golden Triangle</a><br />
<a href="http://pchuck.net/kml/downtown_1_wfffLog_a831ad202de66a8eeaaefabec3e723551957e5f5_270450939.155943_2001.kml">Downtown, pass 1 KML, 17th to 20th</a><br />
<a href="http://pchuck.net/kml/downtown_2_wfffLog_a831ad202de66a8eeaaefabec3e723551957e5f5_270454090.525773_2003.kml">Downtown, pass 2 KML, Champa to Court</a><br />
<a href="http://pchuck.net/kml/downtown_3_wfffLog_a831ad202de66a8eeaaefabec3e723551957e5f5_270455764.386294_2005.kml">Downtown, pass 3 KML, Arapahoe to Wynkoop</a><br />
<a href="http://pchuck.net/kml/downtown_4_wfffLog_a831ad202de66a8eeaaefabec3e723551957e5f5_270457801.713739_2007.kml"> Downtown, pass 4 KML, Commons Parks, Speer, Colfax</a></p>
]]></content:encoded>
			<wfw:commentRss>http://pchuck.net/security/downtown-denver-wi-fi-survey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Comprehensive Wi-Fi Network Discovery</title>
		<link>http://pchuck.net/security/comprehensive-wi-fi-network-discovery/</link>
		<comments>http://pchuck.net/security/comprehensive-wi-fi-network-discovery/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 20:09:17 +0000</pubDate>
		<dc:creator>pchuck</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://pchuck.net/?p=132</guid>
		<description><![CDATA[Introduction Since Pete Shipley first pioneered wardriving in the San Franciso-Bay area, many people have cataloged the locations of 802.11 networks around the world. I still remember the excitement, in the early days, driving the streets of downtown with a makeshift antenna, Orinoco &#8216;Gold&#8217; card, and the soft glow of a Thinkpad 600x illuminating the [...]]]></description>
			<content:encoded><![CDATA[<h3> Introduction </h3>
<div id="attachment_147" class="wp-caption alignright" style="width: 310px"><a href="http://pchuck.net/wp-content/uploads/2009/07/sf_default.gif"><img src="http://pchuck.net/wp-content/uploads/2009/07/sf_default-300x200.gif" alt="San Francisco WiFi nodes, circa 2001" title="sf_default" width="300" height="200" class="size-medium wp-image-147" /></a><p class="wp-caption-text">San Francisco WiFi nodes, circa 2001</p></div>
<p>Since Pete Shipley first pioneered wardriving in the San Franciso-Bay area, many people have cataloged the locations of 802.11 networks around the world.</p>
<p>I still remember the excitement, in the early days, driving the streets of downtown with a makeshift antenna, Orinoco &#8216;Gold&#8217; card, and the soft glow of a Thinkpad 600x illuminating the passenger seat. You could often drive several miles before the faint signal of a distant access point would flicker across the screen.</p>
<p>Much has changed since then, as the number and density of networks have exploded.</p>
<div id="attachment_150" class="wp-caption alignleft" style="width: 235px"><a href="http://pchuck.net/wp-content/uploads/2009/07/Seattle_Wi-Fi_map.png"><img src="http://pchuck.net/wp-content/uploads/2009/07/Seattle_Wi-Fi_map-225x300.png" alt="Seattle Wi-Fi nodes, circa 2004" title="Seattle_Wi-Fi_map" width="225" height="300" class="size-medium wp-image-150" /></a><p class="wp-caption-text">Seattle Wi-Fi nodes, circa 2004</p></div>
<p>Also, small hand-held devices like the Nokia n810 and Apple iPhone are able to scan for networks, track location via GPS and log results, in a small and compact form-factor.</p>
<p>Still, though, it seems that few, if any, network surveys published offer truly comprehensive details on all detectable networks within a given area. </p>
<p>A couple of exceptions are a survey of metro Seattle performed by 100 undergraduate students who detected 5,225 networks in 2004 and the annual RSA/EMC wireless security survey of New York, London and Paris which attempts to log, and provide some analysis of, detectable wireless networks within those three cities.</p>
<p>Most other surveys continue to focus their efforts on main arteries and thoroughfares where large numbers of networks can be detected in short amounts of time.</p>
<h3>Approach</h3>
<p>In the following survey, an attempt is made to detect all available 802.11 wireless networks within the target neighborhood by traversing all publicly accessible streets, alleys and side-roads.</p>
<p>A constant and slow travel velocity is maintained to ensure that, given the antenna&#8217;s sensitivity and the detector&#8217;s scan rate, no available networks go undetected.</p>
<p>Multiple passes are made through the neighborhood to verify consistent detection.</p>
<h3>Target</h3>
<div id="attachment_133" class="wp-caption alignright" style="width: 310px"><a href="http://pchuck.net/wp-content/uploads/2009/07/cherry_creek_north_drive_crop.jpg"><img src="http://pchuck.net/wp-content/uploads/2009/07/cherry_creek_north_drive_crop-300x190.jpg" alt="Observation Path - Cherry Creek North" title="cherry_creek_north_drive_crop" width="300" height="190" class="size-medium wp-image-133" /></a><p class="wp-caption-text">Observation Path - Cherry Creek North</p></div>
<p>For my experiment, I chose the <a href="http://en.wikipedia.org/wiki/Cherry_Creek,_Denver">Cherry Creek North</a> neighborhood of Denver, CO.</p>
<p>According to the 2000 US census, the area has a population of 5,028 in 3,198 households. In addition, 320 businesses, mostly restaurants and boutiques, are located on the southern edge of the neighborhood.</p>
<p>The area covers approximately 0.5 square miles, and is <a href="http://maps.google.com/maps?f=q&#038;source=s_q&#038;hl=en&#038;sll=37.0625,-95.677068&#038;sspn=51.708931,53.173828&#038;ie=UTF8&#038;ll=39.721844,-104.949839&#038;spn=0.012378,0.021157&#038;t=h&#038;z=16">bounded by 1st and 6th Avenues to the south and north, and by University and Colorado Blvds to the east and west</a>.</p>
<h3>Discovery</h3>
<p>On July 18th, a test scan was performed. A small segment of the target area was scanned repeatedly on foot, and by car, at various velocities. Results checked for accuracy and completeness.</p>
<p>On July 19th, I carried out a thorough scan of the neighborhood. A Macbook Air and Columbus V-900 tracking device were used to view precise location and path, validating that all streets and alleys were traversed. Meanwhile, an iPhone 3G and <a href="http://www.aspecto-software.com/rw/applications/wififofum/index.html">Wififofum</a> were used to detect and log detected networks, their location, and attributes.</p>
<h3>Results</h3>
<p>The 70 city blocks which make up the neighborhood were covered in just over two hours.</p>
<p>1,948 wireless 802.11 networks were discovered. </p>
<p>11.6% of the networks observed were hiding their ESSID, and 88.4% were broadcasting.</p>
<p>Most of the networks (57%) had weak or non-existent security activated.</p>
<div id="attachment_135" class="wp-caption alignleft" style="width: 310px"><a href="http://pchuck.net/wp-content/uploads/2009/07/cherry_creek_north_aps_crop.jpg"><img src="http://pchuck.net/wp-content/uploads/2009/07/cherry_creek_north_aps_crop-300x185.jpg" alt="WiFi Networks Detected in Cherry Creek North" title="cherry_creek_north_aps_crop" width="300" height="185" class="size-medium wp-image-135" /></a><p class="wp-caption-text">WiFi Networks Detected in Cherry Creek North</p></div>
<h4>Security</h4>
<p>Strong (43%)</p>
<ul>
<li>WPA2: 422 (21.7%)</li>
<li>WPA: 406 (20.8%)</li>
</ul>
<p>Weak (57%)</p>
<ul>
<li>WEP: 797 (40.9%)</li>
<li>None: 324 (16.6%)</li>
</ul>
<p>The location of the highest network density along the scanning path was detected at the intersection of 3rd Ave and Fillmore St, where 65 networks were detected simultaneously.</p>
<h3>Summary</h3>
<p>1,948 networks were detected in 2 hours, 29s within a 70 block area (0.48 square miles).</p>
<p>On average, a new network was detected every 3.7s during the scan.</p>
<p>Number of wireless networks per&#8230;</p>
<ul>
<li> square mile: 4,091 </li>
<li> city block: 28 </li>
<li> acre: 6 </li>
</ul>
<p>Let&#8217;s compare with the <a href="http://www.rsa.com/solutions/wireless/survey/WLANNY_WP_1008.pdf">2008 RSA/EMC study of New York City</a>.</p>
<p>Their scan detected 9,227 networks and covered a 16 square mile area (conservative estimate) which included &#8220;the entire area of Manhattan, including Brooklyn, Manhattan and Williamsburg Bridges&#8221;.</p>
<p>That&#8217;s 576 access points per square mile, or less than 1/5th the density observed in the Cherry Creek North neighborhood.</p>
<p>It is doubtful that Cherry Creek North has a significantly more dense distribution of WiFi networks than Manhattan. More likely, the survey presented here is more comprehensive in its coverage. </p>
<p>The results show that, by using a rigorous scanning process, which utilizes multiple passes and takes into account the sensitivity and operational characteristics of the detector, network survey accuracy can be drastically increased.</p>
<p>In this survey, 1 wireless network was detected per every 2.5 residents in the neighborhood. </p>
<p>I have not been able to find any other documented survey which shows a higher density of access points per person or square mile.</p>
<p>If you&#8217;d like to view the results in Google Earth&#8230; click:<br />
<a href='http://pchuck.net/kml/cherry_creek_north.kml'>Cherry Creek North WiFi Scan KML</a></p>
]]></content:encoded>
			<wfw:commentRss>http://pchuck.net/security/comprehensive-wi-fi-network-discovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>java portscanner</title>
		<link>http://pchuck.net/security/java-portscanner/</link>
		<comments>http://pchuck.net/security/java-portscanner/#comments</comments>
		<pubDate>Sat, 02 May 1998 17:40:34 +0000</pubDate>
		<dc:creator>pchuck</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://pchuck.net/?p=366</guid>
		<description><![CDATA[net.ultrametrics.security.PortScanner is a command-line utility to scan for tcp services on a range of ports on a host or on a range of hosts. Usage Usage: PortScanner [OPTIONS] hostname [hostname2] optional parameters are: -l port# &#124; --low port# low port number -h port# &#124; --high port# high port number -t n &#124; --threadlimit n spawn [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-family: comic sans ms,helvetica; font-size: xx-small;">net.ultrametrics.security.PortScanner </span> <span style="font-family: comic sans ms,helvetica;"> is a command-line utility to scan for tcp services on a range of        ports on a host or on a range of hosts. </span></p>
<h3><strong>Usage</strong></h3>
<p><span><span style="font-family: courier;"> </span></span></p>
<pre>  Usage: PortScanner [OPTIONS] hostname [hostname2]

    optional parameters are:

      -l port# | --low port#        low port number
      -h port# | --high port#       high port number
      -t n     | --threadlimit n    spawn n threads
      -v       | --verbose          verbose output

 Concurrently scans, using at maximum the number of threads specified,
 for hosts between 'hostname' and 'hostname2' which are accepting tcp
 connections on ports between the low and high ports specified.

 If 'hostname2' is not specified, only 'hostname' is probed.

   i.e. <em>java net.ultrametrics.security.PortScanner 10.0.0.0 10.0.0.255</em></pre>
<p>&nbsp;</p>
<h3><strong>Download</strong></h3>
<ul>
<li>source: <a href="http://www.ultrametrics.net/java/sources_net.ultrametrics.security-0.01.jar">sources_net.ultrametrics.security-0.01.jar</a></li>
<li>classes: <a href="http://www.ultrametrics.net/java/classes_net.ultrametrics.security-0.01.jar">classes_net.ultrametrics.security-0.01.jar</a></li>
<li>javadoc: <a href="http://www.ultrametrics.net/java/javadoc_net.ultrametrics.security-0.01.jar">javadocs_net.ultrametrics.security-0.01.jar</a></li>
</ul>
<p>&nbsp;</p>
<h3>Browse</h3>
<ul>
<li><a href="http://www.ultrametrics.net/java/docs/net.ultrametrics.security/index.html">javadoc</a></li>
</ul>
<p>&nbsp;</p>
<p><em>note: jar files provided are compatible with the jar tool packaged with jdk1.2 and later. </em></p>
]]></content:encoded>
			<wfw:commentRss>http://pchuck.net/security/java-portscanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

