Penetration Testing mailing list archives

Replacing WEP was Re: Dsniff'ng wireless networks


From: Simon Waters <Simon () wretched demon co uk>
Date: Wed, 18 Jul 2001 00:14:50 +0100

Someone is thinking of doing a community network with
Wireless LAN.

WEP seems to offer little in this environment, so thinking
of replacing it with IP based encryption - sort of a public
PKI. Assuming we can get users to switch of non-IP protocols
on their client PCs (I know it is hard to right click
network neighbourhood and pick properties), do we lose any
security at layer two by not using WEP?

i.e. Are we more vulnerable to some other types of attack -
I'm guessing mostly DoS if any more are possible. But hey
they can probably DoS more profitably by stealing the
antennas from the relays and selling them.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


Current thread: