Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
General Security
Tag Cloud
access audio black screen blue screen boot bsod connection crash dell desktop driver drivers dvd email error excel excel 2003 firefox hard drive hardware hijackthis internet keyboard laptop malware monitor motherboard network networking outlook problem recovery router safe mode screen slow sound spyware trojan upgrade vba video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Wireless Security for Notebook Users

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
mobi_khan's Avatar
Member with 45 posts.
 
Join Date: May 2008
Experience: Intermediate
18-Aug-2008, 09:12 AM #1
Wireless Security for Notebook Users
Hi guys,

Two days back I saw that an outsider who was previously company employee came with his own notebook and he tired to access the access point whose security code was known to him but his user name and password was disabled form the sensys domain. One more risky thing was that the user can access the wireless network i.e. by access the access point from outsider the company.

In the first phase to protect unauthorized user form accessing the access point of our company I have asked the IT to change the security code of the access point and do not share it with the notebook user and provide the code manually once on all the machines.

But I want more then that, I want that only notebooks which are authorized can be accessed and authenticated on our domain and any other notebook which is not listed should not be authenticated on the our domain.

Please provide your feedback in this regard.
ferrija1's Avatar
Computer Specs
Distinguished Member with 9,752 posts.
 
Join Date: Apr 2006
Location: Pittsburgh, PA
Experience: Mac Addict
18-Aug-2008, 11:08 AM #2
If that former employee couldn't get onto the network, I don't see why you're so worried, regardless:

If you're using a variant of WPA encryption and don't share the SSID (name of the network), you should be ok. Not sharing the SSID provides decent protection (against average users that are not networking-savvy) but can be beaten by sampling the traffic in the area and noting the SSID.

If you are using wireless routers, you cannot keep the Wi-Fi signals from going outiside your comapny, unless you reposition your routers or lay metal screens along the outer walls of your company's area, which will disrupt the signals. To limit the computers connected, you could use MAC address filtering, but that too can be bypassed, by cloning an authenticated address (a very simple processs)
__________________
An expert is one who knows more and more about less and less until he knows absolutely everything about nothing.
Techmonkeys's Avatar
Senior Member with 632 posts.
 
Join Date: Feb 2005
Location: West Yorks
Experience: Advanced
18-Aug-2008, 11:14 AM #3
non-SSID broadcasting is easier to bypass than MAC ID filtering.

Spoofing a MAC address would mean they would first need to know the MAC address of a machine that is allowed to connect to the wireless, which would be difficult to find out, they then would need to know how to do the mac address filtering.

Using that plus a secure WPA-PSK password would be more than adequate.

SSID broadcasts are irrelevant when you can download a program such as netstumbler for free that will detect any SSID's whether they broadcast or not.

You are also right OP in that getting your technicians to add the password once for the wireless routers and not to let end users know the password either.
__________________
Regards,
Techmonkey
More free Tech Support and chat available @ www.techmonkeys.co.uk
ferrija1's Avatar
Computer Specs
Distinguished Member with 9,752 posts.
 
Join Date: Apr 2006
Location: Pittsburgh, PA
Experience: Mac Addict
19-Aug-2008, 10:24 PM #4
They both suck at protecting anything, they're just there (as I said) to filter out any novice users, and spoofing a MAC address is easy, it's broadcast (along with the SSID) from any machine wirelessly using the network.
mobi_khan's Avatar
Member with 45 posts.
 
Join Date: May 2008
Experience: Intermediate
20-Aug-2008, 06:11 AM #5
Thanks.MAc filtering will definetely provide a level of prtoection, so now only the listed MAC addresses of the notebooks will be able to access the Access Point. This will also help me form the ppl who are using windows mobile and are accessing their system form these mobiles through remote Desktop
lunarlander's Avatar
Computer Specs
Senior Member with 1,329 posts.
 
Join Date: Sep 2007
23-Aug-2008, 03:29 PM #6
I think WPA2 Enterprise can perform authentication. But not to a domain I think. It seems to require a Radius server to do authentication.
calvin-c's Avatar
Senior Member with 739 posts.
 
Join Date: May 2006
Experience: Advanced
24-Aug-2008, 10:55 AM #7
Yes. If you want authentication of the user rather than of the notebook then something like a Radius server is the way to go.
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 09:29 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.