Jump to content

Recommended Posts

Posted

Hi, we recently had a Trapeze RingMaster managed wireless system installed to our school.

Every few weeks, I check my dhcp address leases on our RM CC4 server, and I keep seeing matts-iphone.local appearing.

 

None of the staff have been given our wireless codes, they are strictly for the school laptops, and I am the only person who has or knows our encrypted key.

The fact the name says iphone leads me to believe they can't be plugging in directly to the network and must be using our wireless.

 

How can I monitor this. I have deleted the dhcp lease this afternoon and within 10 minutes, it was back, so clearly this is still active. I have had a good look on the RingMaster software and tried running reports with the mac address in question, but it is coming back with nothing. Maybe I am doing it wrong?

Is there anything else I could try to try and work out how this node is connecting and from where?

 

Thanks :D

Posted

That's a good point and I have had a good check around the building to make sure there are no devices plugged in. I hadn't thought of that, I thought maybe someone had brought a laptop in and plugged it in via Ethernet but named it iphone?

 

The RingMaster system is supposed to give me an alarm for rouge ap's and it has nothing listed in alarms.

Posted

You can (depending on how well the map was done) get a rough idea where the device is in respect to the school map.

Our map was only a bmp rather than a scaled full on diagram, so can be abit off at times.

 

I'm with plexer. We had (on old wireless) a member of staff plugged in there own AP.. and students was using that to connect there PSP's etc.

  • Thanks 1
Posted
That's a good point and I have had a good check around the building to make sure there are no devices plugged in. I hadn't thought of that, I thought maybe someone had brought a laptop in and plugged it in via Ethernet but named it iphone?

 

The RingMaster system is supposed to give me an alarm for rouge ap's and it has nothing listed in alarms.

 

We are always getting alarms for Rogue AP's, that when checked via "Rogue AP locator" (or whatever its called), its always in the homes that are close to the school grounds.

 

We have thought about settings some of the AP's into counter-measure mode, but think its not quite needed atm.

  • Thanks 1
Posted

If you are running 2003 on your dhcp server you can install the mac filter callout dll to deny based on mac address or if you are using 2008 it is allready built in to dhcp.

 

Ben

  • Thanks 1
Posted (edited)
How can I do that, I wasn't aware you could do it. Could I make a reservation and give a duff address?

 

Exactly... Dead easy and will proper annoy them lol

 

Opps, i forgot, i have a dead ip range setup on my network assigned to dodgy mac addresses....

Edited by accura2000
  • Thanks 1
Posted

Very clever! I have just created one now. I gave them an IP of 169.254.0.1 that should put a stop to them using our network however they are! In the mean time, I will investigate further!

 

Thanks again.

Posted

HI

 

You could put a reservation in dhcp with the mac address of the item with a silly ip and that will annoy them. Or you could put netstumbler on a laptop to find the access point. Or find the access point in dhcp put a silly reservation in for that.

 

Just an idea.

 

Richard

  • Thanks 1
Posted
None of the staff have been given our wireless codes, they are strictly for the school laptops, and I am the only person who has or knows our encrypted key.

Could someone have extracted it from the laptops? There are plenty of tools out there to do this, though I think you need admin rights most of the time. (Possibly not with XP).

Posted

How are you determining they're "using" the Wifi?

 

A dhcp lease for an unknown device simply means your wireless controller / AP has handed out a lease (or proxied a lease from your dhcp server) as part of the handshake authentication process. That's normal - it doesn't mean they have access.

 

Assuming your wireless is secured properly and you're using decent passwords, I wouldn't worry too much. If the kid's persistently messing about, find which matthew owns an iPhone and if he's messing about with it mid-lesson it'll get confiscated.

Posted
Are you running windows 7 clients? If so that secure wireless key is as secure as anyone allowed to use the client...
Posted

This all depends how your Trapeze / specific SSIDs are set up... ours uses PEAP, certificate exchange, AD Authentication (ie: for a machine to be allowed onto the WiFi network it must reside in a specific GPO in AD and therefore must be a domain member).

 

Do you have a plain WEP / WPA SSID set up on Ringmaster that allows access with just a key? If not, don't worry about folk sniffing out the key.

 

Do you have Guest Access enabled which allows mobile devices on after being presented with a login screen via Ringmaster's WebPortal which authenticates the user against AD prior to allowing access? If so, they could be legitimately getting on that way... disable it.

 

Also, it could be a jailbroken iPhone hooked up via cable to any Mac or PC, or by bluetooth... running appropriate tethering software, meaning the issue is nothing to do with Wireless, and is simply someone bridging thru their desktop PC - do your staff / students have access to enable bluetooth on school laptops / iMacs etc?

 

Your Trapeze support provider would be the best folks to speak to about how your WiFi setup was done, and how to go about tracking rogue machines based on that.

  • Thanks 1
Posted
even though they have an IP doesnt mean they can do any browsing right ?? Surely they'd have to have your proxy settings setup to even get on the internet (and authentication) and they wouldnt be able to browse the Network as they'd have to have a login to access any resources - not that I think you can on an IPhone anyway.
Posted
Various iPhone apps allow access to various windows network resources such as network shares etc, but if these resources require authentication then the app will also require those auth details.
  • Thanks 1
Posted
How are you determining they're "using" the Wifi?

 

A dhcp lease for an unknown device simply means your wireless controller / AP has handed out a lease (or proxied a lease from your dhcp server) as part of the handshake authentication process. That's normal - it doesn't mean they have access.

 

Assuming your wireless is secured properly and you're using decent passwords, I wouldn't worry too much. If the kid's persistently messing about, find which matthew owns an iPhone and if he's messing about with it mid-lesson it'll get confiscated.

 

Hi, thanks for your post.

All ethernet ports run through a gigabit stack. I have looked for the mac on the stack and there is nothing in any of the logs.

Also the hostname "xyz's-iphone" was a hint it had to be wireless.

As far as I know, iPhones can't connect via ethernet. Although you could easily change your hostname on a pc to "robs-iphone" I guess.

 

I have made a duff reservation for it's mac as mentioned above. Not had a chance to check the dhcp leases yet!

Posted
even though they have an IP doesnt mean they can do any browsing right ?? Surely they'd have to have your proxy settings setup to even get on the internet (and authentication) and they wouldn't be able to browse the Network as they'd have to have a login to access any resources - not that I think you can on an IPhone anyway.

 

True, but we are in London and on LGFL like most schools in this area. A little bit of knowledge and Google searching would soon reveal the famous proxy1.equinox poxy details currently used in most London schools.

 

That's the internet taken care of. But true, they would not get access to any other resources, as Marci said, you would require auth details.

Posted
Also the hostname "xyz's-iphone" was a hint it had to be wireless.

As far as I know, iPhones can't connect via ethernet. Although you could easily change your hostname on a pc to "robs-iphone" I guess.

 

I'm still betting jailbroken phone bluetooth-tethered (or via USB cable) to a laptop and bridging onto the network via that (using iBluever or similar app off cydia)...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...