Sections:
|
Smart Computing Article - Advanced Wireless Security Options
www.smartcomputing.com/editorial/article.asp?artic...
If you already own a wireless AP, you can check with the manufacturer to determine whether it’s upgradeable to WPA2. Wireless APs released in 2003 or after that support 802.11g devices probably support WPA2 with a firmware update. If your wireless AP does not support WPA2, you can use WPA or WEP. Introduction
Key Points:
1. Do not turn off SSID broadcasting. There is a widespread myth that this will hide your WiFi network from hackers. It seems logical, but it's dead wrong. It does not hide your network from serious hackers, and it makes it easier to break in if you disable SSID. There are three potential points of intrusion when you are using a wireless network (WiFi or Bluetooth). 1.) The Internet itself. 2.) If the network is not your own (i.e., a Hotspot), it could be a rogue network, which makes you super-vulnerable because everything you do passes through the perpetrator's computer. 3.) Wireless intrusion: the intruder connects to your wireless node and has access to anything that is exposed to the local network.
Wireless NetworkFollowing a few easy steps can ensure that no one intercepts your Wi-Fi traffic.Becky WaringMonday, April 09, 2007 1:00 AM PDT
Almost all of us have jumped onto someone else's unsecured Wi-Fi network. There's little harm in that if you're just an honest soul looking for an Internet connection. But if you're the owner of an unsecured network, you should be aware that the world's not made up entirely of honest souls--and it's not hard for the dishonest ones to see exactly what you're doing on your network. Sound scary? Here's how to fix the problem. Wi-Fi piggybacking widespread, Sophos research reveals
www.sophos.com/pressoffice/news/articles/2007/11/w... Wi-Fi piggybacking widespread, Sophos research reveals Over 50% of people polled admit they have stolen Wi-Fi internet access![]() Over 50% of people polled admitted they had stolen Wi-Fi internet access from others. IT security and control firm Sophos has revealed new research into the use of other people's Wi-Fi networks to piggyback onto the internet without payment. The research, carried out by Sophos on behalf of The Times, shows that 54 percent of computer users have admitted breaking the law, by using someone else's wireless internet access without permission. According to Sophos, many internet-enabled homes fail to properly secure their wireless connection with passwords and encryption, allowing freeloading passers-by and neighbours to steal internet access rather than paying an Internet Service Provider (ISP) for their own. In addition, while businesses often have security measures in place to protect the Wi-Fi networks within their offices from attack, Sophos experts note that remote users working from home could prove to be a weak link in corporate defenses. General
Also see the WiFi Notebook
What's the difference between a Hub, a Switch and a Router? - Ask Leo!
ask-leo.com/whats_the_difference_between_a_hub_a_s... Summary: Hubs, switches and routers are all computer networking devices with varying capabilities. Unfortunately the terms are also often misused. What's the difference between a Hub, a Switch and a Router? In a word: intelligence. Hubs, switches, and routers are all devices which let you connect one or more computers to other computers, networked devices, or to other networks. Each has two or more connectors called ports into which you plug in the cables to make the connection. Varying degrees of magic happen inside the device, and therein lies the difference. I often see the terms misused so let's clarify what each one really means. How do I know if I'm behind a NAT router? - Ask Leo!
ask-leo.com/how_do_i_know_if_im_behind_a_nat_route... Summary: NAT routers are a fundamental way to share an internet connection while protecting you at the same time. You may already have one. It's easy to check. I've seen you talk about NAT routers as firewalls, and so on. How do I know if I have one? The answer's not as obvious as a lot of people are thinking. Yes, much of the time a NAT router is an additional box ... a device that you plug your computer into that, in turn, plugs into your internet connection. And that box will typically say "router" on it. But that's not the only way you can end up behind a router. Zone Alarm firewall: do I need it if I'm behind a NAT router? - Ask Leo!
ask-leo.com/zone_alarm_firewall_do_i_need_it_if_im... Summary: Zone Alarm is a popular firewall you install on your machine. If you also have a NAT router you may - or may not - need a firewall such as Zone Alarm. I have a WinXP Pro PC behind a NAT router and am getting tired of Zone Alarm to the point where I think Zone Alarm is creating more problems than it solves. Some have suggested that I do not need a software firewall as long as I practice safe computing. Do you agree? And can you recommend a different free software firewall solution just to satisfy my paranoia? As you've seen, there differing opinions on this. In reality it does, indeed, depend on how you use your system and how "safe" your safe computing really is. Wireless LAN Technologies and Microsoft WindowsPublished: July 1, 2001 | Updated: March 14, 2007 IEEE 802.11 wireless LAN technology is a popular option for network connectivity on organization intranets, home networks, and for accessing the Internet. This article describes the benefits of wireless LANs, the support for 802.11 wireless LAN and wireless LAN security standards in Microsoft® Windows®, and general guidelines for wireless LANs in medium to large organizations and small office/home office networks. On This Page
Wireless Router GuideAfter getting started and comparative reviews, this page has links to articles on wireless security, networking utility and security software, and wireless vendors and product reviews.
Security -- Wireless routers are not as secure as hard wired. If you want wireless and security, read the security articles on this page and be prepared to spend some time setting up the security features of your wireless network. Testing -- We recommend that you test the firewall features of a wireless router after installation. See our Firewall Testing page for more information. Firmware -- Router vendors offer updates for their firmware to add new features and to resolve problems found by their customers. Prices -- See our custom Wireless Firewall Router Price List
Networking Utility and Security Software
D-Link Xtreme N Gigabit Router DIR-655: Supports WEP™, WPA™, and WPA2™ encryption security standards and utilizes dual SPI and NAT firewalls.
Linksys WRT150N Wireless-N Home Router: Supports WEP™, WPA™, and WPA2™ encryption security standards and utilizes dual SPI and NAT firewalls.
Netgear Super-G Wireless Router WGT624: SPI and NAT firewalls, WEP and WPA, DoS Attack Detection/Logging, Dropped Packet Log, Security Event Log, E-mail Log, multiple VPN Tunnels (Pass-Through, 2 IPSec, and multiple L2TP & PPT.
D-Link DSL-2640B ADSL2/2+ Modem/Wireless Router 4-Port Switch includes SPI and NAT firewalls plus WEP, WPA, and WPA2 encryption. Linksys Wireless-G Cable Gateway Cable Modem with Built-In Wireless-G Router WCG200: SPI and NAT firewalls, WPA encryption includes parental control features like Internet access time limits and key word blocking. NetGear DG834G Wireless ADSL Firewall Router (54 Mbps) includes SPI and NAT firewalls, WEP, WPA, WPA2, VPN, intrusion logging and reporting, denial-service (DoS) protection. Security Watch: A guide to Wireless Security -- TechNet Magazine, November • December 2005
www.microsoft.com/technet/technetmag/issues/2005/1...
Lifehacker Top 10: Top 10 Wi-Fi Boosts, Tweaks and Apps - Lifehacker
lifehacker.com/software/lifehacker-top-10/top-10-w... No doubt you've got a home wireless network or you've connected to hotspots at the local coffee shop or airport—but are you getting the most out of your Wi-Fi? Whether you want to strengthen, extend, bridge, secure, sniff, detect, or obscure your signal, today we've got our top 10 best Wi-Fi utilities and tweaks for the power wireless user. Photo by thms.nl. WEP was originally demonstrated to be broken back in 2001 and it was broken even worse by a factor of 20 in early 2005 and then broken again by another factor of 20 last month by German researchers. WEP 104-bit encryption can now be cracked in under a minute on an 802.11g network using active ARP-replay packet-injection techniques. Since the TJX breach started around mid 2005, the attackers could have easily cracked the network within half an hour using second-generation of WEP cracking tools. What's most alarming about this is that most of the major retailers during that time were running WEP and many are STILL running some form of WEP. There's no reason to believe the same attackers didn't try this sort of attack on many other retailers and are still actively attacking networks today. Many businesses and organizations including hospitals are STILL running WEP or some other useless form of security. Some are running a slightly better enterprise version of WEP which uses per-session per-user dynamic keys that supposedly rotates every hour but even that's worthless since the third generation of WEP cracking tools can break WEP in under a minute. When I worked as a security consultant for major retailers and organizations during 2004 to 2005, I knew this was a time bomb waiting to go off because the vast majority of businesses and retailers were running bad Wireless LAN security with blatantly weak security. Many businesses refused to fix their security and refuse to this day through a combination of ignorance and denial. Some businesses and retailers listened and upgraded their security to WPA, others flat out refused. I actually had one client to go the extra mile to buy all-new WPA-capable equipment only to be told in the end that they will only implement WEP because that was the "standard" their corporate head quarters used. Getting people to upgrade their security and educate them was hard enough as it was, but the fact that many security professionals and security training courses are still recommending the worst kinds of wireless LAN security exacerbated the situation. I've done my best to spread the word about wireless LAN security and even published a 10-article Guide on enterprise wireless LAN security which is essentially a free eBook. It is essential that businesses and organizations implement the kind of security I mentioned in my enterprise guide. For homes and small home offices, wireless LAN security summed up in a single paragraph. All you need to do is use WPA-PSK security with a RANDOM alpha-numeric pass-phrase that has a MINIMUM of 10 characters. I estimated that a truly random alpha-numeric 10-character WPA-PSK pass-phrase using modern single-core computers will take one thousand PCs working in parallel 500 years to crack. If your hardware doesn't support WPA mode, you can almost always get a free software/firmware upgrade to support it. If the hardware can't be upgraded, businesses can't afford a breach in their data security and they must buy WPA-compliant gear regardless of the cost. Cost shouldn't ever be used as an excuse to have poor security and it won't help you in court when you're getting sued. WPA-compliant access points and wireless cards can be acquired for less than $50 per device. Daily Cup of Tech » Security Is About Being Unattractive
www.dailycupoftech.com/2007/06/12/security-is-abou... As I was writing the post, I knew that someone was going to point out to me that this is not an effective security practice and I was not disappointed, as Adam pointed out in his comment on the post:
Adam also went on to point out how some of my other suggestions provided very weak security:
It is at this point that I would like to whole heartedly agree with Adam! These are all very weak measures of security and provide very little to keep your network safe. I still highly recommend them. Windows Vista Magazine | 5 simple steps to setting up a home network
www.windowsvistamagazine.com/US/28190304998554172/... Having trouble with networking Windows Vista? Here are some solutions. By Nick Peers. Having a network set up in your home is the twenty-first century equivalent of getting a second phone installed in the bedroom. We've aware, however, that this sometimes isn't the most simple process. Here's five solutions to commonly encountered problems, plus two extra points to solving potential problems that can cause trouble for users.
Practice 'safe surfing' with public Wi-Fi signals
What are these mystery wireless networks? Many laptop users have seen unsecured access points like "Free Internet Service" show up in their list of available wireless networks. They appear to be especially common at airports. Attempts to connect to these networks usually don't result in any Internet access. What is the source of these cyber chimeras? The answer is that the majority of these access points are not Internet-accessible networks, but merely peer-to-peer or "ad-hoc" networks connecting one computer to another. Their ubiquity stems from the fact that when a Windows wireless computer connects to a network, it remembers the name or Service Set Identifier (SSID) of that network. The next time you use your laptop, your computer will broadcast that same SSID to other computers, and the users may confuse your signal for a legitimate Internet access point. In this way, names like "Linksys" or "Free Public Wi-Fi" are pollinated from user to user. In most cases, attempts to connect to these networks only result in the user getting frustrated at the lack of an Internet connection and disconnecting. But, according to an advisory paper from Nomad Mobile Research Centre, the feature can be used by attackers to learn a victim's IP address and directly access the computer. The risk is especially high if you have file sharing turned on. In addition, if an attacker uses this method to plant malware on your laptop, you could place your company's network at risk the next time you connect to the network at your job. Another hacker ploy is to set up an "evil twin" signal that broadcasts a site resembling a respectable hotspot such as an airport Wi-Fi service. You may enter credit-card information — thinking you're only buying a few hours of Internet access — but you are actually turning over your account numbers to a cyber criminal. How to protect your wireless laptop So, how can those of us with wireless laptops and networks protect ourselves from the kind of mistakes the security pros were making? Fortunately, you can take several steps to avoid undesired peer-to-peer access and limit your risks when connecting to a wireless hotspot in a public place. Before going any further, however, make sure your own Wi-Fi system is using the latest encryption standard, WPA2 (Wi-Fi Protected Access 2). For details on these and other basics of Wi-Fi security, see Brian Livingston's Top Story in the May 26, 2005, issue. 1. Turn off Wi-Fi when not in use The first and most basic way to limit your risk is to turn off your system's Wi-Fi feature when you're not using it. Many laptop computers have a physical switch to toggle the wireless capabilities. If you don't have a physical switch, you can turn off Wi-Fi in XP by right-clicking the wireless icon in the taskbar "tray" (the area near the clock) and choosing Disable. To turn it back on, go to Control Panel and open the Network Connections window. Right-click the Wireless Network Connection icon and choose Enable. In Vista, go to Control Panel and launch the Network and Sharing Center. Click Manage network connections on the left. Then, right-click the Wireless Network Connection icon and choose Disable. Click Continue if prompted by User Account Control. To reverse this setting, return to this window, right-click the same icon, and choose Enable. As before, click Continue if prompted by User Account Control. Then use the Network and Sharing Center to connect to a network. 2. Install and enable a firewall Make sure you have a firewall enabled on your laptop. If you don't have a third-party firewall, you can turn on Windows built-in firewall by opening Control Panel and launching Windows Firewall. If you have XP Service Pack 2 or Vista, the firewall should be enabled by default. 3. Know the difference The best way to avoid potential attacks via peer-to-peer connections is simply to refuse to connect to an unknown ad-hoc network. Fortunately for XP users, the Wireless Network Connection window clearly distinguishes between the two types of networks. Each ad-hoc network is labeled as a "computer-to-computer network." Infrastructure networks are labeled as "wireless networks." In addition, XP uses distinctive icons to differentiate between the two types of networks: Ad-hoc network icons show two computers, while infrastructure network icons show an antenna (see Figure 1). Vista, however, is a lot less clear on this point. The display of available networks doesn't offer any description to distinguish between ad-hoc and infrastructure networks. The user is forced to rely solely on inscrutable icons. Ad-hoc networks are depicted with three computers connected by green lines, while infrastructure networks are shown as two computers sitting on a network cable (see Figure 2). 4. Clean up your network list In XP, use Windows Control Panel to open the Network Connections window. Right-click Wireless Network Connection and choose Properties. Click the Wireless Networks tab, which displays (among other things) a list of preferred networks (those you have connected to in the past). While you're there, select any suspicious-looking networks (like "Free Public Wi-Fi") and click Remove. In Vista, use Control Panel to open the Network and Sharing Center. Click Manage Wireless Networks in the task pane on the left. Right-click any suspect networks and choose Remove Network. In addition, you should set all of your preferred networks to manual so your system doesn't automatically connect to a rogue network with a matching name. To do that, follow these steps: Step 1. Select any network in the list with "(Automatic)" after its name (XP) or displaying Automatic mode (Vista). Step 2. Click Properties. Step 3. Click the Connection tab. Step 4. Uncheck Connect when this network is in range. Step 5. Click OK. Step 6. Repeat for each automatic connection in the list. 5. Turn off ad-hoc networking in XP While you're in the Wireless Network Connection dialog box (XP only), you may want to take the advice of the Nomad advisory paper, which recommends that users turn off ad-hoc networking: Step 1. In the Wireless Network Connection Properties dialog box, with the Wireless Networks tab selected, click the Advanced button near the bottom of the dialog. Step 2. In the Advanced dialog box, select Access points (infrastructure) networks only. Also, make sure there is no checkmark next to Automatically connect to non-preferred networks. Step 3. Click Close. Unfortunately, changing this setting does not stop ad-hoc networks from appearing in the list of available wireless networks in the Wireless Network Connection window. Nor does it prevent you from connecting to them manually. It does, however, filter out ad-hoc networks from appearing in the list of preferred networks. This setting is not in Vista, which always requires manual connections to ad-hoc networks. 6. Turn off file sharing If you're going to be connected to a public network, such as an airport hotspot, you can reduce the risk of mischief by turning off file sharing: Step 1. In XP, launch Windows Explorer and right-click the folder or drive that's shared. Step 2. Choose Sharing and Security, and turn off sharing for that folder. Step 3. Click OK. Things are much easier in Vista. When you connect to a Wi-Fi network for the first time, you are prompted to designate the network as private or public. Selecting Public automatically turns off file sharing. If you have already connected to the network, you can change this setting by going to Control Panel and launching Network and Sharing Center. Click Customize on the right. Select Public, click Apply, and follow the remaining prompts on screen. 7. Turn off network discovery in Vista Another risk-reducer with public Internet connections is to make your computer invisible on the network you joined. If you designated the connection in Vista as Public, as described above, that's already done for you. If not, you can change that setting independently in the same Network and Sharing Center window. Under Sharing and Discovery, click the On button or the down arrow to the right to display more options. Select Turn off network discovery and click Apply. 8. Use a Virtual Private Network (VPN) Perhaps the best way to protect your wireless communications when using a public network or hotspot is through virtual private networking. For tips on doing so, see the discussion of VPNs in our May 26, 2005, issue. WiFi Security for Small Businesses: 6 Common Fallacies of Wireless Network Security
www.lucidlink.com/2007/03/common-fallacies-of-wire... 6 Common Fallacies of Wireless Network Security
Routers
Instead of installing malware that continues to run like a key logger or trojan, malicious programs are increasingly attacking the network router which is common with any internet connected home and/or office. An unwanted program can quickly make a change to your router settings that will immediately open all your computers to the world. The bad guys won’t have to install a key logger, they’ll be able to record every byte that goes across your network. It’s happening now to thousands of routers which are still using their default name and password.
InformIT: Home Network Router Security Secrets > Turn off UPnP
www.informit.com/articles/article.aspx?p=461084&rl... Home Network Router Security Secrets
Page 1 of 11Next >
Sorry, this author hasn't posted any blogs. Ever delve inside your home network routers and use the hidden security settings that can lock down a network nice and tight? Most people never do. Andy Walker reveals 10 secrets on how to easily access your router's security settings. Most people who install a home network never delve inside the netherworld of security settings on their router. Who can blame them—it’s about as frightening as putting your hand in a shoebox full of rabid gerbils. Nevertheless, it’s worth the effort if you know what you’re doing. That said, here are 10 router settings you can use to make your network more secure. For the purposes of this article, I used a popular router, the DLink DI-524, to show you how to engage the features, because this router doesn’t bite—usually. To use these features, you need to get inside your router and access its control panel. To do this, type the router’s internal IP address into your web browser on a computer on your network like this address for DLink routers: http://192.168.0.1. For Linksys routers, it’s http://192.168.1.1, and http://192.168.2.1 for several other brands. Check your router’s manual if none of these work for you, or look for the Default Gateway IP address when you use the ipconfig /all command (mentioned in tip #5). 1. Turn off UPnP.UPnP, or universal plug and play, is a handy feature that lets devices on your network self-configure on a network, but it’s also a security hazard. A Trojan horse or virus on a computer inside your network could use UPnP to open a hole in your router’s firewall to let outsiders in. So it’s a good idea to turn off UPnP when not in use. To do that, click the Tools tab then the Misc button, and click Disabled next to the UPNP listing. Be sure to click Apply to update the router with this new setting. See Figure 1.
Figure 1 Turn off UPnP in your router to stop malware on an infected computer from opening holes in the router’s firewall. Dated, with errors like WEP, SSID beacon, MAC address filtering, but useful. Security - DNS
Windows XP Windows Vista 1. Open a terminal window and type the following.$ sudo network-admin Note: Root access is required for this step. 2. Change to the DNS tab and enter the following two addresses in the top of the first field labeled DNS Servers.208.67.222.222 To avoid having your settings get revoked after reboots, or after periods of inactivity, do this: $ sudo cp /etc/resolv.conf /etc/resolv.conf.auto You may be required to change eth0 to your own network device's name if it uses a non-standard name. Instructions courtesy of Daniel Aleksandersen Ubuntu Security - Myths
Your network's SSID is still discoverable even if you turn off beacons:
The SSID is a 1 to 32 byte value that functions in wireless networks much the way that NETBIOS Scope functioned in the old bridged networks: to segment the airwaves for usage. If two wireless networks are physically close, the SSIDs label the respective networks, and allow the components of one network to ignore those of the other. SSIDs can also be mapped to VLANs; thus many APs support multiple SSIDs. The SSID is present in the following 802.11 management messages: • BEACONs • PROBE Requests • PROBE Responses • ASSOCIATION Requests • REASSOCIATION Requests This presence in management messages, or frames, is an oft-overlooked detail of the IEEE 802.11 specification that is critical to debunking the myth of SSID hiding. Management messages are always sent in the clear, even when link encryption (WEP or WPA) is used, so the SSID is visible to anyone who can intercept these frames. Debunking the myth of SSID hiding SSID Hiding Is Futile (So Is MAC Address Filtering) - Security Watch
blogs.pcmag.com/securitywatch/2007/10/ssid_hiding_... One of the many Microsoft security blogs makes the point today that disabling SSID broadcast as a security measure is futile and will only defeat the unsophisticated trespasser. It turns out that SSIDs are easily detected even if broadcast is off, if you have the right tools. It's true that if you have an "attacker" who isn't clever enough to use these tools, like some teenager who just wants to use your network, then perhaps they won't notice it and will attack somewhere else. But a well-secured network using WPA or, even better, WPA2, and a non-trivial password, will take care of those people, as well as more capable hackers. I won't embarrass myself by looking them up and linking to them, but I'm sure I've written tips in the past to disable SSID broadcast. Then a few years ago I realized that there were easily-available tools to detect SSIDs even if they weren't broadcasting, and I gave it up. All it does is make life harder for honest people. While he's at it, the author (Steve Riley, a senior security strategist in Microsoft's Trustworthy Computing Group). points out that MAC address filtering is also easily defeated. The only wireless security worth doing is the stuff that's easy - use WPA or WPA2. SSID Hiding Is Futile (So Is MAC Address Filtering) - Security Watch
blogs.pcmag.com/securitywatch/2007/10/ssid_hiding_...
Your Wi-Fi can tell people a lot about you | CNET News.com
news.com.com/2100-7355_3-6163666.html?part=rss&tag... ARLINGTON, Va.--Simply booting up a Wi-Fi-enabled laptop can tell people sniffing wireless network traffic a lot about your computer--and about you. Soon after a computer powers up, it starts looking for wireless networks and network services. Even if the wireless hardware is then shut-off, a snoop may already have caught interesting data. Much more information can be plucked out of the air if the computer is connected to an access point, in particular an access point without security. » The six dumbest ways to secure a wireless LAN | George Ou | ZDNet.com
blogs.zdnet.com/Ou/index.php?p=43 Updated 4/2/2007 - follow-up article here] For the last three years, I've been meaning to put to rest once and for all the urban legends and myths on wireless LAN security. Every time I write an article or blog on wireless LAN security, someone has to come along and regurgitate one of these myths. If that weren't bad enough, many "so called" security experts propagated these myths through speaking engagements and publications and many continue to this day. Many wireless LAN equipment makers continue to recommend many of these schemes to this day. One would think that the fact that none of these schemes made it in to the official IEEE 802.11i security standard would give a clue to their effectiveness, but time and time again that theory is proven wrong. To help you avoid the these schemes, I've created the following list of the six dumbest ways to secure your wireless LAN. Wireless LAN security hall of shame
Dishonorable mention: Some of you might be wondering why I didn't put WEP in as one of the six dumbest ways to secure a wireless LAN. In light of recent developments within the last 6 months, it takes only a few minutes to break a WEP based network which makes WEPcompletely ineffective and a good potential future candidate for the wireless LAN security hall of shame. Where it currently fails to be in the hall of shame is that it still holds up for a few minutes, requires a little skill to launch the packet injection attacks, and isn't propagated as an urban legend for a secure wireless LAN. The top six require no skills, takes less than a minute to crack, and are propagated asurban legend. However, that doesn't mean you should use WEP in any form or shape. This blog wasn't just meant to be funny, it's serious business that so many organizations waste their time and money on worthless security schemes that give them a dangerous false sense of security. If you fall in to any of these six categories, it's time to wake up and implement some real wireless LAN security. For those interestested in some simple advice for their homes and small offices, check out my last blog. Steve Riley on Security : Myth vs. reality: Wireless SSIDs
blogs.technet.com/steriley/archive/2007/10/16/myth... Myth vs. reality: Wireless SSIDsDo you ever wonder sometimes how it is that some ideas just won't die? Like the thought that not broadcasting your wireless network's SSID will somehow make you more secure? This is a myth that needs to be forcibly dragged out behind the woodshed, strangled until it wheezes its last labored breath, then shot several times for good measure. Folks, there are fundamental differences between names, which are public claims of identities, and authenticators, which are secrets used to prove identities, and I've written extensively about this before. An SSID is a network name, not -- I repeat, not -- a password. A wireless network has an SSID to distinguish it from other wireless networks in the vicinity. The SSID was never designed to be hidden, and therefore won't provide your network with any kind of protection if you try to hide it. It's a violation of the 802.11 specification to keep your SSID hidden; the 802.11i specification amendment (which defines WPA2, discussed later) even states that a computer can refuse to communicate with an access point that doesn't broadcast its SSID. And, even if you think your SSID is hidden, it really isn't. Let me explain. All 802.11 wireless networks, regardless of the kind of operating system or encryption you might use, also emit unencrypted frames at times. One kind of unencrypted frame is an association frame. This is what a client computer, or "supplicant" in the 802.11 protocol vernacular, emits when it wants to join a wireless network. Contained within the frame, in clear text of course (since the frame is unencrypted), is the SSID of the network the supplicant wants to join. Both Windows XP and Vista work best when your access points broadcast their SSIDs. XP really doesn't behave well at all with nonbroadcasting SSIDs. Vista has some added smarts to improve this a bit. Normally, Vista continually sends probe requests for nonbroadcasting networks. These probes are similar to unencrypted 802.11 association frames, and will generate clear-text responses from the access points if a nonbroadcasting network is present. You can reduce, but not entirely eliminate, these probes by configuring the wireless client to probe only for automatically-connected nonbroadcasting networks. Both these behaviors make it very easy for an attacker to discover your SSID. The bad guy, perhaps a contractor or a guest in your facility, could run one of many wireless sniffer programs and simply capture the hundreds of association frames or probes that litter your air. No amount of "hiding" configured in your access points can prevent this kind of traffic interception. So there you have it, simple SSID discovery. The old axiom remains true: security by obscurity is no security at all. Hiding an SSID will not hide a wireless network, so ignore any such advice -- and it's amazing how often I continue to see this. By the way, also ignore any advice that says to use MAC address filtering. It's amazingly trivial to spoof the MAC address of an allowed supplicant -- simply sniff the traffic, look at the MAC addresses, and use the neat little SMAC utility to change your MAC to one that's permitted. Nonbroadcasting networks are not secure networks. The right way to secure a wireless network is to use protocols that are designed specifically to address wireless network threats. If you're still using WEP, either static or dynamic, I encourage you to move to WPA2 as soon as possible. For those of you at home running XP and have kept it updated, or if you're running Vista, then, you simply need to enable WPA2. We've got some additional guidance for home/small offices and for enterprise networks with certificate services or without. If you have hardware that's more than two years old and you can't upgrade it, check to see whether it supports WPA (an interim specification released before WPA2 was ratified). Both WPA and WPA2 are built on sound cryptographic principles, they're proven in the field, and they'll keep the bad guys out -- even when you're broadcasting your SSID to the world.
Published 16 October 07 12:08
by
Steve Riley
Filed under: false claims, authentication, security myths, wireless, networking, encryption Should I change my router's password, and if so, how often? - Ask Leo!
ask-leo.com/should_i_change_my_routers_password_an... Summary: Routers typically require a login and password for configuration that comes set to a factory default. Should you change it? Yes. How often? It depends.
This article gives a good implicit understanding of administering WiFi networks. By implication you should set up WPA first, then change your admin password, but only using a wired port. PC World - How to Enhance and Secure Your Wi-Fi Network
www.pcworld.com/article/id,139985/article.html?tk=... How to Enhance and Secure Your Wi-Fi Network You may be so accustomed to having a Wi-Fi network at your home or office that you rarely give it a second thought. That's both the good news and the bad news: good because the network must be working, but bad because it's probably overdue for a tune-up and a security check. Following are several steps you can take to keep your wireless network humming, and your data and connection safe. Wireless LAN security myths that won’t diePosted by George Ou @ 2:26 am Categories: Security, Infrastructure, Mobile/Wireless, Networking, Vista, Desktop Tags:In Focus » See more posts on: Wireless Networking
It's been two years since I wrote "The six dumbest ways to secure a wireless LAN," and it's probably been one of my more successful blog entries ever, with two flashes on Digg. Since that time, I've written a free electronic book on enterprise wireless LAN security for anyone to use and download from TechRepublic. Since it has been two years, I'm going to update the information with more defined categories and better explain why they're so bad from an ROI (return on investment) and security perspective.
The original blog has probably been read by more than a hundred thousand people, but I still can't kill these nasty urban legends because they are so engrained as "best practice." I was shocked and infuriated to find that even some security certifications, like the CISSP, and VISA payment processing compliance requirements, like PCI, are recommending most of these methods as "best practice."
The most common and misguided arguments I hear against my advice and in favor of implementing this nonsense are:
The problem with these arguments is that they're based on some fundamentally wrong assumptions and an inadequate knowledge of how wireless LAN security works.
Rock solid wireless LAN security for the home or small office can be summed up in a single paragraph. All you need to do is use WPA-PSK security with a random alpha-numeric pass-phrase that has a minimum of 10 characters. I estimated that a truly random alpha-numeric 10-character pass-phrase using modern single-core computers will take one thousand PCs working in parallel 500 years to crack. If your hardware doesn't support WPA mode, you can almost always get a free software/firmware upgrade to support it. If WPA mode absolutely can't be supported, you can run WEP (104 bit AKA 128) security, which might take a semi-skilled script kiddy using two PCs in an active attack configuration 10 minutes to break. WEP shouldn't ever be considered effective wireless LAN security, but it's hundreds of times harder to break than any of the myths. WEP can be considered an actual deterrent when nothing better like WPA is available, whereas these myths aren't even worthy of the deterrent title. The ROI for any of the first three wireless LAN security myths is essentially zero. Security - Public Hotspots and other Venues (hotels)
See more in the WiFi (not shared) notebook.
Can hotels sniff my internet traffic? - Ask Leo!
ask-leo.com/can_hotels_sniff_my_internet_traffic.h... Summary: More and more hotels are offering both wired and wireless internet, but along with those connections comes a security risk most folks don't consider.
Yes. Hotel network security is one of the most overlooked risks travelers face. And I'm not just talking wireless, I'm talking any internet connection provided by your hotel. In fact, I'm actually writing this in a hotel room, and yes, I have taken a few precautions. • It's a topic c|net blogger Michael Horowitz has also written about: Ethernet connections in a hotel room are not secure and the title says it all. I'll put it another way: hotel internet connections are just as unsafe as an unsecured wireless hotspot. Good stuff on what to do about it follows online... Ethernet connections in a hotel room are not secure | Defensive Computing - CNET Blogs
blogs.cnet.com/8301-13554_1-9854369-33.html?tag=he... As Steve put it "... one bad person in a hotel could arrange to, without much work, literally intercept all the traffic going to and from the hotel's gateway so that all of the email conversations, all of the traffic of any sort that is being transacted by every other hotel guest, they're able to monitor and intercept."
To recap: websites typically encrypt your password so it cannot be sniffed, but then send you an unencrypted "session-id" for that session. The session-id is either some random data in the URL, or more often, random data in an HTTP cookie. A hacker who sniffs the session-id can then use it to gain access to that session, which usually means gaining access to the account. Thus, the hacker can read your Gmail/HotMail/YahooMail, look at what books you've ordered from Amazon.com, control your MySpace/Facebook page, and so on. The hacker still cannot get your password nor your credit card number, but can most everything else.
Support Alert Newsletter Issue 152 Premium SE Edition
techsupportalert.com/members/Issues/al_current.htm... 1.21 How to Improve Your Wi-Fi Security
Most of the public Wi-Fi networks found in airports and coffee shops are unsecured and present major security risks to users. This useful article [1] discusses the risks and what you can do to minimize them. Me, I always use a Virtual Private Network (VPN) when using public Wi-Fi as it represents a near perfect security solution. If you are tech savvy you can set one up yourself using Hamachi [2] or alternatively use a reputable commercial VPN service provider such as HotspotVPN [3], JWire [4] or WiTopia [5]. There is also a free VPN service provider called HotSpot Shield [6] but I haven't used it and don't know how their service stacks up. [1] http://www.jiwire.com/whitepaper-section1.htm [2] http://www.hamachi.cc/ [3] http://www.hotspotvpn.com/ [4] http://www.jiwire.com/hotspot-helper.htm [5] http://www.witopia.net/ [6] http://www.anchorfree.com/hotspot-shield/ Seven Steps to Safer WiFi - Desktop Security News Analysis - Dark Reading
www.darkreading.com/document.asp?doc_id=119473&WT....
Study: stores put customer data at risk with poor WiFi security practices
arstechnica.com/news.ars/post/20071116-study-store... Be careful of using public wireless hotspots, even if they claim to be secure. There's a good chance they are still vulnerable to hacking and your personal data could be stolen, according to wireless security manufacturer AirDefense. The company monitored wireless access points at stores and other retail outlets in Atlanta, Boston, Chicago, Los Angeles, New York City, San Francisco, London, and Paris as part of an annual wireless security survey and found that a quarter of the 4,748 access points surveyed had no encryption whatsoever. Another 25 percent of the access points used Wired Equivalent Privacy (WEP) to protect against outsiders. AirDefense was not impressed, however, describing it as "one of the weakest protocols for wireless data encryption." Indeed, the largest incident of consumer data theft to date is being blamed on WEP, which has been notoriously easy to hack since as far back as 2001. Just under half (49 percent) of the surveyed hotspots used WiFi Protected Access (WPA) or WPA 2, which AirDefense was much happier about because the protocols offer much stronger encryption than WEP. How Windows Firewall affects network locationsThe “Public place” location blocks certain programs and services from running, to help protect your computer from unauthorized access while you are connected to a network in a public place. If you are connected to a "Public place" network and Windows Firewall is turned on, some programs or services might ask you to unblock them (allow them to communicate through the firewall) so that they work properly. When you unblock a program, Windows Firewall unblocks it for every network with the same location type as the network you are currently connected to. For example, if you connect to a network in a coffee shop and choose "Public place" as the location type and then you unblock an instant messaging program, that program will be unblocked for all networks in the "Public place" location. If you unblock multiple programs while you're connected to a public network, consider changing the network location to "Home" or "Work." It might be safer to change this one network than affect every public network you connect to. But remember that if you make that change, your computer will be visible to others on the network. From Vista Help & Support » A secure Wireless LAN hotspot for anonymous users | George Ou | ZDNet.com
blogs.zdnet.com/Ou/?p=587 As ubiquitous and convenient as Wireless LAN Hotspots are, it is probably the single most dangerous technology to the mobile computer user. From a security standpoint it is an absolute nightmare because of multiple inadequacies. The two biggest issues with Hotspots is that you have no idea if you’re connecting to a legitimate Access Point or if you’re connecting to a hacker’s fake Access Point and everything you send and receive is transmitted in clear text with no encryption.
Vista
Keeping Safe in Windows Vista
In Windows Vista, you connect to a wireless network by first clicking the network icon in the System Tray, then selecting "Connect or disconnect." The "Connect to a Network" screen shows up, with a list of nearby wireless networks. You see the name of each and whether the network is encrypted or not; to get more details about any, hover your mouse over it, as shown in the nearby figure. But those details don't include whether the network is a true hot spot or an ad hoc network. Before you connect to a new wireless network, the only way to tell the difference between an ad hoc network and one in infrastructure mode is to look at the network icon next to it on the "Connect to a Network" screen. As you can see in the nearby figure, the icon for a normal Wi-Fi network is one computer, while the icon for an ad hoc network instead is several computers. That's it; there's no other way to distinguish between the two. Here's another oddity: If you right-click the list of available networks, on the menu that appears, some of them have a Properties menu item and others don't. Only those networks that you've previously visited and saved to your network list will have the Properties menu item. If you choose Properties, select the Connection tab and look next to Network Type, you'll see whether it's an ad hoc network or an access point (a normal hot spot). But if you haven't yet connected to the network (or if you have connected previously but haven't saved it), it won't have the Properties menu item. So you can't use that method of distinguishing between ad hoc and normal Wi-Fi networks when you're looking for a hot spot on the road. Other Steps You can TakeThere are other steps you can take to keep yourself safe, including turning off file sharing and running your company's VPN when at a hot spot. You can also pay to use a VPN such as HotSpotVPN. For details and many other tips for keeping yourself safe, see "How to protect yourself at wireless hot spots". In addition, Authentium is working with financial institutions to create a product called VirtualATM, which will help protect you when you connect to a financial institution. It's expected to be released later this year. Preston Gralla is a contributing editor for Computerworld.com and PC World.com, and the author of more than 35 books, including How the Internet Works. Download details: Wireless Networking in Windows Vista
www.microsoft.com/downloads/details.aspx?FamilyID=... Wireless Networking in Windows VistaBrief DescriptionSecurity, usability, and manageability improvements for Windows Vista wireless clients. New Networking Features in Windows Server 2008 and Windows Vista
technet.microsoft.com/en-us/library/bb726965.aspx
New Networking Features in Windows Server 2008 and Windows Vista
Published: February 15, 2006 | Updated: April 25, 2007 Note The features that are discussed in this article are subject to change. Some might not be included in the final product due to marketing, technical, or other reasons. On This PageIntro to Wi-Fi Networking Using Windows Vista
By Eric Geier
June 12, 2007
One of the numerous changes and enhancements in Windows Vista is the range of networking features. Microsoft tried to increase networking performance and security, though users will have to get used to a new look and interface. Therefore, this series of tutorials will introduce you to some of the enhancements and changes in Windows Vista involving networking, compared to its predecessor, Windows XP, and will show you how to perform common networking configuration tasks. Network and Sharing Center The new Network and Sharing Center (below) provides a one-stop shop for all your networking and Internet configuration needs. You can access the Network and Sharing Center via many methods:
As you can see, this center provides visual maps of your home or office network. The full map that’s accessible from this center provides an easy way to access any shared resources of other PCs and devices on the network. Just below the network map on the Network and Sharing Center, you can view and access your connection information. The Customize link allows you to change the name of the network connection, the type (private or public), and the icon given to the network connection, such as the briefcase you see in figure 1. Next, you’re provided with the status of all the main sharing and discovery settings and the ability to make quick changes, which is a big enhancement from XP. Another exceptional improvement is the set of links on the bottom of the window, showing you all the files and folders your account and computer are sharing on the network. The integrated task pane on the left side of the window provides access to familiar connectivity settings and tasks, as well as a shortcut to the Internet Options and Wireless Firewall settings. New Network Classification Scheme In Windows Vista, the first time you connect to a network, you must classify its location/type: Home, Work, or Public. Here’s the window that pops up after you connect to a new network: This new feature is extremely useful as it automatically modifies the appropriate network settings based upon the location type you choose. For example, say you connect to the Wi-Fi hotspot at your local café; you would choose Public location. Then Vista will automatically disable all network discovery and sharing to protect your documents and privacy while on the unsecured network. Then, say you went back home and connected to your home network, naturally classified as a Home location. Windows Vista then would allow network discovery and sharing, because you trust the other users on the network. Support for Non-Broadcasting Wireless Networks Windows Vista makes it easier to use wireless networks that do not broadcast their SSID (define) (also known as the network name). In Windows XP, these types of networks didn’t appear on the list of available wireless networks; however, they now appear as unnamed networks in Windows Vista. Instead of having to manually add a non-broadcasting wireless network to the preferred network list in order to connect, all you have to do in Vista is select the Unnamed Network, click Connect, and when prompted, enter the SSID. You may think that this degrades the security that hidden networks offer; however, the SSID is still needed in order to connect to the network. Additionally, not broadcasting your SSID doesn’t offer a whole lot of security anyway, a fact that I’ve discussed before. Where’s My Network Places? The My Network Places feature that has been in previous versions of Windows has simply been renamed to Network in Vista. You can access the Network on Vista’s start menu or when viewing your computer contents in Windows Explorer. Furthermore, for even quicker access, you can add the Network icon to your desktop:
Stay Tuned for more on networking using Windows Vista. Eric Geier is the founder and president of Sky-Nets, Ltd., which operates a Wi-Fi hotspot network serving the general aviation community. He has also been a computing and wireless networking author and consultant for several years. Eric’s latest book is Wi-Fi Hotspots: Setting up Public Wireless Internet Access, published by Cisco Press. Connecting to Wi-Fi Networks Using Windows Vista
By Eric Geier
July 10, 2007
As mentioned in Intro to Wi-Fi Networking Using Windows Vista, there have been many changes to the networking features in Windows Vista. Now I’ll cover exactly how to connect to wireless networks and perform other connection configuration tasks using Vista. Although the new networking interfaces in Vista may be better organized and enhanced for the majority of consumers, most IT professionals and advanced PC users won’t care for the redesign. As you’ll see, accessing some networking configuration and connection detail windows now requires more clicks than before. Connecting to a Wireless NetworkOne of the most similar networking tasks in Vista compared to XP is the process of connecting to wireless networks. The only major change is that the connecting window in Vista doesn’t provide direct access to the wireless network preferences and advanced settings. To access these items in Vista, you have to go to the Network and Sharing Center. Here’s how to connect to a Wi-Fi network in Vista: 1. Right-click on the network status icon in the system tray, and select Connect to a network. The connection window pops up:
2. Select the network you would like to connect to, and click Connect. You may be informed that the network is unsecured (not using WEP or WPA), in response to which you would click Connect Anyway to proceed, or you may be prompted that the network is secured and that you need to enter a key to continue. 3. Once the connection is complete, Vista will let you know that it has successfully connected to the network, and you can click Close to exit the connection window. Creating an Ad-hoc (Computer-to-Computer) NetworkCreating an ad-hoc network in Windows XP was a bit crude. You would add a network to the preferred list and check the ad-hoc option, then you would have to do some tinkering to start getting it broadcasting as ad-hoc. However, Windows Vista includes a wizard dedicated to creating peer-to-peer ad-hoc networks. Here’s how to access the ad-hoc setup wizard: 1. Right-click on the network status icon in the system tray, and select Connect to a network. The connection window pops up. 2. Click the Set up a connection or network link. The Connect to a Network window pops up. 3. Choose the Set up a wireless ad hoc (computer-to-computer) network option, and click Next. Then follow the on-screen directions. Modifying Your Preferred Wireless Network ListJust like the majority of the other networking tasks and preferences, to prioritize your wireless networks and to configure other individual settings (such as auto connecting), you need to go to the Network and Sharing Center. Here’s how to access the individual settings and preferences of wireless networks in Vista: 1. Right-click on the network status icon in the system tray, and select Network and Sharing Center. 2. In the Network and Sharing Center, click the Manage wireless networks link on the integrated task pane to the left. The Manage Wireless Networks window pops up:
3. To change the priority of the wireless networks, use the move up/down arrows, which are visible after clicking on an entry. You can also double-click on an entry to configure its connectivity preferences (such as auto connecting) and security settings. Checking Network Connection DetailsIn Windows XP, it was very easy to access the details of your network connections. Just hovering over the status icon in the system tray would give you the SSID or network name, data rate, signal and connectivity status; a quick double-click would give you the activity, duration and IP address information. This is not the case with Vista, however. Hovering over the network status icon in Vista only gives you the SSID, signal and connectivity status; double-clicking only gives you links to access the Connect to a Network window and the Network and Sharing Center. Accessing the other information (IP address and data rate) takes a few more clicks. Here’s how to access your network connection details in Vista: 1. Right-click on the network status icon in the system tray, and select Network and Sharing Center. 2. In the Network and Sharing Center, click the View status link next to the Network Name and SSID info. The Network Connection Status window pops up:
3. You now have access to most of the network connection details; however, for the IP address information, you have to click the Details… button. Tips & Tricks for Wi-Fi Networking with Windows Vista
www.wi-fiplanet.com/tutorials/article.php/3700151 Tips & Tricks for Wi-Fi Networking with Windows Vista
By Eric Geier
September 18, 2007
Although the new Network and Sharing Center in Windows Vista may be great for the average consumer, it can be quite a nuisance for advanced users because of the added steps to access many of the networking configuration settings. While Windows XP didn’t offer an exceptionally user-friendly networking interface, it was quick and easy to access certain network settings if you knew what you were looking for.
This tutorial will wrap up our series on networking with Windows Vista by showing some tips and tricks to help with your transition from Windows XP.
Add the Network Icon to the Desktop
The Network icon (replacement for My Network Places), like the other main system icons, isn’t placed on the desktop by default in Windows Vista. The Recycle Bin is the only desktop icon that automatically appears.
You can access the Network on Vista’s Start Menu or when viewing your computer contents in Windows Explorer. Furthermore, for even quicker access you can add the Network icon to your desktop. Here's how:
1. Right-click on your desktop and select Personalize. 2. Click the Change desktop icons link, on the left in the integrated task pane. 3. Check the icons you wish to appear on the desktop, then click OK to exit.
Quick Access to Network Connections
Disabling or enabling a connection in Windows XP only took a right-click on the network status icon in the system tray; however in Vista you have to open the Network and Sharing Center, click on a link to open the Network Connections window; then you can disable/enable a connection.
To save a few clicks each time you need to manage your network connections, you can create a desktop shortcut directly to the Network Connections window; here’s how:
explorer.exe ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
%SystemRoot%system32netshell.dll
For even quicker access to the Network Connections window, you can add the icon to the Quick Launch toolbar. Just drag the new desktop icon and drop it into the Quick Launch area.
Rename Network to My Network Places
The My Network Places from Windows XP has been renamed simply to Network in Vista. If you’re particular about the naming of your icons or you find it hard to get used to the Network icon after years of seeing My Network Places, you can change it.
Unfortunately, you can’t simply click on the icon and rename it as you can with other icons. You’ll have to do this through a more complex method—by editing the Windows Registry. Here's how:
HKEY_CURRENT_USERSoftwareClassesLocal SettingsSoftwareMicrosoftWindowsShellMuiCache
@C:Windowssystem32NetworkExplorer.dll,-1
The new icon name should now appear.
Add the Internet Explorer (IE) Icon to the Desktop
Along with the other main icons, the Internet Explorer icon isn’t automatically placed on the Vista desktop. In addition, the Internet Explorer icon can’t even be enabled via the desktop icon settings via the Personalization window. This can be rather bothersome when you’re used to clicking on the IE icon to surf the web. Nevertheless, there are ways to get the icon on your desktop:
Here’s the simplest way to add the Internet Explorer icon to the desktop:
Although that was simple, you’ll have the ugly arrow on the Internet Explorer icon, unlike the other main icons like Computer, Network, and Recycle Bin. You can however go through the more advanced method of adding the Internet Explorer icon without the arrow, but this requires editing the Windows Registry:
If using the Classic Start menu, click on Run, type “regedit”, and click OK.
{871C5380-42A0-1069-A2EA-08002B30309D} If the key doesn’t exist, you need to create it: a) Right-click in the right hand pane, select New, and click on DWORD (32-bit) Value. b) Type the above key (including the brackets) into the entry and hit Enter. c) Then double-click on the new key and proceed to the next step. 3. In the Value data field, type “0”, and press OK.
The Internet Explorer icon should now appear on your desktop.
If you haven’t already, check out all the earlier tutorials on networking using Windows Vista: Sharing on a Wi-Fi Network Using Windows Vista
By Eric Geier
August 16, 2007
Now that we've covered network connectivity tasks using the new Windows Vista, we'll discuss the differences of sharing from Windows XP. Although setting up shared resources in Vista is similar to what you may be used to in Windows XP, it can be a bit confusing at first. Therefore, I'll show you step-by-step how to perform common network sharing tasks and configurations. Share Files Using the Public Folder Windows Vista doesn't have the Shared Documents folder (which Windows XP offered), however the Public folder is included which offers a very easy way to share files and documents with others on the same network in addition to other user accounts on the PC. As Figure 1 shows, you can access the Public folder from Windows Explorer or Computer.
You can simply drag and drop (or copy and paste) files and folders into the Public folder (or one of its subfolders) to share them with users on the same PC and others on the same network. Although Vista automatically shares the Public folder with other network users, there is a security measure in place to help prevent unintended sharing of your Public folder when on public and other un-trusted networks, such as Wi-Fi Hotspots. As mentioned in Intro to Wi-Fi Networking Using Windows Vista, there's a new network classification scheme where you're prompted to classify the networks you connect to, as Home, Work, or Public. For example, if you choose Public location, Vista will automatically disable all network discovery and sharing (the Public folder and any manually shared folders) to protect your documents and privacy while on the unsecured network. Then if you go back home and connect to your network (that you classified as Home), sharing will be re-enabled. You can also easily disable the sharing of the Public folder at anytime via the Network and Sharing Center which can be accessed by right-clicking on network status icon in the system tray. Then just scroll down to the green and/or gray status lights, click the arrow to the right of the Public folder sharing light, select your desired setting, and click Apply. Share a Specific Folder
In addition to dragging over files to the Public folder, you can also enable the sharing of just about any folder on your PC, just like you could in Windows XP. Setting up sharing for folders in Vista isn't much more difficult than in XP, though it's a bit more confusing at first. Here's how to do it: 1. Right-click on the folder you want to share and select the Share… option. The File Share window pops-up. Figure 2 shows an example.
The list box with the Name and Permission Level fields are those who can access the shared folder (we'll call it the Access List). The Windows account you're currently logged on is automatically added to the Access List. Share a Printer
Use a Shared Printer Once you have enabled the sharing of a printer, you can add that printer to other PCs on the network so you can print from it. Here's how to do it in Windows Vista:
If you're unable to find the shared printer during the setup, you may want to ensure that printer sharing isn't disabled on the PC hosting the printer. You can check this by opening the Network and Sharing Center and scrolling to the appropriate entry on the status light area Enable Password Protection In Windows Vista you can enable password protection for your shared folders. When enabled, however, your shared resources aren't shared with others on the network. The shared resources will only be available to other user accounts on the same PC; and of course access is only given by entering the password.
View All Your Shared Folders Unlike Windows XP, Vista allows you to easily and quickly see all the folders you're sharing. It's very easy to forget which folders you've shared over time, though this feature enables you to always know exactly what is being shared and to whom. Therefore you can better protect your data and privacy which is particularly important for those who often use un-trusted networks such as Wi-Fi hotspots. Here's how to view the lists of shared files and folders:
It's a good idea to periodically check your shared folders, their permission settings, and their contents to make sure you don't unintentionally share something that's private or sensitive. Stay Tuned for more on networking using Windows Vista. VPN
Defending against insecure hotel networks with a VPN | Defensive Computing - CNET Blogs
blogs.cnet.com/8301-13554_1-9874115-33.html?part=r... Where to rent Two companies that rent VPNs are Witopia and HotSpotVPN. Both offer two types of VPNs, PPTP and SSL. The pros and cons of each type of VPN are not something I'm ready to get into. Suffice it to say that a PPTP VPN is usually cheaper, probably won't require software to be installed, and is not as secure when compared to an SSL-based VPN. The HotSpotVPN-1 service is based on PPTP, while the HotSpotVPN-2 is based on SSL. HotSpotVPN-1 is roughly $9 per month, and HotSpotVPN2 ranges from roughly $11 to $14 per month depending on the strength of the encryption. According to Steve Gibson, the cheapest encryption strength is sufficient. In both cases, yearly charges are 10 times the monthly charge. HotSpotVPN-1 is also available by the day or week. WiTopia offers PersonalVPN (PPTP) and PersonalVPN (SSL). Their SSL-based VPN is only $40 a year (the equivalent service from HotSpot is $110 to $140 per year). Both companies throw in a PPTP-based VPN when you order an SSL-based VPN and they both point out that Apple's iPhone supports PPTP-based VPNs. Using a VPN is a small annoyance, but security and convenience will forever be at odds. Windows XP
The Cable Guy - August 2004
Wireless LAN Enhancements in Windows XP Service Pack 2 Microsoft Windows XP Service Pack 2 (SP2) includes a number of enhancements to support Institute of Electrical and Electronic Engineers (IEEE) 802.11-based wireless local area networks (LANs). These enhancements include the following: Wireless Network Configuration Tips for Windows XP
www.wi-fiplanet.com/tutorials/article.php/3676976 Wireless Network Configuration Tips for Windows XP
By Joseph Moran
May 10, 2007
Configuring or reconfiguring a wireless network — or just adding a new device to an existing one — can often be a hassle. In fact, keeping configuration effort to a minimum is one of the main reasons many people choose (unwisely) to do things like use default SSIDs (define), simplistic and easily guessed encryption keys, or altogether forgo the use of encryption on their WLANs (define). This is especially true when there are lots of wireless systems that need to be set up, because few people relish the task of typing in long and cumbersome text strings over and over again. But if you have several systems running Windows XP SP2, there is a way to avoid some of the repetitive, time-consuming and error-prone data entry. Using a built-in technology called Windows Connect Now (WCN), you can automate the wireless configuration process for many PCs and possibly for other types of wireless devices, too. Save a Step (or Several) Here's how WCN works in a nutshell — instead of typing your SSID and encryption key individually into multiple systems, you can enter your WLAN configuration information once into a WCN wizard. It's then automatically stored in an XML (define) file and copied to a USB (define) flash memory drive, which you can use to set up additional wireless systems and devices without having to renter the information again. Like most technologies, WCN isn't without its limitations. It was originally intended to be built into a host of wireless-enabled devices including routers and printers, and when the feature first debuted there were a handful of such devices that supported it. These days, however, relatively few non-PC devices support WCN (there's a list of compatible devices on Microsoft's WCN web site, but most are dead links indicating a product that's been discontinued). If you have a wireless device with a USB port, check your documentation to see if it's WCN-compatible — one currently available product that supports WCN is D-Link's DNS G-120 storage adapter, as does Microsoft's own Xbox 360 game console. In spite of the drawbacks, WCN can, at the very least, be a useful and time-saving way to configure wireless settings on multiple PCs running Windows XP SP2 — which represents a significant percentage of what people are still running. (Unfortunately, it doesn't work with previous Windows versions, nor unsurprisingly, with non-Windows systems.) Getting Started The first step to using Windows Connect Now is to run the Wireless Network Setup Wizard, which you'll find in the Windows Control Panel. When you launch the wizard for the first time you'll be prompted to enter an SSID for your wireless network and choose whether you want to have Windows automatically create an encryption key or manually assign one yourself. Before clicking Next, be sure to check the box labeled Use WPA (define) encryption instead of WEP (define). If you allow the wizard to generate your encryption key, it will create one using the maximum allowed length. But if you decide to use your own, make it as long and the characters as random as possible, because when it comes to WPA keys, longer means stronger. As you proceed through the wizard you'll be given the option to save the data to a USB flash drive (the default choice) and you'll have to specify the drive letter that corresponds to your USB device. Once you've done that and clicked Next, leave the wizard open, remove the USB device, and plug it into the another XP SP2 system you want to configure. When the pop-up menu appears select the first option — to run the Wireless Network Setup Wizard — and then confirm that you want to add the system to your WLAN. Then remove the USB drive and repeat the process on any additional systems or devices. Note that if you use plug your USB key into a WCN-compatible device other than a PC, it will generally flash a staus LED (define) three times to indicate that it's been successfully configured. (Some additional steps are required with the Xbox 360 — for details consult xbox. Once you've finished configuring all your systems and/or devices, plug the USB drive back into the original XP system you started at. (You'll see the same pop-up menu, which you can dismiss or use to configure that system if you haven't already done so.) Return to the Wireless Network Setup Wizard and click Next, and you'll see a list of the systems and/or devices you've configured. You'll also see a button labeled Print Network Settings, and it's not a bad idea to use it to make yourself a hard copy. The printed record (kept appropriately secured, of course) can come in handy as a reference to manually configure a device that doesn't support Windows Connect Now. By default, there should be a check in the box next to "For security reasons, remove network settings from my flash drive." It's best to leave this option selected and delete the data than to leave your wireless security information on a device that can easily be misplaced and fall into the wrong hands. (Remember — as long as the network settings are present, the flash drive will offer to use them to configure any WCN-compatible device it's plugged into.) However, the good news is that even if you delete the settings, you won't need to re-enter the information if you ever decide you need to use the Wireless Network Setup Wizard again. The next time you run the wizard (from the original system, of course) you'll have the choice to either set up a new network or to add additional devices to your existing one. Your original SSID and encryption key information is retained by the wizard, so if you choose the latter, the information can automatically be recopied to your USB device. WPA
Wi-Fi Protected Access 2 (WPA2) Overview
For a list and additional information on all The Cable Guy columns, click here IntroductionThe original IEEE 802.11 standard provided the following set of security features to secure wireless LAN communication:
Over time, these security features proved to be insufficient to protect wireless LAN communication in common scenarios. To address the security issues of the original IEEE 802.11 standard, the following additional technologies are used:
Wi-Fi Networking News: Weakness in Passphrase Choice in WPA Interface
wifinetnews.com/archives/002452.html Weakness in Passphrase Choice in WPA InterfaceBy Glenn Fleishman By Robert Moskowitz Use of PSK as the key establishment method WPA and 802.11i provide for a Pre-Shared Key (PSK) as an alternative to 802.1X based key establishment. A PSK is a 256 bit number or a passphrase 8 to 63 bytes long. Each station MAY have its own PSK, tied to its MAC address. To date, vendors are only providing for one PSK for an ESS, just as they do for WEP keying. When a PSK is used instead of 802.1X, the PSK is the Pairwise Master Key (PMK) that is used to drive the 4-way handshake and the whole Pairwise Transient Key (PTK) keying hierarchy. There is a straightforward formula for converting a passphrase PSK to the 256-bit value needed for the PMK. This paper will look into the risks of using a PSK and particularly the risk associated with a passphrase-based PSK. Learn The Basics Of WPA2 Wi-Fi Security -- Wi-Fi Security -- InformationWeek
www.informationweek.com/news/showArticle.jhtml?art... Learn The Basics Of WPA2 Wi-Fi Security
Learn how WPA2 can help secure your wireless network, providing encryption and access control, and why it's safer than previous standards.
By Frank Bulk
Network Computing January 27, 2006 12:00 AM
Looking for more secure Wi-Fi? WPA2 (Wi-Fi Protected Access 2) gives wireless networks both confidentiality and data integrity, two terms not previously associated with Wi-Fi.
Security, of course, has long been the trade-off with Wi-Fi. Early wireless networks leaned heavily on VPNs to provide Layer 3 security, which--aside from the additional overhead of encapsulation and the challenges of roaming, quality of service, client support and scalability--left the IP network vulnerable to attacks. The Layer 2-based WPA2 better protects the network.
But WPA2 alone can't provide enterprise security: Combining WPA2 with the IEEE 802.1X port-based authentication protocol for access control should eliminate most security worries. This won't protect you from rogues, denial-of-service attacks or interference, but it will ensure secure wireless communication. AES Encryption And AirPort Extreme Eric Hildum One issue that Mr. Cain may be encountering is the differences that various manufacturers have in implementing some of the details of the WPA-PSK standard, particularly with regards to the number of keys and the method by which a text string is converted to a hexadecimal key. Apple's products use only one key - if his base station has more than one, the keys will be rotated and he will have problems - symptoms of which would be intermittent no access and dropped connections. For best compatibility, configure the wireless access point with one and only one 64 digit hexadecimal key, and enter the same key on the PowerBook. Do NOT use the optional text password/key entry in either system as they may not be converted to a hexadecimal key the same way, which would result in mismatched keys and no access. WPA-PSK: Step-by-Step
By Jeremy deVries
September 30, 2005
Security is all the talk in wireless networks today, whether at home or in the office -- and for good reason. Which security is best for you? WEP (Wired Equivalent Privacy) used to be the standard, but newer and arguably better security standards have been implemented for wireless. Wi-Fi Protected Access (WPA), so named by the Wi-Fi Alliance, is taking the lead alongside an even newer version, WPA2. Both are based on the Institute of Electrical and Electronics Engineers (IEEE) 802.11i ratified amendment. WEP was never a strong protection mechanism, and was easily broken. WPA builds upon WEP, making it more secure by adding extra security algorithms and mechanisms to fight intrusion. With WPA’s more advanced features come more options for configuring security on your network, but the added complexity can turn securing a network into a giant headache. Still, with the right approach, it needn’t be painful. WPA allows for two kinds of security authentication types, WPA-802.1x (AKA WPA-Enterprise) and WPA-PSK (or WPA-Home). WPA-802.1x (RADIUS) signifies that there is a RADIUS (Remote Authentication Dial-in User Service) server on the network. A RADIUS server isn't just for dial-up connections — it is a certificate authenticator that only allows client stations to connect with the Access Point (AP) if it sees a valid certificate on the client, which the server provided earlier. This use of WPA is generally for medium to large businesses, and is generally not used in SOHO (small office/home office) setups. Many APs now come with integrated Authentication Servers (AS) which act as RADIUS servers, giving SOHO users the ability to use WPA-802.1x authentication schemes if they want, even for small groups. But WPA-PSK is the better choice for SOHO users, because of its simple setup and deployment across a multi-vendor environment. WPA-PSK (Wi-Fi Protected Access with Pre-Shared Key) enables users to easily set up and manage a secured WLAN. WPA-PSK uses a pass-phrase, which is between 8 and 63 characters long. This pass-phrase is created and entered by the user into any client station’s configuration utility, as well as into the AP. (A recommendation: do not pick a password already in use within the network, and do not use a variation of your office address.) Generally, when creating or setting up a wireless LAN, the first thing to be configured is the AP, which is then followed by the configuration of client stations. Configuring an AP depends largely upon the manufacturer’s instructions; client station configuration is where the real choices about security come into play. First, we’ll turn to setting up the AP. Access Point ConfigurationIt is my solemn duty to recommend, if you are buying a new access point, that you read through the manual on how it is to be configured as you take it out of the box. Methods for configuring client stations and APs vary widely depending on the manufacturer and configuration utilities; some have their own configuration programs, others are configured by using a Web browser, and still others use a command line interface (CLI), so reading the manual is important. For ease of explanation, I will refer to APs that are configured using Web browsers, and will not go into all the features APs offer. Most APs have a separate page for setting the Network Name, otherwise known as the SSID (Service Set Identifier). On this page, you must specify the same Network Name as on the client stations. For example, if you set the name "My Network SSID" on the client stations, you should therefore use it on the AP as well (or vice versa — most people set up the AP first).
Some APs automatically assume the use of TKIP (temporal key integrity protocol) when WPA-PSK is selected. It is a data encryption method used for WPA-PSK which adds extra security ciphers and algorithms to the preexisting WEP encryption. If it's not automatic, specify TKIP as the encryption type. TKIP isn’t the only data encryption method that can be used, but it's best for our purposes. On some APs, when you select WPA-PSK, a note will pop up suggesting that RADIUS be enabled. Even though WPA-PSK doesn’t require a RADIUS server, you can enable RADIUS (if needed). In these cases, leaving the RADIUS configuration blank, or leaving it as originally configured when you enabled it, should not cause any issues. If the AP you’re configuring doesn’t show any settings for WPA (PSK or other), try upgrading the firmware on the AP. Do this by navigating to the correct location on the AP or on the manufacturer’s Web site. In any event, the user manual should include directions on how to upgrade the AP. Client Station ConfigurationConfiguring the client stations and access points isn’t as daunting a task as it might seem. The ease of configuring client stations depends principally on the configuration utility you are using. Windows XP comes with its own configuration utility built in, Windows Zero Configuration Utility (WZC). However, there are other configuration utilities that offer better efficiency, easier configuration, and better wireless network monitoring. Most client cards come with their own wireless configuration utility, though others depend on Windows. Here we'll describe the configuration of client stations using WZC, which is the lowest common denominator for most users.
The next step is specifying the type of security that will be used to connect to the network. In the Network Authentication field, scroll until WPA-PSK is selected. With WZC, there are two WPA authentications listed: to use WPA with a RADIUS server (802.1x), you would pick the first option of just WPA. The second WPA listed is WPA-PSK; for our setup, we select this to continue configuring a WPA-PSK network. The Data Encryption field below the Network Authentication field specifies the protocol that WPA-PSK will use; choose TKIP. The last step needed to configure the client station is very important, in that the Network Key entered into the client station must be the same as the network key (pass-phrase) that is entered on the AP. Network keys are case-sensitive; capitals, lower-case, numbers, non-alphanumeric symbols ($#!+, etc.) must all be exactly the same. This might sound like a walk in the park, but when setting up a wireless network, many neglect this minute but crucial detail. In some cases, after configuring the client station, issues with connecting to the AP may still arise. In these cases, there are three things to check:
In today’s age of ubiquitous SOHO networks and ever more Wi-Fi in laptops, security is a paramount concern. Unsecured or improperly set up wireless networks can leave you vulnerable to intrusion, viruses, hijacking of bandwidth, and more problems than one can list, which is why properly setting up your secured network using an authentication mechanism such as WPA-PSK is a crucial step in creating a wireless network.
Securing your wireless network with WPA2
WPA2 secures wireless better than WEP or WPA In the Mar. 8 newsletter, I talked about securing wireless routers. One of the suggestions I made was to enable encryption, if your router and wireless network cards support that feature. Doing so helps prevent someone from snooping in your network traffic and using your bandwidth. There are three basic types of encryption for most wireless networks: Wired Equivalent Privacy (WEP), Wi-Fi Protected Access (WPA), and Wi-Fi Protected Access 2 (WPA2). When considering encryption, the basic thing you need to know is that encryption is accomplished using some type of cipher and some length of encryption key to scramble and unscramble the data. WEP and WPA both use the RC4 stream cipher. WEP uses a 40-bit encryption key, while WPA uses a longer 128-bit key. Naturally, WPA provides stronger protection. WPA also uses dynamic keys, whereas WEP keys are static. Dynamic keys change at a interval, which adds to the strenth of WPA protection by making your keys a moving target. WPA can also support 802.1X authentication. In very simplified terms, this is a logon mechanism that verifies who the user is. Without 802.1X in place, WPA isn´t as strong as it could be. In fact, some experts argue that without 802.1X, WPA isn´t much better than WEP. For more information about weaknesses in WPA without 802.1X, see Joel Snyder and Rodney Thayer's 2004 article in Network Computing entitled, " WPA — An accident waiting to happen." Be aware that one popular tool for Mac OS X, called kismac, has the ability to discover encryption keys for both WEP and WPA. Other tools, such as WPA Cracker and CoWPatty, can do the same thing. By contrast, WPA2 uses dynamic encryption keys and the Advanced Encryption Standard (AES) block cipher. This is far stronger than the RC4 cipher used in WEP and WPA. To date, no one has published a way to defeat WPA2 encryption, although that does not mean it isn't possible. In fact, several people have theorized ways that WPA2 could be defeated — it simply hasn't been demostrated yet. So, if you require encryption between your computer and wireless router, and your network hardware and operating system supports WPA2, be sure to use it. If you can't use WPA2, then use WPA; and if you can't use WPA, then use WEP. Just be aware that both WPA and WEP can be cracked with relative ease. Doing so does require specialized software that the average person won't bother locating and using. On the other hand, determined intruders will obtain such software and try to use it. TKIP, AES or TKIP+AES - Wireless Routers - Linksys Community Forums
forums.linksys.com/linksys/board/message?board.id=... The option of WPA2 with "TKIP or AES" allows you to run a mixed system: Those devices that can do WPA2 with AES will use that system, less advanced devices (such as PDA's) that can only do WPA will do WPA with TKIP. If you are having trouble with WPA2 you should note the following: 1) make sure you have the latest driver for your wireless adapter 2) Windows XP requires a patch to run WPA2. Go to Microsoft Knowledge base, article ID=893357 and it will direct you to the patch. Sadly, the patch is not part of the automatic Windows XP updates, so lots of people are missing the patch. Message Edited by toomanydonuts on 06-13-2007 11:12 PM
WPA2 secures wireless better than WEP or WPA
In the Mar. 8 newsletter, I talked about securing wireless routers. One of the suggestions I made was to enable encryption, if your router and wireless network cards support that feature. Doing so helps prevent someone from snooping in your network traffic and using your bandwidth. There are three basic types of encryption for most wireless networks: Wired Equivalent Privacy (WEP), Wi-Fi Protected Access (WPA), and Wi-Fi Protected Access 2 (WPA2). When considering encryption, the basic thing you need to know is that encryption is accomplished using some type of cipher and some length of encryption key to scramble and unscramble the data. WEP and WPA both use the RC4 stream cipher. WEP uses a 40-bit encryption key, while WPA uses a longer 128-bit key. Naturally, WPA provides stronger protection. WPA also uses dynamic keys, whereas WEP keys are static. Dynamic keys change at a interval, which adds to the strenth of WPA protection by making your keys a moving target. WPA can also support 802.1X authentication. In very simplified terms, this is a logon mechanism that verifies who the user is. Without 802.1X in place, WPA isn´t as strong as it could be. In fact, some experts argue that without 802.1X, WPA isn´t much better than WEP. For more information about weaknesses in WPA without 802.1X, see Joel Snyder and Rodney Thayer's 2004 article in Network Computing entitled, " WPA — An accident waiting to happen." Be aware that one popular tool for Mac OS X, called kismac, has the ability to discover encryption keys for both WEP and WPA. Other tools, such as WPA Cracker and CoWPatty, can do the same thing. By contrast, WPA2 uses dynamic encryption keys and the Advanced Encryption Standard (AES) block cipher. This is far stronger than the RC4 cipher used in WEP and WPA. To date, no one has published a way to defeat WPA2 encryption, although that does not mean it isn't possible. In fact, several people have theorized ways that WPA2 could be defeated — it simply hasn't been demostrated yet. So, if you require encryption between your computer and wireless router, and your network hardware and operating system supports WPA2, be sure to use it. If you can't use WPA2, then use WPA; and if you can't use WPA, then use WEP. Just be aware that both WPA and WEP can be cracked with relative ease. Doing so does require specialized software that the average person won't bother locating and using. On the other hand, determined intruders will obtain such software and try to use it. Keep in mind that network security essentially means controlling access. Therefore anything you do to control access is part of your security procedures. Good network security requires a layered approach. The reason is simple and somewhat obvious: If one layer fails, then another layer can help protect your systems and network. For example, if someone found a way to crack your WPA2, then you would already have other layers in place that would help protect your network — if only for a little while longer. There are some additional steps you can take to help protect your wireless network that will make it more difficult for a bad guy to break in. The extra time it takes to crack your system might be just enough for you to power off your network gear because you're going to bed for the evening. A coincidence, yes, but you never know! You can configure your router so that it doesn't broadcast its Service Set Identifier (SSID), which is basically the router's common name. While taking this step doesn't completely eliminate a person's ability to find your router's name (that, too, can be done with special software), it will stop the average passerby from finding it. Yet another step you can take is to configure the router so that it only accepts connections from specific Media Access Control (MAC) addresses, which are unique hardware numbers assigned to network interfaces. As with disabling SSID broadcasts, taking this step doesn't completely prevent someone from connecting to your router. With enough knowledge and the right tools, someone could clone a MAC address that is allowed to connect to your router. But again, the average user who is merely looking for a quick way to check e-mail or view a Web page won't bother with that. They'll simply move on to find another nearby wireless network. So, while both of these precautionary steps can be defeated by a savvy intruder, they will still go a long way towards keeping most, if not all, of your neighbors and strangers from connecting to your network without your permission. And finally, one more step you can take to protect your wireless network is to simply turn it off when you aren't using it! There's no sense in leaving it on when it's not in use, especially at night when you're sleeping. Thanks go out to John Landais for reminding me about the SSID features and MAC filtering. |