Velocity Technical Archive
Is your Wireless Network Secure
Archived Reference: This is a historical technical article preserved from the Velocity Technologies knowledge base. For current Phoenix and East Valley managed IT services, explore our managed IT services or cybersecurity solutions.
Networking professionals are encouraging people to think\ntwice about wireless network security. You might be\nthinking I use WEP-128 bit encryption with MAC address\nfiltering, I’m safe. Or you may be you’ve never even heard\nof WEP, if this is the case you might want to unplug your\nwireless access point immediately. But then again look at\nthe bright side at least you don’t have the false sense of\nsecurity that your network is secure. Perhaps you are the\nsmart guy who knows how insecure wireless networks are. You\ntoo are at just an equal risk!\nYour computer consultant might be partially right when they\nsay WEP will protect your network. It will protect your\nnetwork from casual snooping but that is about it. Last\nyear the FBI was able to crack a WEP protected network in\nless than 3 minutes with tools widely available on the\ninternet. Since then it’s been downhill for WEP.\nAt this point you might be thinking, “Oh well, someone gets\non my network and uses the internet”. This is completely\nfalse. If someone has gone through the process of getting\non your network chances are the only thing they want is not\ninternet access. Any computer security professional will\ntell you that physical access to the network is 95% of the\nsecurity battle. Once this has been accomplished you can\nconsider all of your data compromised. Customer invoices,\ncustomer data, credit card numbers and passwords to\nfinancial institutions will all be in the hands of a hacker.\nOne in many methods can be used to gain access to your\npersonal data, whether it’s through Key loggers, Trojans, or\njust by sniffing your plaintext network traffic.\nMaybe, just maybe, I have not convinced you of the\ninsecurities of wireless networks. Let me tell you about\nanother attack that hackers can use to gain access to your\nnetwork. Let’s say your access points are completely locked\ndown, to your knowledge. A user from your network goes and\nflips on their laptop while sitting in an airport terminal\nwaiting for a plane. They see an available insecure\nwireless network so they click on it and connect. None of us\nhave ever done this before right, itching to check their\nemail one last time before heading out of town? Unbeknownst\nto them they have just clicked on a fake honeypot wireless\nnetwork, set up by a rogue hacker that before they can even\nrealize their machine is already being scanned. Picture for\na moment that user could be anywhere, even sitting at a desk\nin your network. Just as long as the rogue access point is\nstronger than your AP’s radio signal you’re security is\ndone.\nMay be you fall into the category of never setting up\nwireless networks because you read about their insecurities.\nHow then can you be at risk? Just consider for a moment\nthat a user in your organization fires up his wireless card.\nSee’s a wireless network that is named XYZCorp after your\ncompany. So they connect to it and immediately a script is\nhammering their machine for security vulnerabilities. Once\nagain they connected to a rogue access point setup by a\nhacker. Now you might be thinking. “C’mon you must have to\nbe a computer genius to find and run these tools.” Think\nagain, thanks to the kind people over at remote-exploit.org\nall these tools can be downloaded in one big happy ISO file.\nBurned to a CD as an image and bang you’re done, ready to\ntake a drive to the nearest business and start sniffing\ncredit card numbers. Everything wrapped into a nice package\njust waiting for the next script kiddy to start running the\nprograms. You may be thinking ok this is a major problem so\nwhat should I do? Give up my organizations ability to use\nwireless networks? This isn’t exactly what we are saying.\nA newer wireless security technology has taken over in 2004\ncalled WPA. It is more secure than WEP. And so far tools\nare not as readily available to hack your network. But\nconsider the following. WEP was ratified in the late 1990’s\nless than six years later it was exploited. This is typical\nof almost every computer technology. It is only a matter of\ntime before technologies are exploited. Just always\nremember Security is a multi-tiered companywide\nresponsibility. From providing physical security to web\nsite security all matters should be considered serious and\nnot taken lightly. So before you grab a wireless access\npoint and slap it in your network, I urge you to think\ntwice.\nYou may think you are in a sinking boat because you are a\nsmall organization not able to implement the latest\ntechnologies and afford the newest access points. Or maybe\nyou cannot afford to pay an IT staff over 100k-200k a year\nto maintain your medium size network. Executives at\nN2\nNetwork Solutions say you should consider IT outsourcing or\nIT consulting. You can get Industry certified engineers on\na project by project basis. Contractual relationships are\nalso available to dump the responsibility of your network\ninto their hands for a fraction of the price. To keep your\nsmall to medium size network performing like a Fortune 500\nmachine invest the capital and secure your assets.\n