WarDriving & Wireless Penetration Testing

Now that you have an understanding of the vulnerabilities associated with wireless networks and the tools that are available to exploit those vulnerabilities, it s time to look at how an actual penetration test might take place against a wireless network. First, we focus on a network using WEP encryption, and then we look at a WPA-PSK-protected network.
You have been assigned to perform a red team penetration test against Roamer Industries. You have been given no information about the wireless network or the internal network. You have to use publicly available sources to gather information. You know that Roamer Industries has deployed a wireless network, but that is all of the information you have.
Before you do anything else, you investigate the company by performing searches on Google and other available search engines, as well as the USENET newsgroups. You also go to the Roamer Industries public Web site to look for information and perform an ARIN WHOIS lookup on the IP address of their Web site. Quite a bit of important information is gleaned from these searches. The address of their office complex is listed on their Web site. The WHOIS lookup reveals the name and e-mail address of an individual that you discover is a system administrator, judging from the posts he has made on USENET. Additionally, you discover that they are using Microsoft Structured Query Language (SQL) server on at least one system, because that administrator described a configuration issue he...