Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 50 guests and 2 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Wireless
Trackingdown via Wardriving
EH-Net
May 22, 2013, 05:39:45 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Wireless
(Moderator:
don
) >
Trackingdown via Wardriving
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Trackingdown via Wardriving (Read 11573 times)
0 Members and 1 Guest are viewing this topic.
maver
Newbie
Offline
Posts: 3
Trackingdown via Wardriving
«
on:
June 22, 2011, 10:18:33 AM »
Hi, as you can tell him new here. I'm pretty sure this is the forum I should put this in.
So I started searching google for help and this forum kept poping up over and over and looked like the perfect place to go because I wasn't getting very far in getting my question answered.
My friend's laptop was stolen. He has all the guy's personal information, name age which highschool he went to, what his external IP is ect. (he has logmein on the computer) problem is the guy turns the laptop off when he's not using it. So my friend sits there everyday and watching him on the laptop trying to find a moment to grab the laptop and use it real quick. It's a win7 machine with some antivirus. He moused over the network icon and saw he was attached to linksys.
Which is a bummer through tracing his external IP we know the neighborhood, and planned on going wardriving to hunt for the SSID, but with it being linksys we're gonna get a few results.
Now I know that using netsh in win7 you can do something like a show wlan /all and get the mac address for the wireless network so we can pinpoint it. but as well. but with it possibly being an old linksys do you guys know if maybe I could do something to like get the netbios against the internet address to get the mac that way. As a moment of time to type commands on the laptop hasn't presented it's self?
Thank you very much apologies if I've put this in the wrong category.
Logged
El33tsamurai
Full Member
Offline
Posts: 192
Re: Trackingdown via Wardriving
«
Reply #1 on:
June 22, 2011, 10:45:34 AM »
My friend's laptop was stolen.
If he knows where it is why does he just not go to the police?
He has all the guy's personal information, name age which highschool he went to, what his external IP is ect. (he has logmein on the computer) problem is the guy turns the laptop off when he's not using it.
How does he have all this informtion?
So my friend sits there everyday and watching him on the laptop trying to find a moment to grab the laptop and use it real quick. It's a win7 machine with some antivirus. He moused over the network icon and saw he was attached to Linksys.
Did he break into the guys house to get this information? This guy is running a Linksys router without changing the SSID?
Which is a bummer through tracing his external IP we know the neighborhood, and planned on going wardriving to hunt for the SSID, but with it being linksys we're gonna get a few results.
How did you get his external IP? If you know his external IP there is no need to war drive
.
Now I know that using netsh in win7 you can do something like a show wlan /all and get the mac address for the wireless network so we can pinpoint it.
Why are you using windows 7? Linux is needed makes life much easier. This wont work unless you are connected to his network and if its secured which I am sure it is, it is not going to be easy.
but as well. but with it possibly being an old linksys do you guys know if maybe I could do something to like get the netbios against the internet address to get the mac that way. As a moment of time to type commands on the laptop hasn't presented it's self?
Now with all that said. Are you trying to gain access to your friends laptop in this other guys house? If so why are you trying to do this? If the laptop is his does he have proof its his? If so call the cops and get it back.
Logged
CCENT, A+, Network+, Security+
maver
Newbie
Offline
Posts: 3
Re: Trackingdown via Wardriving
«
Reply #2 on:
June 22, 2011, 11:04:29 AM »
We don't have the address that's what we're trying to get.
Got his external IP because i think my friend has rainmeter has as it shown on the desktop.
The rest of the information he got while watching him sign up for dating websites I think.
With the external IP we're still waiting on comcast to get back to us wit the address but it's doesn't appear to be happening anytime soon.
And in order to get a warrant to search the house we first need to know which house it is. With the external IP we only have it traced down to the rough location. So with wardriving we were hopping to find it narrow it down to the exact address, then present it to the police (who we've already reported too) hopefully giving them enough evidence that they can get a warrant.
Of course because the cops only have loose evidence they refuse to move or do anything. As well I believe this guy is a minor so he's name isn't in records.
So that leads me back to us trying to pin point the house. Because we know which neighborhood it is. I figured best way was through wifi because he is connected wirelessly but the SSID is linksys so my next move was to see if we could find the mac of that linksys (hopefully from the internet via his external ip) because we don't want to scare the guy into ditching the laptop by suddenly taking control of it and him shutting it off right away.
so thats why I was asking if there was something I could do to discover that linksys mac via WAN
Logged
maver
Newbie
Offline
Posts: 3
Re: Trackingdown via Wardriving
«
Reply #3 on:
June 22, 2011, 11:07:45 AM »
Quote from: El33tsamurai on June 22, 2011, 10:45:34 AM
He has all the guy's personal information, name age which highschool he went to, what his external IP is ect. (he has logmein on the computer) problem is the guy turns the laptop off when he's not using it.
How does he have all this informtion?
Like I said in my post LogMeIn, it's a remote desktop service. So we do have remote control of the laptop but the guy never leaves it on, only has it on when he uses it.
And I'd imagine if we just started controlling the desktop he would shut off the computer and ditch it. So we've only been using it for watching.
Logged
dmuzial
Guest
Re: Trackingdown via Wardriving
«
Reply #4 on:
June 22, 2011, 11:10:08 AM »
I'm the owner of the laptop. A report was made to the police 3.5 weeks ago, but the cops can't get information from the High school because CPS schools seal student records to everyone until the student graduates (Even to CPD, unless the student gets into an altercation on campus where Police have to get involved)
Subpoenaed Comcast 3 weeks ago, and it takes 12 days to process a subpoena, but when I called the cop yesterday asking about the subpoena status, he asked me what subpoena? And then tried to say he had submitted it weeks ago but Comcast had not gotten back to him yet. So I’m assuming that this is a dead end.
I got the information by recording what he does on the computer using Logmein Central. But, to date, he has yet to do anything with an address, just mostly facebook and pron.
The goal of this is to get the address, or a contact number for the home so the police can reclaim the laptop and possibly some of the other 5 grand in equipment that was stolen. I've got access to the command prompt (Logmein Central allows you to run it in the background), a way to drop files into the computer and the ability to remote control the laptop.
Open to basically anything, I just want my stuff back.
Logged
El33tsamurai
Full Member
Offline
Posts: 192
Re: Trackingdown via Wardriving
«
Reply #5 on:
June 22, 2011, 11:14:46 AM »
Quote from: maver on June 22, 2011, 11:07:45 AM
Quote from: El33tsamurai on June 22, 2011, 10:45:34 AM
He has all the guy's personal information, name age which highschool he went to, what his external IP is ect. (he has logmein on the computer) problem is the guy turns the laptop off when he's not using it.
How does he have all this informtion?
Like I said in my post LogMeIn, it's a remote desktop service. So we do have remote control of the laptop but the guy never leaves it on, only has it on when he uses it.
And I'd imagine if we just started controlling the desktop he would shut off the computer and ditch it. So we've only been using it for watching.
Sorry I missed that part, was reading fast
Logged
CCENT, A+, Network+, Security+
El33tsamurai
Full Member
Offline
Posts: 192
Re: Trackingdown via Wardriving
«
Reply #6 on:
June 22, 2011, 11:19:38 AM »
Quote from: dmuzial on June 22, 2011, 11:10:08 AM
I'm the owner of the laptop. A report was made to the police 3.5 weeks ago, but the cops can't get information from the High school because CPS schools seal student records to everyone until the student graduates (Even to CPD, unless the student gets into an altercation on campus where Police have to get involved)
Subpoenaed Comcast 3 weeks ago, and it takes 12 days to process a subpoena, but when I called the cop yesterday asking about the subpoena status, he asked me what subpoena? And then tried to say he had submitted it weeks ago but Comcast had not gotten back to him yet. So I’m assuming that this is a dead end.
I got the information by recording what he does on the computer using Logmein Central. But, to date, he has yet to do anything with an address, just mostly facebook and pron.
The goal of this is to get the address, or a contact number for the home so the police can reclaim the laptop and possibly some of the other 5 grand in equipment that was stolen. I've got access to the command prompt (Logmein Central allows you to run it in the background), a way to drop files into the computer and the ability to remote control the laptop.
Open to basically anything, I just want my stuff back.
1)
http://www.whatismyip.com/tools/ip-address-lookup.asp
2) get the ISP
3) call the ISP you got the guys last name
4) get the address from the ISP
Logged
CCENT, A+, Network+, Security+
dmuzial
Guest
Re: Trackingdown via Wardriving
«
Reply #7 on:
June 22, 2011, 11:25:21 AM »
I wish. But the ISP wont disclose that information without a Subpoena and I don't have enough information about him to BS my way through it.
Logged
El33tsamurai
Full Member
Offline
Posts: 192
Re: Trackingdown via Wardriving
«
Reply #8 on:
June 22, 2011, 11:42:53 AM »
Well doing that would be wrong and get you into trouble. You know who the kid is from the school right, could you ask the school for his address? maybe find it on his facebook page?
Logged
CCENT, A+, Network+, Security+
jsm725
Newbie
Offline
Posts: 36
Re: Trackingdown via Wardriving
«
Reply #9 on:
June 22, 2011, 11:57:49 AM »
People tend to focus too much on the technical side of recon. Sometimes you need to think outside of the box.
I am assuming he is living at home since he is a minor. So you should be able to look up his parents property tax info by last name, which would give you an address. Completely free information that can be obtained legally on the internet.
If you know what this guy looks like (facebook and dating sites usually have pictures) and his general location...why not just do some old fashion detective work and stake out the neighborhood? Wait till you see him and figure out which house he goes into. Completely legal since you are observing people in a public place. Just don't go looking through windows.
Logged
CISSP, PCI-QSA, OSWP
El33tsamurai
Full Member
Offline
Posts: 192
Re: Trackingdown via Wardriving
«
Reply #10 on:
June 22, 2011, 01:14:07 PM »
Good call on the tax info, you are right sometimes get to excited and forget about the simple stuff :-D
Logged
CCENT, A+, Network+, Security+
dmuzial
Guest
Re: Trackingdown via Wardriving
«
Reply #11 on:
June 22, 2011, 03:15:35 PM »
How would I search tax information by name? Ideas/links?
Logged
tturner
Sr. Member
Offline
Posts: 432
Re: Trackingdown via Wardriving
«
Reply #12 on:
June 22, 2011, 04:10:57 PM »
I'd recommend county property records. For instance, Google "<county name> <state name> county property search". Here's an example:
http://www.brevardpropertyappraiser.com/asp/record.asp
http://www.spokeo.com/
and
http://www.intelius.com/
are also very useful. I like using Tineye as well if I have a photo or link to a photo of someone. it will show you other instances of the same photo on the net. If photos are geotagged you can download the images and harvest GPS coordinates from the EXIF data. maybe try
http://www.sno.phy.queensu.ca/~phil/exiftool/
You can also sometimes get registrant address info from Whois lookups if the guy has a domain. I also like Maltego a lot but I've never used it for a private party so not sure how useful it will be here. For domains and companies it's amazing.
Google groups is a great resource for recon as well. Especially if you know the guys common handles. Doubt it will give you address but might complete the picture for you or give you new avenues to check.
Lastly, one of my new favorites is FOCA from
http://www.informatica64.com/FOCA/
. Might not be much help here b ut I include it for general reference. It queries search engines for a target domain for downloadable files like pdf, doc, etc and then harvests the metadata from the files. I've found internal usernames, dns info, server names, IP addresses, installed applications (Adobe Acrobat 6?! Sweet!) and various other juicy info.
«
Last Edit: June 22, 2011, 04:20:48 PM by tturner
»
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
El33tsamurai
Full Member
Offline
Posts: 192
Re: Trackingdown via Wardriving
«
Reply #13 on:
June 22, 2011, 04:39:08 PM »
Thanks, for the good sites man I will add them to my arsenal!
Logged
CCENT, A+, Network+, Security+
WCNA
Full Member
Offline
Posts: 187
Re: Trackingdown via Wardriving
«
Reply #14 on:
June 23, 2011, 09:19:57 PM »
Because you have remote access to the computer, you should be able to find what is in the preferred network list for the wireless interface. With that info, you can run airbase-ng when you do your wardriving and with a directional antenna pinpoint the exact location. You should look at the wireless megaprimer series at securitytube.net if you need help figuring out what I'm talking about.
Logged
ISC2 Associate, WCNA, CWNA, OSCP, Network+
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News from the Outside World
: Google Dropping Windows For Internal Use
(10) by
Loyatoitada
Special Events
: [Article]-Video: Deep Dive into Red Teaming with the Metasploit Framework
(4) by
BeecyGorror
Security
: christian louboutin cheap artic5843
(0) by
fufig388
Special Events
: [Article]-Survey of Hacking Movies: Framing the Debate on the Gateway Drug into the H...
(14) by
BeecyGorror
/root
: [Article]-Course Review: CPT by InfoSec Institute
(1) by
BeecyGorror
Ethical Hacktivism
: Paranoid parents messing with routers
(21) by
BeecyGorror
Compliance, Regulations & Standards
: SABSA - Sherwood Applied Business Security Architecture
(1) by
BeecyGorror
News Items and General Discussion About EH-Net
: What does EthicalHacker.net bring you?
(12) by
BeecyGorror
News Items and General Discussion About EH-Net
: Burberry UK,2013 Burberry Safety-valve Online Available in London
(13) by
BeecyGorror
News Items and General Discussion About EH-Net
: louis vuitton handbags mhf
(0) by
Vamscoora
Calendar Of Events
: ChicagoCon 2008f
(3) by
BeecyGorror
News Items and General Discussion About EH-Net
: "Free Monthly Giveaways" - Details
(22) by
BeecyGorror
ChicagoCon 2007
: s going to be critical to have universal identity in order for these systems to talk ...
(0) by
Loyatoitada
Malware
: New zero-day exploit for Internet Explorer 7, 8, and 9 on Windows XP, Vista & 7
(13) by
BeecyGorror
Special Events
: [Article]-Webcast: Deep Dive into Red Teaming with the Metasploit Framework
(19) by
BeecyGorror
News Items and General Discussion About EH-Net
: but it needs more help: they Sac Louis Vuitton
(0) by
Loyatoitada
Greetings
: but the desperate effort that comes from being hopeful Nike Blazers Uk
(0) by
Loyatoitada
ChicagoCon 2007
: waterfall Cheap Air Max Sale
(0) by
Loyatoitada
News Items and General Discussion About EH-Net
: The advent of the web happened slowly Nike Blazer Uk
(0) by
Loyatoitada
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.