WPS pin system vulnerability found.

  • Thread starter Thread starter Rydian
  • Start date Start date
  • Views Views 5,071
  • Replies Replies 42
It means you can't get a new device that's wifi-only (tablets, handheld game systems, some conoles) online by itself without having to involve another device.

AND if the people can crack WEP they can can likely sniff/spoof MAC addresses anyways, but if you just use WPA2 then none if it matter because even with a proper MAC they can't get in.
 
MAC filtering is very easy to fake out. You just listen for an approved device and steal the number and save it for when they're not connected. The SSID is broadcast anyways, whenever a packet is sent. But for a little extra protection, turning both of these security features on will help discourage most people. So it's a small investment for a large reward. I don't bother though, as I keep a log of MAC addresses that try to connect. Hehe, that's even better since it tells me if they succeeded.

Disable WPS - and check to make sure it's really disabled! There is a bug in many firmwares that ignores the setting. "WPSpy" and "Reaver" are tools to help crack it. I don't care if someone tries to change my config info on my router because 1) I'm right next to it. 2) I set a random hexkey instead of a passphrase. 3) If WPA2 is cracked, then I need a new firmware/router, anyways! :P

WPSpy can be used to detect if the router really disabled it, I believe. You can also look up the router's model to see if it's 'really' disabled. WRT/Tomato/... firmwares are a surefire way to make sure it's really disabled.

Just a fair warning - The WPS extension to WPA is now as bad as WEP!
 

Site & Scene News

Popular threads in this forum