Hacking for Dummies: Chapter 10 -- Wireless LANs

Hacking for Dummies: Chapter 10 -- Wireless LANs

Written by Kevin Beaver; published by Wiley Publishing

This excerpt is from Chapter 10 Wireless LANs in Hacking for Dummies written by Kevin Beaver and published by Wiley Publishing. You can download the entire chapter here for free.

Wireless local area

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

networks (WLANs) -- specifically, the ones based on the IEEE 802.11 standard -- are increasingly being deployed into both business and home networks. Next to instant messaging and personal video recorders, WLANs are the neatest technology I've used in quite a while. Of course, with any new technology come security issues, and WLANs are no exception. In fact, the 802.11b wireless technology has been the poster child for weak security and network hack attacks for several years running.

WLANs offer a ton of business value, from convenience to reduced network deployment time. Whether your organization allows wireless network access or not, testing for WLAN security vulnerabilities is critical. In this chapter, I cover some common wireless network security vulnerabilities that you should test for. And I discuss some cheap and easy countermeasures you can implement to help ensure that WLANs are not more of a risk to your organization than they're worth.

Understanding the Implications of Wireless Network Vulnerabilities
WLANs are very susceptible to hacker attacks -- even more so than wired networks are. They have vulnerabilities that can allow a hacker to bring your network to its knees and allow your information to be gleaned right out of thin air. If a hacker comprises your WLAN, you can experience the following problems:

  • Loss of network access, including e-mail, Web, and other services that can cause business downtime
  • Loss of confidential information, including passwords, customer data, intellectual property, and more
  • Legal liabilities associated with unauthorized users

Most of the wireless vulnerabilities are in the 802.11 protocol and within wireless access points (APs) -- the central hublike devices that allow wireless clients to connect to the network. Wireless clients have some vulnerabilities as well.

Various fixes have come along in recent years to address these vulnerabilities, but most of these fixes have not been applied or are not enabled by default. You may also have employees installing rogue WLAN equipment on your network without your knowledge; this is the most serious threat to your wireless security and a difficult one to fight off. Even when WLANs are hardened and all the latest patches have been applied, you still may have some serious security problems, such as DoS and man-in-the-middle attacks (like you have on wired networks), that will likely be around for a while.

Download this chapter on WLANs for free.
Read another chapter from Hacking For Dummies on password security.

This was first published in May 2004

Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.