Remote Exploit Forums

Go Back   Remote Exploit Forums > Specialist Topics > Wireless


Wireless Specific topics related to the attack & defense of wireless systems

   

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-27-2007, 12:39 AM
Junior Member
 
Join Date: Jul 2007
Posts: 6
Default Wireless network security for businesses

I work for a small company which sets up networks for small businesses. In the past, my boss would only setup simple WEP on the network. I was wondering how crackable WPA is? Is WPA or WPA2 the solution? I haven't seen any good information on cracking WPA besides running the key against a dictionary list.

Can anyone give me any further information on securing a wireless network beyond being cracked?

Thanks in advance...
Reply With Quote
  #2 (permalink)  
Old 07-27-2007, 12:42 AM
-=Xploitz=-'s Avatar
Senior Member
 
Join Date: Apr 2007
Location: Mesquite, Texas (Dallas County) USA
Posts: 3,489
Default

A "good" dictionary attack is only way so far to crack WPA/WPA2. beyond that..unplugging your APs' power cord when its not in use is the only way to secure any Wi-Fi network.

Last edited by -=Xploitz=-; 07-27-2007 at 12:44 AM.
Reply With Quote
  #3 (permalink)  
Old 07-27-2007, 12:51 AM
Junior Member
 
Join Date: Jul 2007
Posts: 6
Default

Quote:
Originally Posted by -=Xploitz=- View Post
A "good" dictionary attack is only way so far to crack WPA/WPA2. beyond that..unplugging your APs' power cord when its not in use is the only way to secure any Wi-Fi network.

Thanks for the quick answer! So if I use a very complex password with WPA, it should be strong enough for most uses (besides government, bank, etc...)?
Reply With Quote
  #4 (permalink)  
Old 07-27-2007, 12:53 AM
theprez98's Avatar
Super Moderator
 
Join Date: Apr 2007
Location: Maryland
Posts: 2,556
Default

Quote:
Originally Posted by aaaronic View Post
I work for a small company which sets up networks for small businesses. In the past, my boss would only setup simple WEP on the network. I was wondering how crackable WPA is? Is WPA or WPA2 the solution? I haven't seen any good information on cracking WPA besides running the key against a dictionary list.

Can anyone give me any further information on securing a wireless network beyond being cracked?

Thanks in advance...
WPA2 with RADIUS

Also, segregate wireless from wired.
__________________
theprez98
"I want peace on earth and goodwill toward men."
"We are the United States Government. We don't do that sort of thing!"

Last edited by theprez98; 07-27-2007 at 12:56 AM.
Reply With Quote
  #5 (permalink)  
Old 07-27-2007, 12:54 AM
-=Xploitz=-'s Avatar
Senior Member
 
Join Date: Apr 2007
Location: Mesquite, Texas (Dallas County) USA
Posts: 3,489
Default

use something similar to this......

-=XploitZ1014 N3Tw0Rk=-

And your good to go! The word you chose MUST be in the dictionary the "attacker" uses ..or all the other words in the world are useless to them.
Reply With Quote
  #6 (permalink)  
Old 07-27-2007, 01:02 AM
Junior Member
 
Join Date: Jul 2007
Posts: 6
Default

Quote:
Originally Posted by theprez98 View Post
WPA2 with RADIUS

Also, segregate wireless from wired.
Does the average Windows XP machine support WPA2 with RADIUS? How expensive is RADIUS to setup?

Is this necessary or is WPA with a very secure key a better option for a small business?

Also, how do you segregate wireless from wired? Can you elaborate on that please?
Reply With Quote
  #7 (permalink)  
Old 07-27-2007, 01:05 AM
-=Xploitz=-'s Avatar
Senior Member
 
Join Date: Apr 2007
Location: Mesquite, Texas (Dallas County) USA
Posts: 3,489
Default

Remote Access Dial-Up User Service (RADIUS) Authentication and Authorization. RADIUS allows only approved users, via user name and password, access to the network. The server verifies the user before access is given. Different levels of access can be set up as well.


It uses certificates and usernames and passwords for security. I'm sure you can crack it..nothings uncrackable. If I had the set up for WPA2 Enterprize..Id like to take a shot at it myself. If you know the username and password..your in.

For small business..use WPA2 Personal with a key like mine..Capital..lowercase, numbers..spaces..special characters...and LONG!! The longer the better!..and if you forget the key...just reset your router and put another key in.
Reply With Quote
  #8 (permalink)  
Old 07-27-2007, 01:09 AM
Junior Member
 
Join Date: Jul 2007
Posts: 6
Default

Quote:
Originally Posted by -=Xploitz=- View Post
Remote Access Dial-Up User Service (RADIUS) Authentication and Authorization. RADIUS allows only approved users, via user name and password, access to the network. The server verifies the user before access is given. Different levels of access can be set up as well.


It uses certificates and usernames and passwords for security. I'm sure you can crack it..nothings uncrackable. If I had the set up for WPA2 Enterprize..Id like to take a shot at it myself. If you know the username and password..your in.

For small business..use WPA2 Personal with a key like mine..Capital..lowercase, numbers..spaces..special characters...and LONG!! The longer the better!..and if you forget the key...just reset your router and put another key in.
Thanks for the reply! You have been very helpful
Reply With Quote
  #9 (permalink)  
Old 07-27-2007, 02:34 AM
-=Xploitz=-'s Avatar
Senior Member
 
Join Date: Apr 2007
Location: Mesquite, Texas (Dallas County) USA
Posts: 3,489
Default

Your quite welcome aaaronic..anytime m8.
Reply With Quote
  #10 (permalink)  
Old 07-27-2007, 02:39 AM
streaker69's Avatar
Senior Member
 
Join Date: May 2007
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 3,664
Default

Quote:
Originally Posted by theprez98 View Post
WPA2 with RADIUS

Also, segregate wireless from wired.
To make that clear, nothing of any business or sensitive information should pass over the wireless network.
__________________
A 3rd Party Security Audit is the IT equivalent of a Colonoscopy, it's long, intrusive, and when it's done you'll have seen a lot of things you really didn't want to see, and you'd definitely remember that you had it done.

I baby harp seals.
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:37 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2