PDA

View Full Version : Current WLan vulnerabilities


pechspilz
10-22-2004, 12:19 PM
Hi folks

If you use your Streamium in wireless mode: did you know that it takes about 2 GB of data to hack your WEP encryption keys? That's about 2 movies worth of data. Disabling the SSID and blocking unknown MAC addresses won't help a lot either.

So my question to you is, do you bother at all? No risk, no fun?

Neo
10-22-2004, 03:05 PM
I don't really give a damn.
There isn't a hacker in every neighbourhood...and I'm not an interesting target.
And my streamium is hard wired not for security reason but for stability reasons...

the 2 Gb of data is for the 128 bits key size?

pechspilz
10-22-2004, 05:32 PM
Yes that's for the 128 bit key.

It's actually not even a 128 bit key, it's 104 bit and a 24 bit initialization vector, whatever that is.

https://www.hackinthebox.org/article.php?sid=3492

I hope nobody minds if I post that link. It's just for common enlightenment.

pechspilz
10-22-2004, 05:34 PM
They claim with AirSnort you eventually need 100MB to 1 GB. So it's even less than I originally wrote.

HeiB
10-22-2004, 07:20 PM
[ QUOTE ]
Hi folks

If you use your Streamium in wireless mode: did you know that it takes about 2 GB of data to hack your WEP encryption keys? That's about 2 movies worth of data. Disabling the SSID and blocking unknown MAC addresses won't help a lot either.

So my question to you is, do you bother at all? No risk, no fun?

[/ QUOTE ]

I don't suffer from that German paranoia that the whole planet is lusting after the data on my network.
I use the usual precautions (WEP,MAC etc.) and when WPA and other enhancements will become available I'll also use these.

And why would a war driver try to get into my network when there are at least half a dozen OPEN WLANs in my neighbourhood ?

pechspilz
10-23-2004, 01:26 PM
Well, I'm not that concerned about somebody being able to access data on my PCs. I'm more concerned about a person who abuses my internet connection for his own dark deeds. It's me who's going to be held accountable. If I'm home alone at the time and my IP shows up in a log where it should not I'm in deep trouble.