Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Security 1

Status
Not open for further replies.

minxca

Technical User
Apr 25, 2003
576
CA
Hi,
If I disable SSID broadcast, use WEP 128 and MAC Add. filter, how long do you need to hack the network with the latest notebook/pc?

Thanks,
 
With a million captured frames, truely unique SSID and a random WEP key, 64 years on a Pentium 4 2 gigabyte machine is the estimate I saw.
 
hmmmm,

I read from another forum that some guys can crack it within 15 min???
 
You have to realize that it is all an estimate.

But 15 minutes for 128-bit encryption is crap.
You could spend the $8k on a Cray or better for the 15 minutes of time and not do it in 15 minutes.

Please see the voluminous discussion of WEP encryption available on the Web. Then you can go back to the other Forum and tell the guy he is full of crap.

All of this is out-dated discussion anyway. With support now, or within 6 months depending on brand, with native support under XP, WPA rotating keys and a reasonable security policy for key changes even under WEP make this sound silly.

I live in the DC area. Use your NetStumbler around the White House, the Executive Office Building or drive to nearby McClean, VA with your NetStumbler or Linux wireless tools and try it. I will be nice, I will give you 6 years to get access. Of course, you will probably be approached in your car within 15 minutes.

Seriously, WEP is fine, use common sense precautions and change your key regularly. Use all the 802.1x schemes available now. Use proprietary schemes from vendors like Cisco if they apply in your case. Use WPA when the firmware for your router and client are available.

And do not believe everything you read in a Web Forum. Including this one.


 
I presume you haven't tried to crack WEP then.

I can regularly crack WEP in the lab in 3-6 hours. In the real world, it depends on how busy the WLAN is, and, to a certain degree, how often you see reused IVs. But the compromise IS an inevitability, and it certainly will not take 6 years, or even 6 weeks. More like 6 hours to 6 days. MAC address filtering won't help you (since MACs can be spoofed), and disabling broadcast SSIDs, while fooling NetStumbler, will not fool Kismet or like tools. Using AirJack, for example, you can recover the SSID in seconds.



 
OMG!
so joeAB2M, what do you suggest should an ordinary user like me should do? short of disabling all wireless :(
i got 128 bit encryption, plus all the othere settings mentioned above, am i ok?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top