Showing posts with label WiFi Security. Show all posts
Showing posts with label WiFi Security. Show all posts

Getting Internet Service Requires More Than Excellent Signal Strength

As computers in general, and WiFi in particular, become more like home appliances and less tools or toys owned by the geeky or the wealthy, not everybody who needs Internet access will be able to get it at any given time. Some people aren't aware of the details involved, especially when using the convenient WiFi connectivity. Reports like

My Internet connection is Excellent, but when I start Internet Explorer, I see
The page cannot be displayed.
What is going on here?
are becoming more and more common in many forums.

Between turning on on your WiFi equipped computer, and seeing the home page of your choice pop up in the browser window, there are a few details which you need to consider.All of these are issues which involve WiFi connectivity, and all different ways. The bottom line, though, is that WiFi will never replace Ethernet. And there are other issues which affect Internet connectivity in general, but might still affect this computer, alone.

>> Top

MAC Address Filtering

The Media Access Control, or MAC, Address is one of the most universally present identity features in computer networking. Whether your computer uses Internet Protocol (the default and preferred protocol) or IPX/SPX or NetBEUI (possible alternates), as its Layer 3/4 transport, each networking device on your computer will have a MAC Address. Some devices will even have 2 MAC addresses, and here's where a problem starts. Besides the Universally Administered Address (UAA), which is assigned to a network device when it is assembled at the factory, some devices will be assigned a Locally Administered Address (LAA) by the network administrators, when a network is being setup.

Setting up an LAA is trivial in nature. The hard part is deciding what address to use. Once you decide that, just run the Network Adapter Settings Wizard. Depending upon the vendor, the ability to assign a LAA will be somewhere in the wizard. For 3Com, for instance, the Advanced tab will have a value "Network Address". TYpe in the LAA that you wish to use on the adapter in question, hit the OK buttons a couple times, and you're good to go.

If you change the MAC address of the WAN connection on your NAT router, you're setting a LAA there.

One of the most common security selections, when you setup a router, is the ability to filter by client MAC address, and permit network access to a select few addresses. Like hiding the SSID beacon, filtering by MAC address is just another form of security by obscurity. It's similar in effect to disabling DHCP, and manually issuing IP addresses to all computers.

An attacker who is interested in connecting to your WiFi network has only to learn the MAC address of a device on your network, and assign the observed address. As described above, assigning an address is a trivial exercise; and learning an address is the same. Learning an address is simply a prerequisite in interesting exercises such as a Man In The Middle attack, or WEP cracking.

The bottom line? MAC address filtering is probably the lamest form of WiFi security that you can try. It's easy to do, but easy to bypass too.

>> Top

Ad-Hoc Networking

Microsoft Windows is called a Network Operating System. Computers running an operating system like Microsoft Windows (any of the many versions) were designed to be networked. As I've said elsewhere, if you have one computer, you have the beginning of a network.

The minimum complement of equipment, that you need for a computer network, is 2 computers and the appropriate networking components. The simplest networking component set would be two Ethernet adapters (one in each computer), connected by a bit of Ethernet cable, generally (but not always) a cross-over cable.

That's an ad-hoc Ethernet network. It's similar to hub (router / switch) based Ethernet networking, but without a hub (router / switch).

You can also have a network without any Ethernet cable, if you replace the Ethernet adapters with WiFi adapters. That's called an ad-hoc WiFi network.

An Ethernet based ad-hoc network is frequently limited to 2 computers. An Ethernet cable has just 2 ends - to get any more, you need a hub (router / switch). With a WiFi based ad-hoc network, you can have any number of computers connected, with minimal effort.

But there are several disadvantages to ad-hoc WiFi networking.

  • One of the biggest is security. The minimum acceptable standard for WiFi security is WPA. Unfortunately, WPA requires a WiFi Access Point, to manage authentication / encryption. With no WAP, you're limited to using WEP to protect yourself, and WEP just isn't adequate security.
  • With a router "in charge" of the network, you'll generally get more throughput. Client - server (with the server in charge) is more efficient than peer - peer (with no one in charge).
  • Most WiFi equipment, in ad-hoc mode, will only operate in 802.11b mode, and get up to 11M of bandwidth total.
  • Without a router, and a DHCP server built-in, you'll have to use ICS (if you're sharing Internet service), or pre-assign fixed IP addresses to each computer.
  • You'll have to pre-assign channel number and SSID on each computer, as the normal WiFi Client won't find your ad-hoc network by scanning. Nor will it give you a signal strength indicator.
  • You won't be able to disable SSID broadcast (not that this is a bad thing). In ad-hoc mode, SSID broadcast is forceably enabled.


Remaining aware of the limitations of ad-hoc WiFi, see specific details of the setup process

For a quick LAN, ad-hoc WiFi is OK. In an otherwise secure environment (maybe a single conference room deep within your office complex) it's perfect for a quick conference, and application sharing. For long term, really secure networking, though, you can't beat a properly setup, router (WAP) based network.

>> Top

Beware The Honeypot

Many, Many years ago, when the USA was first settled, nobody worried about the neighbours. Anybody living in the wilderness was happy to see another human being - and if you went out to work in the fields during the day, you'd leave the front door latched (don't want the pigs or chickens wandering through the house), but nobody locked anything. If you had a front porch, you'd have an easy chair or two, and a bucket of water there for your guests. Anybody wandering by was free to "set a spell and have a drink".

When WiFi was first developed, nobody cared about freeloading. If you had a WiFi AP, you connected it to your Internet service, and left it open. Anybody wandering by was welcome to "set a spell, and borrow the connection". Then freeloading got serious - people like Walter Nowakowski, in Toronto, became common.

People would protect themselves, and WEP was developed. And people learned to crack WEP.

Some of the more ingenious WiFi owners became devious.

If I have a WiFi AP that's protected, and my neighbour has an AP not protected, any wardrivers will be using my neighbours, right? Nobody is going to go after a protected AP, when there's an unprotected one nearby?

and continued with
OK, if a wardriver sees 2 APs, he can't tell that's not two different people. I'll setup an unprotected AP, and wardrivers can use that.

Kind of like the front porch with the chairs and water bucket.
Yet there was more.
Why should I let folks use my connection, to download kiddie porn? The FBI will notify my ISP, and I'll lose my service. OK, disconnect the Internet from the open AP.

and the open AP became a Honey Pot. You can connect, but you aren't going anywhere.

Some WiFi security experts even laugh about the wanna be wardrivers. Maybe even keep logs by MAC address. The ones who really have idle time to kill might even use NetStumbler or similar software to seek out, by triangulating, the hapless wardriver, maybe take his picture or taunt him otherwise.

The really nasty ones might attach a computer, with a spoofing DNS server, and let you think (initially) that you're connecting to "www.google.com". Then they will try to serve you the hack of the week, from their computer. An old 486 laying around would be perfect for this task. Who cares if it takes 5 minutes to respond? That wardriver isn't going anywhere. Who cares if he gives up?

So, if you are using WiFi, and you're attached to an easy and seemingly available AP that you don't know about, use common sense.
  • Use PingPlotter or a similar tool to make sure that it actually connects somewhere.
  • And, for heavens sake, protect your computer!
  • And learn the difference between seeing
    Connected to XXXXXXX - Signal quality xxxxx.
    and actually having a connection, to the legitimate Internet.

Think.

>> Top

Setup WiFi - And WPA - Carefully

Setting up a WiFi LAN is a great experience. The convenience of surfing the web from your back yard, or sharing files between your main computer and your music server, without running wires here and there, is exhilarating. But there is stress involved.

When you connect a computer to a WiFi LAN, with WPA (and WPA-PSK is absolutely the minimum security measure that you should - no must - take), you are testing a number of things, simultaneously.

  • The WiFi router.
  • Your computer.
  • Your WPA setup.


Now if you do this carefully, and with a small amount of preparation, the whole project can take an hour - or less. Plan it wrong, or make a mistake, and you could be days figuring out the problems. Use a layered strategy - similar to layered testing.
  1. Get each computer connected, by Ethernet, to each other.
  2. Setup, and copy, a key set to each computer.
  3. Get each computer connected, by WiFi, with no security.
  4. Setup WPA on the router, and on each WiFi client.


The different WiFi router vendors have different ideas what type of key their WPA security should work with. Steve Gibson's GRC "Perfect Passwords" Generator will give you a choice of 3. Here's an example of what you might be provided when you click the latter link. Try it, and see.
  • 64 random hexadecimal characters (0-9 and A-F) (not case sensitive):
    1DBE12287EC82B22233C74B356BAC5E4EDC1447168B5F5A9C985C154220E0568

  • 63 random printable ASCII characters (case sensitive):
    Hb+r#^S-T/1!JTP0_~SB 4&rQ7|s"q)7S`teMB`]x_uGATQQ-{B:=%W/_")$w6h

  • 63 random alpha-numeric characters (a-z, A-Z, 0-9):
    0btNigYpFmG5MGDBahRnw203t6jQlCYCNcuvCYgGAZVCFSLSwp7deBMj9Iy7Vfr


All I do is to go to the web page (where it generates a new key set each time - try it), copy the six lines (as in the above list) to a Notepad file, and save the file. Then, with all computers connected by Ethernet (step 1 above), copy the file to each computer. Depending upon the router, one key may work properly, while another won't. Having 3 possibilities, in an identical set on each computer, means repeatedly copying and pasting, without having to worry about getting the computer back online, by other means, to simply copy another file.

After you copy the key set to each computer, start up the WiFi radio, and the WiFi clients. Start with WiFi in open (unencrypted) mode. Make sure that the router works, and you have a working signal, by testing without setting up security.

Since you'll probably be testing the router connection by loading a web page, decide how comfortable you are with giving your neighbourhood open Internet access while you test. If you're not comfortable, then disconnect the Internet feed from the router, while you test, and load the router management web page for your test. Reconnect the Internet service after you get WPA security working.

After you can connect the computer without security, and all network functions work, add WPA-PSK security.
  • Configure the router - copy the appropriate portion of 64 random hexadecimal characters into the router management program.
  • Copy the identical portion of 64 random hexadecimal characters into the client computer WiFi client manager setup wizard.
  • Test the WiFi client. If it works, fine. If not, repeat these steps, trying the 63 random printable ASCII characters, and finally the 63 random alpha-numeric characters.


This is 3 times as complex as it needs to be, and after you've done this a few times, you'll be able to simplify these procedures. But for the first couple times you do this, the careful planning, and the lowered stress level, will make it easier to not make mistakes. By not making mistakes, you're more likely for this to work. And making it work is the reason for my writing this in the first place.

>> Top

An Incredibly Stupid Wardriver

11/26/2003 Toronto Canada Wi-Fi hacker caught downloading child porn


Toronto police stopped Walter Nowakowski for driving the wrong way down a one way street during the early morning hours. Walter had his pants around his ankles, and he was watching a child porn video that he had just downloaded from the Internet, using a hijacked wireless connection from a nearby house.

Following his arrest, Police searched Nowakowski's home when they recovered 10 computers along with thousands of CDs and floppy disks suspected to contain child porn images.

Walter was doing 4 things at the same time.

  1. He was wardriving.
  2. He was driving the vehicle himself.
  3. He was watching what he was downloading, while he was driving.
  4. He had his pants off, because he was enjoying what he was doing so much.

Walter got caught by the police for doing none of the above. Nor did he get caught for being a collector of child porn.

Walter got caught because he found doing all of the above so incredibly easy, that he paid no attention to what he was doing, and drove the wrong way down a one-way street.

If the FBI (or the Canadian equivalent) went knocking on somebody's door and seized equipment that was used in downloading child porn (the FBI has been doing just this), Walter would not have been the one on whose door they would have knocked.

The FBI would have been knocking on the door of the people who provided Walter his Internet service. And those people would have been aware of it only after the FBI got there.

The people providing Walter his Internet service, very likely, have no idea how lucky they were that Walter was so stupid. Since Walter was arrested during the early morning hours, it's likely that everybody was still asleep. Even if any of the inhabitants in the area saw Walter being arrested, or read about it in the newspaper, how likely is it that somebody thought "Gee, maybe that's why my wireless router was so busy?". Yeah right.

Imagine what the smart wardrivers can do? Folks, please, if you're going to have a wireless LAN, Protect Your WLAN from idiots like Walter. And use a Layered Defense on all computers on your LAN - not just the ones connected wirelessly.

WEP Just Isn't Enough Protection Anymore

The discussions about how insecure WEP is have been going on for a while. I introduced a number of you to these WEP security (or insecurity) analyses, one by the University of Berkeley, and another by the University Of Maryland, almost a year ago. Those were academic publications, and a bit heavy on theory.

Also, there was AirCrack, a WEP Key Cracking tool, provided generously to the Internet community. The instructions for AirCrack I could master, with slight difficulty.

In December 2004, and then March 2005, SecurityFocus published WEP: Dead Again, Part 1 followed by WEP: Dead Again, Part 2. These two articles outlined how WEP could be cracked, with some skill required.

And in March 2005, George Ou published Hack most wireless LANs in minutes!.

The sad state of wireless LAN security is that the majority of corporations and hospitals still use dynamic per-user, per-session WEP keys while the majority of retail outlets that I’ve seen still use a single, fixed WEP key.


In May 2005, TomsHardware, a well known computer enthusiasts web magazine, published a pair of articles, which some called WEP Cracking For Dummies, that suggested
After reading these two articles, you should be able to break WEP keys in a matter of minutes.


Part 1: Setup & Network Recon, was published in early May, and Part 2: Performing the Crack, a week or so later.

Maybe a month after WEP Cracking For Dummies, we now have WEP Cracking For Dummies: The Video, where you can watch an entire WEP crack being done before your very eyes.

The cracking process, shown in the 5 minute video, uses 3 components of the Auditor Security Collection, available online.

  • Airodump to sniff packets, and get the MAC address of an unprotected Wireless Access Point.
  • Aireplay to choose, and inject, packets back to the target, yielding the IVs when the right packets are injected.
  • Aircrack to take the IVs generated by Aireplay, and compute the key.

If made part of a bootable CD-ROM, you can run Auditor from your laptop without doing any system work - just boot from CD.

To describe the situation in plain terms, your typical script kiddie wardriver would have been found, last year, shopping at Frys Electronics. This year, at Walmart, or maybe ToysRUs.

If you're still protecting your wireless LAN with WEP, it's time to move up. This week, if not sooner. But, when you setup WPA, use a strong passphrase, or a complex and random sequence of characters.

>> Top

Setting Up A WiFi LAN? Please Protect Yourself!

With an Ethernet LAN, you run cables within your home, and connect your computers and your Internet service. You might run a cable out the back, to your shed or other second building (but please, seriously, plan such connection carefully). But would you run a cable next door, to your neighbor? How about to the neighbor down the block, whom you have yet to meet?

I would bet you just answered "No" to both questions.

Well, with a WiFi LAN, if you don't secure it properly, you might be doing all of the above, and more.

Read about Walter Nowakowski, in Toronto, a couple years ago. Don't expect all of your wireless neighbors to be this stupid. And here's an ongoing Asian story WiFi networks as good targets for exploitation.

The point here is, you need to protect a wireless LAN with more precautions than just the NAT protection on the router. The wireless neighbourhood near you is just as dangerous as the internet around you.


  1. Don't waste time with spells and incantations. Both hiding the SSID, and MAC address filtering, are elaborate forms of security by obscurity. Understand your vulnerabilities.

  2. Require both authentication and encryption for any wireless device. WPA is the minimum level of protection acceptable. Use non-trivial values for encryption. Don't just use words from the dictionary, like the legendary Linksys default "My dog has fleas". Use a properly generated random key.

  3. Enable the router activity log, and examine it regularly. Know what each connection listed represents - you? a neighbor?. Act accordingly.

  4. Don't disable SSID broadcast - some configurations require the SSID broadcast. But change the SSID itself - to something that doesn't identify you, or the equipment.

  5. Change the router management password, and disable remote (WAN) management.

  6. Change the subnet of your LAN - don't use the default.

  7. Disable DHCP, and assign an address to each computer manually.

  8. Install a software firewall on every computer connected to a wireless LAN. Put manually assigned ip addresses in the Local (highly trusted) Zone. Open the firewall for file sharing, only in the Local Zone.

  9. Harden your file sharing security policies, in general.
    • Use non-trivial account names and passwords on every computer connected to a wireless LAN.
    • Disable or delete the Guest userid, if possible (a computer with XP Home is a bad choice for a wireless LAN, connected wired or wireless).
    • Rename Administrator, to a non-trivial value, and give it a non-trivial password.
    • Never use the Administrator renamed account for day to day activities, only when intentionally doing administrative tasks.

  10. Use a Layered Defense on all computers connected to a wireless LAN - not just the ones connected wirelessly. If a wardriver connects wirelessly, all computers on the LAN are at risk.

  11. Stay educated - know what the threats are. Newsgroups alt.internet.wireless and microsoft.public.windows.networking.wireless are good places to start.



Protect yourself. Using a WiFi network that's not yours, without permission, is becoming a crime in most locales. But, a crime is not a crime without several essential steps.

  1. Violation. Somebody has to connect illegally to your network.
  2. Detection. The police have to identify and arrest the violater.
  3. Prosecution. The district attorney has to apply the law, to the law breaker, in court.
  4. Conviction. The judge or jury has to decide that all conditions of the law apply to the actions by the lawbreaker.
  5. Sentencing. The judge has to determine a fair penalty to be paid (in time or money) by the violater.


All of the public officials involved in steps 2 - 4, if they are any good, manage their time carefully. When considering an offender, they decide if their time is properly spent against that offender, or against another. If your case, however important to you, isn't important to them, the Violator is free to go, and possibly to continue using your network.

If you leave your LAN unsecured, this will happen over and over. Regardless of who is legally wrong, you have to secure your WiFi. And you have to encourage your neighbors to do the same.

Disabling the SSID

Many security experts think that broadcasting your SSID, which identifies your WiFi LAN to all of your wireless neighbors, creates a substantial security risk to your LAN. This concept is similar to the justification of stealthing your IP address, as I discussed in Security By Obscurity.

You can disable the broadcast of the SSID in the beacon. This will make your AP invisible, as long as there are no stations associating with it. As soon as any stations (wireless computers) associate with the AP, the SSID will be out there for everybody to see.

Associating with an AP, with SSID beacon disabled, can be done, as long as the SSID is known to the station wishing to associate. But the process is complex, and generates a lot of excess traffic. This traffic exposes your SSID even more than if you had been broadcasting the SSID in the first place.


And, as I said above, you can hide yourself, as long as there is nobody connecting to you. But what's the purpose of having a AP with no clients? And as soon as you have clients, you'll be visible again. Only the truly lame script kiddies don't know about NetStumbler. You won't be invisible to NetStumbler, or similar tools.

Disabling SSID beaconing MAY make you invisible in normal WiFi client manager displays. This is both good, and bad.
  • The upside is that your neighbour, who knows barely enough to find the Ethernet port ("big fat phone plug thingy") on his cable modem, won't know that you're there. You're safe from him trying to hack your WLAN.
  • The downside is that your neighbour doesn't know that you're there. If he picks the same channel that you're using, and your bandwidth suffers because you have to share the channel, you can only blame yourself. Your neighbour will probably end up taking his WiFi Access Point back to the store, because "it doesn't work right". That, too, will be your fault. He won't even know that you're in the area, and come ask for advice, because you're "invisible".
  • A second downside is that you won't be invisible to your neighbour's son, the l33t hax0r. Any script kiddie, or true hacker with any experience, will know about NetStumbler and similar products. He'll scan the channels, and make a list of Access Points, and their SSIDs.
    1. APs with SSID "Linksys", "Netgear", "My Network". Ho hum, so many of those. Check them out when I'm really bored.
    2. APs with obscure SSIDs. Probably well protected - stay away.
    3. And here's an AP with no SSID. This tells Mr L33t Hax0r two things.
      • The owner doesn't want to be seen, so he has something to hide.
      • The owner thinks he can't be seen. If he's that dumb, I'll bet he won't have his AP properly protected either.
      Now we're talking! Let's have some fun with this one.


The reason for having channel number and relative signal strength, in the client manager (WZC and similar products) displays, is to allow your neighbour, when he sets up his WiFi LAN, to pick a channel that is less used. If your neighbour can't see your Access Point on the channel, because you want to be invisible, how is he going to, reliably, pick a less used channel?

Did you ever see the movie The Invisible Man? What were some of the first things that Nick Halloway learned from experience?
  • Don't wear clothes in public, if you want to be invisible.
  • Don't expect folks not to run into you, if you want to walk around in a crowd.

If you think about it, both practices are pretty antisocial. Walking around naked, and walking around invisible, are not keeping to social norms. Neither is using WiFi "naked" (without proper security), or "invisible" (SSID beaconing disabled).

>> Top