Thursday

WLAN Security & WEP

WEP has been dead for some time now. Or it should be. Still alot of people use it (at home). The tools and methods to crack the WEP key have evolved from hours to one hour to 15 minutes to one minute.
That's right. Researchers have now shown that they can break 104-bit WEP in as little as one or two minutes. So WEP has become little more than a minor annoyance. So what doesn't protect your WLAN?

  • Use MAC address filters
  • Using WEP (duh)
  • Disabling SSID
  • Limiting transmit power
What does protect your WLAN? Upgrade the firmware of your Access point to support WPA or even better WPA2. Use Secure Passwords, alphanumeric and as long as possible. Don't use existing words! See dictionary attacks.
At this time, the researchers’ tool, aircrack-ptw (source code)—which they say is similar to aircrack-ng—does not work on 256-bit WPA. So WPA(2) is still considered secure. Of course, for enterprises, don't use WPA-PSK (pre-shared key) and use a RADIUS for centralized authentication. Build a layered defence: password policy, IDS, VLANs, PKI etc.... For example look the following whitepapers:

0 comments: