Wireless & password security Mark Theeuwes. 2 Wireless basics.

46
Wireless & password security Mark Theeuwes

Transcript of Wireless & password security Mark Theeuwes. 2 Wireless basics.

Page 1: Wireless & password security Mark Theeuwes. 2 Wireless basics.

Wireless & password security

Mark Theeuwes

Page 2: Wireless & password security Mark Theeuwes. 2 Wireless basics.

2

Wireless basics

Page 3: Wireless & password security Mark Theeuwes. 2 Wireless basics.

3

Wireless basics

Radio waves

Page 4: Wireless & password security Mark Theeuwes. 2 Wireless basics.

4

Wireless basics

Channels 2,4 GHz (802.11 B/G/N)

Page 5: Wireless & password security Mark Theeuwes. 2 Wireless basics.

5

Wireless basics

Channels 5GHz (802.11 A/N)

Page 6: Wireless & password security Mark Theeuwes. 2 Wireless basics.

6

Wireless basics

Reflection

Absorbtion

Refraction

Scattering

Page 7: Wireless & password security Mark Theeuwes. 2 Wireless basics.

7

Wireless basics

Omnidirectional antenna

Page 8: Wireless & password security Mark Theeuwes. 2 Wireless basics.

8

Wireless basics

Other Antenna’s

Page 9: Wireless & password security Mark Theeuwes. 2 Wireless basics.

9

Wireless basics

WLAN Cell

Page 10: Wireless & password security Mark Theeuwes. 2 Wireless basics.

10

Wireless basics

Range

Page 11: Wireless & password security Mark Theeuwes. 2 Wireless basics.

11

Wireless basics

Roaming

Page 12: Wireless & password security Mark Theeuwes. 2 Wireless basics.

12

Wireless basics

Roaming

Page 13: Wireless & password security Mark Theeuwes. 2 Wireless basics.

13

Wireless basics

Cells

Page 14: Wireless & password security Mark Theeuwes. 2 Wireless basics.

14

Wireless basics

Honey cone

Page 15: Wireless & password security Mark Theeuwes. 2 Wireless basics.

15

Wireless basics

Building

Page 16: Wireless & password security Mark Theeuwes. 2 Wireless basics.

16

Wireless basics

Autonomous Accespoint

Page 17: Wireless & password security Mark Theeuwes. 2 Wireless basics.

17

CiscoWireless

LWAP

Page 18: Wireless & password security Mark Theeuwes. 2 Wireless basics.

18

Cisco Wireless

4) Cisco Secure ACS servers

Printers with wireless workgroup bridge

Notebook Wireless workstations

CISCO AIRONET 1200 I WIRELESS ACCESS POINT CISCO AIRONET 1200 I WIRELESS ACCESS POINT

5) ADS Domain Controllers

RA

DIU

S

LDAP

AES

WEP128

CISCO AIRONET 1200 I WIRELESS ACCESS POINT

CISCO AIRONET 1200 I WIRELESS ACCESS POINT

CISCO AIRONET 1200 I WIRELESS ACCESS POINT

CISCO AIRONET 1200 I WIRELESS ACCESS POINT

LAN LWAP

WLAN controllers

Firewalls

Page 19: Wireless & password security Mark Theeuwes. 2 Wireless basics.

19

Wireless

Page 20: Wireless & password security Mark Theeuwes. 2 Wireless basics.

20

Wireless basics

Association

Page 21: Wireless & password security Mark Theeuwes. 2 Wireless basics.

21

Wireless basics

Security options

Page 22: Wireless & password security Mark Theeuwes. 2 Wireless basics.

22

Wireless attacks

Page 23: Wireless & password security Mark Theeuwes. 2 Wireless basics.

23

Wireless attacks

Page 24: Wireless & password security Mark Theeuwes. 2 Wireless basics.

24

WEP cracking

Page 25: Wireless & password security Mark Theeuwes. 2 Wireless basics.

25

WPA2 cracking

Page 26: Wireless & password security Mark Theeuwes. 2 Wireless basics.

26

Passwords

Page 27: Wireless & password security Mark Theeuwes. 2 Wireless basics.

27

Strong passwords

Page 28: Wireless & password security Mark Theeuwes. 2 Wireless basics.

28

Passwords

password

2Mypassword

2MyPa$$w0rd!

1Ef$aŎX9s2!#

Page 29: Wireless & password security Mark Theeuwes. 2 Wireless basics.

29

Password policy considerations

What is too simple ? Password age ? Password length ?

Page 30: Wireless & password security Mark Theeuwes. 2 Wireless basics.

30

Passwords

Page 31: Wireless & password security Mark Theeuwes. 2 Wireless basics.

31

Strong passwords

Page 32: Wireless & password security Mark Theeuwes. 2 Wireless basics.

32

Myspace attack 2006 (34.000 passwords)

Page 33: Wireless & password security Mark Theeuwes. 2 Wireless basics.

33

Myspace attack 2006

Page 34: Wireless & password security Mark Theeuwes. 2 Wireless basics.

34

Most common passwords (America)

password1, abc123, myspace1, password, blink182, qwerty1, fuckyou, 123abc, baseball1, football1, 123456, soccer, monkey1, liverpool1, princess1, jordan23, slipknot1, superman1, iloveyou1, monkey

Page 35: Wireless & password security Mark Theeuwes. 2 Wireless basics.

35

Password hashes

Page 36: Wireless & password security Mark Theeuwes. 2 Wireless basics.

36

Password hashes

Page 37: Wireless & password security Mark Theeuwes. 2 Wireless basics.

37

Password hacking

Page 38: Wireless & password security Mark Theeuwes. 2 Wireless basics.

38

Password guessing

The word "password" The same as the user name Name of the user Birthdays or birth places Relatives Pets Favorite colors, foods, places, etc.

Page 39: Wireless & password security Mark Theeuwes. 2 Wireless basics.

39

Dictionary attacks

Page 40: Wireless & password security Mark Theeuwes. 2 Wireless basics.

40

Brute force

Page 41: Wireless & password security Mark Theeuwes. 2 Wireless basics.

41

Rainbow tables

NTLM hashes

Page 42: Wireless & password security Mark Theeuwes. 2 Wireless basics.

42

Password database Fontys Venlo (10 years ago)

Page 43: Wireless & password security Mark Theeuwes. 2 Wireless basics.

43

Future ?

Page 44: Wireless & password security Mark Theeuwes. 2 Wireless basics.

44

Security is a trade off

Page 45: Wireless & password security Mark Theeuwes. 2 Wireless basics.

45

Questions

Page 46: Wireless & password security Mark Theeuwes. 2 Wireless basics.

46