Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > What happens if someone fakes an existing MAC address?

Reply
Thread Tools Display Modes

What happens if someone fakes an existing MAC address?

 
 
Marcel Joustra
Guest
Posts: n/a

 
      09-01-2004, 08:14 PM
In our network, we had some problems possibily caused by intruders. So the
least thing we could do is to filter on MAC addresses. But what if one of
these intruders discover what MAC adresses are in use? (In fact not hard to
discover, even there is WEP. We can't use WPA because we have to replace all
of our clients equipment:-(
A MAC address is very easy to clone. If someone does this, will this block
an existing user? Is it possible for the intruder to gain access to the
(local) part of the network? (all other connections are VPN)


Regards,


Marcel


--
Posted by news://news.nb.nu
 
Reply With Quote
 
 
 
 
Thomas =?ISO-8859-1?Q?Kr=FCger?=
Guest
Posts: n/a

 
      09-01-2004, 08:47 PM
Marcel Joustra wrote:

> In our network, we had some problems possibily caused by intruders. So the
> least thing we could do is to filter on MAC addresses.
> But what if one of
> these intruders discover what MAC adresses are in use?


The intrudes will pass the MAC filter without any problem.

> (In fact not hard
> to discover, even there is WEP.


WEP will not hide the MAC address. It's still transmited with every packet.

> We can't use WPA because we have to
> replace all of our clients equipment:-(


WAP will not hide the MAC address also.
As you can see the MAC filter is one of the most insecure securety feature.

> A MAC address is very easy to clone.


Yep, on Linux the intruder just has to do a "ifconfig interface hw ether
new_mac_address".

> If someone does this, will this block
> an existing user?


That hardly depends on the firmware of the access point and how it reacts on
double authentication. And how the client reacts on receiving it's own
packets. In most cases the both system will keep working but there will be
some errors.

> Is it possible for the intruder to gain access to the
> (local) part of the network? (all other connections are VPN)


If he also has the WEP key he has the same access level as the faked user.
The WEP key can be retrieved with tools like airsnort by sniffing a big
amount of data from the WLAN.

Thomas
 
Reply With Quote
 
Marcel Joustra
Guest
Posts: n/a

 
      09-06-2004, 05:18 AM

"Thomas Krüger" <(E-Mail Removed)> schreef in bericht
news:ch5chc$jrf$03$(E-Mail Removed)...

>
> The intrudes will pass the MAC filter without any problem.
>


Agree



>
> WEP will not hide the MAC address. It's still transmited with every

packet.
>


Hmm, thats waht i didn't know......

>
> WAP will not hide the MAC address also.
> As you can see the MAC filter is one of the most insecure securety

feature.
>
> > A MAC address is very easy to clone.

>
> Yep, on Linux the intruder just has to do a "ifconfig interface hw ether
> new_mac_address".
>


Most standalone wireless interfaces can do that also:-(


> > If someone does this, will this block
> > an existing user?

>
> That hardly depends on the firmware of the access point and how it reacts

on
> double authentication. And how the client reacts on receiving it's own
> packets. In most cases the both system will keep working but there will be
> some errors.
>



Hmm, that's something which can be tested at the office....



> If he also has the WEP key he has the same access level as the faked user.
> The WEP key can be retrieved with tools like airsnort by sniffing a big
> amount of data from the WLAN.
>



Yep. Thats why all traffic over the network are encrypted VPN tunnels.
He/she can't use the internetconnection, but he/she can jam the local
network which much off local traffic.


Marcel


--
Posted by news://news.nb.nu
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Want to add wireless to existing lan Dick Wireless Networks 9 02-08-2009 05:51 PM
trying to add another AP to an existing network Sopwith Wireless Internet 1 06-20-2007 06:33 AM
Adding DSL to existing wireless network but in different room than existing router? costasz@gmail.com Wireless Internet 0 08-12-2005 05:07 PM
AOL over existing BB Connection? BJH Broadband 17 01-23-2005 07:47 AM
PS2 to my existing D-Link 614+ ? -: R.A.T Boy :- Wireless Internet 4 01-03-2004 08:26 PM



1 2 3 4 5 6 7 8 9 10 11