WPS pin system vulnerability found.

  • Thread starter Thread starter Rydian
  • Start date Start date
  • Views Views 5,071
  • Replies Replies 42
IMO, if you want to access Wi-Fi connection with a regular DS, use a Nintendo Wi-Fi USB connector.
Even though people say they work really bad, I've never had any issues with mine. It always did everything I wanted.

As a bonus, people won't be able to connect to it without your authorization, unless they had physical access to your computer.

The only problem is that the adapter has mostly been discontinued.
 
IMO, if you want to access Wi-Fi connection with a regular DS, use a Nintendo Wi-Fi USB connector.
Even though people say they work really bad, I've never had any issues with mine. It always did everything I wanted.

As a bonus, people won't be able to connect to it without your authorization, unless they had physical access to your computer.
The Wi-Fi connector is a piece of shit with software that is buggy as hell and doesn't work on Vista or 7 without some serious tweaking. No one should get it.

Oh and if you don't want people connecting to your wireless network, USE A PASS PHRASE.

Those fake antiviruses work by first making the user feel insecure by saying their computer is loaded with viruses, and, to be honest, if you don't have an antivirus and you're foolish enough to fall for an ad like that, you probably have a virus anyway. They then suddenly have a solution for you.

If you honestly felt insecure without an advertisement telling you that you should, time would be invested in finding some sort of antivirus.
There's still the (high) chance that they'll get stuck with a bad one though. Many a time have I had to fix a computer where all it took was to uninstall their old AV and install Avast.
Social engineering.
 
Oh and if you don't want people connecting to your wireless network, USE A PASS PHRASE.
Which will be incredibly easy to crack given that it'd be WEP.

By the way, drivers were made for Windows Vista. They're available on the Nintendo website.
I've used the connector for ages and both the Wi-Fi connection and software were stable enough.
 
http://www.smallnetbuilder.com/wireless/wireless-howto/30278-how-to-crack-wpa--wpa2
Even WPA isn't perfect. Use the largest (random) keysize you can and WPA2. It's not like you need to memorize dozens of hexadecimal digits when you can just write them on the bottom of the router. You know, the one with open physical ports if they have physical access to it? (LOL yeah if they can read the password, they can just hook up direct) Might as well play it safe.
 
disabling wps is the first thing i did when i connected my new router o.0 good to know



And that's why I always disable WPS on my routers.
_
I havn't read the source so dunno if it was mentioned there, but not all routers actually disable WPS when you choose the disable option in the firmware O_o so just because your smart enough to turn it off doesn't mean it definitely is (i found one of my old routers had this issue, lucky i don't use it anymore), not sure if a list has been compiled of routers effected by this yet.

I tried the recently released tool that exploits this and out of the 5 neighbours "legitimate test networks" i tried it on, four were susceptible to the attack. Unfortunately so was mine, as my flatmate uses a separate router to mine, and still had WPS running :-( (My router uses the stupid WPS button as a wireless on/off switch, thanks to DDWRT :P ) (saying that though, i've successfully got into two err... "legitimate test networks"...runnign WPA/WPA2 just using dictionary attacks, so even without WPS some people are that stupid. (and lets not go to the three networks just in range of my flat that still only use WEP...)

But to be honest this is the sacrifice for convenience, generally the easier/more convenient it is for the end user the more you have to sacrifice security, it's why things such as side-jacking cookies etc are still so easy. A good example i've used is Google Accounts, they have the option for two step security where you have a code sent to your phone aswell as needing your password, it makes your account next to impossible to brute force, and even if they obtained your password they cannot get on without your phone - do people enable this, no, as the inconvenience outweighs what they consider to be the security risk of this - even I consider it not worth the effort, and i'm generally a very paranoid person when it comes to online data security.

And all this is without even including how broken the wifi becon system is... i can convince 99% of devices to connect to me by pretending to be the wifi access point they are looking for, no security needed! "wifi phone/laptop/tablet goes hey is XXXXX around :unsure: " "yep that's me :ph34r: honest" "great i'll connect now ^_^" And of course with all your traffic going through some unknown person they can redirect pages, sniff packets, etc etc...
 
And no amount of encryption prevents someone from simply jamming the protocols with noise. It only makes it a lot harder to prevent the router and wireless client from detecting it and trying to resend the data. Someone even found a way to break SSL over a LAN so now everyone's moving on to the 3.1 (Now called TLS 1.1?).
 
IMO, if you want to access Wi-Fi connection with a regular DS, use a Nintendo Wi-Fi USB connector.
Even though people say they work really bad, I've never had any issues with mine. It always did everything I wanted.

As a bonus, people won't be able to connect to it without your authorization, unless they had physical access to your computer.
The Wi-Fi connector is a piece of shit with software that is buggy as hell and doesn't work on Vista or 7 without some serious tweaking. No one should get it.

Oh and if you don't want people connecting to your wireless network, USE A PASS PHRASE.

So run it in XP. Surely you can spare 512MB for an XP virtual machine, right?
 
IMO, if you want to access Wi-Fi connection with a regular DS, use a Nintendo Wi-Fi USB connector.
Even though people say they work really bad, I've never had any issues with mine. It always did everything I wanted.

As a bonus, people won't be able to connect to it without your authorization, unless they had physical access to your computer.
The Wi-Fi connector is a piece of shit with software that is buggy as hell and doesn't work on Vista or 7 without some serious tweaking. No one should get it.

Oh and if you don't want people connecting to your wireless network, USE A PASS PHRASE.

So run it in XP. Surely you can spare 512MB for an XP virtual machine, right?
I'm not sure if the USB connector can run in a virtual machine.
I've read about attempting to use the connector under Windows 7 and never heard anything about using a virtual machine (Not even on here.)
 
The best security is MAC filtering and disabling access of Router settings through wireless
MAC addresses are in headers and easily sniffed/spoofed, it's as secure as WEP nowadays as in it's only preventative to normal users.
 
There's no advantage to not using MAC filtering, though.
It adds a layer of security, even if it is easily circumvented.

But disabling router settings access through wireless is a good idea.
Unless you want people to change the password and SSID of your router from distance.
They could even change the admin password for the router, effectively locking you out of your router.
Luckily, there usually is a button on the back of routers to reset it to default settings.
 
  • Like
Reactions: 1 person
The best way to not get hacked is to not give off motivation to be tampered with. Even simply having a router set up is enough motivation to be messed with.
 
There's no advantage to not using MAC filtering, though.
It adds a layer of security, even if it is easily circumvented.

But disabling router settings access through wireless is a good idea.
Unless you want people to change the password and SSID of your router from distance.
They could even change the admin password for the router, effectively locking you out of your router.
Luckily, there usually is a button on the back of routers to reset it to default settings.
Scenario 1:
I have a new device I want to connect to my router. I can enter the WPA2 code and BOOM! Device connects.
Scenario 2:
I have a new device I want to connect to my router. I turn on the device, find its MAC address then boot up my computer to login to the router via a cable to add this to the MAC filter settings.

Which would you say is quicker and easier?
 

Site & Scene News

Popular threads in this forum