SandyBaby wrote:
> 1. change the admin userid/password for the router.
That an important but often forgetten point.
> 2. disable ssid broadcast, so nobody can see your access point.
Well that won't help. Hiding the SSID can give you a lot of troubles but it
does not really increase security. The SSID is broadcasted on every logon
so it can be found out by everybody. The positon of your WLAN can be found
anyway, with or without broadcasted SSID.
> 3. enable WEP (or preferably WPA if your AP supports it).
You may see the manual to do so.
Check if all your components support WPA. If they do use "WPA-PSK" and enter
a long and random secret key.
> 4. enable MAC address filtering so that only authorised wifi adapters
> can connect to the AP.
That's even more useless then the hidden SSID. The MAC address is sent with
every packet (even the encrypted) and it's very simple to fake it.
> 5. enable your firewall.
> 6. make sure your anti virus is kept up to date.
> 7. surf safely - don't download and install dodgy software - never open
> email attachments unless you are absolutely sure they are safe.
That are no special WLAN security hints but also very important.
I just have to add that you have to read carefull what the firewall tool is
asking. Never click 'OK' or 'Allow' without knowing what it means.
But even without firewall you are pretty save. An attacker from the internet
can see the router only.
And last but not least:
8. NEVER, NEVER, NEVER, use the Internet Explorer!
Nearly every dialer, trojan horse or virus infecting your system from an
internet page is doing so by using Internet Explorer scriping features
(including several security problems). On other browser like Mozilla or
Opera they just won't work.
Thomas
|