Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1
All right now we've seen some pretty scary stuff in this section and this lecture.
2
I want to talk about how to prevent some of these attacks or securing our networks from them.
3
So the first thing that we spoke about was captive portals and we see how we can gain access to these
4
networks using three methods.
5
And even if the first two methods didn't work then the third would rely on the users and will gain access
6
as shown that proves that a captive portals are not secure at all.
7
So in order to get the functionality of a captive portal but stay secure the best thing to do is to
8
use WPA enterprise with a radius server and then give each user an individual username and password.
9
This way you can still prevent some people from connecting.
10
You can still disable some of the passwords.
11
Who can control these users and see each what each one of them is doing.
12
But at the same time the people authenticate using the WPA or WPA to authentication procedure.
13
So it's much more secure.
14
The data is going to be sent encrypted so people that are not connected to the network cannot sniff
15
it.
16
They can't just connect and do IRP spoofing.
17
And at the same time you're getting the same functionality that you'll get from a captive portal.
18
Next we've seen how easy it is to crack WEP with S-K with shared key authentication so it goes without
19
saying don't use web.
20
Regardless of how you implement it even if you think that you implemented it in a more secure manner
21
just don't use work period.
22
Next is WPX and we see how we can force some routers to have their password or their pen.
23
Again there are secure ways of implementing them.
24
P.s. if you disable push button authentication and lock after a number of failed attempts but again
25
if you want to be secure just disable WPX.
26
That'll just make griever not work at all.
27
Then we see more advanced worthless attacks.
28
So if WEP is not used WPA as is enabled.
29
We're talking about you using the BPA or WPA too.
30
And the only way to gain access to your network is use in word that I can receive advice to all these
31
attacks where we can use big words lists and save and restore our programs and use the GPL for cracking
32
to make it faster.
33
No all of these are still worthless attacks.
34
So if you use a long password say minimum of 16 characters with letters numbers and symbols then it's
35
going to be very very difficult to get your password even using the methods that I showed you right
36
now.
37
Obviously the longer the password the harder it is to get the key for it because it's a word this attack.
38
So the key has to be there in the wordlist that the hacker is using.
39
Now the last method that we've seen and we said that this is the last resort is used in an evil to an
40
attack.
41
And we see how we can use that to gain access to WPA or WPA to networks and we also see how to use that
42
to gain access to captive portals.
43
Now in both of these methods we're relying on the humans on the users that use the network.
44
So when it goes down to that then there is nothing you can do in terms of the software or the hardware.
45
The hacker is literally exploiting the people that use the network.
46
So the only thing you can do in this case is educate your users.
47
So if you have a small group of users you can just have a talk and tell them here look this is an attack
48
that can be used.
49
Be careful from it if you get the authenticated or disconnected from your network.
50
Make sure when you connect that you connect to the same network and make sure that the network you're
51
connecting to is actually using encryption.
52
So it's not an open network.
53
Also tell them never enter the network key in a web interface because as we seen when we're running
54
the evil twin attack we always ask for the password and a web interface.
55
So make sure that your users know.
56
They should never answer the key and a web interface.
57
And if they already enter the key they'll never be asked for it again unless they clicked on Forgot
58
the network which they should know.
59
So to summarize if you want to secure your network from the Ganey got attacks that we've seen so far.
60
First don't use captive photos implementable Dhupia enterprise if you want a similar functionality to
61
never use WEP three disable W.P. as for use WPA or WPA too with a complex password of letters characters
62
numbers and symbols.
63
5.
64
Educate your users to make sure they to be victims of a social engineering attack.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.