Re: Locate wifi client Oct 16 2013 03:54AM
ToddAndMargo (ToddAndMargo zoho com)
Re: Locate wifi client.eml
Re: Locate wifi client
ToddAndMargo <ToddAndMargo (at) zoho (dot) com [email concealed]>
10/10/2013 07:23 PM
security-basics (at) securityfocus (dot) com [email concealed]

On 10/09/2013 09:32 AM, Robert Larsen wrote:
> Hi
> Anybody knows about hardware/software used for locating a wifi client?
> Somebody is downloading torrents at full speed on our network and nobody
> will admit it (or simply stop), and we really don't want to restrict
> network usage since there are many legal stuff on torrent sites too so
> is there a way of finding a client with a specific mac address?
> What will I need?
> Robert

Hi Robert.

You are probably compromized from the outside. There
are jerks that love doing that so they can hide their

If it is coming from the inside, the culprit
won't be able to get his job done -- too much goofing
off. Their supervisor's will notice.

This is what I would do:

I presume you have a Linux computer at your
disposal? I like this one:
You can try it as a live CD first. (It really
is a CD, not a DVD.)

1) make sure your Wireless access point (WAP) is using
a good security protocol, such as WPA2. Note that
WEP is virtuall no security at all. Change the
logon password to the WAP, to keep other out
and finding out the WPA2 passphrase.

2) change your WPA2 passphrase (password) to
something 12 characters or longer. I find that
phrases are easier for folks to remember.
Love latin phrases. And don't tell anyone.
Let them come to you.

3) See who is on your network with nmap. The "#"
means root user:

# nmap -sP your_network

On mine network:
# nmap -sP

Starting Nmap 6.25 ( ) at 2013-10-10 19:11 PDT
Nmap scan report for
Host is up (0.0022s latency).
MAC Address: 00:18:3A:18:5E:8E (Westell Technologies)
Nmap scan report for
Host is up.
Nmap scan report for
Host is up (0.012s latency).
MAC Address: 00:0D:4B:89:26:47 (Roku)
Nmap scan report for
Host is up (0.013s latency).
MAC Address: 00:0D:4B:5A:6C:1B (Roku)
Nmap done: 256 IP addresses (4 hosts up) scanned in 15.86 seconds

You can also try the -Pn to disable ping. A lot
of person firewalls block ping (ICMP).

Love to know what you find.


Computers are like air conditioners.
They malfunction when you open windows


