Whoa, a educated security thread at techtalk,long time no-c, however I will take a sec to correct some things and apply some input. Let's see
That in itself is a reason I will never recommend wireless without lead walls.
WOW.....man I thought you said you work for the DoD in another thread! "Leadwalls"....do what?
Line of site wireless connections are quite secure and very popular with the DoD, remember!
Wireless can be very secure, line of sight using a spread spectrum signal is one example. This requires the attacker to physically be between the terminal and the access point as well as requiring them the pick up singals which are below the noise floor. And if you don't believe me google noise floor and do the math.
If you are worried about threats that can break this, you are going up against some serious heavies. Kiddies, crackers, corporate spies, ect.......
FYI...WEP is actually Wired Equivalent Privacy.
Wow, you are right, It also stands for .......
WEP Wireless Encryption Privacy
WEP Wireless Encryption Protocol (network security)
WEP Wage Earner Plan (bankruptcy)
WEP Water Entry Point
WEP Water-Extended Polymer
WEP Weapon
WEP Well-known Entry Point
WEP West European Politics
WEP Windfall Elimination Provision (Social Security benefits)
WEP Wisconsin Electric Power
WEP Word Error Probability
WEP Work Experience Program (workfare) ect........ God bless google.
Here's my thoughts on it:
Bad part about MAC Addresses is that they can be spoofed.
If they're using MAc address filtering it's trivial to change your MAC adress, it's weak security and just plain bad policy. Any skiddie can blow through that..........
Hacker stratification.
Industry views
Tier I: The best of the best the folks with an IQ high enough to boil water 3X's over. Only a handle full exist.
* The ability to find new vunerablities
* Ability to write exploit code and tools
Tier II: Have the ability to understand the vunerability
* Are IT savvy
* Intelligent enough to use the exploit code and tools with persicion
Tier III: "Skiddies"
* Inexpert
* Ability to download exploit code and tools
* Very little understanding of the acutal vulnerabilty
* Randomly fire off scripts untill something works.
Source:
http://www.amazon.com/exec/obidos/t...249753?v=glance
It's a good little book.
If you want ultimate secure WEP, you'll have to drop a few thousand on Cisco's switching key technology or else just wait until a new standard comes out that has more security.
One of my roomates who I work with, he is a senior WAN hardware manager (Cisco, 3Com, Linksys, etc...) he disagrees. Our company contracts to all branches of the military, DoD, Fourtune 500 companies ect....
Did you know that there are readily available programs that can hack you WEP? I can think of three script kiddie programs that anyone can download and use piece of cake.
KoppixSTD
To me, if my neighbor happens to be someone who can download a script and use it, then I'm going to be giving him or her free access and giving myself one heck of a headache.
Yeah, it's ashame that people can't read TFM's anymore and configure properly.
******Edit Directions for changing the NIC's MAC address
/sbin/ifconfig etho down
/sbin/ifconfig etho hw ether 00:A0:CC:64:C7:21
/sbin/ifconfig etho up