Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

powdarrmonkey

Edu Supporters
  • Posts

    5,017
  • Joined

Everything posted by powdarrmonkey

  1. The pre-shared key forms what TKIP calls the 'base key', along with some unique address details and random numbers, which is then hashed. It's generated each time a station associates with an AP, and then the base key is used along with a packet sequence number and some other random data to encrypt each packet. If memory serves me correctly, the key rotation happens because the station is required to re-authenticate every so often, which changes the base key. Having a sequence number is also how the AP prevents replay and collision attacks. The sequence number is 48 bits, so it takes a couple of thousand years to repeat itself, making a collision practically impossible. If you use 802.11x authentication, the base key is generated by the RADIUS server and transmitted to the access point within your wired network boundaries, which is what makes it so much more secure than a pre-shared key, some vulnerable parts of which have to be transmitted over the air.
  2. The Debian project. Counting any kind of metrics would probably be a waste of my time
  3. WEP is a fixed, shared key system - there's one key, everyone knows it, and if you know it you can read other people's traffic. WPA and WPA2 are rotating key systems: having shaken hands with the access point, you are issued a key to cipher with for a fixed amount of time, then you discard it and get another. Enterprise WPA uses RADIUS and a central server to do the initial authentication, Personal WPA (or WPA-PSK) uses a shared key to initially authenticate, that you discard once you're issued with a ciphering key. WPA and WPA2 are essentially the same system, except that WPA uses only the Temporal Key Integrity Protocol, whereas WPA2 can use the Advanced Encryption Standard instead. TKIP rotates the temporal (cipher) key every 10,000 packets. The underlying temporal key is actually a WEP key; what matters is that it's changed regularly so you (hopefully) can't sniff enough packets to perform a brute force attack, and can't use replay attacks to produce dummy traffic to attack. AES is much faster to calculate ciphers and is very well suited to hardware ciphering, but is also often only found with dedicated hardware. So, if you want to be attacked, use WEP. For high compatibility, use WPA or WPA2 with TKIP, or if your devices can all support it and you want to minimise delays use WPA2 with hardware AES. If you use RADIUS, you can centralise authentication and reduce shared key vulnerability and administration overhead; if you don't, use good passphrase as a shared key and guard it carefully.
  4. *tut* I suppoooose...
  5. Yes. If in doubt, sysprep.
  6. Unless you have a gold arrangement with Microsoft they must be supplied during Windows Welcome.
  7. You'll need all .Net runtimes, not just 1.1 and 3.5 - include 2.0 and 3.0 as well. We've just started using Foxit with mixed results, the most annoying being the automatic update it tries and fails to perform.
  8. I've had mixed results with compatibles - some absolutely fine, others were a disaster. It's pot luck really, but liquid ink seems to be easier to get right than toner (don't even go near solid ink compatibles ).
  9. Your friendly neighbourhood powdarrmonkey can do it for a beer.
  10. I believe Active Directory Federation Services can help you with that, but I've never (yet) used it.
  11. Hey, I've been waiting a month now Ah well. Enjoy yourself
  12. Depends on the VAT registration status of the seller. The same rules apply as for a real shop.
  13. Blind guess: someone has set this up for you, including registering the domain and organising the hosting, but not given you any administration details. The registration details including an address are on Nominet, try getting hold of your agent there.
  14. To be fair I have done it by myself, but the difficulty always comes when it's half way into the rails and you realise you can't manage... it hurt my foot quite a lot
  15. ...and then make your patch fairly generic and send it upstream, where everybody can benifit
  16. Follow the instructions to mount the rails or shelf in your cabinet, make sure they're secure and then get at least one other person to help you slide the server onto them.
  17. There isn't.
  18. Please paste the outputs of sudo ls -la /etc/apache2/mods-enabled cat /etc/apache2/mods-enabled/dir.conf
  19. http://www.edugeek.net/forums/mis-systems/38051-sims-windows-7-a.html
  20. Export the branch you're interested in (or the whole thing), make your changes, export again and compare the two with a diff program like GNU diff. Make sure you export in the right format: Track Changes to the Windows Registry Edit: oh, wait, you already do this. sorry.
  21. (powdarrmonkey thinks it's time to get different dinner register software...)
  22. Hmm, works for me.. (I don't use SCCM though, that might be it).
  23. You might have a point. It hogs my sound output lots too
  24. No, because they are irrelevant. You're looking for broadcast traffic as oppose to unicast, not protocol differences.
×
×
  • Create New...