WarDriving & Wireless Penetration Testing

In order to successfully perform a penetration test on a wireless network, it is important to understand the core technologies represented in a toolkit. What does WLAN discovery mean and why is it important to penetration testers? There are a number of different methods for attacking WEP-encrypted networks. Why are some more effective than others? Is a dictionary attack against Lightweight Extensible Authentication Protocol (LEAP) the same as a dictionary attack against WPA-PSK? Once a penetration tester understands the technology behind the tool he or she is going to use, his or her chances of success increase significantly.
There are two types of WLAN discovery scanners active and passive. Active scanners rely on the Service Set Identifier (SSID) broadcast beacon to detect the existence of an access point. An access point can be cloaked by disabling the SSID broadcast in the beacon frame; however, while this renders active scanners ineffective, it doesn t stop penetration testers from discovering the WLAN. Passive scanners require that a WLAN adapter be placed in rfmon (monitor) mode. This allows the card to see all of the packets being generated by any access point within range; thus, discovering access points even if the SSID is not sent in the broadcast beacon.
When a passive scanner initially detects a cloaked access point, the SSID is usually not known, because it isn t included in the broadcast frame (see Figures 7.1 and 7.2).