| View previous topic :: View next topic |
| Author |
Message |
Rottweiler EVDO User
Joined: 20 May 2006 Posts: 34 Location: Heber Springs, Arkansas
|
Posted: Sat Apr 19, 2008 1:52 pm Post subject: Is the CTR350 secure? |
|
|
I'm going to be taking my CTR350/UM150 on vacation. I'll be staying a condo for a week and don't want to pay the resort's confiscatory rates for wifi access so I'm bringing my own "free" access.
I was thinking about leaving the wireless with no security and allow any of the other guests to use it if they wish. (I won't be using it that much; no skin off my back if they glom a bit of free surfing.)
But I don't want anyone to crack into the CTR web interface or otherwise muck with it. Can I allow open access and not worry?
If I decide to log into the CTR350 could they potentially read my password as I log in to the admin interface wirelessly? |
|
| Back to top |
|
 |
manganos EVDO User
Joined: 09 Jun 2007 Posts: 52 Location: Dinwiddie, VA
|
Posted: Sun Apr 20, 2008 5:46 pm Post subject: |
|
|
If someone can find out the mac address of your router you are SOL. They can really mess ya up Run the basic setup and you will be good to go.  |
|
| Back to top |
|
 |
Rottweiler EVDO User
Joined: 20 May 2006 Posts: 34 Location: Heber Springs, Arkansas
|
Posted: Sun Apr 20, 2008 6:32 pm Post subject: |
|
|
| manganos wrote: | If someone can find out the mac address of your router you are SOL. They can really mess ya up  |
Thanks. What can they do by knowing the MAC address? |
|
| Back to top |
|
 |
andy6432668 EVDO User
Joined: 02 Jun 2005 Posts: 50
|
Posted: Sun Apr 20, 2008 7:00 pm Post subject: |
|
|
| They can turn that router into a paper weight ! |
|
| Back to top |
|
 |
tz1 EVDO Junkie
Joined: 29 Sep 2005 Posts: 432 Location: http://kr1gps.dyndns.org:8888/
|
Posted: Mon Apr 21, 2008 7:06 am Post subject: |
|
|
Change the administration password to something reasonably strong (that doesn't include the digits of the MAC address like the default password).
That should make it sufficiently secure. (And if it is open, few would bother trying to get into the admin interface). |
|
| Back to top |
|
 |
rally1 EVDO Newbie
Joined: 27 Sep 2005 Posts: 10
|
Posted: Mon Apr 21, 2008 12:18 pm Post subject: |
|
|
Yes they can read you password very easily with a free program such as airsnort or similar new ones. Just like when you are sitting in the airport or hotel and using unencrypted wifi.
Will they, probably not. |
|
| Back to top |
|
 |
dario EVDO Fledgling
Joined: 03 Jan 2008 Posts: 12
|
Posted: Mon Apr 21, 2008 1:17 pm Post subject: Re: Is the CTR350 secure? |
|
|
| Rottweiler wrote: | I'm going to be taking my CTR350/UM150 on vacation. I'll be staying a condo for a week and don't want to pay the resort's confiscatory rates for wifi access so I'm bringing my own "free" access.
I was thinking about leaving the wireless with no security and allow any of the other guests to use it if they wish. (I won't be using it that much; no skin off my back if they glom a bit of free surfing.)
But I don't want anyone to crack into the CTR web interface or otherwise muck with it. Can I allow open access and not worry?
If I decide to log into the CTR350 could they potentially read my password as I log in to the admin interface wirelessly? |
The only thing I would be wary of is....hmmm let say a user wanted to download the anarchist cookbook, download child images or email the whitehouse a bad message...Guess who the government would be coming after. In this day, I would be cautious on leaving your network open. Messing around with my router will be least of my concerns. |
|
| Back to top |
|
 |
Rottweiler EVDO User
Joined: 20 May 2006 Posts: 34 Location: Heber Springs, Arkansas
|
Posted: Mon Apr 21, 2008 2:39 pm Post subject: |
|
|
| andy6432668 wrote: | | They can turn that router into a paper weight ! |
How? |
|
| Back to top |
|
 |
rickey318 EVDO User
Joined: 07 Mar 2008 Posts: 87 Location: Shreveport, LA
|
Posted: Mon Apr 21, 2008 3:42 pm Post subject: |
|
|
| andy6432668 wrote: | | They can turn that router into a paper weight ! |
True!! But who will want to be hacking a router that offers them free internet at a (I bet High Price) resort???  |
|
| Back to top |
|
 |
manganos EVDO User
Joined: 09 Jun 2007 Posts: 52 Location: Dinwiddie, VA
|
Posted: Mon Apr 21, 2008 7:13 pm Post subject: |
|
|
| Point is that you don't want anyone you don't know (even some you do know) using your internet connection to get on the net. Someone at my work just got charged with 30 counts of child porn. Maybe he is guilty or maybe someone sat outside of his home with a laptop and used his connection b/c it was not secure. I don't want to take that chance. Password it and secure it the best you can. |
|
| Back to top |
|
 |
tz1 EVDO Junkie
Joined: 29 Sep 2005 Posts: 432 Location: http://kr1gps.dyndns.org:8888/
|
Posted: Tue Apr 22, 2008 9:47 am Post subject: |
|
|
| The "password" system CradlePoint implemented uses an encrypted MD5 with salt challenge scheme. It is NOT out in the open so airsnort won't by itself help, but I don't know how strong the mechanism is (and have doubts). |
|
| Back to top |
|
 |
rally1 EVDO Newbie
Joined: 27 Sep 2005 Posts: 10
|
Posted: Tue Apr 22, 2008 11:16 pm Post subject: |
|
|
| Except that the default password is the easily viewable MAC address. |
|
| Back to top |
|
 |
tz1 EVDO Junkie
Joined: 29 Sep 2005 Posts: 432 Location: http://kr1gps.dyndns.org:8888/
|
Posted: Wed Apr 23, 2008 8:16 am Post subject: |
|
|
| rally1 wrote: | | Except that the default password is the easily viewable MAC address. |
Worse, the default ESSID has the last three digits of the MAC address, and the others tend to be patterned.
It is a bit silly to have a default password that isn't blank or something like "default" when it is clearly visible. This is one of the "so smart it's stupid" things I find annoying about CradlePoint.
Security and reliability tend to require simplicity because too often measures can cancel out instead of combining to increase strength. |
|
| Back to top |
|
 |
|