Link to home
Start Free TrialLog in
Avatar of MikeMiller
MikeMiller

asked on

Wireless Hackers - What CAN they do?

I was discussing the advantages/disadvatages of the different levels of wirelss security for 802.11 wirless networks. Someone said they leave theirs wide open because they dont feel anyone can do anything if they do pickup the signal outside his house. "What CAN they do?". I know you can port scan and look for vulnerabilites, but are there more serious and direct hacks where you can gain access?

What is possible once you are on the same router and subnet by picking up a stray signal?

mike
Avatar of ghana
ghana
Flag of Germany image

If security is based on WEP then hackers can sniff packets. WEP keys are static and not dynamic. Because of that it depends on the traffic on the WLAN how long it takes to find out the keys and to hack the net.

I know people who don't care about WLAN security because they won't see any problems if others using their network infrastructure. It doesn't disturb if others are able to use the WLAN to get internet access. From my point of view this can cause problems too: If hackers use the cracked WLAN access to start DoS attacks against remote servers then this will be done with the IP address(es) of the WLAN owner. If the attacked site goes down and they were able to find out the attacking IP the WLAN owner will be responsible for possible loss of money and so on.
Avatar of zamoti
zamoti

As Ghana said, most people don't really care because they believe that there is nothing terribly important on the network.  One of the most useful things for someone to exploit is the antonymity of somebody else's Internet connection.  As said, they could launch bot attacks using your IP (the attack would be likely traced back to you because if they're using your connection, they're not terribly interested in using a bunch of proxies to cover their tracks.)  They might not be the script-kiddy type, but a real criminal might use the connection to send messages to cohorts.  Not to get too far flung with this, but if a terrorist wanted a means of hard-to-trace communication, they could easily get a laptop with a parabolic antenna, go driving and find a nice suburban neighborhood with lots of insecure WAPs.  I know, getting a little Tom Clancy here...

All of the above stuff would assume that the attacker is in proximity of your WLAN.  If somebody is standing on the sidewalk in front of your home with a laptop, you might be able to figure out what he/she is up to.  However, since most people don't change the default password on their router/AP, they can easily access the configuration and open ports to your network.  Then they could go home and take their time figuring out a way to get into your computer, install some sort of BS server (kazaa, gaming, DDoS bot, etc.)

Basically with enough time and resources, they could basically do whatever they want.  Sniff packets, send you to fake web sites steal passwords, steal credit card numbers, make you cry.  You get the picture.  

Would you want complete strangers to have access to your telephone?  Not much different really.

Cheers,

Z

Avatar of MikeMiller

ASKER

Since they are on the same router as your PC, is it easy for them to gain access to the PC?

With wireless aside, if someone is on the same router and subnet as you, is it easy to Hack their Windows PC?

mike
ASKER CERTIFIED SOLUTION
Avatar of zamoti
zamoti

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Cool.  Thanks.
To make a WLAN secure I would recommend to use WPA instead of WEP. Because WPA is using dynamic created keys it's impossible to get the key with sniffing. Of course you should choose a strong password with WPA.
if the wireless is unsecured thenanyone can connect to the network as if it were wired. have full access, use the internet print tons of pages on the printer look at documents on the computer, its as if it were art of the internal network. now if every pc on the internal network was so locked down that you cant do anything and dhcp was disabled then they cant do muchother than getting a link light unless they want to spend a LONG time port sniffing all the known ip's untill they fin the network.