Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > Wireless Authentication and SID

Reply
Thread Tools Display Modes

Wireless Authentication and SID

 
 
BrettMcClellan
Guest
Posts: n/a

 
      02-13-2008, 04:35 PM

Scenario - Windows 2000 Domain called ABC.com using IAS policies with
PEAP authentication.

Question - Does the authentication of a wireless client go as deep as
the SID of the client to authenticate? Or just the computer and user
account info?

Could somebody create a domain the same as ABC.com and join their
laptop to that domain using the same computer name, username and
password as a computer on the real ABC.com domain. Then go into the
building of ABC and get authenticated successfully onto the real ABC.com
wireless network?


------------------------------------------------------------------------
View this thread: http://www.wirelessforums.org/showthread.php?t=38694
http://www.wirelessforums.org

 
Reply With Quote
 
 
 
 
Jeff Liebermann
Guest
Posts: n/a

 
      02-14-2008, 12:16 AM
On Wed, 13 Feb 2008 12:35:43 -0500, BrettMcClellan
<(E-Mail Removed)> wrote:

>Scenario - Windows 2000 Domain called ABC.com using IAS policies with
>PEAP authentication.


OK.

>Question - Does the authentication of a wireless client go as deep as
>the SID of the client to authenticate? Or just the computer and user
>account info?


No SID is used, which would authenticate the machine, not the user.
IAS is Microsoft's implimentation of RADIUS authentication.
<http://technet2.microsoft.com/windowsserver/en/library/e9a30a60-7f8b-435f-b210-d47c3b7ecb961033.mspx?mfr=true>
There's a sample transaction that gives an idea of what gets sent. It
varies by the type of connection.

>Could somebody create a domain the same as ABC.com and join their
>laptop to that domain using the same computer name, username and
>password as a computer on the real ABC.com domain. Then go into the
>building of ABC and get authenticated successfully onto the real ABC.com
>wireless network?


No. Authentication would fail at the RADIUS authenticator and MS-CHAP
challenge steps. What's missing is that the spoofed client does not
have a valid certificate. See above URL under "authentication
process". Note that the SID (system ID) is used with AD (Active
Directory) forests, which you're probably not running on W2K server.


--
# Jeff Liebermann 150 Felker St #D Santa Cruz CA 95060
# 831-336-2558 (E-Mail Removed)
# http://802.11junk.com (E-Mail Removed)
# http://www.LearnByDestroying.com AE6KS
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Wireless Authentication Warren Windows Networking 0 11-28-2006 01:33 PM
WEP authentication, why WEP authentication scheme is flawed and how it can be attacked Johnny Wireless Internet 3 08-02-2006 03:44 AM
Wireless authentication: IAS Event 2 DPM Windows Networking 0 04-10-2006 03:42 PM
Wireless authentication prblms zuke Wireless Networks 1 11-16-2005 03:39 PM
wireless authentication kd Wireless Internet 1 10-28-2004 12:06 PM



1 2 3 4 5 6 7 8 9 10 11