Re: [fw-wiz] (In)security of wireless LANs and the Cisco Wireless Security Sui te

From: R. DuFresne (dufresne_at_sysinfo.com)
Date: 11/04/03

  • Next message: David Wagner: "Re: [fw-wiz] (In)security of wireless LANs and the Cisco Wireless Security Sui te"
    To: John Adams <jna@retina.net>
    Date: Tue, 4 Nov 2003 14:58:26 -0500 (EST)
    
    

    On Tue, 4 Nov 2003, John Adams wrote:

    > On Tue, 4 Nov 2003, R. DuFresne wrote:
    >
    > > to be on premisses to use, if the AP's are properly tuned so as to not
    > > braodcast outside the building perimiters <and this means walking the
    > > grounds with a wireless sniffer to ensure> then your risks are again
    > > reduced.
    >
    > There are a limited number of wireless cards that can have their output
    > power reduced (tuned, as you say) but that will never ensure any form of
    > protection against a determined attacker.
    >
    > While your wireless -card- may not be able to see the airport, someone who
    > really wants in to your network can drive across the street, set up a
    > 24dbI (or greater) directional antenna on a tripod, aimed squarely at your
    > AP, and they'll see your network.
    >
    Understood, yet, it was, and I maybe mistaken here, suggested in a number
    of AP offerings I've looked at recently that AP's were now being able to
    'tune' their signals. In addition to proper location of said equipment as
    well as other intervening obstructions along the pathways <i.e. walls,
    metal, micro wave devices, etc>.

    Of course, I would not rely upon this for total security, course, I'd
    certainly not trust a wireless device in a critical situation security
    wise either. It's my real impression no matter what one does, too much
    information still leaks and makes attacks that much more a possibility.
    Other do feel wireless is ready for primetime, this is *not* my
    impresssion.

    Thanks,

    Ron DuFresne

    -- 
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            admin & senior security consultant:  sysinfo.com
                            http://sysinfo.com
    "Cutting the space budget really restores my faith in humanity.  It
    eliminates dreams, goals, and ideals and lets us get straight to the
    business of hate, debauchery, and self-annihilation."
                    -- Johnny Hart
    testing, only testing, and damn good at it too!
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: David Wagner: "Re: [fw-wiz] (In)security of wireless LANs and the Cisco Wireless Security Sui te"

    Relevant Pages

    • Re: Two wireless routers one network
      ... neighborhood kids trying to use my wireless than from any books or web ... I don't expect my customers to ... My level of security and paranoia largely depends on the risks and ... >>I notice you didn't say anything about my comments about monitoring ...
      (alt.internet.wireless)
    • RE: palm VIIx wireless modem
      ... Here is a Wireless LAN Security FAQ, ... What are solutions to minimizing WLAN risk? ... that connects clients to the internal network. ...
      (Security-Basics)
    • RE: Wireless Security
      ... Subject: Wireless Security ... ::: In the situation you mentioned, a person was allowed to use the car. ... :: "10-keys" of coke delivered to them at THAT address. ...
      (Security-Basics)
    • RE: Wireless Audit Cost
      ... "complete analysis" - to me this means that a full audit of both ... the wired and wireless networks is taking place. ... network off the internal LAN. ... >network has the usual security measures in place, ...
      (Pen-Test)
    • Re: no phone line? & 2way voice. move over joel
      ... Simon XT delivers added wireless and interactive capabilities through ... today announced enhancements to Simon ... complete and secure advanced wireless security solution including ... a wireless security system offering burglary and fire ...
      (alt.security.alarms)