<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Wireless Security forum - dslreports.com community</title>
<link>http://www.dslreports.com/forum/wsecurity</link>
<description>Wireless Security forum current topics</description>
<language>en</language>
<copyright>Copyright 2007, dslreports.com</copyright>
<pubDate>Wed, 10 Feb 2010 01:45:30 EDT</pubDate>
<lastBuildDate>Wed, 10 Feb 2010 01:45:30 EDT</lastBuildDate>

<image>
<title>dslreports.com</title>
<url>http://i.dslr.net/bbrdisc1.gif</url>
<link>http://www.dslreports.com</link>
<width>19</width>
<height>18</height>
<description>bbr disc</description>
</image>

<item>
<title>Router Support Tech Security Risk?</title>
<link>http://www.dslreports.com/forum/remark,23700223</link>
<description><![CDATA[I was on the phone with a tech from a wireless router company working through some wireless connection problems. During the course of the conversation the tech asked for
IP address
Pass-phrase
SSID
He then was able to access the router and read back to me my admin password that I had changed as well as making several changes to the router config.
After thinking about it I went back in, changed the admin password, and the pass-phrase.  Will this suffice in securing my network?  BTW my cable broadband does not use a static IP.

Thanks for the help.  I'm new at this and somewhat concerned.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23700223</guid>
<pubDate>2010-01-25 14:45:19</pubDate>
</item>

<item>
<title>Wanted:Reference Material, Documentation &#x26;amp; Tools</title>
<link>http://www.dslreports.com/forum/remark,23341645</link>
<description><![CDATA[Good Afternoon.

I am a telecommunication student working on a term project.  The topic wireless security is broad, and as such we have decided to focus on items of potential interest for our peers that directly related to security.  We believe that Wireless Lan Controllers with the use of Lightweight APs may be a good point.  

For the practical portion the recent Cisco Skyjacking vulnerability is something we may  be able to demonstrate.  We have some school provided equipment.  Mainly a few APs that would need to be converted to Lightweight mode as well as a single WLC, 2100.

What I hope this community may help provide are suggestions on the material to review, or tools that may help with the creation of this demonstration.

The plan:

: 1 AP (more 1100 and 1200 series if needed), and 1 WLC

- AP in lightweight mode receives RRM (Over-the-air-provisioning - OTAP) from 'rogue client or such'
- WLC is on some network or directly on Internet
- L:AP gets WLC IP from OTAP message and goes to connect to it
-- L:AP Connects via wired connection out over Internet on UDP 12222 or 12223 to the WLC 

- WLC sends 'revised configuration' to the L:AP
- L:AP is now accessible via the 'rogue client' only
- L:AP can be converted to Hybrid Remote Access Point (H-REAP) which allows WAN connectivity to not trravese the tunnel back to the WLC before exiting to some resource like the Internet

Any and all suggestions would be great via a POST or PM.  I understand and agree with any decision to with hold potentially malicious tools or knowledge of those tools to conform with the ideas and principles of this forum.  

I will be posting something similar in the Cisco forum, Shortly.  Thank you.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23341645</guid>
<pubDate>2009-11-14 17:02:19</pubDate>
</item>

<item>
<title>Referred to Wireless Security Forum - please assist</title>
<link>http://www.dslreports.com/forum/remark,23702343</link>
<description><![CDATA[the link below points to a post I posted on the Wireless Networking forum. According to the fellow who had much greater knowledge than I, he suggested I repost my dilemma on this forum. Fair warning, I'm outta my league mostly on this one, but it's a mystery that has me concerned regarding an apparent unknown highjacker on my home network. I'd greatly appreciate some expertise here. Thank you.

http://www.dslreports.com/forum/r23677219-Actiontec-GT701WG-wireless-hitchhiker]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23702343</guid>
<pubDate>2010-01-25 21:08:06</pubDate>
</item>

<item>
<title>wireless client has no host name?</title>
<link>http://www.dslreports.com/forum/remark,23583661</link>
<description><![CDATA[i have an AP with a particular SSID that i let anyone connect to. i check on the activity from time to time and often i see MACs associated with the AP that have no hostname.

[att=1]

is there a system where a wireless client not having a hostname is typical? if so, what system? phones? blackberries? linux?

i know that winxp wont let you (through the gui) get away with a computer that has no hostname. i assume this goes for all windows products.

looking for some type of reproducable senario here. im not big on conjecture.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23583661</guid>
<pubDate>2010-01-03 20:05:47</pubDate>
</item>

<item>
<title>Wireless Network Secure?</title>
<link>http://www.dslreports.com/forum/remark,23727033</link>
<description><![CDATA[I have a 802.11g wireless network at home on a WRT54G v5 using WPA2-PSK encryption with a 16 character password. Up to 8 clients connect to it wirelessly while a desktop and network drive are connected to the router on 100Mbps ethernet cables. 

Is my network secure enough? Should I implement stuff like SSID hiding and MAC filtering?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23727033</guid>
<pubDate>2010-01-30 06:19:25</pubDate>
</item>

<item>
<title>Wireless connection in hotel</title>
<link>http://www.dslreports.com/forum/remark,23718049</link>
<description><![CDATA[I'll be spending a month in a hotel while renovations are being done in my condo and will be using a wireless network supplied by the hotel.

The first time you open IE you get the hotel's page which asks for a password and has a check box that asks if you have a VPN. I don't.

I'm on a Windows Vista Home laptop and use McAfee Security suite.

What do I need to do to protect myself and protect private information? 

I know just enough about wireless security to set up my home router properly, past that I'm in the dark. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23718049</guid>
<pubDate>2010-01-28 14:23:34</pubDate>
</item>

<item>
<title>mac filtering between with windows 7 and vista laptop</title>
<link>http://www.dslreports.com/forum/remark,23523275</link>
<description><![CDATA[i was using mac filtering for my wireless vista laptop and
belkin n router and all was fine. when i tried to add windows 7
laptop to mac filtering list i could no longer access the internet
with either wireless laptop. i was only able to get limited access without internet.
when i disable mac filtering i can access internet with both
laptops.

can anyone explain what the problem might be?

thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23523275</guid>
<pubDate>2009-12-21 08:33:31</pubDate>
</item>

<item>
<title>802.1x seems to be failing me</title>
<link>http://www.dslreports.com/forum/remark,23691463</link>
<description><![CDATA[Ok, we bought an HP MSM410 just to test out the range and see how well they worked before we went ahead and bought about 20 more.  The range is better than the old Cisco 802.11b AP's we had before, so I wanted to make sure I was capable of setting these AP's up securely.  I've never messed with 802.1x before, but followed Microsoft's guide as closely as I could.  And I can't get it working.  I'm running the NPS server on Windows 2008 Server with the RADIUS client setup.  I installed AD Certificate Services and installed the certificate on the laptop I'm testing with.  I set the NPS server to not even bother looking at the authentication and to accept all clients just to troubleshoot.  However, the laptop is still sitting at "Validating identity" (XP Pro SP3).  

Looking through the logs on the AP I see the following:
http://pastebin.com/m2f179764

If I delete all the connection settings on the laptop, it says it can't find a certificate if I just double-click on the connection.

If I select the certificate, it just sits there at validating identity, even though it shows the AP got the access-accept message.

I have no idea what to do here... any help would be appreciated.  I'll start reading through the MS guide again to see if I missed something.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23691463</guid>
<pubDate>2010-01-23 16:05:42</pubDate>
</item>

</channel>
</rss>
