Showing posts with label Wireless. Show all posts
Showing posts with label Wireless. Show all posts

Monday, November 30, 2009

VoIP Hacks: Tips & Tools for Internet Telephony



VoIP Hacks: Tips & Tools for Internet Telephony
O'Reilly Media | ISBN: 0596101333 | December 1, 2005 | CHM | 306 pages | 6 MB

Voice over Internet Protocol (VoIP) is gaining a lot of attention these days, as more companies and individuals switch from standard telephone service to phone service via the Internet. The reason is simple: A single network to carry voice and data is easier to scale, maintain, and administer. As an added bonus, it's also cheaper, because VoIP is free of the endless government regulations and tariffs imposed upon phone companies.

VoIP is simply overflowing with hack potential, and "VoIP Hacks" is the practical guide from O'Reilly that presents these possibilities to you. It provides dozens of hands-on projects
for building a VoIP network, showing you how to tweak and customize a multitude of exciting things to get the job done. Along the way, you'll also learn which standards and practices
work best for your particular environment. Among the quick and clever solutions showcased in the book are those for:

gauging VoIP readiness on an enterprise network
using SIP, H.323, and other signaling specifications
providing low-layer security in a VoIP environment
employing IP hardphones, analog telephone adapters, and softPBX servers dealing with and avoiding the most common VoIP deployment mistakes
In reality, "VoIP Hacks" contains only a small subset of VoIP knowledge-enough to serve as an introduction to the world of VoIP and teach you how to use it to save money, be more productive, or just impress your friends. If you love to tinker and optimize, this is the one technology, and the one book, you must investigate.



Saturday, September 12, 2009

Stay safe on a public wireless network


A few precautions to take when using wireless hotspots, to ensure that your computer’s security doesn’t land in a spot. Like everything technological, wireless hotspots are a boon and a bane. While they ensure quick and easy Internet access, they also pose big risks for your laptop.

First, communication over most public wireless networks is unencrypted, so that anyone on the same network can use some tools to read the data you transfer. Unless you’re communicating with your office via VPN (Virtual Private Network), which ensures a secure, encrypted channel even over the public network.

Second, rogue attacks are very easily executed on the public wireless network. One of these is the ‘evil twin’ attack. In this case, the attacker uses a laptop or other mobile device to place a wireless access point (WAP) close to your computer, one that gives a more powerful signal than the access point you intend to connect to. The name of such a ‘rogue’ network would probably be a known name, such as Linksys, so that you wouldn’t be suspicious about connecting. Once you do connect, all your data will flow through the attacker’s laptop to the Internet.

The third big risk is ‘over the shoulder’. Say you’re checking email or shopping online at a crowded cafĂ© or hotel lounge. There are chances of someone peeking at your usernames, passwords, and credit-card details as you enter them.

Here are a few ways in which you can guard against these risks.

• Take care while browsing
Public hotspots are definitely much less secure than your office networks. So try to avoid using them for transactions that require high levels of security, such as online banking or shopping. Reserve these for when you’re in a more secure environment.

• Use secure means
As far as possible, use VPNs for secure communication. Access email via Secure Socket Layer (SSL) sessions—many email providers support these. You could also avoid going to websites that require you to send sensitive information in clear-text, unencrypted format.

• Avoid evil twin attacks
To guard yourself against an evil twin attack while you’re trying to connect to a public network, carefully observe the icons on the screen that shows available network connections. If any icon shows two computers connected together, it’s a peer-to-peer network, something that’s used in evil twin attacks. Do not connect to such a network—the legitimate network would have the icon of a light beacon, and if it supports encryption, you will also see a padlock icon next to it. Prefer to connect to such an access point.

You can also tweak your Windows settings to avoid evil twin attacks. From the Wireless Networks panel, you can disable automatic connections; you can also configure your machine to “Connect to access point (infrastructure) networks only”. You could also give your home network a distinct name that cannot be confused with the names of other networks, so that there is less possibility of connecting to an ‘evil twin’ from home.

• Turn off all sharing
Your laptop may be configured for file and printer sharing. You should turn that off when you’re using a public hotspot. If you use share programs such as iTunes or have other shared directories on your laptop, you should turn those off too, unless you want to share your music and other preferences with a lot of strangers.

• Remember the basics
As always, the last line of defense is on your machine—a personal firewall and anti-virus and anti-spyware software are crucial. You should also have applied all the latest security patches to update

How to Secure a Wireless Network


Wireless networks are extremely convenient, but that convenience comes at a price: security. With a traditional wired network, data is channeled through cables and cannot be easily intercepted. With a wireless network, data is beamed through the sky and can be more easily intercepted – unless, that is, you have appropriate security measures in place. This article explains how to secure a wireless network against attack.

Before outlining the steps you should take to secure a wireless network, let’s quickly look at a couple of things that you probably don’t want to do: namely, disabling SSID broadcasting and enabling MAC filtering. The SSID is the name of your wireless network and its broadcast to enable people to easily find and connect to your network. Numerous Websites – in fact, just about every Website - recommend disabling SSID broadcasting (if the bad guys can find it they can hack it, right?) and enabling MAC filtering. However, MAC filtering is so easily bypassed as to render it almost completely redundant. With regards to SSID broadcasting, you can read more about this here.

So, if you shouldn’t disable your SSID broadcast, what should you do? Read on!

1. Use encryption. To stop outsiders being able to data this transmitted over your wireless network, the data should be encrypted. There are 3 wireless encryption standards: WEP, WPA and WPA2. WEP is the oldest and most easily cracked standard, so ideally you should use WPA or, better yet, WPA2.

2. Change the default account names and passwords. The majority of access points (APs) use default account names/passwords set by the manufacturer that are known to one and all. Change them to something unique.

3. Segment your network. Even when best practice is adhered to, a wireless network will be less secure than a wired network. Segmentation creates a barrier between the physical network and wireless network – by using a firewall, for example - and enables you to control access/communication between them. Unfortunately, this can be a somewhat complex job and, unless you have a fair amount of in-house expertise, you’ll probably need to retain the services of a consultant.

4. Authenticate users. RADIUS provides you with far more control over access to the WLAN. For more information, visit Microsoft's overview on securing wireless LANs with certificate services and the FreeRADIUS Project.

5. Update your firmware. The manufacturers of AP devices often release firmware updates to fix bugs and security vulnerabilities. So, keep your firmware updated.
Security is only as strong as its weakest link. Long and too often the wireless network is the weakest link. In simple environments, the network can probably be DIY’d; however, security matters do become more challenging in complex environments and in such cases the best advice may well be to leverage the expertise of a consultant.

One final bit of advice: the value of securing your own wireless network will be eroded if your data is bounced in unencrypted form over other networks. Educate your users and make sure that they are aware of the risks associated with connecting to an insecure network.