RE: Dumb question abt. Wireless WEP security

From: Bruyere, Michel (mbruyere_at_ezemcanada.com)
Date: 01/23/04

  • Next message: Rosenhan, David: "RE: Network Access Quarantine"
    To: security-basics@securityfocus.com
    Date: Fri, 23 Jan 2004 09:33:38 -0500
    
    

    <SNIP>
    > customer (SMB/SOHO) locations we used normal WiFi gear. We used MAC
    > control, disabled the broadcasting of the SSID and enabled WEP and that
    > was a good 'secure by default' solution. The attacker would need to
    > guess the SSID,
    <SNIP>

    This is not the best way to go, as for the SSID hiding. Someone posted a
    paper on this fact at the following link that resumes well why it is not a
    good thing to disable it. In short, disabling the broadcast just ends up
    adding the SSID to more packets "in transit".
     
    Here is the link for the paper
    http://www.icsalabs.com/html/communities/WLAN/wp_ssid_hiding.pdf

    And while talking about Mac, this should be a nice reading
    http://home.jwu.edu/jwright/papers/wlan-mac-spoof.pdf

    My 0.02$

    M.Bruyere

    ---------------------------------------------------------------------------
    Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any
    course! All of our class sizes are guaranteed to be 10 students or less.
    We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention,
    and many other technical hands on courses.
    Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off
    any course!
    ----------------------------------------------------------------------------


  • Next message: Rosenhan, David: "RE: Network Access Quarantine"

    Relevant Pages

    • RE: Dumb question abt. Wireless WEP security
      ... <SNIP> ... disabled the broadcasting of the SSID and enabled WEP and ... > guess the SSID, ... disabling the broadcast just ends ...
      (Security-Basics)
    • Re: Linksys routers
      ... encounter if you are using WZC by disabling the SSID broadcast with Windows ... Linksys says to disable the SSID Broadcast ... If a wireless device broadcasting SSID comes ...
      (microsoft.public.windowsxp.network_web)
    • Re: Newbie security question
      ... It doesn't have to broadcast it, you can manually enter the SSID in your ... computers connection and it will attempt to find a router with that SSID ... Changing the SSID is the first thing, turning off the broadcasting of ... > I myself can not connect (and when I set the right MAC I can)). ...
      (comp.security.firewalls)
    • Re: Linksys routers
      ... Linksys says to disable the SSID Broadcast ... Many networking experts now realize that disabling SSID causes problems with WZC ... If a wireless device broadcasting SSID comes online ...
      (microsoft.public.windowsxp.network_web)
    • Re: Newbie security question
      ... Leythos wrote: ... >> connect to 'my' MAC), I am sufficiently protected on the wireless side. ... > 128 bit, a MAC filter that you are safe, BUT since you are broadcasting ... > broadcasting of the SSID. ...
      (comp.security.firewalls)