RE: Netstumbling

From: Ken Kousky (kkousky@ip3inc.com)
Date: Wed Mar 05 2003 - 12:04:06 EST


Don't have the answers you're looking for ...but more questions. I've
heard from many professionals that various state wiretapping laws
consider sniffing, be it wireless or simply dsniff, a form of
wiretapping and it is illegal. Not sure of the legal consequences
either. For the most part, wiretapping restrictions were targeted at LE
and the admissibility of evidence. When individuals do it, I'm not clear
if it is a criminal or civil act...but would love to hear more from
anybody with knowledge in this area.

KWK

-----Original Message-----
From: stonewall [mailto:stonewall@cavtel.net]
Sent: Wednesday, March 05, 2003 9:15 AM
To: pen-test@securityfocus.com
Subject: Netstumbling

HI, I need some advice.

I am interested in the reaction that list members have gotten from
various
government agencies while netstumbling. Is there any clear guidance on
the
legality of 'stumbling? I am talking here about just 'stumbling, not
set to
auto reconfigure the card, just assessment and locating WAPs.

You cannot be in the security business without being able to assess
threats.
In this business, paranoia is not paranoia, it is due diligence. I
believe
that anyone serious about security must be able to assess wireless
zones,
overlapping areas, buildings with multiple WAPs, etc. But have you been
threatened by LE personnel in the process?

Thanks in advance for your info.

stonewall

------------------------------------------------------------------------

----
Are your vulnerability scans producing just another report?
Manage the entire remediation process with StillSecure VAM's
Vulnerability Repair Workflow.
Download a free 15-day trial:
http://www2.stillsecure.com/download/sf_vuln_list.html
----------------------------------------------------------------------------
Are your vulnerability scans producing just another report?
Manage the entire remediation process with StillSecure VAM's
Vulnerability Repair Workflow.
Download a free 15-day trial:
http://www2.stillsecure.com/download/sf_vuln_list.html


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:53:29 EDT