Overclock.net › Forums › Software, Programming and Coding › Networking & Security › WPS on Spare router as Access Point
New Posts  All Forums:Forum Nav:

WPS on Spare router as Access Point - Page 2

post #11 of 18
Thread Starter 
Quote:
Originally Posted by dushan24 View Post

Quote:
Originally Posted by werds View Post

Ok I know people skim a lot but did you not catch the first line that said I understand why and normally have it de-activated? I only activate it maybe 2 or 3 times a year for an evening when I have guests that I do not want to walk around helping 6 to 8 people punch in a rather LONG password to get on my network...

It was a simple technical question that I resolved. It would have been more helpful if instead of a blanket "DONT DO IT! WPS BAD", people could have answered the question and then explained why it is a good idea NOT to have WPS active for those that do not know or understand.

I originally wasn't going to post again in this thread because of the first less than useful response but decided the community only improves through sharing information. That information being that WPS would work in the situation I discussed, and any person implementing it should be allowed to make their own threat assessment as to whether they wish to run WPS or not based on information placed forth...

You didn't actually say specifically you knew of this issue :-)

Yes, it annoys me too when people don't answer the question being asked.

But I though I did answer it.
My answer was don't use WPS and just enter the key and have the DHCP assign addresses.

Anyway, no need to start a pointless argument, I'm glad your issue is resolved.

PS: Also, someone else viewing this thread might not know about ReaverWPS so I think it's good it was mentioned.

You are right I didn't specifically say it lol and the post I just made was more aimed towards the general public (partially also because of my annoyance tbh) as it annoys me when people in general ignore the main question in a thread or fail to address it in any way. I should have noted a thank you that you pointed out the specific issue that WPS has lol. No argument being looked for on my part - just hoping people make more complete helpful posts (as that is how our community will continue to grow - hell it was the reason I joined OCN!)

 

@PCC - TBH I do not have first hand knowledge but from what I was told by a friend more into wardriving than I was that WPS tends to have very very weak pin security (I checked out of the 6 different routers I have by resetting them to factory defaults 4 of them only had 4 digit pins unless I manually changed them! One of them had an 8 digit pin by default as well). Now for the longest while I have always been using hexadecimal strings for my pins which is why adding someone manually is a pain for me. But anyways what I learned was that for some routers the program in question just basically brute forces the pin on WPS on some routers it can even do this even AFTER WPS had been disabled. Not sure if that is still the case though.

 

I am fortunate I live in an area with a decent amount of distance from home to home, making wardriving a little bit more conspicuous and probably less fruitful lol.

    
CPUMotherboardGraphicsRAM
i5 3570K Gigabyte GA-77X-UD5H IGP Intel HD4000 G.SKILL Ripjaws X Series 8GB (2x4GB) DDR3 1600 
Hard DriveOptical DriveOSMonitor
512gb Crucial M4 & 2x750GB WD Blacks in Raid 0 Lite-On iHAS424-98 Windows 7 Ultimate SP1 64-Bit Acer G24 24" 2ms@1920x1200 
KeyboardPowerCaseMouse
USB Keyboard SILVERSTONE ST1000-P 1000W Case Labs MH10 #1 Logitech Wireless 
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
i5 3570K Gigabyte GA-77X-UD5H IGP Intel HD4000 G.SKILL Ripjaws X Series 8GB (2x4GB) DDR3 1600 
Hard DriveOptical DriveOSMonitor
512gb Crucial M4 & 2x750GB WD Blacks in Raid 0 Lite-On iHAS424-98 Windows 7 Ultimate SP1 64-Bit Acer G24 24" 2ms@1920x1200 
KeyboardPowerCaseMouse
USB Keyboard SILVERSTONE ST1000-P 1000W Case Labs MH10 #1 Logitech Wireless 
  hide details  
Reply
post #12 of 18
Thread Starter 
Quote:
Originally Posted by dushan24 View Post

Quote:
Originally Posted by werds View Post

BTW - for those who also do not realize even with WPS disabled many routers are still susceptible to this brute force attack...

Installing DD-WRT should alleviate this issue,
It has no support for WPS.

Correct me if I'm wrong...?
(Though I'm confident I'm right since I 1: Read this on the DD-WRT site and 2: Run DD-WRT myself)

 

You are correct, none of my DDWRT routers can use their WPS buttons as it is not supported in any of the builds I have seen so far. I was testing out this little bit with one of my routers that still had stock on it because of the utility that WPS brings :)

 

Also I think it is fair to add something else I ran across today. Apparently WPS must be disabled on both the main router AND all access points. Disabling it at just one node still allows WPS access (decided to test a hypothesis after your earlier post lol)

    
CPUMotherboardGraphicsRAM
i5 3570K Gigabyte GA-77X-UD5H IGP Intel HD4000 G.SKILL Ripjaws X Series 8GB (2x4GB) DDR3 1600 
Hard DriveOptical DriveOSMonitor
512gb Crucial M4 & 2x750GB WD Blacks in Raid 0 Lite-On iHAS424-98 Windows 7 Ultimate SP1 64-Bit Acer G24 24" 2ms@1920x1200 
KeyboardPowerCaseMouse
USB Keyboard SILVERSTONE ST1000-P 1000W Case Labs MH10 #1 Logitech Wireless 
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
i5 3570K Gigabyte GA-77X-UD5H IGP Intel HD4000 G.SKILL Ripjaws X Series 8GB (2x4GB) DDR3 1600 
Hard DriveOptical DriveOSMonitor
512gb Crucial M4 & 2x750GB WD Blacks in Raid 0 Lite-On iHAS424-98 Windows 7 Ultimate SP1 64-Bit Acer G24 24" 2ms@1920x1200 
KeyboardPowerCaseMouse
USB Keyboard SILVERSTONE ST1000-P 1000W Case Labs MH10 #1 Logitech Wireless 
  hide details  
Reply
post #13 of 18
Quote:
Originally Posted by werds View Post

You are right I didn't specifically say it lol and the post I just made was more aimed towards the general public (partially also because of my annoyance tbh) as it annoys me when people in general ignore the main question in a thread or fail to address it in any way. I should have noted a thank you that you pointed out the specific issue that WPS has lol. No argument being looked for on my part - just hoping people make more complete helpful posts (as that is how our community will continue to grow - hell it was the reason I joined OCN!)

@PCC - TBH I do not have first hand knowledge but from what I was told by a friend more into wardriving than I was that WPS tends to have very very weak pin security (I checked out of the 6 different routers I have by resetting them to factory defaults 4 of them only had 4 digit pins unless I manually changed them! One of them had an 8 digit pin by default as well). Now for the longest while I have always been using hexadecimal strings for my pins which is why adding someone manually is a pain for me. But anyways what I learned was that for some routers the program in question just basically brute forces the pin on WPS on some routers it can even do this even AFTER WPS had been disabled. Not sure if that is still the case though.

I am fortunate I live in an area with a decent amount of distance from home to home, making wardriving a little bit more conspicuous and probably less fruitful lol.

All good smile.gif
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II SLI MSI GTX560 Ti TwinFrozr II SLI 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 1600MHz CL9 XMS3 (2 x 4GB) OCZ Vertex 3 SSD Western Digital Caviar Black 1TB 7200RPM 64MB C... Western Digital Caviar Green 1TB ~5900RPM 64MB ... 
Optical DriveCoolingOSMonitor
Lite-On 24x DVD-RW CoolerMaster V8 Windows 7 Professional SP1 3 x Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II SLI MSI GTX560 Ti TwinFrozr II SLI 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 1600MHz CL9 XMS3 (2 x 4GB) OCZ Vertex 3 SSD Western Digital Caviar Black 1TB 7200RPM 64MB C... Western Digital Caviar Green 1TB ~5900RPM 64MB ... 
Optical DriveCoolingOSMonitor
Lite-On 24x DVD-RW CoolerMaster V8 Windows 7 Professional SP1 3 x Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
post #14 of 18
Quote:
Originally Posted by werds View Post

Also I think it is fair to add something else I ran across today. Apparently WPS must be disabled on both the main router AND all access points. Disabling it at just one node still allows WPS access (decided to test a hypothesis after your earlier post lol)

Yep, that's correct.

Consumer routers aren't intelligent enough to work out that when bridged, if WPS is off on one than it should be off on the other.

Enterprise ones that are totally managed can do this though. However they generally don't have WPS as they are commonly used with 802.1x
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II SLI MSI GTX560 Ti TwinFrozr II SLI 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 1600MHz CL9 XMS3 (2 x 4GB) OCZ Vertex 3 SSD Western Digital Caviar Black 1TB 7200RPM 64MB C... Western Digital Caviar Green 1TB ~5900RPM 64MB ... 
Optical DriveCoolingOSMonitor
Lite-On 24x DVD-RW CoolerMaster V8 Windows 7 Professional SP1 3 x Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II SLI MSI GTX560 Ti TwinFrozr II SLI 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 1600MHz CL9 XMS3 (2 x 4GB) OCZ Vertex 3 SSD Western Digital Caviar Black 1TB 7200RPM 64MB C... Western Digital Caviar Green 1TB ~5900RPM 64MB ... 
Optical DriveCoolingOSMonitor
Lite-On 24x DVD-RW CoolerMaster V8 Windows 7 Professional SP1 3 x Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
post #15 of 18
I have a choice with the WPS buttons on my Intellinet access point and the software that came with my ASUS PCIe wireless NIC to generate varying lenght security codes (all the way from a minimum of 8 to a max of 64 characters).Is the use of the WPS button to generate a 64 character security key also considered a degradation in security?Some of the replies in the thread seem to imply that WPA2 is also easily broken.I ask if I make my network one of the harder to hack (harder not impossible) will a war driver simply pick an easier target (I can see two unsecured networks right now).What I have pulled out from my reading so far is simply the old ideas of not broadcasting a SSID who's name aids in the hack and as always the countinued use of strong passwords/passphrases.I was going to take a look today on how to increase security on an Asterisk PBX (perhaps a proxy).I am for any way to decrease the value of packets that are snatched out of the air.VPN and Radius are two techniques that are available,I now must decide if they get me to where I am trying to get to.

My main goal is not the protection of data I have accumulated but the unauthorized use of my network.This unauthorized use would be from the outside,not a family member on the inside as no one touches my gear.
Edited by PCCstudent - 10/30/12 at 9:18am
WC Rig
(13 items)
 
  
CPUMotherboardGraphicsRAM
i7-930@4.05GHz ASUS P6X58D-Preminum XFX GeForce 275 896mb 6GB Corsair TR3X6G1600C8D 
Hard DriveOptical DriveOSMonitor
WD 150gb Raptor LightScan Win 7 64-bit Acer 22" 
KeyboardPowerCaseMouse
G15 Corsair HX620W Antec 1200 several various 
Mouse Pad
none 
  hide details  
Reply
WC Rig
(13 items)
 
  
CPUMotherboardGraphicsRAM
i7-930@4.05GHz ASUS P6X58D-Preminum XFX GeForce 275 896mb 6GB Corsair TR3X6G1600C8D 
Hard DriveOptical DriveOSMonitor
WD 150gb Raptor LightScan Win 7 64-bit Acer 22" 
KeyboardPowerCaseMouse
G15 Corsair HX620W Antec 1200 several various 
Mouse Pad
none 
  hide details  
Reply
post #16 of 18
Quote:
Originally Posted by PCCstudent View Post

I have a choice with the WPS buttons on my Intellinet access point and the software that came with my ASUS PCIe wireless NIC to generate varying lenght security codes (all the way from a minimum of 8 to a max of 64 characters).Is the use of the WPS button to generate a 64 character security key also considered a degradation in security?Some of the replies in the thread seem to imply that WPA2 is also easily broken.I ask if I make my network one of the harder to hack (harder not impossible) will a war driver simply pick an easier target (I can see two unsecured networks right now).What I have pulled out from my reading so far is simply the old ideas of not broadcasting a SSID who's name aids in the hack and as always the countinued use of strong passwords/passphrases.I was going to take a look today on how to increase security on an Asterisk PBX (perhaps a proxy).I am for any way to decrease the value of packets that are snatched out of the air.VPN and Radius are two techniques that are available,I now must decide if they get me to where I am trying to get to.
My main goal is not the protection of data I have accumulated but the unauthorized use of my network.This unauthorized use would be from the outside,not a family member on the inside as no one touches my gear.

The length of the WPS pin does not matter in this case.
ReaverWPS attacks the system used to encrypt the PIN (which is very weak) rather than brute forcing the PIN itself.

Don't use WPS...

A VPN will do nothing to secure your wireless network from unauthorized access, it just encrypts your traffic across the internet not within the network itself. Proxying your VoIP (Asterix) again will not work for LAN traffic. Both these things are good security measures, but won't work for securing your WiFi. Furthermore, I get the impression you want to do this to "double encrypt" your packets being sent wirelessly. Don't bother, WPA2 already does this, and an attacker will capture your packets purely to extract a key for the wireless.

Hiding your SSID is also relatively pointless, people can still see the network...

RADIUS is good, but you need an LDAP server and other infrastructure to use it.

Regarding WPA2 itself, AFAIK there has been no reported break, I think the guy was saying that with the WPS exploit, it is easy to get by WPA2

PS: If there are open networks in range of you, I'd be surprised if anyone tried hacking yours...
Edited by dushan24 - 10/30/12 at 5:52pm
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II SLI MSI GTX560 Ti TwinFrozr II SLI 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 1600MHz CL9 XMS3 (2 x 4GB) OCZ Vertex 3 SSD Western Digital Caviar Black 1TB 7200RPM 64MB C... Western Digital Caviar Green 1TB ~5900RPM 64MB ... 
Optical DriveCoolingOSMonitor
Lite-On 24x DVD-RW CoolerMaster V8 Windows 7 Professional SP1 3 x Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II SLI MSI GTX560 Ti TwinFrozr II SLI 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 1600MHz CL9 XMS3 (2 x 4GB) OCZ Vertex 3 SSD Western Digital Caviar Black 1TB 7200RPM 64MB C... Western Digital Caviar Green 1TB ~5900RPM 64MB ... 
Optical DriveCoolingOSMonitor
Lite-On 24x DVD-RW CoolerMaster V8 Windows 7 Professional SP1 3 x Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
post #17 of 18
I wonder if it is bad manners to let people they are broadcasting unsecured.
WC Rig
(13 items)
 
  
CPUMotherboardGraphicsRAM
i7-930@4.05GHz ASUS P6X58D-Preminum XFX GeForce 275 896mb 6GB Corsair TR3X6G1600C8D 
Hard DriveOptical DriveOSMonitor
WD 150gb Raptor LightScan Win 7 64-bit Acer 22" 
KeyboardPowerCaseMouse
G15 Corsair HX620W Antec 1200 several various 
Mouse Pad
none 
  hide details  
Reply
WC Rig
(13 items)
 
  
CPUMotherboardGraphicsRAM
i7-930@4.05GHz ASUS P6X58D-Preminum XFX GeForce 275 896mb 6GB Corsair TR3X6G1600C8D 
Hard DriveOptical DriveOSMonitor
WD 150gb Raptor LightScan Win 7 64-bit Acer 22" 
KeyboardPowerCaseMouse
G15 Corsair HX620W Antec 1200 several various 
Mouse Pad
none 
  hide details  
Reply
post #18 of 18
Quote:
Originally Posted by PCCstudent View Post

I wonder if it is bad manners to let people they are broadcasting unsecured.
It's their problem for being stupid enough not to do it.
Securing a is so easy.
There is info online everywhere, even the manufacturers tell you to do it in the manual
And some new routers come pre-configured with a WPA2 key set...
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II SLI MSI GTX560 Ti TwinFrozr II SLI 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 1600MHz CL9 XMS3 (2 x 4GB) OCZ Vertex 3 SSD Western Digital Caviar Black 1TB 7200RPM 64MB C... Western Digital Caviar Green 1TB ~5900RPM 64MB ... 
Optical DriveCoolingOSMonitor
Lite-On 24x DVD-RW CoolerMaster V8 Windows 7 Professional SP1 3 x Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II SLI MSI GTX560 Ti TwinFrozr II SLI 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 1600MHz CL9 XMS3 (2 x 4GB) OCZ Vertex 3 SSD Western Digital Caviar Black 1TB 7200RPM 64MB C... Western Digital Caviar Green 1TB ~5900RPM 64MB ... 
Optical DriveCoolingOSMonitor
Lite-On 24x DVD-RW CoolerMaster V8 Windows 7 Professional SP1 3 x Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Networking & Security
Overclock.net › Forums › Software, Programming and Coding › Networking & Security › WPS on Spare router as Access Point