Posts

Showing posts with the label WPA2

Wireless Security Methods - WEP, WPA1/2/3 & Personal and Enterprise

Image
Security is of the upmost importance when it comes to network and even more so when we are talking about Wi-Fi. Wi-Fi, as part of it's base fundamental is wireless and even with configuration options does go outside of your preferred area. This can cause a bit of an issue whereby someone can sit outside, with an adapter and monitor and potentially attack your wireless network. In this post, we will go over a high level description of the main security protocols out and about in the wireless world.  Thankfully keeping a handle of which ones are out there is quite simple. The Wi-Fi Alliance, setup in 1999 (by numerous companies to promote compatibility) owns the Wi-Fi trademark and subsequently develops the security protocols, which we'll discuss below.  There is four main Wi-Fi security protocols that you might see out and about and those are as follows, WEP, WPA, WPA2 and finally WPA3. Each have their pros and cons which we will also discuss on top of best practice configura...

WPA2 - RSN Information Element

Image
Within certain WLAN management frames (Beacons, Probe Response, Association Request, and Reassociation Request), there is the Robust Security Network Information Elements (RSN IE) in Wi-Fi Protect Access 2 (WPA2) capable networks. It sits in the Tagged Parameters part of the frame and displays the security capabilities of its associated Basic Service Set (BSS). Robust Secure Network (RNS) was created within the 802.11i amendment, Wired Equivalent Privacy (WEP) is not considered a valid Robust Secure Network (RSN) due to security vulnerabilities which is one of the main reasons for 802.11i being created in the first place and a result will not contain any RSN information. There are three sections that we are going to look at today those being the Pairwise Cipher Suite, Group Cipher Suite, and the Authenticated Key Management (AKM) suite with the overall layout of all three shown below from a packet capture I did. Depending on the configuration of the BSS (Personal and Enterprise) t...