WLAN with encryption and ARP-spoofing

From: Markus Schabel (markus.schabel_at_tgm.ac.at)
Date: 03/01/04

  • Next message: H Carvey: "Re: Port Knocking questions"
    Date: Mon, 01 Mar 2004 20:33:26 +0100
    To: security-basics@securityfocus.com
    
    

    Hello!

    While preparing for a security-seminar I played a bit around with
    ARP-spoofing on switches. After that we thougth a bit about encrypted
    WLAN's and found out that we can also sniff all packets when we use
    ARP-spoofing, so the encryption (even with keychanging applied) isn't
    really useful since it is no problem to grep all packets decrypted.

    Do you have any idea's how this can be prevented?

    best regards,
    Markus

    ---------------------------------------------------------------------------
    Free 30-day trial: firewall with virus/spam protection, URL filtering, VPN,
    wireless security

    Protect your network against hackers, viruses, spam and other risks with Astaro
    Security Linux, the comprehensive security solution that combines six
    applications in one software solution for ease of use and lower total cost of
    ownership.

    Download your free trial at
    http://www.securityfocus.com/sponsor/Astaro_security-basics_040301
    ----------------------------------------------------------------------------


  • Next message: H Carvey: "Re: Port Knocking questions"

    Relevant Pages

    • CryptoSurvey -- Results ..
      ... Many same or similar behavioral barriers for the ... effective utilization of many security solutions still exist limiting ... applications of encryption technologies currently in commercial ... Many people do not care about cryptography and/or security products ...
      (sci.crypt)
    • CryptoSurvey -- Results ..
      ... Many same or similar behavioral barriers for the ... effective utilization of many security solutions still exist limiting ... applications of encryption technologies currently in commercial ... Many people do not care about cryptography and/or security products ...
      (sci.crypt)
    • Re: OT - Kuwait
      ... > One place where I agree with you is that the scope of government intrusion ... > into the private matters of Americans is much greater than most Americans ... >>> strict security procedures to prevent unauthorized release of the keys. ... >> Feds Want to Control Encryption ...
      (alt.sports.football.pro.ne-patriots)
    • Re: OT - Kuwait
      ... Making the case for encryption standards that would allow the Feds to ... One place where I agree with you is that the scope of government intrusion ... into the private matters of Americans is much greater than most Americans ... >> strict security procedures to prevent unauthorized release of the keys. ...
      (alt.sports.football.pro.ne-patriots)
    • Re: National Security Backdoor in telnetd - all versions.
      ... >>against the Secret Service for their violations of civil rights. ... encryption techniques to protect critical resources. ... plants have absolutely horrid security resulting from these stupidities. ... Of course I doubt you have an NDA with the government - so ...
      (comp.os.linux.security)