Spent a weekend wardriving around Aberystwyth with a laptop, an external antenna, and a USB GPS receiver. The goal was to map every wireless network in town and see how many were still running open or WEP-only. The results were not encouraging.

Kit

The setup was a ThinkPad T42 running Debian with Kismet 2006-04-R1, a Senao NL-2511CD Plus EXT2 card (Prism2 chipset, proper monitor mode), a 7dBi omni antenna stuck to the car roof with a mag mount, and a Garmin eTrex Legend connected via serial-to-USB. Total cost for the add-ons was about 60 quid from eBay.

Kismet was configured to log in GPS-XML format so I could get coordinates for each network. The drive covered most of Aberystwyth - up and down the prom, through town, around Penglais campus, and along the Llanbadarn road.

Results

Over roughly 4 hours of driving (with a stop for chips), Kismet picked up 847 unique access points. Here is the breakdown:

Encryption     Count   Percentage
----------------------------------
Open (none)      218      25.7%
WEP              389      45.9%
WPA/WPA2         214      25.3%
Unknown           26       3.1%
----------------------------------
Total            847     100.0%

So about a quarter of all networks had no encryption at all. Nearly half were running WEP, which at this point is trivially crackable with aircrack-ng and a few minutes of packet capture. Only a quarter had proper WPA or WPA2 protection.

Plotting on Google Maps

Google Maps API v2 makes this fairly straightforward. I wrote a Perl script to parse the Kismet GPS-XML output and generate a JavaScript array of markers with SSID, encryption type, signal strength, and coordinates. Each marker is colour-coded: red for open, amber for WEP, green for WPA.

The core of the plotting code looks like this:

var map = new GMap2(document.getElementById("map"));
map.setCenter(new GLatLng(52.4153, -4.0829), 14);
map.addControl(new GLargeMapControl());

for (var i = 0; i < networks.length; i++) {
    var n = networks[i];
    var icon = new GIcon(G_DEFAULT_ICON);
    if (n.enc == "None") icon.image = "red-dot.png";
    else if (n.enc == "WEP") icon.image = "amber-dot.png";
    else icon.image = "green-dot.png";

    var marker = new GMarker(new GLatLng(n.lat, n.lon), {icon: icon});
    GEvent.addListener(marker, "click", function() {
        marker.openInfoWindowHtml("<b>" + n.ssid + "</b><br>" + n.enc);
    });
    map.addOverlay(marker);
}

The Perl script that generates the networks array from Kismet logs:

#!/usr/bin/perl
use XML::Simple;
my $xml = XMLin('Kismet-GPS.xml', ForceArray => ['gps-point']);
print "var networks = [\n";
for my $net (@{$xml->{'gps-point'}}) {
    next unless $net->{bssid} =~ /^([0-9A-F]{2}:){5}[0-9A-F]{2}$/i;
    printf '  {ssid:"%s", enc:"%s", lat:%.6f, lon:%.6f},' . "\n",
        $net->{ssid} || "hidden",
        $net->{encryption} || "Unknown",
        $net->{'avg-lat'},
        $net->{'avg-lon'};
}
print "];\n";

Observations

The university campus area had the highest density of networks, which is not surprising. The halls of residence on Penglais hill were almost entirely open or WEP - students plugging in cheap access points without changing defaults. The town centre was a mix, with a few shops running open hotspots intentionally.

The most common SSIDs were "default", "linksys", "NETGEAR", and "BTHomeHub-XXXX". The BT ones were at least running WPA by default, which is something. The Linksys and Netgear ones were overwhelmingly open or WEP with the factory key.

One network was broadcasting the SSID "FREE INTERNET COME IN" which is either very generous or a honeypot. I did not connect to find out.

What this means

If you are running an open or WEP network in 2006, you should assume that anyone within range can see your traffic. WEP cracking tools are freely available and require no special skill to use. Switch to WPA2-PSK with a decent passphrase - at least 12 characters, not a dictionary word.

I might do another scan in six months to see if things have improved. Aber is a small enough town that you can cover it properly in an afternoon.