Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Wireless Networking
Home Forums Register Search Today's Posts Mark Forums Read

WPA2-Enterprise security

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 20-Aug-2008, 02:23 PM
warrmr warrmr is offline
Valued Member
Posts: 123
Points: 33 warrmr has between 1 & 100 points
Power: 4
None
Join Date: 09 Sep 2007
Location: Solihull, Birmingham
Age: 23
Certifications: MCP 70-270, 70-290
WIP: MCSA + Messaging, MCSE + Security
WPA2-Enterprise security

Hi guys,

I have a few questions to ask around here and it concerns the security of a WPA2-Enterprise secured wireless network.
I have just baught myself a ZyAIR G2000 Plus wireless router and i have gone for this one because it has a inbuilt cutdown RADIUS server that supports 32 clients and im abit paranoied about wireless networks in general.

Now from what i understand of WPA2 enterprise is that it consists of 2 parts Association and Authentication. so there are 3 things that are needed to be able to use the network they are a valid certificate, a username and a password.

I think if you forged the certificate you could still associate with the AP but without the username password you could not authenticate with RADIUS therefore not be able to access the network resources.

What i am asking is how secure it this setup i know the most secure way is not to have wireless and limit physical access to the network, but this is not a choice in my new flat as i wont be able to wire up the network points without getting a network engeneer contractor to do it and pay through the nose ( a term of my lease that any electrical/plumbing or communication works have to be contracted out).

Also with the certificates there are 2 options the first is to goto a CA like verisign and get one of theres and pay lots of money or the second is to use the inbuilt CA and make your own self certifyed certificate.
How easy would it be for a malitious person to spoof the certificate for my AP?

One final note I am NOT asking how to hack/crack WPA2-enterprise i just want to know if its possible and how easy it is and if its been done before.
I know WEP and WPA-PSK has been done and now anyone can do it with readly avalable software off the interent and minimum *nix knowlage.

Also I currently own a netgear fvs124G router/firewall vpn box, that i am replacing with this AP now i want to know is there a way of rigging this up on the LAN side of the AP to act as a VPN server so that i could dial into my network and allow my sister access while she is at uni. I dont want to have to setup a dedicated VPN server i woudl prefer if it was in some form of low power embedded device ( i know this is asking alot.)

 
Reply With Quote
  #2  
Old 20-Aug-2008, 02:42 PM
Qs's Avatar
Qs Qs is offline
Semi-Honorary Member
Posts: 1,359
Points: 1292 Qs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 points
Power: 27
None
Join Date: 13 May 2008
Location: Lichfield, West Midlands
Age: 21
Certifications: HND Applied IT, CCNA
WIP: MCDST, MCP, A+, N+
Weirdly I found exactly the same post on the remote exploit forums (Link)

Anyway... Information which may calm your worries can be found at the following:-

Wi-Fi Protected Access - Link

Additional information specifically concerning WPA2 - Link


Hope this helps.

Qs




Base 8 is just like Base 10, if you are missing two fingers.
 
Reply With Quote
  #3  
Old 20-Aug-2008, 02:45 PM
warrmr warrmr is offline
Valued Member
Posts: 123
Points: 33 warrmr has between 1 & 100 points
Power: 4
None
Join Date: 09 Sep 2007
Location: Solihull, Birmingham
Age: 23
Certifications: MCP 70-270, 70-290
WIP: MCSA + Messaging, MCSE + Security
Quote:
Originally Posted by Qs View Post
Weirdly I found exactly the same post on the remote exploit forums (Link)

Anyway... Information which may calm your worries can be found at the following:-

Wi-Fi Protected Access - Link

Additional information specifically concerning WPA2 - Link


Hope this helps.

Qs

The posts were made by the same person what are the chances :P
thanx for the links looks like there is abit of info there to read

 
Reply With Quote
  #4  
Old 20-Aug-2008, 02:52 PM
Qs's Avatar
Qs Qs is offline
Semi-Honorary Member
Posts: 1,359
Points: 1292 Qs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 points
Power: 27
None
Join Date: 13 May 2008
Location: Lichfield, West Midlands
Age: 21
Certifications: HND Applied IT, CCNA
WIP: MCDST, MCP, A+, N+
Quote:
Originally Posted by warrmr View Post
The posts were made by the same person what are the chances :P
Really? lol

Quote:
Originally Posted by warrmr View Post
thanx for the links looks like there is abit of info there to read
No problem, hope it quells your worries. If not, there's always alcohol.




Base 8 is just like Base 10, if you are missing two fingers.
 
Reply With Quote
  #5  
Old 20-Aug-2008, 03:12 PM
warrmr warrmr is offline
Valued Member
Posts: 123
Points: 33 warrmr has between 1 & 100 points
Power: 4
None
Join Date: 09 Sep 2007
Location: Solihull, Birmingham
Age: 23
Certifications: MCP 70-270, 70-290
WIP: MCSA + Messaging, MCSE + Security
after reading through those links it looks like WPA2 is very secure and then combined with an authentication protocol like Peap/RADUS no one is going to get far.

the wikipedia aretical doesnt really cover much abotu WPA2 enterprise but im assuming it will use the same AES encription protogol alongside the PEAP/RADIUS authentication.


so the weakest points will be the indervidual users passwords and the Preshared Key if one is used.

and the certificate is hard to fake without knowing the things used to generate it and if its from an online CA then its really hard to fake. or am i looking at things the wrong way.

Cryptography is well over my head so im just pulling bits that i understand aout of all of the acrimons and complicated bits.

 
Reply With Quote
  #6  
Old 20-Aug-2008, 03:16 PM
Qs's Avatar
Qs Qs is offline
Semi-Honorary Member
Posts: 1,359
Points: 1292 Qs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 points
Power: 27
None
Join Date: 13 May 2008
Location: Lichfield, West Midlands
Age: 21
Certifications: HND Applied IT, CCNA
WIP: MCDST, MCP, A+, N+
Glad the information helped you

Everyone's a bit paranoid about wireless but yeah, make sure your key/passwords are chosen well and you should be fine.

Qs




Base 8 is just like Base 10, if you are missing two fingers.
 
Reply With Quote
  #7  
Old 20-Aug-2008, 04:47 PM
BosonMichael's Avatar
BosonMichael BosonMichael is offline
Certification Guru
Posts: 12,462
Points: 6508 BosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 points
Power: 193
None
Join Date: 02 Nov 2006
Location: near Nashville, TN
Age: 39
Certifications: MCSE+I, MCSE: Securi.. huh? out of room?
WIP: Just about everything!
I think we've found someone to take GBLs place during his 3-month absence.

In truth, when GBL returns, I won't even need to post anymore!


BosonMichael
MCSE+I, MCSE: Security, MCDST, MCDBA, OCP, CCNP, CCDP, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
Served proudly, US Army, 98C Intelligence Analyst, '89-'92
 
Reply With Quote
  #8  
Old 21-Aug-2008, 12:02 PM
Qs's Avatar
Qs Qs is offline
Semi-Honorary Member
Posts: 1,359
Points: 1292 Qs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 points
Power: 27
None
Join Date: 13 May 2008
Location: Lichfield, West Midlands
Age: 21
Certifications: HND Applied IT, CCNA
WIP: MCDST, MCP, A+, N+
Quote:
Originally Posted by BosonMichael View Post
I think we've found someone to take GBLs place during his 3-month absence.




Base 8 is just like Base 10, if you are missing two fingers.
 
Reply With Quote
  #9  
Old 23-Aug-2008, 01:55 AM
warrmr warrmr is offline
Valued Member
Posts: 123
Points: 33 warrmr has between 1 & 100 points
Power: 4
None
Join Date: 09 Sep 2007
Location: Solihull, Birmingham
Age: 23
Certifications: MCP 70-270, 70-290
WIP: MCSA + Messaging, MCSE + Security
This is what i love about this forum, you ask a qurestion and you get an answer within a few hours. where as my thread on the remote exploit forums that Qs linked to with the same question has been viewed 86 times and not one reply.

 
Reply With Quote
  #10  
Old 23-Aug-2008, 02:01 AM
Mr.Cheeks's Avatar
Mr.Cheeks Mr.Cheeks is offline CertForums News Posting Member
Soz Hun I have a headache
Posts: 4,817
Points: 2647 Mr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 points
Power: 80
None
Join Date: 23 Feb 2006
The love for CF is strong!


RIP Dave - You will never be forgotten!
Another good post?
If so, tell a friend, if not, f*ck off then!


 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Wireless Networking


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Great Apache security book ffreeloader The Lounge - Off Topic 3 13-Mar-2008 04:37 PM
Network Security Assessment, 2nd Edition tripwire45 Reviews 2 21-Dec-2007 08:06 PM
Starting a Career in Cyber Security tripwire45 News 1 08-Nov-2007 06:26 PM
Installing a CA Ally Security Exams 2 21-Jan-2006 01:21 PM


All times are GMT +1. The time now is 07:48 AM.

Powered by vBulletin® Version 3.6.11
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages