aptools.sourceforge.net

. . :. :: :.: ::.::: .:. .: : ::: .. :. .:..: :.. ::
aptools
NAVIGATION >> PROJECT SUMMARY SUPPORT FORUMS CVS DOWNLOAD RELEASES MAILING LISTS CONTACT
NEWS .:
Winfingerprint CLI version available for testing.   vacuum - 2005-07-18 10:06
MySQL + PHP Developer Needed   vacuum - 2004-11-25 07:09
Wininterrogate 0.1.7 Released   vacuum - 2004-09-26 08:55
Winfingerprint 0.5.12 Released   vacuum - 2004-07-29 10:21
Pixilate 0.4a   vacuum - 2003-07-17 06:36


SourceForge Logo

Rate aptools at securityfocus.com



APTools Screenshot
APTools Screenshot
Supported Platforms: Win32 / Unix
Tested Clients: Windows 2000/XP, Solaris 8, FreeBSD 4.x, Linux
Tested Access Points: Cisco Aironet 340 with Basic HTTP Authentication Enabled/Disabled.
REQUIREMENTS
Due to limited equipment availability, APTools was developed and tested utilizing Cisco Aironet 340 Access Points, Cisco Routers running IOS Release 12.0(1)T and later, and Cisco Switches. CiscoSecure AAA and telnet.

LIMITATIONS
Win32 GUI needs Multithreading. Does Not Support SSH, SNMP, SSL or HTTP Digest Authentication.

BETA TESTERS AND DEVELOPERS WANTED
Non Cisco equipment support needs testing and feedback. APTools code will be available via CVS for those wishing to contribute patches.
Using MAC Address information gathered from http://standards.ieee.org/regauth/oui/index.shtml and http://www.netstumbler.org I have added UNTESTED support for the following Access Points:
ManufacturerMAC Address RangeConfiguration Method Open Ports
3Com 0001.03|0004.76|0050.da|0800.02 web based
Addtron 0040.33|0090.d1 Proprietary Utility
Advanced Multimedia Internet 0050.18
Apple 0030.65 AirPort Base Station Configurator
Aironet 0040.96telnet, http, serial cable managed
23/tcp     open        telnet
68/udp     open        bootpc
80/tcp     open        http
161/udp    open        snmp
Atmel 0004.25
Bay Networks 0020.d8
BreezeNet 0010.e7
Cabletron (Enterasys) 0001.f4|00e0.63 Proprietary Utility
Camtec 0000.ff
Compaq 0050.8bProprietary Utility
D-Link 0005.5d|0040.05|0090.4bProprietary Utility
Delta Networks 0030.ab
Intel 0002.b3 web based
Linksys 0003.2f|0004.5asnmp and usb based configuration
Model BEFW11S4 : HTTP Managed
53/udp     open        domain
67/udp     open        bootps
69/udp     open        tftp 
80/tcp     open        http
520/udp    open        route
Lucent 0002.2d|0060.1d|0202.2d
Nokia 00e0.03
Samsung 0000.f0|0002.78
Senao Intl 0002.6f
SMC 00e0.29|0090.d1
SOHOware 0080.c6
Sony 0800.46
Symbol 00a0.f8|00a0.0f
Z-Com 0060.b3
Zoom 0040.36 web based

If you are able to confirm the identification of any of the above access points (or are able to provide information for an access point not mentioned) please send an email with as many details as possible to vacuum@users.sourceforge.net.

ROUTERS AND SWITCHES:
The "Access Point Type" Drop Down menu is also able to accept a command. This can be (ab)used in a number of ways, but its intention is to allow testing of various non-Cisco devices.

Suggested Tests:
What I am looking for is a way to filter only specified MAC Addresses on the router/switch so that the parsing can be done on the router/switch side of things. Otherwise the parsing can be implemented withing APTools.
Foundry Networks Routers and switches:
As you can see, Foundry Networks supports filtering, I just need confirmation that this syntax is correct for a Cisco Aironet: "show arp mac-address 0.4.0.9.6 ffff.ff00.0000" The following command displays all ARP entries for MAC addresses that begin with "abcd":
BigIron# show arp mac-address a.b.c.d ffff.0000.0000
Lucent ComOS:
show arp Interface
The interface specification--for example, ether0, frm1, or frmw1. Use the command ifconfig to obtain a list of available interfaces.
3Com:
SHow -IP ADDRess
Juniper:
show arp

. . . MORE TO COME
:. OTHER PERSONAL PROJECTS
Winfingerprint and Wininterrogate
:. PRESENTATIONS
10/15/2001 SANS conference San Diego, CA
APTools Powerpoint presentation can be found here.
11/28/2001 Computer Security 2001 conference Mexico City, Mexico
Honeynet Powerpoint presentation can be found here.
05/08/2002 Networld+Interop 2002 conference Las Vegas, NV
Honeynet Powerpoint presentation on Intrusion Deception
Copyright 1999-2002 Kirby Kuehl