Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #31 (permalink)  
Old 06-18-2007, 04:55 AM
Roger Harrison
Guest
 
Posts: n/a
Default Re: First time home wireless - how to match PC to router - setup question

On Sun, 17 Jun 2007 19:47:58 -0700, Jeff Liebermann wrote:
> if I have physical access, I can extract the key from the registry.

Thanks to you, I am now better informed. I would assume this
WPA2-Pre-shared-key can also be extracted with a "virus" or a "trojan" ...
Is that correct?

> I believe that 20 characters minimum is considered best practices.

I just type away on the router to set the key and then write it down to
bring to the PCs. These pre-shared keys are around 20 or 25 characters but
I'll go longer from now on now that I know it's the holy grail.

>>One question: Do I have to use 192.168.xxx.xxx?

> 10.0.0.0 - 10.255.255.255 (10/8 prefix)
> 172.16.0.0 - 172.31.255.255 (172.16/12 prefix)
> 192.168.0.0 - 192.168.255.255 (192.168/16 prefix)
> They don't route anywhere.

Interesting. Very interesting. I think I'll rotate through these additional
addresses in my Sunday changes. I'll read up on the netmask stuff as it
seems to be the opposite of what I thought originally. Thanks.

> DHCP range limiting was never intended to be [a] security feature.

Bummer. Got it.

> when I worked in engineering many years ago, the drafting department
> gave me a "change everything" rubber stamp as a present.

I believe it!

> As I said in my previous rant, your primary and probably sole real
> security feature is the WPA or WPA2 shared key.

I'll spend more time making the WPA2-PSK key longer and harder to guess.
I've been using all the funky characters and I will try to use at least 30
characters each week.

>There is a wireless Windoze workaround at:
> <http://www.cacetech.com/products/airpcap.htm>

I'll check this suggestion out as I am very interested in seeing my first
packets ever!

> Either use a hub, which is really a repeater that repeats
> everything going into any port to all the other ports, or get a high
> end ethernet switch that has a configurable monitor port.]

All I have is a windows pc with a wireless router. I don't know about
"hubs" or "switches". Presumably the router is both a hub and a switch.

> Yep. That's what I've been trying to explain for the last 3 messages.
> Using DHCP to limit available IP's with a /25 netmask doesn't work.

As I said, and as you said, I need to bone up on the netmask!


>> Does netstumbler really provide the MAC addresses of the
>> client machines?

> No. Netstumbler is NOT a passive sniffer.
> I suggest using backtrack & kismet.
> That should show client MAC addresses

I think I'll set up a separate spare PC for that as it sounds interesting.
I also have Knoppix CDs so I might see if I can somehow use Knoppix with
Kismet.

> I often have the two routers
> connect to each other, thus forming a VPN tunnel,
> which makes my office and home network look like one big LAN.
> All the traffic is encrypted by the tunnel, so hotspot sniffing
> is useless.
> They run DD-WRT V23 SP2 and SP3 respectively. Try it:
> <https://home.LearnByDestroying.com:8080>

I saw "Suzy", "micron", and "BLITZEN". :)

> Use some form of monitoring to determine what your network is
> doing and who is on it.

Got it. I'm working on that as noted above.

> You might want to read the FAQ for alt.internet.wireless.
> FAQ for Wireless Internet: <http://Wireless.wikia.com>
> FAQ for Wi-Fi: <http://wireless.wikia.com/wiki/Wi-Fi>
> Wi-Fi How To: <http://wireless.wikia.com/wiki/Wi-Fi_HowTo>
> Fixes to Wi-Fi Problems: <http://wireless.wikia.com/wiki/Wi-Fi_Fixes>

Will do! Thanks!

I hope to learn more and more and more so I'll go quiet a while so I can
learn without troubling others!

Reply With Quote
  #32 (permalink)  
Old 06-18-2007, 06:03 AM
Jeff Liebermann
Guest
 
Posts: n/a
Default Re: First time home wireless - how to match PC to router - setup question

Roger Harrison <RogerJHarrison2@aol.com> hath wroth:

>On Sun, 17 Jun 2007 19:47:58 -0700, Jeff Liebermann wrote:
>> if I have physical access, I can extract the key from the registry.

>Thanks to you, I am now better informed. I would assume this
>WPA2-Pre-shared-key can also be extracted with a "virus" or a "trojan" ...
>Is that correct?


Yes, I think they can. I don't know of any that do that, but it could
be done. I don't think that's the danger. Walking up to the computah
with a USB dongle and script, and extracting the registry keys, is all
that's required. I think I saw it being done in a busy coffee shop,
but I'm not sure. No keyboard entry required, just an autorun.inf
file and a VBS script.

>I'll spend more time making the WPA2-PSK key longer and harder to guess.
>I've been using all the funky characters and I will try to use at least 30
>characters each week.


John Navas posts this regularly to alt.internet.wireless on selection
of WPA keys.
<http://groups.google.com/group/alt.internet.wireless/msg/631f552840a5bb12>

>> Yep. That's what I've been trying to explain for the last 3 messages.
>> Using DHCP to limit available IP's with a /25 netmask doesn't work.

>As I said, and as you said, I need to bone up on the netmask!


Oops. I mean't /24 network (256 IP's).

>> No. Netstumbler is NOT a passive sniffer.
>> I suggest using backtrack & kismet.
>> That should show client MAC addresses

>I think I'll set up a separate spare PC for that as it sounds interesting.
>I also have Knoppix CDs so I might see if I can somehow use Knoppix with
>Kismet.


Backtrack is based on Knoppix. If Knoppix works, then Backtrack
probably will also work. The difference is that the Backtrack CDROM
has all the nifty hacker tools already installed, working, and tested.

>> They run DD-WRT V23 SP2 and SP3 respectively. Try it:
>> <https://home.LearnByDestroying.com:8080>

>I saw "Suzy", "micron", and "BLITZEN". :)


Suzy is a neighbors laptop. The one labelled * is another laptop at
the same location, but that has no visible machine name. Micron is a
kids desktop at a different neighbor. Blitzen is a customers laptop
on my desk which is currently driving me insane. Note that the list
only includes clients that are issued DHCP addresses. If the client
uses a static IP address, it will NOT show up on the list.

Ooops. I forgot to disable listing of the full MAC address. (fixed).

>I hope to learn more and more and more so I'll go quiet a while so I can
>learn without troubling others!


Good luck.

--
Jeff Liebermann jeffl@cruzio.com
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558

Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Wireless router is no longer a router? Ikke alt.internet.wireless 7 02-01-2007 10:23 PM
Help!: setup Belkin wireless router on LAN ImaChessNut@gmail.com alt.internet.wireless 2 01-11-2007 02:38 AM
Wired and Wireless greenfield setup BCage alt.internet.wireless 7 12-31-2006 04:12 AM
Best location for wireless router in 2-story home? LurfysMa alt.internet.wireless 7 11-03-2005 06:38 AM
Hacking attempt? MoNk Wireless Networking Discussion 1 05-11-2005 09:21 AM


All times are GMT. The time now is 01:15 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45