War driving

Moving through an area with a wireless-capable device to discover, record and map wireless networks, their names, security settings and locations, as reconnaissance.

War driving is searching for wireless networks while moving through an area, commonly in a vehicle, with a laptop or phone, a suitable antenna and location data. The software records each network it hears: the name (SSID), the hardware address of the access point, the security in use, the signal strength and where it was heard. The result maps which networks reach beyond their buildings and which are weakly protected. On foot it is sometimes called war walking. Collecting what a network openly broadcasts is largely passive; using a network found this way without authorisation is a separate act, and in many jurisdictions an offence.

War driving is reconnaissance, not an attack on its own. Networks still using WEP or no encryption stand out at once, which is why WPA2 or WPA3 matters. A hidden SSID does not hide the network, because the name still appears in frames that clients send when they connect. Limiting signal leakage helps, and authorised surveys of your own sites find a rogue access point before an outsider does.

Exam relevance: a scenario is likely to describe someone outside the premises cataloguing wireless networks. Candidates are expected to recognise that as war driving, to treat it as reconnaissance, and to choose strong encryption and authentication over hiding the SSID as the response.