WEPHack Posted September 23, 2013 Posted September 23, 2013 Some students have managed to access our network by hacking the WEP key - WEP is used because we have some old laptops that can't cope with WPA. The domain itself is secured, along with the resources on it. The gateway should be secured with NTLM auth, so they can't get to the Internet. Clearly there could be effects on the wireless network in terms of load, devices connecting to WAPs. Can anyone see any other consequences of this, and have any other suggestions for what to do? (The plan is to change the WEP key, FWIW, and see if WPA is viable in any way at all)
synaesthesia Posted September 23, 2013 Posted September 23, 2013 If you have laptops old enough to not support at least WPA then they also won't be able to run Windows 7 when you should be getting them shifted off by April. I think that should be part of the case for getting sorted, despite the summer just gone being the best time to have done that. You could replace the wireless cards if you really must get by, you should be able to source them cheap enough as they'll be old enough. There is no way anyone should be using WEP - if I can hack it in 2 minutes flat with out of the box tools (and I'm no hacker) then someone with intent could do so in seconds. You might as well have an open network. 1
WEPHack Posted September 23, 2013 Author Posted September 23, 2013 One additional question. If we switch to WPA, should it be any particular flavour, or is any form of WPA sufficiently secure?
synaesthesia Posted September 23, 2013 Posted September 23, 2013 WPA2 Personal or Enterprise, depending on what your wireless system and hardware is capable. Most will have a "mixed" mode. 1
WEPHack Posted September 23, 2013 Author Posted September 23, 2013 Does it matter whether TKIP or AES, or any particular bit length for the key?
Arthur Posted September 23, 2013 Posted September 23, 2013 Does it matter whether TKIP or AES Definitely AES, because TKIP is insecure. 1
Arthur Posted September 23, 2013 Posted September 23, 2013 WEP is used because we have some old laptops that can't cope with WPA. Could you fit new wireless cards that support WPA2? 1
m25man Posted September 23, 2013 Posted September 23, 2013 AES is essential to get above 54Mbps if your APs support it. Depending on your topology one thing to be careful of is DHCP exhaustion. If the kids can all attach devices to your lan they can dry up your DHCP pool in no time regardless of anything else they might do. 1
WEPHack Posted September 23, 2013 Author Posted September 23, 2013 Could you fit new wireless cards that support WPA2? It's a possibility. I need to check how many laptops are affected, although oddly they are running Win 7. Is TKIP actually hackable? Just to make sure I'm going for the right flavour of WPA.
Arthur Posted September 23, 2013 Posted September 23, 2013 Is TKIP actually hackable? Unfortunately yes, and as m25man mentioned above you need to use AES to get > 54Mbps wireless speeds. 1
m25man Posted September 23, 2013 Posted September 23, 2013 A flaw in a feature added to Wi-Fi, called Wi-Fi Protected Setup, allows WPA and WPA2 security to be bypassed and effectively broken in many situations.[2] WPA and WPA2 security implemented without using the Wi-Fi Protected Setup feature are unaffected by the security vulnerability. That doesn't mean it cant be hacked with the right tools and time anything can be hacked. Your problem is reliance on a passphrase or memorable key as the only means of securing your Wifi isn't enough. Any kid with limited knowledge can lift the key from your OS given physical access to a machine. Radius (802.11x) is your only real option for securing the LAN, WEP, WPA, WPA2 is there to prevent casual eavesdropping or deciphering of you data as it travels through the air not to be the primary means of securing your network. 1
Michael Posted September 23, 2013 Posted September 23, 2013 I agree with all the above - WPA2-PSK AES is the way to go, but I'm curious to know what wireless adapters are installed in these devices? Even the oldest notebook I've ever used supported WPA2-PSK AES once Windows XP SP3 was installed. The fact they're running Win 7 is strange I must admit as Win 7 supports the strongest encryption out the box. 1
WEPHack Posted September 23, 2013 Author Posted September 23, 2013 My fault probably. I accepted from a previous manager of the system that it was on WEP because of an issue with these older laptops. I'll do some testing.
Michael Posted September 23, 2013 Posted September 23, 2013 My fault probably. I accepted from a previous manager of the system that it was on WEP because of an issue with these older laptops. I'll do some testing. Let us all know how you get on - encryption technologies in notebooks/phones have always been a software limitation rather than a physical limitation. Physically it's the speed/frequency you're connecting at wirelessly which determines whether you need to upgrade from wireless G to wireless N for example. Looking at the wireless adapter in my Win 7 notebook, I can't even select WEP as an option but I can still select 'Open' (unsecure) weirdly.
Arthur Posted September 23, 2013 Posted September 23, 2013 Even the oldest notebook I've ever used supported WPA2-PSK AES once Windows XP SP3 was installed. A WiFi card like the Intel Pro/Wireless 2200BG doesn't support WPA2 or AES even with XP SP3. Hopefully @WEPHack hasn't got any of those. 1
Guest Guest Posted September 23, 2013 Posted September 23, 2013 As mentioned it's really time to get rid, but... Depending on your APs you could set up WPA2-xx on one radio/ssid, and WEP with an allowed MAC address list on the other. Never been in that situation so it may not be possible on your APs, it may not be possible on any APs...
jmak Posted September 23, 2013 Posted September 23, 2013 In a scrape when I had a laptop I needed to keep going for a month until a planned refresh, I bought one of these micro USB wifi adapters It definitely supported WPA and was a lot easier than replacing the wifi card. It was actually the fastest wifi connection in the school at the time Might not be quite so good on student machines though... 1
WEPHack Posted September 24, 2013 Author Posted September 24, 2013 I've tested 4 laptops, from our oldest to newest, with WPA2-AES 504 bit key (most of our APs are Netgear WG302's, so I've tested with one of these using the latest 4.2.17 firmware). Ironically our newest Lenovo laptops just refuse to connect with this config. I will double check, but I'm fairly sure they have the latest (Intel) drivers (Centrino Wireless-N 2230). These are all Win 7.
Michael Posted September 24, 2013 Posted September 24, 2013 A WiFi card like the Intel Pro/Wireless 2200BG doesn't support WPA2 or AES even with XP SP3. Hopefully @WEPHack hasn't got any of those. You can according to this link and I'm pretty sure I've come across these before and they worked fine with WPA2, but only at wireless B at a whopping 11Mbps 1
WEPHack Posted September 24, 2013 Author Posted September 24, 2013 As an aside, it transpires that WEP wasn't hacked. A student went onto a teacher's laptop, looked at the wireless settings (click "show characters") and wrote down the WEP key. We've told teachers time and time again to not leave their laptops unsupervised.
Michael Posted September 24, 2013 Posted September 24, 2013 I've tested 4 laptops, from our oldest to newest, with WPA2-AES 504 bit key (most of our APs are Netgear WG302's, so I've tested with one of these using the latest 4.2.17 firmware). Ironically our newest Lenovo laptops just refuse to connect with this config. I will double check, but I'm fairly sure they have the latest (Intel) drivers (Centrino Wireless-N 2230). These are all Win 7. Realistically WPA2 AES doesn't need to be 504 bit. Even using the minimum 8 characters is perfectly OK - just avoid dictionary words and you'll be fine. WPA2 AES is breakable, but for the time it takes someone attempting to have a go, they'll soon give up 1
Michael Posted September 24, 2013 Posted September 24, 2013 As an aside, it transpires that WEP wasn't hacked. A student went onto a teacher's laptop, looked at the wireless settings (click "show characters") and wrote down the WEP key. We've told teachers time and time again to not leave their laptops unsupervised. As for this problem, you should either block Control Panel completely for teachers or customise the Control Panel. Both are possible via GPO. 1
neilmac Posted September 24, 2013 Posted September 24, 2013 WEP.... wow People up to no good love piggybacking into WEP networks. You should take this extremely seriously. You should only use WPA2/AES. WEP was regarded as broken by 1999. The WiFi alliance implemented WPA while the IEEE 802.11i standard was developed. WPA uses the same RC4 hashing technique as WEP, however TKIP generates a temporary encryption key to encode data, and the keys are produced during the 4-way handshake immediately after association. WPA could be implemented with a firmware upgrade and was designed to last about 4 years until 802.11i, which was implemented by the WiFi alliance as WPA2. WPA2 introduces the concept of the Robust Secure Network (RSN). It uses the same 4 way handshake to generate a temporary key, however it uses AES in place of RC4 and CCMP in place of TKIP. Advanced processing required new hardware in access points. Enterprise encryption us a bit of a misnomer. It generally uses Radius to authenticate the user or device. Once the authentication is complete there is still a 4-wayhandshake. A network is classed as a true RSN if it's WPA2 only, if it's WPA/WPA it's called a transitional network. The aim should ALWAYS be to get yourself to a true RSN. Any security is going to be vulnerable if you use a weak key. An attacker can capture the 4-way handshake and run an analysis against a set common passwords. If yours is on it then the key will be found. If you use enterprise security it can come at a cost of roaming times in delay sensitive applications like VoIP, which is why some admin's mistakenly use WEP on VoIP systems (I have seen it). 802.11k and 802.11r allow for fast BSS transitions, and Cisco/Apple are one of the first to get this working well. If you have Enterprise and need fast roaming look into that. However, it's not the only answer. Some vendors implement Dynamic Pre-Shared Key - enterprise level of security without the admin headache. Each user gets their own key. It works great. However here is my advice it you are responsible for running this network. 1) educate yourself on the fundamentals of WiFi. Why is it so many people are responsible for WLAN deployment and admin who have zero training and even worse, make no attempt at getting any training. It baffles me. 2) Put some serious planning into what your network is supposed to be doing now, in three years and in 5 years. 3) Take immediate steps to remove WEP, even if it means old laptops can't connect (which I doubt - are they older than XP ?) 4) Examine all options to provide good security. Remember, security is also about protecting your users. If you are in education there will be huge implications if security is breached (data protection, student records, etc). Hackers are predators, they will pick off the weak ones first. 5) If in doubt, talk to a professional WiFi person. In fact, this should be rule 1. Talk to a professional WiFi person. NM 2
CHR1S Posted September 24, 2013 Posted September 24, 2013 WEP and WPS are as @m25man stated very very easy to hack, add an ARP spoof and your whole network is compromised, even https. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now