Wireless LAN Design and Setup
Home
Book Chapter:
EMAIL THIS

Hacking for Dummies: Chapter 10 -- Wireless LANs

24 May 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

This excerpt is from Chapter 10 Wireless LANs from the book Hacking for Dummies written by Kevin Beaver and published by Wiley Publishing. You can download the entire chapter here for free.

Wireless local area networks (WLANs) -- specifically, the ones based on the IEEE 802.11 standard -- are increasingly being deployed into both business and home networks. Next to instant messaging and personal video recorders, WLANs are the neatest technology I've used in quite a while. Of course, with any new technology come security issues, and WLANs are no exception. In fact, the 802.11b wireless technology has been the poster child for weak security and network hack attacks for several years running.

WLANs offer a ton of business value, from convenience to reduced network deployment time. Whether your organization allows wireless network access or not, testing for WLAN security vulnerabilities is critical. In this chapter, I cover some common wireless network security vulnerabilities that you should test for. And I discuss some cheap and easy countermeasures you can implement to help ensure that WLANs are not more of a risk to your organization than they're worth.

Understanding the Implications of Wireless Network Vulnerabilities
WLANs are very susceptible to hacker attacks -- even more so than wired networks are. They have vulnerabilities that can allow a hacker to bring your network to its knees and allow your information to be gleaned right out of thin air. If a hacker comprises your WLAN, you can experience the following problems:

  • Loss of network access, including e-mail, Web, and other services that can cause business downtime
  • Loss of confidential information, including passwords, customer data, intellectual property, and more
  • Legal liabilities associated with unauthorized users

Most of the wireless vulnerabilities are in the 802.11 protocol and within wireless access points (APs) -- the central hublike devices that allow wireless clients to connect to the network. Wireless clients have some vulnerabilities as well.

Various fixes have come along in recent years to address these vulnerabilities, but most of these fixes have not been applied or are not enabled by default. You may also have employees installing rogue WLAN equipment on your network without your knowledge; this is the most serious threat to your wireless security and a difficult one to fight off. Even when WLANs are hardened and all the latest patches have been applied, you still may have some serious security problems, such as DoS and man-in-the-middle attacks (like you have on wired networks), that will likely be around for a while.

Download this chapter on WLANs for free.
Read another chapter from Hacking For Dummies on password security.
Read other book excerpts and reviews.



BROWSE BY TAG
Wireless Network Security: Setup and Tools,   Wireless LAN Design and Setup,   Enterprise Network Security,   Application and Platform Security,   Enterprise Vulnerability Management,   Vulnerability Risk Assessment,   Enterprise Data Protection,   Enterprise Data Governance,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Wireless LAN Design and Setup
Wireless network guidelines for PCI DSS compliance
Best Wireless Security Products
How to prevent wireless DoS attacks
Lesson 4 quiz: How to use wireless IPS
Wireless intrusion prevention systems: Overlay vs. embedded sensors
Rogue AP containment methods
How to monitor WLAN performance with WIPS
The role of VPN in an enterprise wireless network
Wireless AP placement basics
Lesson 3 quiz: Who goes there?
Wireless LAN Design and Setup Research

Vulnerability Risk Assessment
What patch management metrics does Project Quant use?
Screencast: How to launch an OpenVAS scan
Trusteer CEO criticizes Adobe, touts better patch deployments
Patch management study shows IT taking significant risks
Vulnerability mitigation study shows need for faster patching
Microsoft to issue security report card, new tool at Black Hat
Newest malware threats
Are Web application penetration tests still important?
PCI compliance requirement 6: Systems and applications
Cybercrime and threat management
Vulnerability Risk Assessment Research

Enterprise Data Governance
How to protect distributed information flows
Interpreting 'risk' in the Massachusetts data protection law
Creating an enterprise data protection framework
Analyst DLP study finds maturity, ranks top DLP vendors
Voltage, RSA spar over tokenization, data protection
Twitter gets condemned by CISOs at Forrester forum
PCI DSS compliance requirements: Ensuring data integrity
Trustwave acquires data loss prevention vendor Vericept
Data has become too distributed to secure, Forrester says
Cloud-based security services should start private

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
evil twin  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts