RE: Wireless security question

adisegna_at_siscocorp.com
Date: 12/24/04

  • Next message: TStark: "Fedora 3 Wireless Promiscuous (Monitor) Mode"
    Date: Fri, 24 Dec 2004 10:14:18 -0500
    To: <security-basics@securityfocus.com>
    
    

    Join the laptop to the domain. Push out a policy that disables the wireless services. If you have a central administration point for all APs ban the MAC address of the card.

    AD

    -----Original Message-----
    From: Liran Cohen [mailto:theog@tehila.gov.il]
    Sent: Thursday, December 23, 2004 3:43 AM
    To: Marty
    Cc: Sec Basic
    Subject: Re: Wireless security question

    Actually I don't think it is possible to prohibit wireless networks from
    laptops, since some laptops come with their wireless card built in, what
    more, I do believe that one should concentrate most of the efforts in
    finding the solution on one's network, and not on the clients side to
    solve such problems. How about creating a separate LAN for mobile
    devices? which will be heavily monitored and limited in it's services
    (maybe even wireless :) ) and require port authentication on every
    switch on you're LAN (IEEE 802.1X) so that you'll know who's connected
    where, and the laptop computers will be forced to that "special" LAN, on
    which you may restrict and monitor traffic easier.

    BTW, in my opinion, USB mass storage devices (disk on key etc...) pose a
    higher threat than Laptops. :)

    Liran Cohen
    TheOg

    Marty wrote:
    > Hi gang!
    >
    > Here is a question for you...
    >
    > We have a secure network with no wireless
    > connections whatsoever.
    >
    > One of our laptop came in with credentials to log
    > on to the network through the Ethernet cable BUT
    > the person had just added a wireless card to his
    > laptop.
    >
    > This situation actually came up and the person
    > could see external wireless networks (from other
    > companies around our building) and access
    > Internet through there. Yeah I know they're
    > stupid, but it's the real world!
    >
    > This seems like a potential threat for taking our
    > data out the back door.
    > Copy files accessed through our network to
    > another network and voilà! No trace at all of the
    > mischief.
    >
    > We monitor internet access and block non-company
    > Email (Yahoo, Hotmail etc.).
    >
    > Suggestions?
    >
    > Thanks and Happy Holidays!
    >
    > Marty!
    >
    >
    > __________________________________________________________
    > Lèche-vitrine ou lèche-écran ?
    > magasinage.yahoo.ca


  • Next message: TStark: "Fedora 3 Wireless Promiscuous (Monitor) Mode"

    Relevant Pages

    • [NMRC Advisory] Microsoft Windows Wireless Exposure on Laptops
      ... Application: Wireless Network Connection ... This advisory documents an anomaly involving Microsoft's Wireless Network ... If a laptop connects to an ad-hoc network it can later start ... This is known as a Link-Local address, and by default Link-Local is turned on on all Windows platforms on all interfaces, including wireless interfaces. ...
      (Bugtraq)
    • Re: Linksys WRT54G acts like a dumb hub, no DHCP or wireless capabilities
      ... laptop and the PC would lose connection with the router. ... Well, the results are the same: I can connect to the wireless network, ... but after about 10 minutes I will lose connection with the router. ...
      (alt.internet.wireless)
    • Re: Sharing access denied -Too confused or stupid to figure out sh
      ... I could run it from laptop through network. ... USB for wireless broadband is attached to PC1 ... It is Not clear to ne your current Network topology and how the local ...
      (microsoft.public.windowsxp.network_web)
    • [NT] Microsoft Windows Wireless Exposure on Laptops
      ... Microsoft Windows Wireless Exposure on Laptops ... If a Windows based laptop connects to an ad-hoc network it can later start ... * Microsoft Windows XP Home Edition Gold Wireless Network Connection ...
      (Securiteam)
    • Re: One Users My Documents no longer redirected.
      ... to auto-magically update everything without them needing to find a network ... So I would think that a wireless 54 mbps connection would be ... and one laptop, and try it for a day or two to see what happens. ... should have guidelines for the number of simultaneous client connections ...
      (microsoft.public.windows.server.sbs)