[Wolves] wireless - bambam

Jono Bacon wolves at mailman.lug.org.uk
Wed Sep 17 13:47:01 2003


Hi Fizzy,

I just read the article and I knew wireless was pretty
insecure, but I didnt realise you could fiddle MAC
addresses and WEP so easily.

Would it be possible to filter all traffic through SSH
or something so even if someone gets access, they need
as key to do anything useful or read your traffic?

I suppose we need some software that acts like a
daemon to check forged MAC addresses and boot them off
the network - I don't know how plausable this is
though.

The other option of course is if there is a way of
password protecting a session.

  Jono

--- fizzy <fizzyorguk@yahoo.com> wrote:
> Just read the article at:
> 
>
http://www.oreillynet.com/pub/a/wireless/excerpt/wirlsshacks_chap1/
> 
> and must say it's pretty shocking! As far as i'm
> aware
> the methods mentioned (MAC control, WEP and
> disabling
> SSID broadcast) are the ONLY options available for
> security on a majority of wireless gateways.
> 
> As I consider my future wireless network it looks
> like
> it's going to be hard work, the only safe way I can
> think of is to allow only VPN network connections to
> the wireless network, easy in theory but not so
> simple
> to actually do! :)
> 
> The only reasuring bit was in the comments at the
> end
> - 
> 
> "However, Lucent changed its Orinoco firmware in
> September 2002 to stop its cards transmitting weak
> packets. I have never managed to crack an Orinoco
> card
> running up-to-date software."
> 
> So WEP can be secure, but i have to buy new hardware
> :\
> 
> The only other resource i've found is no cat
> (http://nocat.net/) but that seems pretty crap too.
> 
> Am i missing something here? Is all wireless
> stupidly
> insecure or is there some easy way of doing things
> i'm
> missing out on?
> 
> fizz
> 
>
________________________________________________________________________
> Want to chat instantly with your online friends? 
> Get the FREE Yahoo!
> Messenger http://mail.messenger.yahoo.co.uk
> 
> _______________________________________________
> Wolves mailing list
> Wolves@mailman.lug.org.uk
> http://mailman.lug.org.uk/mailman/listinfo/wolves


=====
Jono Bacon - http://www.jonobacon.org/
Professional Writer / Web Developer / Musician

__________________________________
Do you Yahoo!?
Yahoo! SiteBuilder - Free, easy-to-use web site design software
http://sitebuilder.yahoo.com