Wi-Fi Technology Forum - Wireless Mobile News and Forums Setup Your Own Wi-Fi Hotspot

Wi-Fi Technology Forum - Wireless Mobile News and Forums

User's Login





 


 Log in Problems?
 New User? Sign Up!

News & Articles

Partners

Wi-Fi Hotspots Directory

NewsLetters

You are currently not logged in, but you can still subscribe to our newsletter.



Search


Other Resources



Wi-Fi News Archive

Search Archive

Past Articles

  • Monday, September 22
  • New Start-up Danish Company Introduces Latest Wi-Fi Solution
  • Thursday, September 18
  • Sensium™ Intelligent Wireless Body Monitoring System On Show at San Francisco IT Event
  • Tuesday, September 16
  • CommProve Secures $14 Million Financing To Support International Expansion
  • Thursday, September 11
  • 4ipnet Addresses Business Demand With A New Wireless Office Solution
  • Tuesday, September 09
  • Israeli Fabless Semiconductor Company Percello Announces $12 million Series B financing
  • Tuesday, September 02
  • University of Macau Deploys Campus-Wide Aruba Adaptive Wireless LAN
  • Thursday, August 21
  • WeFi Launched on Symbian For Easy Wi-Fi Access Including Nokia S60
  • Thursday, August 14
  • Crossover To Promote ADC’s InterReach Wireless Systems in Canada
  • Wednesday, August 06
  • Mobile Video and Voice Applications To Reduce Interstate Crime
  • Tuesday, August 05
  • St Pancras International First UK station To Offer Free Wi-Fi Access
  • Lates Stories

  • Vodafone 2008 Partner Award Goes To Seeker Wireless (Oct 09, 2008)
  • Toumaz's Chief To Explore Wireless Body Monitoring Solution at Club Industry 2008 (Oct 09, 2008)
  • SecuWipe First Data Erasure Utility For PDAs And Smartphones Released (Oct 03, 2008)
  • Meru Wi-Fi Access Solution Will Prove Reliable at Rotherham High School (Oct 01, 2008)
  • The New Vx 700 Payment Solution Integrates With VeriFone’s SCR710 (Sep 29, 2008)
  • Dimension Data Uses Wi-Fi 802.11n WLAN Suite To Optimize Wireless Network (Sep 29, 2008)
  • ip.access Edges The UK's Top 50 Fastest Growing Technology Companies (Sep 29, 2008)
  • EMCC Launches Cross-platform Independent Mobile VoIP Engine (Sep 29, 2008)
  • Eye-Fi Plans To Expand Distribution Internationally To Japan And Canada (Sep 23, 2008)
  • Rajant's Wireless Mesh Networking Solution Deployed In Australia (Sep 22, 2008)
  • Categories Menu

    -Announcements (Nov 12, 2004)
    -Business and Market (Nov 08, 2006)
    -Cellular & Mobile Media (May 06, 2008)
    -Conferences and Events (Sep 18, 2008)
    -Corporate News (Oct 09, 2008)
    -Finance, Investment and Stocks (Sep 16, 2008)
    -getting unwired, un-wired or dewired (Sep 24, 2003)
    -ISP Watch! (Apr 01, 2005)
    -Manufacturers and Products (Oct 09, 2008)
    -Mobile, Pocket and Handheld (Sep 22, 2008)
    -Prints and Publications (Jul 12, 2006)
    -Reports and Papers (Apr 15, 2008)
    -Security & Encryption (Feb 25, 2008)
    -Software and Solutions (Oct 03, 2008)
    -Standards & Certification (Mar 19, 2008)
    -Technology Trends and Markets (Jul 09, 2007)
    -Telecommunications (Jul 15, 2008)
    -Wi-Fi Hotspots and Providers (Oct 01, 2008)
    -WISPs News (Jul 28, 2008)

    A threat posed by SNMP use over WLAN




    A paper dealing with Wi-Fi Security ( Gianluigi Me, PhD).

    A paper dealing with WLAN Security, highlighting the dangers and pit-falls as a consequence of using an unsecured Simple Network Management Protocol (SNMP). In this paper, Dr Gianluigi shows how hackers and eavesdroppers exploit this neglected vulnerability. Using diagrams, He goes even further to point out in detail the dangerous threat hidden in breaking WEP communications exploiting Access Points.


    -------



    (Italiano: PDF - HTML )
    (Gianluigi Me, PhD)

    Introduction

    Attacks on WEP compromise confidentiality of communications. One of the main threats is posed by eavesdroppers listening to private communication on wireless LAN. But there’s a more dangerous threat hidden in breaking WEP communications. In fact, some access points can be managed via wireless link, usually with a proprietary application, relying on SNMP protocol. Executing these operations can represent a frightening vulnerability for the whole Wireless LAN, because the eavesdropper can know the password to access in read/write mode the access point. This means that he/she shares the administration privileges with the WLAN administrator and can manage your wireless LAN in a malicious way.



    An SNMP model


    The Simple Network Management Protocol (SNMP) uses a manager/Management Information Base (MIB)/agent paradigm, as shown in Figure 1





    Figure 1


    This paradigm is based on a manager asking an agent for information in a certain coded format such as that in a MIB. The receiving agent processes the request, retrieves that information, and returns it or the reason of unavailability. In this manager/MIB/agent paradigm, the user interface plays just a presentation layer, it is graphics-based and designed to make data retrieval and the resulting presentation more usable. Management applications offer a way to format retrieved data and offer extra layer of user control of Network Management Station (NMS) functions.


    Securing Agents and NMSs


    Version 1 of SNMP offers sketchy tools to secure the communication process between the NMS and an agent. Only the limited protection of authentication comes with SNMP in the form of a community name. More robust mechanism to eoffer security can lay on TCP/IP by third-party software. For example, the only protection against unauthorized access is a string of characters in SNMP header, called Community name. This is an NMS’s access authority that an agent will check before performing the task requested in the SNMP message. All the agents that respond to the same NMS will have the same two Community Names. The Get Community Name instructs the agent to allow reading of MIB variables. The Set Community Name authorizes the agent to write a value to a MIB object that is designated as read-writable. Some texts identify these as the Read and Write Community Names.

    Most vendors have their agents and NMS out-of-the-box configured with the Community Name set to “public”. It is recommended to the network manager to change those settings on the agents and the NMS. If these configuration values are not changed, any NMS can access and change agent information.


    Added:  Thursday, October 28, 2004
    Submitter: Administrator | webmaster@wi-fitechnology.com
    Score:
    hits: 3915
    Language: eng
    Page: 1/2

    Next (2/2) Next




    [ Back to papers index ]