Oddity - Two wireless signals available same MAC. Hacking?

blancj

Distinguished
Mar 18, 2006
25
0
18,530
Recently I noticed my Wireless connection is sometimes oddly slow, generally without any immediately noticeable interferance; ie by signal strength and enviormental observation.
As it happens today I updated my driver for my mini-PCI in my laptop, which also has a alternate wireless control app, other than the default XP version.
But now when I refresh the "visible sites" I get a 2nd visible network with the same MAC address as my access point. It tends to have a slight to very different signal stremgth, sometimes even more in terms of dBm. It should be noted that the 2nd available signal doesnt have my SSID (which is not broadcast BTW, WEP is on also, which I do know just keeps the normally honest person honest.)

So with the idea that it is a Netgear wg602 ver 3 G/B access point....
Am I getting hacked or is it more likely that is a function of the router listening for a B signal?

Thanks for reading all that and the input.
 

blue68f100

Distinguished
Dec 25, 2005
1,803
0
19,780
That is a technique used by hackers to trap personal info like user ID's and PW as alone as packet sniffing for anyone connecting to the rouge AP. If you are only using 11b WEP, It's time to upgrade to 11g and WPA with a real strong encryption key.

If what you say is correct you may want to notify the authorities.
 

blancj

Distinguished
Mar 18, 2006
25
0
18,530
I feared it might be something like that. Is there software available that can determine where the spoofed AP is? I have two available laptops to do the work if needed. I am about to try the 'turn mine off and walk around the "yard" with my laptop...'

One almost certainty, if this is the case, is that its one of my near neighbors since it is fairly constant and not a horrble quality signal.

The problem I have is that my Tivo adaptor doesnt support WPA.

Thanks Blue!
 

blue68f100

Distinguished
Dec 25, 2005
1,803
0
19,780
Clear out all temp and cache files out and make sure it not just left over from the upgrade.

Download and use netstumbler to run a scan. Just turn yours off for a brief time. Change your wep keys, and SSID, hide if your tivo will work in the dark.

If you confirm what you suspect. Call the authorites, there are laws against it.

Then I would change any and all PW that might have been compromized.

You may want to do a double router setup or setup the 11b by it's self.