Showing posts with label Wireless. Show all posts
Showing posts with label Wireless. Show all posts

Wednesday, November 24, 2010

Finding the MAC address on wired and wireless network cards

The response of the Media Access Control Question

In recent weeks I have a lot 'of e-mails about Ethernet cards, both wired and wireless, and more specifically, about Media Access Control (MAC). I think the main reason that I have received many questions about Ethernet cards, and MAC addresses is people trying to own wireless home networks and their desire to use the MAC address filtering to secure. This type of filter in wireless networks can be configured toAllow or deny use of specific computers or connect to the wireless network based on the MAC.

My first thought was that of a single article on wireless Ethernet MAC addresses and write. After thinking, I decided to expand on this and to move some specific information about Ethernet cards and communication.

Different ways to find your MAC address and much more

There are several ways to Ethernet protocol and communication and information. Many Ethernet cardmanufacturer's proprietary software that can reveal this information, but behave differently depending on the manufacturer. So we'll use the Windows 2000 and XP "ipconfig" utility since this is available in most Windows operating systems.

First, go to "Start" -> "Run" and type "cmd" without quotes. Then press the Enter key. At the command prompt type "ipconfig / all", again without the quotes. In fact, just typing ipconfig without the '/ all will work, but it will onlyprovide summary information of network adapters. An example of what one might see by typing "ipconfig / all" command is below each said in green:

Fault Tolerant and High Availability Computer Systems

There are several ways to Ethernet protocol and communication and information. Many software vendors Ethernet card owners who can reveal this information, but behave differently depending on themanufacturer. So we'll use the Windows 2000 and XP "ipconfig" utility since this is available in most Windows operating systems.

First, go to "Start" -> "Run" and type "cmd" without quotes. Then press the Enter key. At the command prompt type "ipconfig / all", again without the quotes. In fact, just typing ipconfig without the '/ all will work, but provide only summary information of network adapters. An example of what one might see by typing"Ipconfig / all" command is as follows:

Output of "ipconfig / all" command

Windows IP Configuration

Host Name. . . . . . . . . . . . : Home Computer

This is the name of the computer, usually defined during the installation of Windows. However, it can be changed after installation.

Primary DNS Suffix.. . . . . . : Domain.com

If your computer has an active network, such as a Microsoft Windows domain this entry may contain the name ofdomain.

Node Type. . . . . . . . . . . . : Unknown

The node type can say unknown, or peer-to-peer, or in some cases "hybrid". It is an institution that has to do with Windows Internet Naming Services used in certain types of Windows domain networks.

IP Routing Enabled. . . . . . . . : No

This setting determines whether Windows XP or 2000 functions as an IP router. If you have two or more network cards you can configure the system to act as a router, forwarding communicationsrequests from one network to another. Windows 2000 can be configured to do this in a nice straight forward, Windows XP will need a change in the registry.

WINS Proxy Enabled. . . . . . . . : No

WINS Proxy is another institution that is linked to the "Node Type" we discussed earlier. It is not normally a required setting in a home or small office or the newer type of Microsoft Windows domains.

Ethernet adapter Wireless Network Connection 2:

If youover Ethernet (network) cards in your system, if I were in this laptop, you will have multiple listings. This is the second Ethernet card, a wireless Ethernet card inside.

Description. . . . . . . . . . . : Broadcom 802.11b / g WLAN

This is the description of the Ethernet card, usually the name / manufacturer and type of Ethernet card. In this case it is a Broadcom wireless Ethernet card built into my laptop.

Physical Address. . . . . . . . . :00-90-4B-F1-6E-4A

And here we have the MAC address. The MAC address is a 48-bit hexadecimal code and is suppose to be a completely unique address. It is 48 bits because each number or letter in hexadecimal represents 8 bits. Hexadecimal numbers range from 0,1,2,3,4,5,6,7,8,9, A, B, C, D, E, F. There are 6 alpha-numeric codes is 6 * 8 = 48 (bit). The first 3 codes identify the manufacturer of the card and the other codes are used to create a unique number. Theoretically there should never be acard with the same MAC address of a local network. However, there are some exceptions. There are software tools that allow you to change this code. In reality, this is a step some hackers take to attack other machines on a local network. I speak the local network because MAC addresses are not routable between network segments. By spoofing this address, you can impersonate another machine on the network. Traffic that was bound for the objective may be redirected to the hacker's computer. This isthe address is also possible to use a physical address or MAC address table before setting up wireless access point to support MAC address filtering to people.

DHCP enabled. . . . . . . . . . . : Yes

DHCP or Dynamic Host Control Protocol, if enabled means your computers IP address provided by a DHCP server on the network. The DHCP server can cable wireless access point / router DSL, cable modem or a network server. Although aDHCP server is enabled on the network, the computer operating system will automatically generate a random IP address within a predefined interval. This means you could network a group of interconnected, without having to manually assign the IP settings.

IP address. . . . . . . . . . . . : 192.168.0.117

This parameter allows your current IP address. The address above is what is called a "private" addresses. There are several classes of IP addressesare reserved for private use. This means that for the internal network, local or private home or office. Such addresses are not, or not, are routable on the Internet. The Internet routes called "valid" IP addresses. The cable / DSL router or cable modem has a valid IP address assigned to the "outside" of the network. The external interface of the phone or cable TV cable.

Subnet Mask. . . . . . . . . . . : 255.255.255.0

Subnet Mask is aspecial issue, or in a sense, the filter, which breaks your IP address, in this case a private IP address in certain areas. IP addresses and subnet mask can be a complicated issue and would require an entire article to be about.

Default Gateway. . . . . . . . . : 192.168.0.254

The default gateway IP addresses of the above, the IP address of the device that will route your request, such as when you try to browse a website on the Internet. It 's a bit complicatedthan that, but as a gateway or router traffic to different networks, the other private networks. At home or small office, this gateway most likely is your cable modem / DSL or router.

DHCP Server ... . . . . . . . . : 192.168.0.49

The DHCP server, remember we talked a bit 'above, the device indicates that the computer has an IP address and other information. DHCP server can assign all kinds of information, including: StandardGateway, DNS (Domain Name), IP address, Subnet Mask, Time Server, and more.

DNS Server ... . . . . . . . . : 192.168.0.49, 64.105.197.58

The DNS servers are internal or external, to fully resolve the names (FQDN), such as http://www.defendingthenet.com full domain of IP addresses. This is because computers are not really about your request using the domain, use the IP address assigned to the FQDN. For mosthome or small office, DNS server IP address from your primary Cable / DSL Router. The Cable / DSL Router to ask an external DNS server on the Internet to perform address the effective resolution of the FQDN to IP. The address 192.168.0.49 is an internal private device on my network that 64.105.197.58 is an external public Internet DNS server and is available in case my router has difficulty performing the DNSResolution tasks.

Lease obtained. . . . . . . . . . : Sunday, March 19, 2006 18:38:16

This information tells you when the computer received its IP address and other information from a DHCP server. You will notice that says "Lease obtained", it is because most of the DHCP server just give the IP address lease from a pool of addresses available. For example, the pool may be 192.168.1.1 through 192.168.1.50. So your DHCP server has 50 IP addresses to choose from whenassigning the IP address of your computer.

Lease expires. . . . . . . . . . : Wednesday, March 29, 2006 21:38:16

If the IP address assigned by the DHCP server will attempt to lease expiring lease is the same or a different IP address. This can usually be changed on the DHCP server. For example, on some fully functional DHCP server, you can never rent due within one day and so on.

Why are so MAC addressesImportant and how they work

To jump back into the MAC address for just a bit '. You might think that IP addresses are the most important thing when it comes to network communication. The reality is, MAC addresses are very important because without them computers would not be able to communicate over Ethernet networks. When a computer wants to talk to another computer on a local network, broadcasts a query, or ask a question, who owns a particular IP address. For example,The computer can say, "Who is 192.168.0.254". Using the information above, my default gateway is 192.168.0.254 and say "I am" 00-90-4B-F1-6E-4A "192.168.0.254". You send the MAC address. That the MAC address then in what is called a (ARP) Address Resolution Protocol table on your computer. You can use this information to the command prompt like you did above and typing "arp-a". You can obtain information such as the following:

Internet Address Physical AddressType

192.168.0.49 00-12-17-5C-A2-27 dynamic

192.168.0.109 00-12-17-5C-A2-27 dynamic

192.168.0.112 00-0C-76-93-94-b2 dynamic

192.168.0.254 00-0E-2E-2e-15-61 dynamic

How can a hacker use MAC addresses in an attack

You will notice that the IP addresses and the right of their MAC addresses. Without this information, without the MAC address, it would not be reading this right now. MAC addresses are not routable, such as IP addresses. They work on localor private network. However, the devices on the Internet, to perform the same tasks. Routers and switches keep a list of their colleagues MAC address devices such as computers and devices on your home or office network. I mentioned that MAC addresses can be modified to meet demand. For example, if I'm on your corporate network and you had an internal Web server that took personal information as input, I could tell the computer to my laptop for the websitebroadcasting my MAC address with the real web server IP address. I would do if the computer asks, "Who is the" Real Web Server ". I could set up a fake web server that looks just like the real thing, and start gathering information that the real web servers normally collect. You can see how it can be dangerous.

Conclusion

There are many other simple ways to protect your MAC address, but can be a bit 'of confusion if you have more than oneinternal network. Most external USB or PCMCIA wired and wireless Ethernet cards have their MAC address printed on them. Where the wired or wireless network adapter in your computer, such as in laptops, the MAC address is sometimes printed on the bottom of the laptop. Even Desktop systems cards that are inserted in PCI slots have the MAC address printed on the Ethernet card.

You can print or publish this article free of charge as long as the bylines areincluded.

Original URL (the web version of this article)

http://www.defendingthenet.com/NewsLetters/FindingYourMACAddressOnWiredAndWirelessNetworkCards.htm

Friends Link : Network Tools Store. LOWER Prices

Sunday, October 24, 2010

The dangers of leaving your unsecured wireless network

If the search for wireless networks in a busy city where you would be surprised at how many unsecured networks, see, many people are not aware of the dangers, but I would like these sketches.

Why I am referring to a unsecured wireless network that is accessible without the need for a network key, even if WEP is terribly insecure I will not even cover its weaknesses in this article. Provide an attacker in a series that can connect to unsecuredwireless network and the local network infrastructure. Ok, so now what? The attack would have a scan on the IP subnet to determine what is currently connected to the network. At this point the attacker can perform several scans (port scans, and so on) against these targets. It should be noted that this type of scan would not be possible outside the network as a router usually acts as a firewall and only forward traffic to the ports assigned to transmit.

Withthe above in mind, you run the risk of certain exploits as a striker is a part of your network, what services are dependent on use and if you do not have a software firewall in place, but the following are the most serious exploits that are the real dangers that your privacy and confidential information possible, and in general a software firewall will not protect you against this danger.

ARP poisoning - To be placed byallows an attacker to "put down" like a computer or other device, usually your router! This is done simply by sending a certain amount of ARP replies to the victim say that is the MAC address of the router. The victim then updates the ARP table and sends all traffic destined for the router to the attackers MAC address. In this way the attack can then monitor all traffic coming to and from the victim. This should explain why the risk is very low. Anotherconfidential information (username, password) are sent over the Internet in plain text or with weak encryption, allowing the attacker to your email account or other websites that are using compromised. There is also the problem of the attacker almost everything can be done online! including all MSN conversations, etc.

DHCP spoofing - This exploit requires a bit 'more patience in the name of the attackers, however, if implemented could be very bad news forvictim. The attacker creates a DHCP server on their system, when a new user is online address where the card is automatically set to an IP, DHCP server, the attackers attempt to provide a DHCP packet before the router is, if the victim accepts the request the attacker can include all the details they want, usually their IP address as gateway and DNS server (s) of these problems are presented below.

DNS Poisoning -This is the most serious form of abuse, the attacker can do this in two ways. The first is explained above, the second is for the attacker to gain access to the router (unsecured networks are most in default, this means that the password for the router is usually standard and can be easily guessed or found online! ) And that change the DNS server it uses for one of the attackers (this could be a classroom on the attackers machine, or a rogue statehosted elsewhere) All the attacker needs to do now is create a DNS record to redirect the victim to rogue imitations of websites, these usually look the same, but once the user name and password are entered and submitted, which are sent the striker in place of where they should be sent! The attacker can also send the details page aftewards correct site, then the attack is completely unnoticed. Obviously this is a very big problem, especiallyfor sites such as eBay, PayPal, and especially online banking.

These exploits are on the most common use for an attacker to obtain sensitive information, there are many, and much depends on the design of the machine on the network and victims.

In short, it is clear that leaving an unsecured wireless network can have serious consequences, and gives attackers an open door to their access to various confidential information. The following securityprecautions are recommended for maximum security for home users to give:

-Always protect your network with a WPA or WPA2, make sure that the key is long in length and complexity. Avoid WEP at all, is unnecessary and can be divided into a couple of minutes that an attacker has a good signal.

-Implement MAC address filtering, this only makes the movement of domains MAC addresses. While MAC addresses can be spoofed, it can be a difficult process, as an attacker to intercept traffic and anaylseframe headers for the source / destination MAC address of an authenticated client to see, this can be very difficult for a customer associates.

t-Don 'your SSID broadcast, but that alone will not stop an attacker, it is an extra layer of security.

-Use a software firewall, I recommend Agnitum Outpost.

Although no system can ever be 100% sure, it is important to implement security as far as possible to prevent attacks to exploit. With the abovepoints instead of a striker has been a very difficult time gaining access to the network.

Recommend : Video Cards Store. LOWER Prices HTC Phone Store Vulnerability Security

Monday, August 30, 2010

Wireless Network Trouble Shooting

Wireless Network Trouble Shooting

1. Wireless Adapter - First check to see if your wireless adapter is on and working properly. If you are using a PCMICA wireless adapter ensure that the card is pressed completely in. If the wireless adapter card was not plugged in when you started your laptop you may want to restart your computer for a fresh start. If you are using a laptop with a built in wireless adapter. What Wireless Network - Check the bottom right hand task bar to see if you are connected to a wireless network. Many people are connected to the wrong wireless network with a weak signal or hardly any connectivity. You want to change your wireless adapter setting to choose Infrastructure access points only so you're not connecting to rogue wireless access points.

3. SSID and ME - Next check your wireless settings for the following: DO you have the correct SSID typed in, is your encryption key typed in correctly, does your wireless router and wireless adapter have the same security settings.

4. DHCP ME - If you don't have a manual TCP/IP address then your wireless router needs to have it's DHCP server turned on. Connected to your web interface and turn on your DHCP server. Next go to your wireless network icon in the bottom right hand corner and disable your wireless adapter and then enable it. This will renew your DHCP request to the routers DHCP server.

5. PING!- Next we will use a command line function called PING. Type "cmd" in the run box, this will bring up your DOS window. Now type in ping and then type in the TCP/IP addressof your default gateway. If you have not changed it your default gateway's ip address should be 192.168.1.1 or 192.168.0.1. If you receive a reply then you know that you are connected properly to your router.

6. WWW...WHAT - Now try and surf the web. Go to google.com or another simple page. If nothing comes up then you might have a manually configured IP address with the correct DNS servers entered. Connect to your wireless routers web interface and check the status. You are looking for the multiple DNS server IP address. Copy these IP addresses into you adapters TCP/IP settings and hit ok.

7. Google ME - Once your DNS servers are entered you should be able to surf the net. If you still can't surf the net try restarting your computer and check you cables again to make sure you haven't missed something.

Thanks To : Blu Ray Disks Sony Bravia Save! Store

Sunday, August 15, 2010

The Dangers Of Leaving Your Wireless Network Unsecured

If you were to browse for wireless networks in a busy city you would be surprised at how many unsecured networks you will find, many people are oblivious to the dangers, however I would like to outline these.

By unsecure I am referring to a wireless network that is accessible without the need for a network key, although WEP is horribly insecure also I will not be covering its vulnerabilities in this article. Providing an attacker is in range he can connect to an unsecured wireless network and become a part of the local network. Ok so now what? The attack could then run an ip scan on the subnet to establish what is currently connected to the network. At this point the attacker could run various scans (port scans and so on) against the targets. It should be noted that this kind of scan would not be possible from outside of the network as usually a router acts as a firewall and only forwards on traffic to ports that have been assigned for forwarding.

With the above in mind you are at risk to certain exploits if an attacker becomes a part of your local area network, these however are dependent upon what services you are running and if you have any software firewall in place, however the following are more serious exploits that are the real dangers that will jeopardize your privacy and possible confidential details, and generally a software firewall will NOT protect you from these.

ARP poisoning - To put it simply this exploit enables an attacker to 'pose' as another computer or device, usually your router! This can be done simply by sending a certain amount of arp replies to the victim saying that he has the MAC address of the router. The victim then updates its ARP table and sends all traffic destined for the router to the attackers MAC address. By doing this the attack can then monitor ALL traffic coming in and out of the victim. This needs very little explanation as to why it poses a risk. A lot of confidential details (usernames,passwords) are sent over the internet in plain text or with weak encryption, thus allowing the attacker to compromise your email accounts or other websites you use. There is also the problem of the attacker being able to view pretty much everything your doing online! including all your msn conversations etc.

DHCP spoofing - This exploit requires a little more patience on the attackers behalf however if executed it can be very bad news for the victim. The attacker creates a DHCP server on their system, when a new user comes online whose adapter is set to automatically assign an ip address; the attackers DHCP server attempts to offer a DHCP packet before the router does, if the victim acknowledges the request the attacker can include any details they want, usually their own IP address as the gateway and also DNS server(s) The problems of this are explained below.

DNS poisoning - This is the most serious type of exploit, the attacker can execute this in two ways. The first is explained above, the second is for the attacker to gain access to the router (most unsecured networks are left with default settings, this means the password for the router is usually default also and can easily be found online or guessed!) and then changing the DNS server that it uses to one of the attackers (this could be a local one on the attackers machine, or a rogue one hosted elsewhere) All the attacker needs to do now is create some rogue DNS records that redirect the victim to imitations of websites, usually these look identical however once the username and password are entered and submitted, they get sent to the attacker instead of where they should be sent! The attacker can even get the page to forward the details onto the correct site aftewards, therefore the attack going completely unnoticed. Obviously this is a very big problem especially for sites such as ebay, paypal, and especially online banking.

These exploits above are the most common for an attacker to use to gain confidential information, there are many more and a lot are dependent upon the setup of the network and victims machine.

In summary, it is clear to see that leaving a wireless network unsecure can have serious implications, and gives attackers an open door for them to gain access to all kinds of confidential information. The following security precautions are advised to give optimal security for home users:

-Always secure your network with a WPA or WPA2 key, make sure that the key is long in length and also complex. Avoid WEP at all costs, it is redundant and can be broken in minutes providing an attacker has a good signal.

-Implement MAC address filtering, this only allows traffic from registered MAC addresses. While MAC addresses can be spoofed, it can be a hard process as an attacker has to sniff traffic and anaylse frame headers to see source/target MAC addresses of an authenticated client, this can be very difficult for an unassociated client.

-Don't broadcast your SSID, while this on its own will not stop an attacker, it is an extra layer of security.

-Use a software firewall, I recommend Agnitum Outpost.

While no system in the world will ever be 100% secure, it is important to implement as many security precautions as possible to prevent attackers from exploiting. With the above points in place an attacker would have an extremely hard time ever gaining access to your network.

Thanks To : Network Attack Case, Information Blu-Ray Movies Store