<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>A blog on Information Technology &#38; Security Governance</title>
	<atom:link href="http://infosecgov.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecgov.wordpress.com</link>
	<description>by Shashank Pandey</description>
	<lastBuildDate>Fri, 26 Sep 2008 14:16:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='infosecgov.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>A blog on Information Technology &#38; Security Governance</title>
		<link>http://infosecgov.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://infosecgov.wordpress.com/osd.xml" title="A blog on Information Technology &#38; Security Governance" />
	<atom:link rel='hub' href='http://infosecgov.wordpress.com/?pushpress=hub'/>
		<item>
		<title>NMAP v 4.75 is out now!</title>
		<link>http://infosecgov.wordpress.com/2008/09/26/nmap-v-475-is-out-now/</link>
		<comments>http://infosecgov.wordpress.com/2008/09/26/nmap-v-475-is-out-now/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 14:16:37 +0000</pubDate>
		<dc:creator>Shashank</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Fyodor]]></category>
		<category><![CDATA[Network Mapping]]></category>
		<category><![CDATA[Nmap 4.75]]></category>
		<category><![CDATA[OS fingerprinting]]></category>
		<category><![CDATA[Zenmap]]></category>

		<guid isPermaLink="false">http://infosecgov.wordpress.com/?p=22</guid>
		<description><![CDATA[NMAP v 4.75 is out now!   A new version (4.75) of the popular network scanner is available for download now. This version of Nmap allows for a neat graphical representation of your scan results through Zenmap. The network topology is shown in the form of concentric circles indicating the distance between the scanned host and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecgov.wordpress.com&amp;blog=4724508&amp;post=22&amp;subd=infosecgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="text-align:justify;margin:0;"><strong><span style="font-size:12pt;"><span style="font-family:Calibri;">NMAP v 4.75 is out now!</span></span></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"> </p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">A new version (4.75) of the popular network scanner is available for download now. This version of Nmap allows for a neat graphical representation of your scan results through <a href="https://infosecgov.wordpress.com/wp-admin/”http://nmap.org/zenmap">Zenmap</a>. The network topology is shown in the form of concentric circles indicating the distance between the scanned host and your computer from where the scan originates. Each concentric circle here represents a hop. Hosts are represented in the form of circles of different sizes and the more number the number of open ports in a host, the bigger is the size of the circle that represents it. Images of the Zenmap features along with their explanation can be found <a href="http://nmap.org/book/zenmap-topology.html">here</a>.</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"> </p>
<p class="MsoNormal" style="text-align:justify;margin:0;"> </p>
<p class="MsoNormal" style="text-align:justify;margin:0;"> </p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Apart from the graphical representation of network topology and some other new features. This latest version of Nmap contains many new OS signatures which should improve the accuracy of results. I will be very shortly using this version of Nmap on one of my penetration testing assignments and post more if required. If you have used it already in any of your scans, do share your insights on this blog!</span></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosecgov.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosecgov.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosecgov.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosecgov.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosecgov.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosecgov.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosecgov.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosecgov.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosecgov.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosecgov.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosecgov.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosecgov.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosecgov.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosecgov.wordpress.com/22/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecgov.wordpress.com&amp;blog=4724508&amp;post=22&amp;subd=infosecgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecgov.wordpress.com/2008/09/26/nmap-v-475-is-out-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a04c090ce574a88b83373e554721f85?s=96&#38;d=identicon" medium="image">
			<media:title type="html">infosecgov</media:title>
		</media:content>
	</item>
		<item>
		<title>When (evil) hackers hammer the Stock prices</title>
		<link>http://infosecgov.wordpress.com/2008/09/17/when-evil-hackers-hammer-the-stock-prices/</link>
		<comments>http://infosecgov.wordpress.com/2008/09/17/when-evil-hackers-hammer-the-stock-prices/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 17:54:57 +0000</pubDate>
		<dc:creator>Shashank</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[American Airlines]]></category>
		<category><![CDATA[Bankruptcy]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[stocks]]></category>

		<guid isPermaLink="false">http://infosecgov.wordpress.com/?p=13</guid>
		<description><![CDATA[When (evil) hackers hammer the Stock prices     Can evil hackers/cyber criminals/competitors affect the stock prices of a corporation? We are not talking about sophisticated hacks aimed at accessing confidential information or conducting massive denial of attacks on web interests of a business. Instead, let’s consider a case where a hacker ‘poisons’ the information [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecgov.wordpress.com&amp;blog=4724508&amp;post=13&amp;subd=infosecgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div></div>
<div><span style="font-size:12pt;"></span></div>
<p><span style="font-size:12pt;"><span style="font-family:Calibri;"></p>
<p class="MsoNormal" style="text-align:center;margin:0;" align="center"><strong><span style="text-decoration:underline;"><span style="font-size:16pt;">When (evil) hackers hammer the Stock prices</span></span></strong></p>
<p> </p>
<p> </p>
<p></span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Can evil hackers/cyber criminals/competitors affect the stock prices of a corporation? We are not talking about sophisticated hacks aimed at accessing confidential information or conducting massive denial of attacks on web interests of a business. Instead, let’s consider a case where a hacker ‘poisons’ the information available about the (financial) health of a corporation. You may ask: &#8220;How does that happen and how would it impact the trading of securities like stocks? “</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Consider the following hypothetical case then:</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-family:Calibri;"><strong><span style="font-size:12pt;">Phase 1</span></strong><span style="font-size:12pt;">: Evil hackers/crime mobs/competitors break into news websites and add (false) damaging information (in the form of a fake article) about the financial well being of a corporation X. The title of such an article could look like “Senior Management of Corporation X is selling company shares in anticipation of impending bankruptcy&#8221;.<span>  </span></span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-family:Calibri;"><strong><span style="font-size:12pt;">Phase 2</span></strong><span style="font-size:12pt;">: On the internet, the news travels at the speed of light (or even faster!) .This fake article may be quickly indexed by search engines and then would available to a wider population. Also, to further increase traffic to the fake article and to in turn increase the page rankings on Google et al , a hacker could use botnet herds to visit this article. Once this (fake and grim) news is seen by enough people , Bloggers and market analysts alike wouldn’t hesitate to share their (pessimistic) opinions and predictions about the future of the corporation X.</span></span><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-family:Calibri;"><strong><span style="font-size:12pt;">Phrase 3:</span></strong><span style="font-size:12pt;"> Stock markets incorporate any available information at blazing speed. As stock traders, MBAs et al would know, the efficient market hypothesis or the concept of &#8220;Market Efficiency&#8221; suggests that any new information is readily absorbed and reflected in the stock prices. To a certain extent, this is intuitive as well. So now a mass paranoia may lead to massive selling of the stocks and sending the stock prices of corporation X crashing down. Now in times of credit crunch, economic depression, soaring oil prices, global warming and what not, bankruptcy is always an option.. </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Now off course, some readers may feel that this is FUD and some others may feel that the above situation has been expressed in a very simplistic manner as if it impacting the stock prices and forcing a corporation towards bankruptcy was the easiest thing to do on the planet. The readers in the latter category might be right though. However, those who think it’s a hypothetical case, might wish to <a href="http://www.theregister.co.uk/2008/09/10/ua_bankruptcy_farce/">read this piece of news </a>.‘Apparently’ a 6 yr old write-up about bankruptcy fears related to United Airlines resurfaced on a news website in 2008, as a current affairs piece and brought down the stock prices of the airlines. This impact on stock price of United Airlines is believed to be a result of stock scamming techniques such as the one described above in this post. Agreed that only time will tell if this indeed was the case for American Airlines but there shouldn&#8217;t be any doubt about the probability of such threats materializing and the fact that we could see more of them in the near future.</span></span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/infosecgov.wordpress.com/13/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/infosecgov.wordpress.com/13/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosecgov.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosecgov.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosecgov.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosecgov.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosecgov.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosecgov.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosecgov.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosecgov.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosecgov.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosecgov.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosecgov.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosecgov.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosecgov.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosecgov.wordpress.com/13/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecgov.wordpress.com&amp;blog=4724508&amp;post=13&amp;subd=infosecgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecgov.wordpress.com/2008/09/17/when-evil-hackers-hammer-the-stock-prices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a04c090ce574a88b83373e554721f85?s=96&#38;d=identicon" medium="image">
			<media:title type="html">infosecgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Are you are helping a terrorist with your wireless internet connection?</title>
		<link>http://infosecgov.wordpress.com/2008/09/16/are-you-are-helping-a-terrorist-with-your-wireless-internet-connection/</link>
		<comments>http://infosecgov.wordpress.com/2008/09/16/are-you-are-helping-a-terrorist-with-your-wireless-internet-connection/#comments</comments>
		<pubDate>Tue, 16 Sep 2008 17:59:08 +0000</pubDate>
		<dc:creator>Shashank</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Delhi Bomb Blasts]]></category>
		<category><![CDATA[Insecure Wireless network]]></category>
		<category><![CDATA[Ken Haywood]]></category>
		<category><![CDATA[Wireless network security]]></category>

		<guid isPermaLink="false">http://infosecgov.wordpress.com/?p=3</guid>
		<description><![CDATA[ Are you helping a terrorist with your wireless internet connection?   Terrorists today have become tech savvy. Modus operandi of terrorist-group(s) in recent bomb-blasts in Indian cities of Jaipur, Bangalore, and Ahmadabad and just now in Delhi proves it.   As has been reported in the media, law enforcement agencies believe that insecure wireless networks belonging [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecgov.wordpress.com&amp;blog=4724508&amp;post=3&amp;subd=infosecgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="text-align:center;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> <strong><span style="text-decoration:underline;"><span style="font-size:16pt;">Are you helping a terrorist with your wireless internet connection?</span></span></strong></span></span></p>
<p class="MsoNormal" style="text-align:center;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"><strong></strong> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Terrorists today have become tech savvy. Modus operandi of terrorist-group(s) in recent bomb-blasts in Indian cities of Jaipur, Bangalore, and Ahmadabad and just now in Delhi proves it. <span> </span><span> </span>As has been reported in the media, law enforcement agencies believe that insecure wireless networks belonging to individuals (like “Ken Haywood) and institutions like universities were misused by terrorists to send emails to the press claiming responsibility for the blasts. See <a href="http://timesofindia.indiatimes.com/WiFi_system_Safe_option_for_tech-savvy_terrorists/articleshow/3484066.cms">this Times of India article </a>if you need any further background on the above.</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-indent:-.25in;text-align:justify;margin:0 0 0 .25in;"><span style="font-size:16pt;font-family:Wingdings;"><span>v<span style="font-family:&quot;"> </span></span></span><strong><em><span style="text-decoration:underline;"><span style="font-size:16pt;"><span style="font-family:Calibri;">So what’s the problem?</span></span></span></em></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">In the past, intelligence agencies/law enforcement agencies have been able to track such emails to a specific IP address used by criminals/terrorists. However, now the terrorists have become smarter than before, it seems. Such ruthless mercenaries now look out for vulnerable wireless networks used by general public for Internet access in homes or offices etc. <span> </span>This act of surveying an area for open/exposed/unprotected wireless networks is called “war driving” and can be carried out by a terrorist sitting in his car outside your home/office. Once the terrorists find a vulnerable wireless network (like the one with no password), it becomes a piece of cake for them to hijack and use that Internet connection to send emails of any kind to anybody (like the press or the law enforcement). <span> </span>These dubious persons, who are ruthless and impudent to the extent of insanity, needn’t be standing<span>  </span>right next to you and <span> </span>could use a laptop or a less conspicuous PDA for ‘war driving’ from a distance of 20-100 meters from your network. When the law enforcement analyses at the header of such emails (to trace where the email came from) they find the IP address belonging to the vulnerable wireless network which was exploited by the terrorist and helpless individuals are interrogated<span style="color:#ff0000;">. </span></span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-indent:-.25in;text-align:justify;margin:0 0 0 .25in;"><span style="font-size:16pt;font-family:Wingdings;"><span>v<span style="font-family:&quot;"> </span></span></span><strong><em><span style="text-decoration:underline;"><span style="font-size:16pt;"><span style="font-family:Calibri;">How can a home wireless network be secured?</span></span></span></em></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">What could be done to minimize the risk of terrorists exploiting your home, university or company wireless network? At this juncture, let me clarify here that, we are not talking about full-fledged sophisticated wireless security solutions or techniques but at least some basic things which can be done by system admins managing wireless networks or techies with a home wireless network to secure their own and their neighbor’s wireless network! These are as follows:</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong><em><span style="font-size:12pt;"><span style="font-family:Calibri;">a)<span>  </span>Keep a strong password for your Access Point (AP)</span></span></em></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Most access points come with a default (factory set) password which can be used by an administrator to login to the AP through a web browser and make configuration changes. Several hacking websites publish a list of such access points (of various brands) along with their factory set passwords. Needless to say, such lists are available to anybody with minimal Google skills and off course to the terrorists and therefore if you haven’t changed this default password, sooner or later your wireless network may be broken into. </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">To change your access points default password, you can login into your AP with a web browser (if such functionality is supported). <span> </span>e.g., some Access Points, like those from D-link and Linksys can be configured through the URLs: http://192.168.0.1 and http://192.168.1.1 respectively. After the login, you should see a password tab where you can configure your AP with a strong password. A strong password would be a combination of numbers, letters in small alphabets and some letters in caps lock and would preferably be of 8 characters length or so. If such a password sounds inconvenient to remember then you could keep a password based on any random phrase which you can remember like &#8220;the rabbit goes fox hunting&#8221;. Also, it would serve well from security point of view to change the password periodically, say once every month or so.</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong><em><span style="font-size:12pt;"><span style="font-family:Calibri;">b) Make your network invisible</span></span></em></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Hackers/Terrorists may use software tools to scan an area/location to find out the various wifi networks in that area. Your access point generally broadcasts your network name (SSID) freely in the air and anybody should be able to detect its presence and attempt to connect to it. Some of these wireless network detection tools can be defeated by hiding your network presence. For this you need to configure your wireless access point to disable SSID broadcasts. </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">You can log into your Access point and select “Disable SSID” (or something similar; see your AP manual) to disable such broadcasts. Note that, you will now need to manually configure your desktop/laptop or PDAs with your new network name to be able to access your wireless internet connection.</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong><em><span style="font-size:12pt;"><span style="font-family:Calibri;">c) Change the Default SSID</span></span></em></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Like the factory set passwords, APs also come with a default network name (default SSID). Even if you hide your network as described in (b) above, if somebody knows your network name, he/she can still find your network. Lists of default network names along with the brand of Access points are freely available on the Internet and act as a tool in the terrorist’s war driving chest.</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Therefore, it is recommended that you login to your access point and assign a new network name (other than the factory set).</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong><em></em></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong><em><span style="font-size:12pt;"><span style="font-family:Calibri;">d) Strong Encryption key</span></span></em></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Access to your network should be restricted with a strong encryption key based on a wireless security standard. Your wireless client (software on your laptop or PC) uses this key to authenticate to your Access point and enables you to access the wireless network and/or associated internet connection. This key/password should be strong. Many people such as those whose wireless connection was actually exploited by the terrorist group, e.g., “Indian Mujahidin&#8221;, probably (seems so from the news reports) did not have any password or encryption key for their network.</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-family:Calibri;"><span style="font-size:12pt;">At least some form of encryption (like the one based on the WEP standard) should be configured for your wireless networks. Although, WEP (W</span><span style="font-size:small;">ireless Equivalent Protocol) is<span style="font-size:12pt;"> inherently insecure, but it’s certainly better than having no encryption. Note that, it doesn’t matter how strong a ‘version’ (like 128 bit) of WEP is used. WEP’s inherent flaws can be easily exploited (encryption can be cracked by readily made tools available on the Internet). Therefore, if you wish to use a stronger encryption, you should disable WEP and enable WPA (</span>Wi-Fi Protected Access) <span style="font-size:12pt;">encryption which is more secure than WEP and relatively harder to break into. An even stronger encryption standard for wireless networks is WPA 2.Note that your wireless router /AP may not support WPA /WPA2, in which case WEP remains the only option. If you end up using WEP encryption, make sure you change your encryption key (password) periodically.</span></span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong><em><span style="font-size:12pt;"><span style="font-family:Calibri;">e) Switch off Wireless network when not in Use</span></span></em></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">This should be self explanatory!</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong><em><span style="font-size:12pt;"><span style="font-family:Calibri;">f) Restrict access by MAC Address</span></span></em></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"> </p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Many APs also allow you to define the specific computers/systems which can connect to your wireless network. This is achieved by specifying ‘allowed’ MAC addresses in the access point configuration. MAC address is a unique identifier for any network adapter (like your wireless network card). You can configure your AP to only allow access to your systems (like laptops etc.) to connect to the wireless network.</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"> </p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">To re-emphasize, this article is focused towards home/small office wireless network security, For a robust wireless security solution , one would also need to consider wireless intrusion detection systems, maintain auditing trails which are reviewed frequently , implementing encryption key management procedures , performing periodic wireless security reviews, RADIUS authentication etc.</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><strong></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"> </p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">For a home wireless Internet connection, at least the first 5 steps should be taken by a home user. I have tried to make the wireless security concepts simpler so that they can be referred to by anybody with minimal knowledge of wireless security. You can use the above list to secure your network or consult with specialists in your area to ensure that your wireless network is safe. If you aren’t a techie, the above will help you to be a bit more aware about what may be required for securing your wireless networks. At least after reading the above list of safeguards you might be able to ask your Internet connection provider or a techie nearby to secure your network! Also, though the implementation method (how to do it) of above mentioned safeguards vary by Access Point brands, the principles are the same. It’s best to seek expert help (like your wireless Internet connection setup guy) or network administrators and consult the manual that comes along with the APs to ensure that the above safeguards are implemented properly.</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-indent:-.25in;text-align:justify;margin:0 0 0 .25in;"><span style="font-size:16pt;font-family:Wingdings;"><span>v<span style="font-family:&quot;"> </span></span></span><strong><em><span style="text-decoration:underline;"><span style="font-size:16pt;"><span style="font-family:Calibri;">Food for Thought</span></span></span></em></strong></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-family:Calibri;"><span style="font-size:12pt;">You might wonder if all the above effort in securing your wifi network is justified. “Can it happen to me? It might have happened to “</span><span style="font-size:12pt;">Ken Haywood” or others but it won’t happen to me”. I bet both Ken Haywood and other thought the same before the Anti Terrorism Squad came knocking on their doors!</span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"> </span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;">Consider, implementing wireless security measures as being diligent and being a responsible citizen. We demonstrate such attributes when we look out for unattended objects in a public area and inform the law enforcement. Now given that the scourge of terrorism is reaching new frontiers and becoming more sophisticated, the magnitude of our prudence/diligence also has to increase and be in consonance with the current trend. It’s not a matter of choice anymore; it’s a matter of survival…<span style="font-size:12pt;"><span class="msoDel"><del datetime="02"></del></span></span></span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<p class="MsoNormal" style="text-align:justify;margin:0;"><span style="font-size:12pt;"><span style="font-family:Calibri;"> </span></span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/infosecgov.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/infosecgov.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infosecgov.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infosecgov.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infosecgov.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infosecgov.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infosecgov.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infosecgov.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infosecgov.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infosecgov.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infosecgov.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infosecgov.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infosecgov.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infosecgov.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infosecgov.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infosecgov.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecgov.wordpress.com&amp;blog=4724508&amp;post=3&amp;subd=infosecgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecgov.wordpress.com/2008/09/16/are-you-are-helping-a-terrorist-with-your-wireless-internet-connection/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a04c090ce574a88b83373e554721f85?s=96&#38;d=identicon" medium="image">
			<media:title type="html">infosecgov</media:title>
		</media:content>
	</item>
	</channel>
</rss>
