Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Securing my network


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Networking

Securing my network
Reply
 
Thread Tools
Old 17-04-2006, 12:28   #1
cf.member
 
Join Date: Mar 2006
Posts: 17
Euph0ria is an unknown quantity at this point
Securing my network

Hi folks, hope everyone is having a smashing easter

I just got my wireless connection up and running with the help of Rob and just wanted to know the best way to check that it is secure without messing with any settings that I am unsure of.

Now, when I set it up I created a passkey which I had to input when using the linksys software monitor in the taskbar to connect to my router, so i'm guessing some sort of security is enabled. I also chose WPA personal on the setup but can't find anywhere in the settings were I can see it enabled.

I just want to make sure that everything is secure

Cheers

- Paul
Euph0ria is offline   Reply With Quote
Old 17-04-2006, 12:48   #2
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: Securing my network

You could also restrict the MAC addresses allowed to connect to your router, so that only those that you know and have specified, can successfully connect. However, this is not a foolproof method - it can be easily bypassed.

You may want to consider disabling broadcasting your SSID, but personally I don't advocate this. The theory is that if you don't broadcast it, people won't stumble on your WLAN by accident. However, it is trivially easy to find a WLAN - even with the SSID disabled - if you're in the vicinity of the router by using a tool such as netstumbler. As your SSID is leaked out constantly in any case, hiding the SSID is imo pretty pointless.

Also, if your SSID is hidden, then it could mean that your neighbours are unaware that you've got a WLAN setup, and there is the potential for you to both be broadcasting on the same channel - if you can't see any other WLANs in your vicinity, then you're not necessarily going to think that you're sharing a channel, but if you can see that there is another WLAN that you can pick-up, then you're more likiely to consider switching channels.
__________________
Quidquid latine dictum sit, altum sonatur.
Gareth is offline   Reply With Quote
Old 17-04-2006, 13:11   #3
cf.member
 
Join Date: Mar 2006
Posts: 17
Euph0ria is an unknown quantity at this point
Re: Securing my network

Quote:
Originally Posted by Gareth
You could also restrict the MAC addresses allowed to connect to your router, so that only those that you know and have specified, can successfully connect. However, this is not a foolproof method - it can be easily bypassed.

You may want to consider disabling broadcasting your SSID, but personally I don't advocate this. The theory is that if you don't broadcast it, people won't stumble on your WLAN by accident. However, it is trivially easy to find a WLAN - even with the SSID disabled - if you're in the vicinity of the router by using a tool such as netstumbler. As your SSID is leaked out constantly in any case, hiding the SSID is imo pretty pointless.

Also, if your SSID is hidden, then it could mean that your neighbours are unaware that you've got a WLAN setup, and there is the potential for you to both be broadcasting on the same channel - if you can't see any other WLANs in your vicinity, then you're not necessarily going to think that you're sharing a channel, but if you can see that there is another WLAN that you can pick-up, then you're more likiely to consider switching channels.
Ok, got that in theory all I need to do now is know were to check if I have the WPA active.

Will the passkey I setup stop others accessing my network?
Euph0ria is offline   Reply With Quote
Old 17-04-2006, 15:07   #4
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: Securing my network

If it's set-up on the router as being required, then you'd not be able to connect on the laptop if it wasn't configured. So, if the router is showing it OK, then you're fine

---------- Post added at 15:07 ---------- Previous post was at 15:07 ----------

As for the passkey question, yep.
__________________
Quidquid latine dictum sit, altum sonatur.
Gareth is offline   Reply With Quote
Old 17-04-2006, 16:32   #5
 
Druchii's Avatar
 
Join Date: Mar 2006
Location: Oslo, Norway.
Services: Get.no 26Mb/3Mb Cable
Posts: 6,559
Druchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronze
Druchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronze
Send a message via Skype™ to Druchii
Re: Securing my network

Quote:
You could also restrict the MAC addresses allowed to connect to your router, so that only those that you know and have specified, can successfully connect. However, this is not a foolproof method - it can be easily bypassed.
After hearin that i want to know how ? I have my router set up like this and am now sort of worried.
__________________
Intel C2D E8400@4Ghz (52c) | 2Gb HyperX RAM | nVidia 8800GT 512Mb (700/1000) | Corsair VX550w PSU | Gigabyte EP35-DS3R | Win XP SP3 | 500Gb Seagate Barracuda 7200.11
Druchii is online now   Reply With Quote
Old 17-04-2006, 19:28   #6
cf.member
 
Join Date: Mar 2006
Posts: 17
Euph0ria is an unknown quantity at this point
Re: Securing my network

Quote:
Originally Posted by Gareth

---------- Post added at 15:07 ---------- Previous post was at 15:07 ----------

As for the passkey question, yep.
That's what I wanted to hear
Euph0ria is offline   Reply With Quote
Old 17-04-2006, 20:28   #7
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: Securing my network

Quote:
Originally Posted by Druchii
Quote:
You could also restrict the MAC addresses allowed to connect to your router, so that only those that you know and have specified, can successfully connect. However, this is not a foolproof method - it can be easily bypassed.
After hearin that i want to know how ? I have my router set up like this and am now sort of worried.
Sorry, didn't mean to worry anyone

If you're interested in learning more about this, I would strongly recommend downloading a copy of BackTrack (www.remote-exploit.org) and reading up about the various tools found in the Wireless section of BackTrack.

Briefly, to exploit a WLAN using MAC filtering, you'd sit and catch packets being broadcast legitimatly between the AP and the clients, and once you'd determined that a MAC address had been successfully authenticated with the AP, you'd change the MAC of your wireless card to spoof the one you grabbed. Using something such as wellenreiter and either ethereal or tcpdump, or kismet, or netstumbler, etc... this kinda thing is pretty trivial.

It's also possible to set up a laptop with a wireless card to pretend to be a wireless AP, at which point any PCs with a wireless card will try connecting to it to get the details, which is another way of obtaining MAC addresses, amongst other things.

However, just to put this into perspective, chances are people who know how to do this are not going to go to the effort just to access your home WLAN - this is mostly reserved for corporate WLAN access. So, don't have nightmares... sleep tight
__________________
Quidquid latine dictum sit, altum sonatur.
Gareth is offline   Reply With Quote
Old 17-04-2006, 20:48   #8
 
Druchii's Avatar
 
Join Date: Mar 2006
Location: Oslo, Norway.
Services: Get.no 26Mb/3Mb Cable
Posts: 6,559
Druchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronze
Druchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronze
Send a message via Skype™ to Druchii
Re: Securing my network

Quote:
Originally Posted by Gareth
Sorry, didn't mean to worry anyone If you're interested in learning more about this, I would strongly recommend downloading a copy of BackTrack (www.remote-exploit.org) and reading up about the various tools found in the Wireless section of BackTrack. Briefly, to exploit a WLAN using MAC filtering, you'd sit and catch packets being broadcast legitimatly between the AP and the clients, and once you'd determined that a MAC address had been successfully authenticated with the AP, you'd change the MAC of your wireless card to spoof the one you grabbed. Using something such as wellenreiter and either ethereal or tcpdump, or kismet, or netstumbler, etc... this kinda thing is pretty trivial. It's also possible to set up a laptop with a wireless card to pretend to be a wireless AP, at which point any PCs with a wireless card will try connecting to it to get the details, which is another way of obtaining MAC addresses, amongst other things. However, just to put this into perspective, chances are people who know how to do this are not going to go to the effort just to access your home WLAN - this is mostly reserved for corporate WLAN access. So, don't have nightmares... sleep tight
Haha, nice ending.

I get how this works, and yeah, i think i can put up with kicking someone off my network if they tried so hard to get in.. haha.
__________________
Intel C2D E8400@4Ghz (52c) | 2Gb HyperX RAM | nVidia 8800GT 512Mb (700/1000) | Corsair VX550w PSU | Gigabyte EP35-DS3R | Win XP SP3 | 500Gb Seagate Barracuda 7200.11
Druchii is online now   Reply With Quote
Old 18-04-2006, 17:20   #9
cf.member
 
Join Date: Mar 2006
Posts: 17
Euph0ria is an unknown quantity at this point
Re: Securing my network

One thing I notice is that the network monitor icon and wireless connection icon disappear from the tray after a while, so I can't really tell how good a signal I am getting unless I relaunch the program.

Is this normal?
Euph0ria is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 10:34.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)