Jump to content

Recommended Posts

Posted

Some students have managed to access our network by hacking the WEP key - WEP is used because we have some old laptops that can't cope with WPA.

 

The domain itself is secured, along with the resources on it. The gateway should be secured with NTLM auth, so they can't get to the Internet.

 

Clearly there could be effects on the wireless network in terms of load, devices connecting to WAPs.

 

Can anyone see any other consequences of this, and have any other suggestions for what to do?

 

(The plan is to change the WEP key, FWIW, and see if WPA is viable in any way at all)

Posted
If you have laptops old enough to not support at least WPA then they also won't be able to run Windows 7 when you should be getting them shifted off by April. I think that should be part of the case for getting sorted, despite the summer just gone being the best time to have done that. You could replace the wireless cards if you really must get by, you should be able to source them cheap enough as they'll be old enough. There is no way anyone should be using WEP - if I can hack it in 2 minutes flat with out of the box tools (and I'm no hacker) then someone with intent could do so in seconds. You might as well have an open network.
  • Thanks 1
Posted

AES is essential to get above 54Mbps if your APs support it.

 

Depending on your topology one thing to be careful of is DHCP exhaustion. If the kids can all attach devices to your lan they can dry up your DHCP pool in no time regardless of anything else they might do.

  • Thanks 1
Posted
Could you fit new wireless cards that support WPA2?

It's a possibility. I need to check how many laptops are affected, although oddly they are running Win 7.

 

Is TKIP actually hackable? Just to make sure I'm going for the right flavour of WPA.

Posted

A flaw in a feature added to Wi-Fi, called Wi-Fi Protected Setup, allows WPA and WPA2 security to be bypassed and effectively broken in many situations.[2] WPA and WPA2 security implemented without using the Wi-Fi Protected Setup feature are unaffected by the security vulnerability.

 

That doesn't mean it cant be hacked with the right tools and time anything can be hacked.

 

Your problem is reliance on a passphrase or memorable key as the only means of securing your Wifi isn't enough. Any kid with limited knowledge can lift the key from your OS given physical access to a machine.

Radius (802.11x) is your only real option for securing the LAN, WEP, WPA, WPA2 is there to prevent casual eavesdropping or deciphering of you data as it travels through the air not to be the primary means of securing your network.

  • Thanks 1
Posted

I agree with all the above - WPA2-PSK AES is the way to go, but I'm curious to know what wireless adapters are installed in these devices?

 

Even the oldest notebook I've ever used supported WPA2-PSK AES once Windows XP SP3 was installed. The fact they're running Win 7 is strange I must admit as Win 7 supports the strongest encryption out the box.

  • Thanks 1
Posted
My fault probably. I accepted from a previous manager of the system that it was on WEP because of an issue with these older laptops. I'll do some testing.
Posted
My fault probably. I accepted from a previous manager of the system that it was on WEP because of an issue with these older laptops. I'll do some testing.

 

Let us all know how you get on - encryption technologies in notebooks/phones have always been a software limitation rather than a physical limitation. Physically it's the speed/frequency you're connecting at wirelessly which determines whether you need to upgrade from wireless G to wireless N for example.

 

Looking at the wireless adapter in my Win 7 notebook, I can't even select WEP as an option but I can still select 'Open' (unsecure) weirdly.

Posted

As mentioned it's really time to get rid, but...

 

Depending on your APs you could set up WPA2-xx on one radio/ssid, and WEP with an allowed MAC address list on the other. Never been in that situation so it may not be possible on your APs, it may not be possible on any APs...

Posted

In a scrape when I had a laptop I needed to keep going for a month until a planned refresh, I bought one of these micro USB wifi adapters

 

It definitely supported WPA and was a lot easier than replacing the wifi card. It was actually the fastest wifi connection in the school at the time :) Might not be quite so good on student machines though...

  • Thanks 1
Posted
I've tested 4 laptops, from our oldest to newest, with WPA2-AES 504 bit key (most of our APs are Netgear WG302's, so I've tested with one of these using the latest 4.2.17 firmware). Ironically our newest Lenovo laptops just refuse to connect with this config. I will double check, but I'm fairly sure they have the latest (Intel) drivers (Centrino Wireless-N 2230). These are all Win 7.
Posted
As an aside, it transpires that WEP wasn't hacked. A student went onto a teacher's laptop, looked at the wireless settings (click "show characters") and wrote down the WEP key. We've told teachers time and time again to not leave their laptops unsupervised.
Posted
I've tested 4 laptops, from our oldest to newest, with WPA2-AES 504 bit key (most of our APs are Netgear WG302's, so I've tested with one of these using the latest 4.2.17 firmware). Ironically our newest Lenovo laptops just refuse to connect with this config. I will double check, but I'm fairly sure they have the latest (Intel) drivers (Centrino Wireless-N 2230). These are all Win 7.

 

Realistically WPA2 AES doesn't need to be 504 bit. Even using the minimum 8 characters is perfectly OK - just avoid dictionary words and you'll be fine. WPA2 AES is breakable, but for the time it takes someone attempting to have a go, they'll soon give up :)

  • Thanks 1
Posted
As an aside, it transpires that WEP wasn't hacked. A student went onto a teacher's laptop, looked at the wireless settings (click "show characters") and wrote down the WEP key. We've told teachers time and time again to not leave their laptops unsupervised.

 

As for this problem, you should either block Control Panel completely for teachers or customise the Control Panel. Both are possible via GPO.

  • Thanks 1
Posted

WEP.... wow

 

People up to no good love piggybacking into WEP networks. You should take this extremely seriously.

 

You should only use WPA2/AES.

 

WEP was regarded as broken by 1999. The WiFi alliance implemented WPA while the IEEE 802.11i standard was developed. WPA uses the same RC4 hashing technique as WEP, however TKIP generates a temporary encryption key to encode data, and the keys are produced during the 4-way handshake immediately after association. WPA could be implemented with a firmware upgrade and was designed to last about 4 years until 802.11i, which was implemented by the WiFi alliance as WPA2.

 

WPA2 introduces the concept of the Robust Secure Network (RSN). It uses the same 4 way handshake to generate a temporary key, however it uses AES in place of RC4 and CCMP in place of TKIP. Advanced processing required new hardware in access points.

 

Enterprise encryption us a bit of a misnomer. It generally uses Radius to authenticate the user or device. Once the authentication is complete there is still a 4-wayhandshake.

 

A network is classed as a true RSN if it's WPA2 only, if it's WPA/WPA it's called a transitional network. The aim should ALWAYS be to get yourself to a true RSN.

 

Any security is going to be vulnerable if you use a weak key. An attacker can capture the 4-way handshake and run an analysis against a set common passwords. If yours is on it then the key will be found.

 

If you use enterprise security it can come at a cost of roaming times in delay sensitive applications like VoIP, which is why some admin's mistakenly use WEP on VoIP systems (I have seen it). 802.11k and 802.11r allow for fast BSS transitions, and Cisco/Apple are one of the first to get this working well. If you have Enterprise and need fast roaming look into that.

 

However, it's not the only answer. Some vendors implement Dynamic Pre-Shared Key - enterprise level of security without the admin headache. Each user gets their own key. It works great.

 

However here is my advice it you are responsible for running this network.

 

1) educate yourself on the fundamentals of WiFi. Why is it so many people are responsible for WLAN deployment and admin who have zero training and even worse, make no attempt at getting any training. It baffles me.

 

2) Put some serious planning into what your network is supposed to be doing now, in three years and in 5 years.

 

3) Take immediate steps to remove WEP, even if it means old laptops can't connect (which I doubt - are they older than XP ?)

 

4) Examine all options to provide good security. Remember, security is also about protecting your users. If you are in education there will be huge implications if security is breached (data protection, student records, etc). Hackers are predators, they will pick off the weak ones first.

 

5) If in doubt, talk to a professional WiFi person. In fact, this should be rule 1. Talk to a professional WiFi person.

 

NM

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...