Road Warrior At Risk: The Dangers Of Ad-Hoc Wireless Networking

Airport Menace: The Wireless Peeping Tomheart attack!After this, he moved up to the seat
----------------------------------------next to mine and we
As a network security consultant, I travel quitespent the next hour or so configuring his laptop
frequently.securely,
At times, it seems like the airport is my secondstarting with securing his computers local
home. Iadministrator
actually like to fly, it's a moment in time whereaccount. At one point during the configuration, he
no one canmade the
reach me by e-mail, or mobile phone.It never failsstatement that I got real lucky because his local
that something interesting happens to me atadmin
the airport. I've even met some famous peopleaccount did not have a password. My response
during myto him was, I
travels. A few months ago, I ran into Frankget lucky quite often.Who Else Has Your Client
Bielec, from theList
TLC show, Trading Spaces. But one of my-----------------------------
favorite things toJust think of the possibilities. What do you have
do at the airport is browse the wireless Ethernetto lose if
waves. I'msomeone is able to just peruse the files and data
never really surprised at what I find. I'm just gladon your
I knowlaptop? Do you maintain your customer list on
more about wireless Ethernet than the averageyour laptop
road warrior.The Dangers Of Ad-Hoc Wireless(Do you want this in the hands of a competitor)?
NetworkingHow about
-----------------------------------------your personal finances (Identity theft ring a bell)?
Most people who have wireless Ethernet atSo many
home, or thepeople I talk to initially say, "I really don't have
office, connect to the wireless network byanything of great importance on this system".
attaching to aThen they
wireless Access Point, or AP. This method ofthink a little bit and start rattling of things they
wirelessnever
networking is called "Infrastructure Mode". If youreally thought about before. All of a sudden, they
have aget
secure wireless network configured inconcerned.The fact is, whether it be
"Infrastructure Mode""Infrastructure Mode", or
you are using MAC address filtering, some level"Ad-Hoc" wireless Ethernet communications, if
ofnot properly
encryption, and have made some additionalconfigured and secured, can pose a significant
changes to your APrisk. There
in order to prevent just anyone from using it orare thousands of articles on the Internet about
capturingthe dangers
data. For more information on configuring yourof improperly configured wireless networks, yet
"Infrastructure Mode" wireless network take athe number
look at theof unsecured networks seems to be getting
"Wireless Network Security" page at Defendinggreater, not less.Strength And Posture Does
The Net.LinksReduce Your Risks
------------------------------------------------
for those who are not using "InfrastructureKeep in mind that your objective should be to
Mode",reduce the
and are configured to communicate fromchances that you will become a target for
machine to machine,computer
or "Ad-Hoc", there are a few things you shouldcompromise. When I was growing up in South
be aware of.A wireless Ad-Hoc network allowsPhiladelphia, I
you to communicate withremember my father telling me that when you
other wireless Ethernet systems without using awalk down the
wirelessstreet, especially in the evening, to walk tall, and
access point. It's kind of a peer to peerproject
configuration anda position of strength and authority. Why,
it works rather well. The problem is, most peoplebecause thugs
just settypically pick out those who look like an easy
it up, and forget about it. At home, it's not atarget. The
hugesame thing goes for computer security. Reduce
problem, but when your on the road, it couldthe risks of
cause you abecoming a target buy configuring your system
great deal of grief. The airport is probably thewith a strong
best placesecurity policy.When I perform security
to find Ad-Hoc networks. Business men andassessments, I create a list of
women, delayedpotential targets, and potential methods of
once again, power up their laptops and get tocompromise. I
workthen prioritize that list by which system, with a
completing the days tasks, or planningparticular
tomorrows agendas.I can't tell you how manyvulnerability, may be easiest to compromise.
systems I find in the airportThose at the
configured this way. Not just in the terminal, butbottom of the list typically never come on my
on theradar screen;
plane. About three months ago, just after wethe best scenario it to keep of the radar
reachedaltogether.Conclusion
cruising altitude and were allowed to use our----------
"approvedIf your are using wireless Ethernet, no matter
electronic devices", I found that the gentlemanwhat
two seats upconfiguration, follow a few rules and keep
from me had a laptop configured as Ad-Hoc. Heyourself secure
walked by meagainst most common types of compromise.1.
about ten minutes later and commented on howAbove all, make sure all your user accounts have
much he likedstrong
my laptop. I thanked him, and asked if his laptoppasswords, especially those that have
was on,administrative control
and configured to use wireless Ethernet, he saidover your system;2. Configure your wireless
yes.To make a long story short, I showed himnetwork to use some sort of
that I could seeencryption. I know there is a lot of concern
his laptops wireless Ethernet and informed him ofabout the
the"crackability" of WEP, but if this is all you have to
danger. He asked me if I could access his hardwork
drive, and Iwith, and then use it. It is still helpful;3. If possible,
told him that it might be possible. He asked meuse MAC addresses filtering to restrict
to see if Iunwanted systems from attaching to your
could, so I obliged. After configuring my laptop towireless network;4. Make sure the firmware for
use theyour AP's and wireless
same IP address class as his, and typing "net useEthernet cards are up to date. These updates
*can be found on
hiscomputersIPAddressc$ "" /USER:administrator",your card or AP's support site.Remember, if you
Iare compromised over your wireless network
received a notice that the connection wasit can be near impossible to track down where
successful andthe attack
drive Z: was now mapped to his computer. Icame from. Worse yet, think about how many
performed asystems become
directory listing of his hard drive and the guycompromised, and no one ever knows it?
almost had a