Saturday, March 28, 2009
How Do You Change A Padlock Combination
Cisco has published, as every last Wednesday of March, eight security bulletins that address 10 vulnerabilities in its Cisco IOS operating system, which could be exploited by attackers to cause a denial of service or privilege escalation.
Briefly, the vulnerabilities are:
* It has been found that a sequence of TCP packets could cause a denial of service on Cisco IOS devices that are configured as an Easy VPN Server using Cisco Tunneling Control Protocol (CTCP .) It recommends applying the patches available or use IPSec NAT-T as an alternative.
The vulnerability is documented in the Cisco bug ID CSCsr16693 and CSCsu21828:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsr16693
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails. do? method = fetchBugDetails & BUGID = CSCsu21828
* vulnerability exists when handling IP sockets could be exploited by an attacker to cause denial of service, through a sequence of TCP / IP packets specially crafted, when enabled certain property Cisco IOS.
The vulnerability is documented in Cisco bug ID CSCsm27071:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm27071
* A vulnerability has been found on systems configured for Cisco IOS Mobile IP Network Address Translation (NAT) Traversal or Mobile IPv6 that could be exploited to cause a denial of service, causing the system interface process traffic ceases.
The vulnerability is documented in Cisco bug ID CSCsm97220 and CSCso05337:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm97220
http://tools.cisco .com / Support / BugToolKit / search / getBugDetails.do? method = fetchBugDetails & BUGID = CSCso05337
* There is a server-side failure in the implementation Secure Copy (SCP) in Cisco IOS could be exploited by an authenticated user with command line interface (CLI) to gain escalated privileges. The user can transfer files to or from, the device that is configured as a SCP. This could be exploited to access and write to any file on the device, can gain total control over it.
The vulnerability is documented in Cisco bug ID CSCsv38166:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsv38166
* We have found a vulnerability in Cisco IOS in the implementation of Session Initiation Protocol (SIP) which could be exploited by remote attackers to force a reboot of the device.
The vulnerability is documented in Cisco bug ID CSCsu11522:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsu11522
* found that multiple features Cisco IOS could allow a remote attacker to cause a denial of service on the affected system via a sequence of specially crafted TCP packets.
The vulnerability is documented in Cisco bug ID CSCsr29468:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsr29468
* We found a vulnerability when processing specially crafted UDP packets that would affect other property of Cisco IOS. If any of the affected is enabled, and specially crafted UDP packets sent to the affected device, it could stop processing traffic through the interface.
The vulnerability is documented in Cisco bug ID CSCsk64158:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsk64158
* found two vulnerabilities in Cisco IOS WebVPN or SSLVPN that could be exploited by an unauthenticated remote attacker to cause a denial of service on the device.
The first failure would occur when receiving specially crafted HTTPS packets and is documented in Cisco bug ID CSCsk62253:
http://www.cisco.com/pcgi-bin/Support/Bugtool/onebug.pl?bugid=CSCsk62253
The second problem is caused by a memory leak in the device when processing SSL sessions that have been disrupted unexpectedly. The issue is documented in Cisco bug ID CSCsw24700:
http://www.cisco.com/pcgi-bin/Support/Bugtool/onebug.pl?bugid=CSCsw24700
More Information:
Summary of Cisco
Bundled Software IOS Advisories, March 25, 2009
http://www.cisco.com/warp/public/707/cisco-sa-20090325-bundle.shtml
Source: http://www.hispasec.com/unaaldia/3807
Tuesday, March 17, 2009
Free Rick Solomon One Night In Paris
The Cisco Unified Communications solution is a set of products and communications applications
that collects and integrates voice, video and data.
The ruling could be exploited if an attacker intercepts the client credentials sent from Cisco Unified Communications Manager after you have authenticated to the synchronization process.
Cisco, through the usual channels, has made available to customers
solutions to solve the problem.
is advised to consult the table of vulnerable versions and countermeasures
:
http://www.cisco.com/warp/public/707/cisco-sa-20090311-cucmpab.shtml
More Information:
Cisco Security Advisory: Cisco Unified Communications Manager IP Phone Address Book Synchronizer Personal Privilege Escalation Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20090311-cucmpab.shtml
Source: www.hispasec.com/unaaldia/ 3794
Monday, March 2, 2009
Brampton Corelle Dinnerware Sale
Welcome !!!!!!
Here is a link to some videos superchulisimos speaking, as you can imagine on VoIP. I hope you find it useful. Greetings.
VoIP2DAY What is?
VoIP2DAY born as a meeting place in the world of Voice and Video over IP in Spain and Portugal. Large fairs CeBIT generalists SIMO or have been weakened, and the really interesting thing in this day run are highly specialized fairs like the one in question.
The event is designed with the aspiration to establish itself as a benchmark annual boost for the growing local market and pointer to global technological level. That is why the participation of visitors is fundamental and most important of all, that your experience is valued as enriching post to mark your calendar and next year.
From the experience gained over the years as participants VoIP fairs in Europe and America, the organization has tried to pick the best of them and correct some of its shortcomings, the following are key to this new forum:
+ Fair for Professionals Only on weekdays
+ Free to attendees after registration required
Three Day Tours + + Exhibition Area
Manufacturers, Distributors and Integrators Conference
+ Zone 2 days tácnico orientation commercial and business cases and 1 day Axiter purely technical and community development of communication systems based on Free Software
+ Discussion Board on the day of the Open Source Community Days
+ Topics for days to focus the interest of visitors and exhibitors
+ Match in space and time during the trading days with the fair and complementary salon Call Center
Saturday, January 31, 2009
When I Floss It Smells
In this figure shows the compatibility IOS release, indicating integrated version of CUCM, CUCM GUI version (WEB) available to install and technical specifications.
Therefore, when downloading the package mentioned in the image x, we must keep this list so that all the functions to be implemented to run without any problems.
Now, if you want to download some of these files can be done separately from the Internet address where you can view http://tools.cisco.com/support/downloads/go/Redirect.x?mdfid=278875240 all files related to software, telephones, and other applications from a single browser window, as shown in Figure:
From this menu you can select the phone available in this case, 7940G, and download utilities, software and firmware SIP / SCCP, among others, as shown in Figure:
In this case, it will download the package "cmterm-7940-7960-sccp.8-0-10.zip "which contains the firmware files required for SCCP IP phone 7940G.
The package contains the following files:
- P00308001000.bin
- P00308001000.loads
- P00308001000.sb2
- P00308001000.sbn
Everyone should go to Flash using TFTP.
Since both routers are available in a version 22T IOS Early Deployment "will download an additional package" cme-124-20T1.zip "from which we can mention the following files:
- 7970-backgrounds.tar: Wallpapers for mobile IP.
- cme-gui-7.0.0.1.tar: Web interface management CUCM.
- ringtone.tar: Set additional ringtones.
- music-on-hold.au: Sound audio waiting for calls between the PSTN and the local network.
- cme-BACD-2.1.2.2.tar: sound files for IVR.
For now be uploaded to the flash packages "Cme-gui-7.0.0.1.tar" and "music-on-hold.au" recalling that to unzip the package. Tar to proceed with the command "archive tar / Xtract tftp: / / xxxx / cme-gui- 7.0.0.1.tar flash: ".
kyrios
Friday, January 30, 2009
Is A Hiatus Hernia Bad To Have In Women
CUCM Enabling the VoIP service
Files Needed Once the basic configuration, you can configure the Cisco Unified Communications Manager Express.
should bear in mind the interactions that occur between CUCM and IP phone, since that first assigned by the router to the IP phone is an IP address, then checks the attached device, and if telephone previously loaded firmware is housed in the flash, and finally, assigns VLAN and IP address corresponding final.
The first thing you should do is copy the files necessary to run IP phones. In this case, the images stay in flash SCCP Cisco IP Phone 7940G. Therefore, a Cisco CCO account, you must download the latest version of firmware of these IP phones.
The web address is http://www.cisco.com/cgi-bin/tablebuild.pl/ip-key discharge, which display a list of files as shown and described below in Figure:
files shown in the image x files necessary to run IP phones, web interface, IVR, among other features. The difference in version is presented and is significant in the "release", which tells us which version of CUCM must be available in the IOS to work with the respective package files.
This is important to know and apply this set of files properly. A guide for this is the compatibility matrix for CUCM version of IOS. She is presented in the following web address:
http://www.cisco.com/en/US/docs/voice_ip_comm/cucme/requirements/guide/33matrix.htm.
kyrios
Monday, January 26, 2009
Need A Greeting For Church Welcome
Cisco has released an update to Cisco Unified Communications Manager 5.x and 6.x that fixes a security flaw that could allow an attacker remote cause a denial of service.
The Cisco Unified Communications solution is a suite of communications products and applications that collects and integrates voice, video and data.
Service Certificate Authority Proxy Function (CAPF) fails to properly handle malformed inputs, which could cause an interruption in voice services. The CAPF service is disabled by default.
Cisco through the usual channels, has made available to customers
solutions to solve the problem.
is advised to consult the table of vulnerable versions and countermeasures
:
More Information:
Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerability CAPF
http://www.cisco.com/warp/public/707/cisco-sa-20090121-cucmcapf.shtml
Source: www.
Sunday, January 25, 2009
Pitryriasis Rosea Scars Coco Butter
First you have to be very clear grounds for attacking a router.
attack a router:
- Make a denial of service attack (DoS) to the router and the network to which it belongs. Engage
- other through the routers. Forward
- network firewalls, IDS or other services.
- Monitor and record incoming or outgoing traffic on the network.
- Redirect network traffic to another point.
must also be clear philosophy work of a Cisco router. It is composed mainly of two memories which stores the data:
The reports are:
RAM:
memory is a persistent, meaning that what is stored in it is cleared at shutdown.
It stores:
- Active Configuration.
- PivotTables: ARP, Routing, NAT, ACL violations, statistics ...
Flash Memory:
is persistent, even turning off the computer, this memory is not erased.
In this report is stored:
- boot configuration.
- IOS system files.
To begin the analysis we have to take into account, based on data on the working philosophy of the router, a specific methodology, which consists of:
- not shut down or restart the router, obviously lose all data stored in RAM. Which are all important data for analysis without this data, the analysis does not make sense. Isolate
- network router, especially if the attack has already been done. Always careful not to disconnect the power. In some cases can be performed without isolation but after collecting information, to monitor if the activity continues. Sign
- for forensic analysis via the console port on the router and not through the network, because it would corrupt the scene. Recording the session
- complete analysis of the console log file.
- Run commands that display settings, but never run router configuration commands.
- After removing the volatile information, we can analyze the vulnerabilities of the router and scanning services through the network.
consider these recommendations, we turn to the commands that we have to use the console to remove the active configuration and pivot tables. The console session in which you run commands, should be recorded.
The commands are:
- show clock detail
- show version show running-config startup-
- show config show reload
- show ip route show ip arp show users
- show logging
- show ip interface show interfaces show tcp brief
- all
- show ip sockets
- show ip nat translations verbose
- show ip cache flow show ip cef
- show snmp user show snmp group
- show clock detail
We may also use an automated tool to collect this information, it is CREED (Cisco Router Evidence Extraction Disk). A self-bootable disk that runs a script to obtain this information by running these commands:
# terminal length 0
# dir / all
# show clock detail
# show ntp # show version
# show running-config
# show startup-config show reload
# # show ip route # show ip arp
# show
# show users
logging # show interfaces # show ip interfaces
# show access-lists
# show tcp brief all
# show ip sockets
# show ip nat translations verbose
# show ip cache flow
# show ip cef
# show snmp users
# show snmp groups
# show clock detail
# exit
After obtaining this information we will find vulnerabilities or services that have been able to compromise the security of the router.
use tools to analyze vulnerabilities as: Router Audit Tool (RAT) and Nipper.
To analyze service use: nmap, Torch Cisco, Cisco Snmp Tool ...
More information and downloads Torch Cisco, Cisco Snmp Tool and Router Audit Tool (RAT) in the post "Tools to secure Cisco devices"
More information and download of Nipper in the post "Cisco Security Audit"
Source: Guru computing
Saturday, January 24, 2009
Pokemon Shiny Gold Market
The server market will have a new member from the 2009. Cisco Systems will expand its marketing line in the coming months and will commence operations server development, whose main feature is the addition of a sophisticated scheme of virtualization software, reports the American newspaper The New York Times.
IBM, Hewlett Packard (HP) and Dell, three of the major server manufacturers in the world, which in turn reflected collaborative relationships with Cisco could fragment or limit its relations with the firm, According to the connotation expressed in the paper U.S., as the ad refers to the claims of the company enlarge their trade despite participating in unfamiliar areas.
should be noted that the decision to Cisco in the market penetration of servers, has been described as risky and daring by different analysts, because this sector has meant more profitable hub of the company, compared to computer network systems and wireless communication, dominating niches very well, mean remanence of about 40 billion dollars annually and 65 percent in fringe benefits. "We this not as a new market, but as a market transition, "the source said Padmasree Warrior, chief technology unit of Cisco Systems.
For its part, the hardware analyst, Brent Bracelin said "This is the most important and most talked about product of the year. There will be massive reactions from competitors such as IBM and HP, but we hope that this will open the way for industry consolidation. "
exploit the computing sector virtualization
Over the past few years, companies that manufacture computers and servers, have adopted the technology virtualization software to save energy in their devices, enhancing the performance of the units themselves and finally catapult your sales. The same newspaper article from New York, notes that this technology will be the main feature of Cisco servers, however, stressed that the networking and virtualization as the supply of Cisco, both taking the company's technology and signature VMware specializing in the development of virtualization software.
Source: electronicosonline.com
Ice Skating Party Invite
- MPLS Fundamentals: A Comprehensive Introduction to MPLS Theory and Practice. Luc De Ghein. Cisco Press.
- Advanced MPLS Design and Implementation. Vivek Alwayn. Cisco Press.
MPLS technology ( RFC 3031) is an IETF open standard technology that basically fits " tag switching, Cisco's proprietary system and stressed against the IP Switching, similar technology proposed by Ipsilon Networks but restricted to the ATM architecture.
is a technology for transporting data at MAN and WAN network belonging to the family of technologies based on packet switching. It also provides a shuttle service oriented data access through the creation of virtual circuits, prior to transport information. A level OSI model of communications is located between the link level and network level, so we can talk about a fictional level 2.5. The core of this technology is that packet forwarding is done based on some labels that are included in the protocol header. These labels are changing jump to jump and define a path (LSP) has been calculated in advance by the network nodes based on predefined criteria called FEC (ie traffic destined for a network with a range of requirements of high service quality). Note the difference with traditional IP transport, in which the control plane and data plane are intertwined. The tags define the way and are distributed based on a protocol for the exchange of labels ( LDP, RSVP-TE , MP-BGP, etc.).
MPLS technology is being adopted by most Internet service providers (ISP) allowing them to reduce costs in the operation of the network and offer their customers SLAs with QoS real commitments , which is becoming a real need with the introduction of the VoIP business. The reduction in operating costs is because MPLS allows multiple services to offer virtually transport (Ethernet, ATM, FR, HDLC, PPP, etc.) With a single network, so it is no longer necessary to maintain and configure equipment different networks, with a corresponding reduction in specialist staff involved. This feature of MPLS is known for AToM (Any Transport Over MPLS). However, at present its peak comes from the hand of another service, virtual private network (VPN) and security will be in the service in which the input focus.
Some terms that are central to understanding what will be listed below. Each contains a hyperlink to the definition.
- PE router (Provider Edge Router) or E-LSR (Label Switching Edge Router) Router
- P (Provider Router) or LSR (Label Switching Router)
- Label Switched Path (LSP )
- Forwarding Equivalent Class (FEC) Virtual
- Routing and Forwarding Instance (VRF)
- Route distinguised (RD)
Before discussing the security of virtual private networks based on MPLS technology is essential to have a high-level view of how to provide this service .
Each PE router can be connected to multiple CE routers within the same or different clients. The CE routers are those that interact directly with level three PE routers of the ISP, which give access to the MPLS network. Are therefore non-existence of an MPLS network and do not understand labels, LSP, LDP, VRF, etc. Each PE router maintains a separate routing table for each VPN also of global. That is, if a PE supports the delegations of two different companies keep two separate routing tables, one for each company and the global routing table in which routes are kept inside the MPLS core itself. PE router interface that connects to an EC must have an IP address within the address range of the VPN to which it belongs CE, so that the ISP involved in directing the company to which it serves. This lack of transparency is probably the only disadvantage of MPLS VPN service. Following the explanation, each CE propagates routes (reachability information) from its routing table into the PE (either by IGP or through eBGP) and this in turn propagates to the EC routes that come from other PE, reported in turn by its EC neighbors. Communication PE-PE routing requires a more detailed explanation. This is done by as iBGP routes are exchanged all the VPNs to which the ISP serves. Since two different companies belonging to VPN can opt for the same private address space, you need to find a mechanism to distinguish. This is the goal of RD, which is nothing more than an extension of BGP, which is used when it propagates the routes between PE routers. It is important to note that the P routers, which form the core MPLS network, do not participate in the exchange of VPN routes. These only run one IGP routing protocol among themselves and with the PE to exchange reachability information of the MPLS core, information to be used to distribute labels that allow the forwarding of packets within the core (see below).
Now that we know how to build the routing tables, need to know how to propagate different VPN packets across the network. When a packet arrives at a PE from a CE with a host destination is in a remote delegation, is encapsulated with the corresponding MPLS header. This header also includes two nested MPLS cloud, the deepest identifies the VPN to which it belongs the outer package and allows the network to perform MPLS forwarding the packet to the destination PE. Once the packet arrives at PE right, it removes the outer label and the label is set deeper, which tells which VPN the packet belongs, and hence what interface (and therefore to what CE) to forward the packet. Finally, the EC partner is responsible for getting the package to the destination host. Completed
and this "brief" introduction to MPLS technology we are able to analyze the fundamentals of security VPN service. Assuming we do not have access to equipment MPLS core network (routers PE and P), and from the point of view of an attacker, what more we could be interesting is to see from a VPN to what we do have access (eg, are employees of a company that has contracted a service-based VPN MPLS) can either intercept the traffic and access to computers belonging to another VPN, or build a denial of service to other VPN.
As can be inferred from the explanations above, if the attacker whether in a branch office located within a particular VPN, when you want to access another delegation just see that your traffic is a route that passes IP at least four different jumps (EC-PE-PE-CE), the first jump the default GW. This default GW is actually the EC of its delegation which communicates with a virtual router, known as VRF MPLS terminology, and that is just the route table associated with the VPN and packet forwarding instance associated . As we know, both are included in the PE router.
Thus, the first option that can happen to us to try to access a different VPN would send packets encapsulated with a MPLS header which in turn will incorporate appropriate tags. These labels, because they are not known a priori, could be determined through trial and error. Thus, if we were not interested in a specific target but indiscriminately reach other VPN client ISP, could serve perfectly. However, the RFC states that when you get a MPLS packet through an interface associated with a CE, it is discarded automatically. Enno Rey, in a presentation made at the Blackhat a couple of years ago, said he had checked with Cisco routers and in all cases was verified compliance with the RFC.
Another possible attack would take an incorrect implementation of the connections to CE-PE level. Imagine for a moment that two CE belonging to different VPNs are connected to respective virtual interfaces that are actually the same physical interface. Suppose further that the links from the PE focus on a switch before connecting against PE using VLAN technology . Could not make an attack on the VLANs (for example with Yersinia ) if you commit the CE router in order to finish accessing the VPN client from another ISP? In these cases it is best to implement separate physical links PE-CE.
also desirable that the interfaces of PE routers that connect to incorporate EC ACLs that only allow traffic routing. Any additional services could be exploited by an attacker to gain access to the PE router (remote login, tft for loading configurations, etc.).
regard to denial of service, what better way to let a delegation alone knock out the EP that lets you communicate with other delegations. How to do it, then taking advantage of the only service that should be accessible, some dynamic routing protocol that runs between our EC and EP. Imagine that flooded the EP with a number of routes invented and that change every few minutes. If the router is not configured properly, we will flood your memory and bring the CPU to 100% leaving it unusable for the rest of VPNs to which they served.
Source: http://blog.s21sec.com
Kate Playground Access
Let's finish up the infrastructure WPA, for which we will start implementing our RADIUS server. For an organization to have a RADIUS server is not only a secure solution for wireless connections is also an important element in the authentication of VPN connections, both between remote sites to customers or to the solutions we come up NAP (Network Access Protection) and will soon be implemented in all companies.
If the RADIUS server implementation is something few users or not you want to deploy a dedicated server, you can easily purchase routers and / or Wireless Access Points, including within its firmware, small system RADIUS servers with EAP-MD5 authentication in most cases. Obviously this is a bit scalable solution because, first, forces us to replicate the user database in the firmware and also in the case that we have 2 or more Access Point we have to duplicate these users at all the AP or link them to think.
We will implement the solution as a RADIUS server for Microsoft, Internet Authentication Service (IAS). This is that in Windows 2000 Server is provided as a separate download but is a service that comes "standard" in Windows Server 2003 and installed like any other, with the option Control Panel Add / Remove Programs. This is a network component so that IAS should be selected within them.
Once installed you have to register the RADIUS server in Active Directory of our organization, and for that three options, the easy, from the management console IAS MMC , highlight your IAS server and choose the option "Regristrar Active Directory" (Figure 2), the craft: At the end, doing so through the console only is adding the machine account to certain privileged groups, so that we can do it manually and add the machine account of our IAS server to the security group RAS and IAS in Active Directory, and commands: You can also use the same process using the netsh command from the command line.
Once registered we can proceed to configure your IAS server. Three simple steps. First configure the logging of connections, both the correct and the failed to get an idea of \u200b\u200bwhat is happening with our network. This is a simple operation to detect intrusion attempts or connections "unusual" customer.
Second set up a Remote Access Policy, ie, who will be able to connect remotely, or what is the same in our environment, who will be able to make a wireless connection. To complete the server configuration we are going to be establishing the connection options, ie we require mechanisms to authenticate users.
Remote Access Policy
With IAS we can create remote access policies for all types of connections, VPN Client, Wireless Client, and even for network clients, which is what NAP is based. In this case we will create a Remote Access Policy for our customers and we Wireless create it by following the wizard. Select the option for Remote Access Policy and began:
After entering the name of the policy dialogue box we got to where we are required to type Remote Access Policy that we are creating, as you can see in the image we have policies for VPN connections, dial calls Dial-up telephone lines point to point for wireless connections and even for ethernet connections, which will be used NAP. Select the Wireless option, of course, and continue forward.
As we wish to integrate the security of connections within the infrastructure of our company, we create ourselves in our Active Directory user group in this case called "Bad" (pardon the pun), which will let users authorize the Remote Access Policy. It is necessary that users have permission to dial, as for the VPN connection or Dial-Up, as is the permission that is used for remote connections. As this is a bit cumbersome, selecting all the users and give them that permission, you can use an option Once created the policy with the wizard, on the properties to ignore and that permission be granted from IAS directly dial permission if you are the Remote Access Policy.
The authorization can be both user and machine level so we could make a double authentication, ie, authorized users and machines authorized. Once elected
user group must choose the authentication system. The two options to choose from.
Option 1: PEAP (Protected EAP), which as we saw last month generated using a TLS channel with server certificate, in this case the IAS server, then choose an authentication method the client will either password, sent by the MS-CHAP v2 protocol, or be used directly to a digital certificate thereof which tend on the client machine or a smartcard.
Option 2: Do not have canal TLS EAP authentication before, so we use a smart card based authentication and digital certificate installed on the client machine.
These options have finished creating the Remote Access Policy for our example. Note that you can create remote access policies so as we wish. These policies are to be evaluated as firewalls fewer higher order and applied the first match. Thus, we have authenticated connections from machines, or valid connections from any machine for some users, or connections are authenticated with passwords for devices that do not support smartcard, etc ... a need for infrastructure.
policy we, entering their properties, define some specific values \u200b\u200bof it, as if time slot for the connection, time limits, IP address allocation, etc ... to further refine policy options.
Connection Request Policy
Okay, we have created the policy for our wireless customers, which will be authenticated or not our RADIUS server, now we have to configure the structure of authentication requests within our RADIUS servers . To do this we create a Connection Request Policy, ie which is the order of validation of the connections in the case we have a complex infrastructure.
default policy is created determines that the RADIUS server authenticate connections that originate directly or through a VPN connection using the database in Active Directory. Authentication If the RADIUS server or give another if the requests come through an ISP or any other parameter you want to check the connection, such as phone numbers on a dial-up or wireless card manufacturer we can create new connection policies. For our example, the default policy is perfect. High
RADIUS Client
We have defined Remote Access Policy and the Connection Request Policy, we set the trail and have the IAS server registered in Active Directory, what's left? For only discharging Acess points and / or Wireless Routers that can make requests to our server to authenticate clients. To do this in the RADIUS Clients create a new one.
RADIUS Client
first thing we request is the name we are going to give the access point and what is the DNS name or IP address from which it is accessible to our IAS server. Second, we must choose the type of RADIUS client is because although there is a standard, many manufacturers have made small changes on it in the form of communication.
Finally, most importantly, the shared secret between our RADIUS server and client. Is the mutual authentication is used. We might think that is an unsafe, since the shared key is not the best of ways of authenticating connections, but it is assumed that the physical connection between the client and the RADIUS server is a private and secured.
When we finish this wizard, and registered as a RADIUS client to our AP, but the communication will not operate until a symmetrical manner to give high point in our RADIUS server Access or Wireless Router.
IAS RADIUS
To register to the RADIUS server must enter the administration tool in our Wireless Access Point and set the RADIUS server's IP address, port , which by default is 1812 and the shared secret. And it would be.
Client Configuration
To end the connection in the infrastructure we create the connection from the client, so it went into the options and give your network card Register a new wireless network. We discharged the same SSID, select the option of WPA and TKIP encryption. We spent the second part of authentication where you can select "PEAP" or "Digital Certificate or Smartcard."
Customer must realize that if we can use to authenticate using PEAP MS Chap v2 password or digital certificate or smartcard, while if we use digital certificate or smartcard can not use password. In both cases we choose the certification that we are using to validate all digital certificates for server and client, so you can see in the properties of both configurations.
On the left is that we have used Digital Certificate or Smartcard and how we choose which will be our certificate and who is the certification that validates them. To the right is seen as an entity used to validate the server certificate to create the TLS tunnel and like then we can choose the way to authenticate with EAP-MSCHAP v2 or EAP-TLS.
802.11i WPA2 (Wi-Fi Protected Access 2)
WPA was born without a standard to support it in its origins, but taking into account what would be the 802.11i standard that would improve the WEP-based solutions. For this purpose, drafts and the information was obtained for WPA evolve. When they had a clear idea of \u200b\u200bwhat appeared would be 802.11i WPA2. What are the differences between WPA and WPA2? The answer should be said is that few and many. Much as long as it is based on the 802.11i standard that if a little change and if we consider that WPA was already focused on that destination. The main novelty is the system that includes AES encryption.
AES (Advanced Encryption Standard) AES
born as an initiative of the American government to replace DES as the encryption system. AES algorithm had a name before and was looking through a "mega-competition" worldwide algorithm which should be used. Rijndael was selected at the end is so named because of the curious mixture of the names of the two creators. From a technical standpoint, AES is the option we should use encryption with WPA2, but the use of AES involves the use of various encryption algorithms below. Actually, the algorithm is called 802.11i RSN (Robust Security Network) is a system that negotiates the encryption algorithm and authentication between the options supported and configured on client and server. RSN use permits you to negotiate with backward compatibility in the case of being necessary to live with devices that do not support AES and TKIP or WEP used as phones, PDAs, or older operating systems. RSN supports WEP-104 WEP, TKIP, WRAP and CCMP implementations are AES block cipher and stream cipher. Is not it all very sencillito?
business infrastructure
To mount a solution of this kind can not lie in the assembly manual that we used in these examples, but we rely on the utilities offered by the Active Directory. First, for the implementation of this infrastructure we have assumed that we had made a display of user and machine certificates within our organization. That is, PKI is the underlying infrastructure. Second, we have made configurations of the connections of individual customers, but this can be automated with policies.
This policy created a new organizational unit of the machine you want configured to use wireless connections and within settings machine level we created a new Wireless Connection Policy. Once we set the properties to establish what are the options for the wireless connection we want to create in customers. Here we must configure the same options we have seen in creating a connection from the client: SSID, Authentication, Encryption, and after authentication options.
Other options of securing a wireless network
Yes, there are other options for securing wireless networks and businesses have been using basically two approaches based on the same: Authenticating connections.
To authenticate connections can use a different entry point to the wireless device, ie, instead of authenticating to the Access Point, you can let it connect to but after the AP you want we will find the company network will not allow connections that do not come from an authenticated client. And how clients authenticate valid?
Option 1: With VPN connections. Clients connect to the AP and from that connection is authenticated to the VPN server. Once the VPN server has been established that a client is valid and may be imposed on the network.
Option 2: Using digital certificates and IPSec. If the organization's network is deployed with IPSec communications, you can only communicate over the network connecting the client who has a digital certificate. This option is less desirable because communications unencrypted if that can be captured by an intruder and can even get information that is not desirable.
Farewell and Close
three months have been talking about how to secure a wireless network and because you have to do it, so you have no excuse. Secures your network for three reasons.
1) There is technology to do so.
2) It is difficult and you know it.
3) Always thinking of someone boring like "fun."
Author: Chema Alonso. Microsoft MVP Windows Security
Friday, January 23, 2009
Die Sims 3 Electro Songs
Risk Despite this people still think that there are too many risks, so this month, we will see who can make a hacker with a wireless network outside. Parasite
the style of Venom, the alien costume of Spiderman, many of the wireless networks of today have to / s parasites living with them, that is, that or those neighbors who gladly save a few euros use based on your connection. Usually the least of the problems and also the most uncomfortable, like having a chronic ailment in our Internet connection. Running
crimes
In this country there are different research groups within crimes telematics bodies security. These bodies are responsible for pursuing the intrusions of black hat hackers, or defacements (graffiti web page) of crackers or denial of service (DOS = Denial Of Service) or "dose" of the crashers, or ... .. Its mission is to find evidence which may have been the source of the attack and it is looking for the attacker's IP address. If the hacker has used techniques based anonymous proxy network anonymous TOR (The Onion Routing), the IP addresses of exotic countries will impede the investigation easily follow safety equipment, but ... anonymity these techniques are often slow, the easiest way is to get off the park, enjoy the good weather and use the IP address of wireless router unprotected turn. When the Police and / or the Civil Guard come home from the neighbor and seal the computer will be explained. Can you imagine coming to your house to precintaros the computer for something that never done? Then from there a forensic analysis is performed offline with a tool such Encase and ... Maybe include, for silly things that should not or ... well, I'm going, keep going.
Information Access
When you're on your wireless network, the connection works as a hub, then all the communications issued, if they are in radio visibility of the signal may be captured by the attacker. Thus, they may be MSN Messenger conversations (which are not encrypted) file transfers are made by these little programs (photos, office documents, music, etc ...) and can even record your voice conversations over IP in mp3 files Ethereal programs (that records. au), orekaudio, the same Cain or vomit.
Identity Theft
If you are in your wireless network and can capture all traffic is made between your computer and the Access Point, then, if you connect to Hotmail, or a bank or e-mail your company or any site with credentials, the attacker can steal your passwords with programs like Cain, that comes with the complete suite for the cracking of them if they go encrypted.
Image: Stealing Passwords with Cain ", overloaded."
Okay, I guess this information will help you want securing wireless networks and as we saw in the first part, last month, the use of WEP is not acceptable, so we continue to see the alternatives.
WPA (Wireless Protected Access)
The Fi Alliance, in the period while approving the 802.11i standard that would replace WEP definitely proposed the use of the following security technologies that were already described in the draft would be the definitive standard. José Manuel Alarcón wrote in PCW number 232 of June this year an extensive article on WPA, so here we go a bit more direct.
WPA encryption
encryption system used in WPA change on WEP (RC4 with 64 keys and 128 bits) using TKIP (Temporal Key Integrity Protocol). TKIP still uses RC4 protocol, but in this case minimizing exposure to attack by using the following modifications.
- The Initialization Vector (IV) is too short in WEP, 24 bits. TKIP is used in 48-bit IVs. This, a priori only lengthen the process, but would still be valid the same type of attack.
- Data Integrity. WEP could be modified bits in the data and change the CRC32, ie could change. It uses a new protocol "Michael" MIC (Messatge Integrity Protocol) encryption is TKIP.
- WEP uses the primary key to encrypt and authenticate. TKIP generates a master key of 256 bits when the client authenticates which is called the Pairwise Master Key (PMK). PMK using more AP MAC address, MAC address of the Client and two random numbers were created for one another by the AP and client generated keys derived. In total 6 keys TKIP uses derivatives:
or Data Encryption Key: 128 bits and used to encrypt messages. Date
or Integrity Key: 128 bits and used in the MIC protocol to ensure the integrity (no change) of the message.
or EAPOL-Key Encryption Key: EAPOL messages are used to authenticate the connection, and when performing authentication processes using special keys.
or EAPOL-Key Integrity Key: Also key is used for MIC party authentication messages.
or Multicast Encryption Key: 128 bits to encrypt multicast data.
or Multicast Integrity Key: 128 bits to ensure the integrity of multicast messages.
- always use the same WEP key. TKIP is generated in a process of rekeying periodically to generate new temporary key.
- WEP is no protection Reinjection packages. That is, a packet can be captured and reinjected into the network, allowing for increased traffic. TKIP can not do this because it is used IV as the protection counter. Summarizing
TKIP TKIP
operation can be summarized as follows. When the client authenticates generates a master key (PMK) of 256 bits. From it, using the MAC address of the client, the AP and two random numbers generated by the client and the AP, 6 temporary keys are determined. These keys are used to encrypt and secure the data transmitted and also differentiates between data messages and authentication control. Each time a customer re-authenticate a new PMK is generated and periodically change the keys derived. Furthermore there is control of "replay" of packages using the IV which has increased from 24 to 48 bits. So here would be a stronghold of the WEP protocol, but also how to encrypt and decrypt has changed a bit.
Encryption Process
Step 1: With the IV, the destination address and the Data Encryption Key is generated using a blending algorithm Encryption Key Package (Per Packer Encryption Key).
Step 2: Using the destination address, source address, packet priority, the data to send and Data Integrity Key is calculated using Michael MIC algorithm.
Step 3: Calculate the ICV (Integrity Check Value from the CRC-32).
Step 4: With the IV and the packet encryption key is generated, with the keystream RC4 PRNG encryption is the same size as the data, the MIC and ICV.
Step 5: XOR is performed between the RC4 Keystream and data, MIC and ICV to produce the encrypted message.
Step 6: IV is added to the package.
The main difference is the use of a different key per packet, which is derived from a temporary key (which changes periodically) which in turn is derived from the Master Key, which changes with each authentication process.
Decryption Process
Step 1: IV and is extracted together with the Destination Address and the Data Encryption Key is generated packet encryption key.
Step 2: With the package encryption key and the IV is generated RC4
Keystream Step 3: XOR is made between the RC4 Keystream and the encrypted message to obtain the decrypted message.
Step 4: ICV is calculated and compared with it was in the package to accept or discard the packet.
Step 5: In the Destination Address, the Source Address, Data and Data Integrity Michael Key used to calculate the MIC.
Step 6: It compares the received MIC and the MIC calculated. If not equal the packet is discarded.
The decryption process, as you can see, is symmetrical encryption.
WPA authentication
Wireless To authenticate connections we have 2 distinct environments, home environment and business environment.
WPA-PSK
In a domestic environment we usually have only one access point (AP) and a number of clients. We do not use external servers so we will not deploy a complex infrastructure (or does she?). In this environment we use a solution based on shared key (Pre-Shared Key) to configure the clients and the Access Point.
Image: WPA on the AP
Choosing the Shared Key (PSK) should be as long and random as possible (not like we have in the capture of the screen). The PSK must be configured on the clients and used to authenticate connections and generate the master key. An attacker can, from an authentication package a client application brute force algorithm to obtain the PSK that will allow the user to authenticate, but not worth it to get the information that is transmitted to another customer and another client data will be encrypted by the temporary key and therefore would have to find the keys time to ascertain the per-packet key and decrypt the traffic. These temporary keys can be ascertained after the event and find out the traffic has been transmitted. If we use a random 63-character key time break by brute force makes such attacks infeasible. If instead the password is short, an attacker that captures the authentication package (handsake or greeting) could launch a dictionary attack or force the program AirCrack fruit.
Image: dictionary attack on WPA-PSK Aircrak
Client Configuration WPA-PSK
To configure WPA-PSK client on MS Windows XP is sufficient to configure the properties of a new wireless network by selecting WPA-PSK as an authenticated system, TKIP as encryption and shared key set for each customer:
Image: WPA PSK Customer
EAP (Extensible Authentication Protocol) EAP
born as an evolution of PPP (Point to Point Protocol) allowing us to negotiate the authentication between the client, also known Supplicant and Authentication Server. Unlike PPP, EAP is first established the connection, then negotiates the authentication method (EAP Method) between the Supplicant and the Authentication Server and finally granted access or denied the connection. This allows clients to be authenticated in different ways by the same server whenever and brother both agree on the authentication method. EAP allows different authentication methods but the most common are:
- EAP - MD5 - CHAP: In this method we use a challenge response with the encrypted password in MD5 CHAP mechanism. This mechanism is not often used in connection insecure (public network) and reserves and dedicated lines only for compatibility with older versions because CHAP has been violated.
- EAP-TLS: use as client credential a user certificate. So, anyone who wants to authenticate your password must not have but a digital certificate.
- Protected EAP (PEAP): With this method, prior to the EAP negotiation between the client or supplicant and the authentication server establishes a secure TLS channel, similar to that used in HTTPS, so it is necessary that our server has a certificate authentication server. Once established that channel will proceed to the EAP session, which may be:
or PEAP-MSCHAP v2: As in the previous method first establishes a TLS channel between the Supplicant and the Authentication Server and then start a session challenge MS CHAPv2 response to authenticate the client.
or PEAP-TLS: Again this is a method that uses TLS secure channel before sending the credentials of the supplicant. In this case, the credential that the client will present a digital certificate. In this method we must use a server certificate to establish TLS channel EAP pre-session and then a digital certificate for the client to authenticate.
These are methods that can be used to authenticate our connections to each of us to choose we must establish appropriate mechanisms, so if we use EAP-TLS to install a digital certificate on each of the petitioners to authenticate, if we use PEAP-MSCHAPv2 have to have a digital certificate on the authentication server and you use PEAP-TLS will require digital certificates for all participants of the communication.
RADIUS server (Remote Authentication Dial-In User Service)
RADIUS is a protocol authentication has become an industry standard to validate users through different methods. Transactions in each of the communications between the client and server are encrypted using a shared key. This shared key is never sent over the network and each request for authentication between a RADIUS client and RADIUS server must be encrypted with this shared key.
When we want to establish a Wireless client authentication to a RADIUS client network will be the Access Point and RADIUS server containing the database of clients that can connect. To this end, the Access Point we set:
- The IP address
RADIUS server - RADIUS server port, usually 1812.
- The Shared Key.
Image: RADIUS Server Settings in the AP
The RADIUS server will set the shared key for each customer that can make a RADIUS request. In the next month will finish installing the infrastructure and see how to configure Microsoft Internet Authentication Server server (MS IAS), which is the Microsoft RADIUS server. 802.1x
To use the Wireless connection PAD system is necessary to use a protocol to encapsulate traffic from the wireless connection to the authentication server. In a community will have an authentication server, which will set policy on what may or may not connect supplication to the organization, and that will be within a protected area of \u200b\u200bour network. Wireless Access Point will have direct connection to the authentication server and which require a process of authentication for a particular supplicant. 802.1x born as a way to allow any element of the network (switches, APs, ....) Demand an authentication process for a connection that has just taken place. 802.1x uses EAPOL (EAP Over LAN) because what is going to make is an encapsulation EAP protocol on the private network to reach the Authentication Server. Thus, as shown in the chart, the process is as follows:
Step 1: A client is associated with the AP using the 802.11 protocol
Step 2: The supplicant starts the 802.1X authentication process because the AP does not grant access to the network and choose the EAP-Method.
Step 3: Authenticator to the Supplicant identity requires
Step 4: Identity delivers Supplicant to Authenticator which will broadcast the Authentication Server. As you can see, the Authentication Server is a RADIUS server to request credentials for that identity to Autentcador.
Step 5: Credentials requests Authenticator the supplicant. Pado
6: Supplicant Authenticator delivers credentials to be relayed to the authentication server (RADIUS server)
Step 7: RADIUS server validates the credentials and accepts the connection.
Step 6: The Authenticator accept delivery after the EAPOL-Key connection is not just a sequence of bits to use as a master key in the process of encryption algorithm TKIP. Thus, whenever we have an authentication process or re-authentication generates a new Master Key.
Image: EAPOL Authentication
Rochester Brazilian Wax
Frame Relay is a technology data transmission and voice, high-speed packet switching. Notable for its low cost compared to leased lines.
is classified as a non-broadcast multi-access network (NBMA), ie does not send broadcast packets. Comes from X.25 and inherits many of its features.
Frame Relay provides a switched network to different clients at the same time, but is based on that they never need to transmit data constantly. FR works by providing a portion of bandwidth to each user, allowing even exceed their guaranteed bandwidth if resources are available. FR
When hiring, we hired a bandwidth or average since and can transmit data. This is known as Committed Information Rate (CIR). is possible to overcome the CIR, but then the data is sent as a "best effort" and discard frames in case of congestion.
encapsulation types
There are two types: Cisco and IETP (Internet Engineering Task Force). When connecting equipment other than Cisco will have to opt for the latter.
Virtual Circuits
Frame Relay operates using virtual circuits that connect two DTE devices, making it appear that are connected through a circuit, when in fact do so by a large shared infrastructure.
There are two types of virtual circuits:
- Permanent Virtual Circuit (PVC) : they are the most common. Are permanent because they create mappings between transmission equipment for repeated use. Eliminate the need for establishment and release of the connection. Switched
- Virtual Circuit (SVC) . are generated dynamically for each connection, and removed when done.
PVCs are identified by a DTE Data Link Connection Identifiers or DLCIs. These interfaces are used in to distinguish between different virtual circuits. Inverse ARP allows us to map DLCIs to IP addresses, ie translates addresses from level 2 to level 3, the reverse ARP.
The DLCIs are considered locally significant. When a router1 want to send a frame to Router2, uses IARP or manual mapping to translate the DLCI to an IP address. Then sends the frame with DLCI in the header of the RF. The RF switch supplier receives it, and use the port corresponding to the DLCI. It is significant that locally, between him and the next switch.
Local Management Interface LMI
is a standard used between the router and the first RF switch. Can transmit information, the virtual circuit state. Communicates information about:
- keepalive: checked that need to stream data.
- Multicasting: extension that allows you to distribute routing information protocol and ARP over Frame Relay network (use reserved for multicast DLCI). Addressing global
- : provides global significance to DLCIs (unique address on the WAN). This causes it to behave like a LAN.
- virtual circuit state: allows packets to be sent through a circuit nonexistent.
There are three types of messages LMI: Cisco, ANSI and Q.933A.
congestion control
The switch notifies the DTE FR congestion problems. There are three bits with a different meaning:
- Discard Eligibility (DE): when transmitting packets beyond the CIR of a PVC, any package can be discarded if congestion occurs. The excess bits are marked with the assets in the head and the FR switch will discard if the network is congested.
- Forward Explicit Congestion Notification (FECN): FR when the switch detects congestion in the network, activates the FECN bit in the header of FR and the destination DTE knows that the road was congested.
- Backward Explicit Congestion Notification (BECN): when the switch detects congestion in the network enables the BECN in a frame for the home router. So notice that there is congestion.
Subinterfaces
is possible to have multiple virtual circuits for a single interface and treat each one as different interfaces, using the concept of subinterface. Logical interfaces are treated as defined by the IOS.
Several subinterfaces will share a hardware interface, and configuration level will operate as if they were physically different (multiplexing). There are two types:
- Point-to-point: virtual circuit connects one router another. Each pair of routers is point to point on its own subnet and each point to point subinterface has a single DLCI. Multipoint
- : using a single multipoint subinterface to establish multiple PVC connections to multiple physical interfaces or subinterfaces on remote routers. All interfaces involved are on the same subnet.
Thursday, January 22, 2009
Blue Eyes And Darkhair On Men
Cisco has released an update to Cisco Security Manager 3.x fixes a security flaw that could allow an attacker unauthenticated remote could bypass certain security restrictions.
When Cisco Security Manager is used with Cisco IPS Event Viewer (IEV) could open certain TCP ports in the Cisco Security Manager server and IEV client, which could be used by a remote attacker to login as root IEV MySQL database and its server.
Cisco, through the usual channels, has provided its customers with solutions to solve the problem.
is advised to consult the table of vulnerable versions and countermeasures:
http://www.cisco.com/warp/public/707/cisco-sa-20090121-csm.shtml
More Information:
Cisco Security Advisory: Cisco Security Manager Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20090121-csm.shtml
Source: www.hispasec.com
What Kind Of Weave Does Lala Where
Attacking Wireless networks have long since become a sport, a diversion or a hobby. In almost all the media have written articles on how to hack wireless networks (I myself wrote an article about this same almost 2 years ago) and even in the Microsoft Security Days 2005 and the tour went Technet Security giving demonstrations of how easily you can make an attack on a wireless network.
However, it is still common wireless network attacks to succeed. Why is this happening? Justifications such as Who is going to attack me? Or if I have nothing important, I do not use my network that often reflect a lack of knowledge of risk or a problem of technical knowledge of how you can secure a wireless network. Let's do a quick review of the security technologies Wireless networks and seeing the risks of each one of them to choose a good option when protecting our network.
Wireless Technology
Any connection to make wireless LAN is considered, but we will focus on the WLAN, or Wireless Local Area Network. Wireless networks can be of two types, Ad-hoc, which would be a network between two computers same network (peer) or Infrastructure, which simulate a network connection based on a hub or hub connections. This is important because it mediates the types of attacks can be performed.
standards governing these technologies are the 802.11 and the first that reached the public were the 802.11b and 802.11g standards that allow data rates from 11 Mb / s to 108 Mb / s. From 2004, working on the 802.11n standard that will allow deployments of up to 500 Mb / s and is expected to be published later this year or early 2007. Surprisingly, as happened with the pending 802.11i (we'll talk about it a little later) is already ahead of the market and are available for purchase 802.11n devices are designed according to the information in the draft [1] standard was approved. To complete some of the "letters" that can be found in standards, there 802.11e version, designed for streaming video and audio in real time using quality of service protocols.
Okay, so far about "letters" that mark some features of the connections, but not security. Let's move on.
Defining a WLan
The first thing to define is the name of our WLAN network, and for that brief definitions to clarify:
- BSS (Basic Service Set). It refers to a set of machines belonging to the same wireless network and share a common point of access to the wireless network (AP)
- BSSID (Basic Service Set Identifier): The identifier that is used to refer to a BSS. Has the MAC address structure and generally all manufacturers use the MAC address of AP. This is important because attackers find this value to identify the clients on the network. To do this, attackers look for in network communications that machines are connecting to the AP.
- ESS (Extended Service Set). BSS is a set of forming a network, usually will be a complete WLAN.
- SSID (Service Set Identifier): The name of the WLAN, understandable to the user, which we configure: mi_wlan, escrufi or wlan1.
- ESSID (Extender Set Service Identifier): The ESS ID is transparent to the user and carries information the SSID.
MAC Protection To prevent unwanted clients from connecting many AP offers options to create white lists of equipment that can be connected according to the MAC address of the customer. To this are added the AP machine directions we want to allow and ready.
This is not a security measure as it is fairly robust easy to jump to an attacker. Using any network analysis tool com wlan Netstumbler we discover the SSID, channel and frequency being used and the MAC of the AP.
Once you know the MAC of the AP to know the customer authorized Macs as easy as opening a Sniffer as AiroPeek network and see what addresses are communicated to the MAC of the AP. Those are the authorized MACs. Once you have the list of authorized addresses, because the attacker is configured with a valid MAC one of the many tools that are available for spoof (impersonate) addresses and will have already skipped this protection.
Conclusion: The MAC address filtering is not a good security protection, it's easy for an attacker to bypass this protection.
Authentication and Encryption Keys
64 and 128-bit WEP
The 802.11 standard defines a system for authentication and encryption of communications Wlan called WEP (Wireless Equivalent Privacy).
WEP uses a keyword that will be used to authenticate to WEP networks closed to encrypt messages and communication.
To generate the key, in many AP calls for a sentence and then after it generated 5 different keys to ensure the best chance in the election of the same, but others simply asked to be introduced with restrictions length that is configured and ready.
for encryption of each frame plus a changing sequence of bits, called Initialization Vector (IV), so they do not always use the same key for encryption and decryption. Thus, two identical messages will not generate the same result as the encryption key changes.
As you can see in the image, in this case we have an AP that can generate 5 key from a phrase or directly set a key. When we have 5 key, we check which is what we will use it only uses 1 WEP key to everything. As you can see we have selected a choice of 64-bit WEP key, of which 5 bytes (40 bits) are the key and the remaining 24 bits are the IV. That is, in normal communication would have 2 to 24 different encryption keys.
For 128-bit WEP we will have 13 fixed bytes (104 bytes) and 24-bit shifting (IV), ie we have the same number of keys but longer.
Encryption and Decryption Process
To understand the process of authentication in WLAN networks with WEP is necessary to explain in advance the process of encryption and decryption as it is used during the authentication process for a client.
The encryption process is as follows:
Step 1: Selection of the IV (24 bits). The standard does not require a specific formula.
Step 2: Joining the WEP key and IV to generate a sequence of 64 or 128 bits. This value is Keystream called RC4.
Step 3: It happens that sequence by an RC4 algorithm to generate an encrypted value of that particular key.
Step 4: It generates a value of integrity of the message to be transmitted (ICV) to verify that the message has been decoded correctly and is added to the bottom.
Step 5: Make a XOR between the message and the message generated keystream RC4 encryption.
Step 6: Add the encrypted message the IV used for the recipient is able to decrypt the message.
The decryption process is the reverse:
Step 1: read the message received IV
Step 2: paste the WEP key IV
Step 3: RC4 generates Keystream
Step 4: XOR ago between the encrypted message and the RC4 keystream and gets the message and the ICV.
Step 5: It checks the ICV to the message received. Process
Authentication When a client connects to a WLAN must be authenticated. This authentication can be opened, ie there is no measure of demand so that you can associate with the network, or closed, which will produce a process of recognition of a valid client.
Thus, WEP authentication uses a very simple idea. If you have the WEP key encryption will be able to give me back what you send. Thus, the client calls connect and the AP 128 generates a sequence of bytes that the client sends encryption. Cilento decodes that string of 128 bytes and returns it in another frame encrypted with another IV. For mutual authentication to the process is repeated in reverse, ie the AP sending the connection request to the client and repeated sending the encrypted string of 128 bytes from client to AP.
WEP Security Is it safe to use WEP then? For the truth is no. For years it was shown that could be broken, and today break a WEP is fairly trivial, and within minutes you get out the WEP key. The attacker only has to capture enough frames encrypted with the same IV, the WEP key is in all messages, so if they get enough messages encrypted with the same IV can make a mathematical interpolation and within seconds you get out the WEP key. To get enough messages encrypted with the same IV, the attacker can simply wait or generate many messages repeated through traffic injection tool. Today, for the attackers is very easy to break the WEP because there are free tools simple enough to circumvent the process carried out to break the WEP.
But even here in Spain, where a research group on the subject of Wireless security (http://hwagm.elhacker.net/) have developed GUI tools to be more Sencillito.
Once you have generated a sufficient capture file is passed through the cracker that will return the WEP key being used.
WLanDecrypter
A concrete specification WEP networks has occurred in Spain. A TV company Internet installed in their wireless networks to customers whenever they set as a value of type SSID: WLAN_XX.
These networks use a simple WEP key has been discovered. The key is made with the first letter of the brand of router used in case (Comtrend, Zyxel, Xavi) and MAC of the router's WAN interface. Also the name of the network is WLAN_XX where XX are the last two digits of the MAC address of WAN interface. Since each router has a partnership between the manufacturer of the wireless interface and WAN interface, since they are made in series and with the same parts, if we know the wireless MAC interface also know the first 3 pairs of hexadecimal digits the WAN MAC (corresponding to manufacturer).
In short, with a simple and capture a network message within a few seconds to break the WEP key for this type of network. Until companies change their policies.
Network Addressing
For an attacker to find the network address must be used in a WLAN that has been cast is also a trivial step:
- The network DHCP server, the attacker's computer will be configured automatically and you will not do anything. If you have supplanted MAC address of a client, the attacker can not use this IP address because it is already being used by another (because the DHCP server assigns addresses based on MAC addresses), but will be to see the range of addresses that can be used and gateway.
- The network has DHCP: Client connects to a valid IP address and by capturing the network with a sniffer (Wireshark, Ethereal, AiroPeek, ...). In a catch in traffic will quickly see which IP addresses are being used. To find the gateway will only have to find a connection between an internal team with an external IP. That message, necessarily have been sent to the gateway, then the MAC destination of that message is the MAC of the gateway. Just use the ARP to find the IP associated with that MAC.
802.11i, WPA and WPA2
Having seen, everyone knew he had to do something with the Wireless Network Security. The only solution that arose with this situation was to make VPN connections from the client to be connected to a WLAN to a server on the network to get encrypted connections, that is, treat the WLAN as an insecure network like the Internet and performing encryption and authentication over the mechanisms that give us servers VPN. The IEEE 802.11
announced a new safe version would be called 802.11i WLAN security protocols change of WLANs. As the approval process was long a standard and the market needed a quick fix, a group of companies, united under the organization set up Wi-Fi Alliance WPA (Wireless Protected Access) as a practical implementation of what would become the next standard 802.11 i.