Jump to content

WEPHack

Members
  • Posts

    30
  • Joined

  • Last visited

Everything posted by WEPHack

  1. Having done a lot more troubleshooting, and tested many combinations of laptop and WAP, the problem only seems to be with the Lenovo/Intel Centrino chipset and the WG302 running any form of WPA encryption. The Lenovo connects without issue to the WNDAP350 and WPA, and the WG302 and WEP. The built-in WG302 log is pretty useless so I will have to get SYSLOG up and running, which I haven't done for a while. We're changing the key tomorrow, so I'll have to leave a second SSID for WEP enabled until I can figure out what's wrong. Could it be that these (very old) WG302 APs just aren't going to be compatible with this Intel wireless chipset?...
  2. (The poll doesn't show on the iPhone app)
  3. Timbo343: there is a poll at the top of the thread. It requires you to enter some text in the post as well :-/
  4. What wireless network hardware do you use?
  5. I've checked, and you do. The faux pas was that this particular teacher had been given local admin privileges to install some software. Lesson learned. m25man: I think when we renew the wireless, hopefully next April, we will get some expert consultancy to ensure we choose something suitably secure. For now we'll have to go with WPA, if the infrastructure/devices are up to it...
  6. It doesn't seem to differentiate and just has a single field for entry of the key. I'm using a website based generator to create the key. That's good news at least! Although I'm wary of these WAPs as they just seem to behave strangely. Even more so our newer Netgear WAPs, the WNDAP350. Certainly where we are it's just pressure at every level i.e. not enough budget to easily change what's an expensive item (both consulting and hardware) when done properly, and getting training is not easy when you're required most of the time. It's not impossible though, and a wireless replacement was already pencilled in for next FY, although it's still likely to be £10-20k+, even more with a possible change also required to our wired infrastructure (new higher bandwidth switches, VLAN setup etc.). With the tablets I've not had much chance to troubleshoot. It sees the SSID on a scan, but just doesn't connect. SSID is just an alphanumeric string with the name of the school and a "2" at the end. No spaces or symbols.
  7. Education is certainly a difficult environment. You have extremely sensitive data combined with low budgets for hardware, and are then expected to work miracles. A lot of staff, including senior staff, just don't realise the pressure. To boot I've been trying to sort out a mess of an IT department for a couple of years now, replacing hardware that desperately needs sorting, along with all the documentation required to properly support. This is with minimal human resources as well.
  8. I was trying with a 504 bit key. The suggestion is that light is 64 bit, and medium is 160 bit. From what has happened a reasonably long key would be wise in case someone tries to write it down (albeit we'll try and prevent access to the key as best possible). The APs are certainly accepting the 504 bit key, but our Android tablets here don't seem to like it. So many variables though it's hard to know whether it's this, the level of encryption, or AP compatibility.
  9. Could length of WPA key cause compatibility/connection issues with some devices? I'm trying to troubleshoot why some of our mishmash of devices won't connect to WPA.
  10. Having checked, the WAP does offer a joint WPA/WPA2 mode, and that does seem to be working with this wireless chipset. I'm guessing it tries to negotiate at the stronger encryption, then drops lower if it can't make the connection. There was mention above of WPA being hackable with TKIP. How does that compare with WEP hacking for time, ease etc.? One advantage to a longer wireless key is it makes it near impossible to remember if seen, so I may opt for the long key for this reason alone.
  11. So I've confirmed that the Lenovo/Intel Centrino Wireless-N 2230 chipset won't connect to the WG302 (with the latest firmware) using WPA2 AES. It will with WPA TKIP. It's fine with the WNDAP350, so I'm guessing the issue is with the WG302. Is there any huge benefit in switching from WEP to WPA TKIP if we're going to be changing all this in 6 months anyway?
  12. Yep, that's the site I linked to above. Seems slightly heavy handed, so just checking there's not something a little more elegant GP-wise.
  13. Is that the likes of Radius? Beyond me technically, but I can refer to a consultant.
  14. I learnt something new, that you can actually see what wireless key has been entered on your PC by going to the wireless profile's properties, then to the security tab, and then ticking "show characters". I was stunned that MS allow you to do this, and as per my other thread this was how some students got hold of our wireless key. The only method I can find to prevent this via GP is defined in a response here (albeit for Windows Vista, so may not work) How to Disable function "Show Character" in wireless connection? Does anyone know of another mechanism for doing this?
  15. An update to the WG302 has enabled profiles, and the WNDAP350 can do that out of the box. There's still this compatibility issue with the Lenovos/Intel Centrino Wireless-N 2230 which I need to troubleshoot. My concern is that these are just the laptops tested, and we have several more oddballs. I'll see how the compatibility testing goes...
  16. Mostly Netgear WG302. Some Netgear WNDAP350. All individually setup. I'd prefer a managed solution, but as per the above it won't be happening until at least the next FY. Clearly we'd then need to look at the network infrastructure as a whole, to make sure it will all work together.
  17. As per the above though I've got some new Lenovo laptops with Intel chipsets that won't connect to our Netgear WG302 AP's configured with WPA2 AES. We have a very mixed fleet of laptops so my nightmare scenario is changing the key and it not working on some models - the teachers have to have a working Internet connection, even a day or two of no connection is a huge problem for them. Going forward we will look next FY at replacing the wireless solution with something managed, if budget allows. (Budget being another problem...)
  18. Does having a 504 bit key increase the amount of time it takes to hack? Does the length of the key have any other effect? e.g. connection speed. I've used a random generator to create the 504 bit key, so definitely not dictionary. Control panel is blocked other than display, yet you can still get to it through the notification area. Is some specific block required?
  19. As an aside, it transpires that WEP wasn't hacked. A student went onto a teacher's laptop, looked at the wireless settings (click "show characters") and wrote down the WEP key. We've told teachers time and time again to not leave their laptops unsupervised.
  20. I've tested 4 laptops, from our oldest to newest, with WPA2-AES 504 bit key (most of our APs are Netgear WG302's, so I've tested with one of these using the latest 4.2.17 firmware). Ironically our newest Lenovo laptops just refuse to connect with this config. I will double check, but I'm fairly sure they have the latest (Intel) drivers (Centrino Wireless-N 2230). These are all Win 7.
  21. My fault probably. I accepted from a previous manager of the system that it was on WEP because of an issue with these older laptops. I'll do some testing.
  22. It's a possibility. I need to check how many laptops are affected, although oddly they are running Win 7. Is TKIP actually hackable? Just to make sure I'm going for the right flavour of WPA.
  23. Does it matter whether TKIP or AES, or any particular bit length for the key?
  24. One additional question. If we switch to WPA, should it be any particular flavour, or is any form of WPA sufficiently secure?
  25. Some students have managed to access our network by hacking the WEP key - WEP is used because we have some old laptops that can't cope with WPA. The domain itself is secured, along with the resources on it. The gateway should be secured with NTLM auth, so they can't get to the Internet. Clearly there could be effects on the wireless network in terms of load, devices connecting to WAPs. Can anyone see any other consequences of this, and have any other suggestions for what to do? (The plan is to change the WEP key, FWIW, and see if WPA is viable in any way at all)
×
×
  • Create New...