Wardriving
Wardriving is scanning for Wi-Fi networks from a moving vehicle to map targets. How attackers use it and how to keep your wireless edge off the map.
Wardriving is the practice of driving (or walking — "warwalking") through an area with a Wi-Fi–capable device to discover, log and map wireless networks. The kit is trivial: a laptop or phone, a scanning app, a GPS receiver and optionally a high-gain antenna. The name descends from "war dialing," the 1980s technique of dialing phone numbers in bulk to find modems. Wardriving itself — passively listening for networks that broadcast their presence — is generally not illegal; what attackers do with the map afterwards is.
How it works
A wardriver's scan records each network's name (SSID), hardware addresses, channel, signal strength, encryption type and location. Aggregated over a city, that becomes a target map: corporate networks still running weak or no encryption, access points with default names betraying unconfigured hardware, guest networks bleeding into parking lots, and unauthorized employee-installed hotspots — classic shadow IT. Public databases built from crowdsourced scans let an attacker do much of this reconnaissance without leaving home, making wardriving data a physical-world cousin of OSINT. The follow-on attacks are where the damage happens: cracking weak Wi-Fi encryption, or parking nearby and standing up an evil twin or rogue access point that impersonates the legitimate network and harvests credentials from auto-connecting devices.
How to defend against it
You cannot stop anyone from listening, so the goal is to be uninteresting on the map. Use WPA3 (or at minimum WPA2-Enterprise with certificate-based authentication) on corporate SSIDs, kill WPS, and keep guest and corporate networks fully segmented. Manage the radio footprint: tune access-point power so coverage ends near your walls rather than across the street. Use wireless intrusion detection to alert on lookalike SSIDs and unauthorized access points on your premises. And train the human layer: employees should know that corporate devices silently auto-joining "known" networks is how evil twins win, a scenario worth including alongside the physical-recon threats in our guide to tailgating, shoulder surfing and dumpster diving and in your security awareness program.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo