Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Seems widespread; sad state of affairs... wonder how many locations suffer from (mis)configured APs battling each other..

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortig...

"In addition to monitoring rogue APs, you can actively prevent your users from connecting to them. When suppression is activated against an AP, the FortiGate WiFi controller sends deauthentication messages to the rogue AP’s clients, posing as the rogue AP, and also sends deauthentication messages to the rogue AP, posing as its clients."



Rogue APs are generally defined as APs that you don't manage but have been connected to your wired network. Obviously this could be a significant security risk. I don't think they're sending deauth messages to every client/AP they see.

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortig...


It looks like it allows you to mark any AP as "rogue" even if they're not detected as "on-wire" despite that not being the purpose of the feature.


I would define "rogue" as any AP intentionally using the SSID of my network to trick users into connecting to it instead of my own infrastructure.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: