Security Basics mailing list archives

RE: Wireless Network assessment


From: "Duston Sickler" <dustons () charter net>
Date: Tue, 28 Oct 2003 22:23:51 -0600

Think of it as how you would secure that segment if it's switch rack was in
the parking lot.


Duston Sickler
CompTIA A+ Certified


-----Original Message-----
From: John T. Hoffoss [mailto:hoff0438 () umn edu]
Sent: Monday, October 27, 2003 8:29 PM
To: security-basics () securityfocus com
Subject: Re: Wireless Network assessment


(Google: wireless security assessment howto)

Start here: http://www.infopeople.org/howto/security/network/wireless.html
Then here: http://www.secwiz.com/Default.aspx?tabid=24
Read about ethereal with regards to wireless. Read this:
http://www.informit.com/isapi/product_id~%7BBD2FCF75-BDEF-4AD4-B0DB-C0258281
1000%7D/content/index.asp

Then (having never actually done a wireless security assessment) I would
go in, see if they're VPNing over the wireless connection. If so, make
sure the wireless network segment is a seperate segment from their wired
LAN (i.e. 192.168...) and if not, I would tell them to get a clue.

Without taking into account a wireless application, `wireless security' is
still an oxymoron unless you have spent some time researching it.

(Note: I am not necessarilly in possession of this clue, but I have some
idea about it...)

John

On Mon, Oct 27, 2003 at 10:48:07PM -0000, Andres Martinez wrote:


I'm ready to perform my first wireless security assessment, I have some
experience performing wired security assesments, more than the tools that
are available to perform the scan, I'm concern for the testing methodology
and procedures since I believe that the nature of the wireless world it is
totally different, can somebody point me to the right direction

thanks

Andres


---------------------------------------------------------------------------
Forum Systems PRESIDIO: PGP / XML GATEWAY APPLIANCE
The Presidio integrates PGP data encryption and XML Web Services security to
simplify the management and deployment of PGP and reduce overall PGP costs
by up to 80%.
FREE WHITEPAPER & 30 Day Trial -
http://www.securityfocus.com/sponsor/ForumSystems_security-basics_031027
----------------------------------------------------------------------------


---------------------------------------------------------------------------
Forum Systems PRESIDIO: PGP / XML GATEWAY APPLIANCE
The Presidio integrates PGP data encryption and XML Web Services security to 
simplify the management and deployment of PGP and reduce overall PGP costs 
by up to 80%.
FREE WHITEPAPER & 30 Day Trial - 
http://www.securityfocus.com/sponsor/ForumSystems_security-basics_031027 
----------------------------------------------------------------------------


Current thread: