Discuss EVDO PC Cards, ExpressCards, EVDO USB, PDAs, Phones, Coverage and Mobile Broadband Cards. Discuss Verizon and Sprint Coverage. CradlePoint CTR350 / PHS300/ MBR1000 & Kyocera KR1 / KR2 & LinkSys WRT54G3G-ST Forums!
EVDOforums.com
Discussion forum for EVDO users
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Our sites Include: EVDO Info :: EVDO Forums :: EVDO Maps :: EVDO Blog :: 3Gstore.com

To purchase your EVDO Card / Antenna / Amplifier / Router from the EVDO Experts, just contact us!

Is the CTR350 secure?

 
Post new topic   Reply to topic    EVDOforums.com Forum Index -> CradlePoint CTR350 / CTR500 / PHS300 / MBR1000 EVDO Router Support Forum
View previous topic :: View next topic  
Author Message
Rottweiler
EVDO User


Joined: 20 May 2006
Posts: 34
Location: Heber Springs, Arkansas

PostPosted: Sat Apr 19, 2008 1:52 pm    Post subject: Is the CTR350 secure? Reply with quote

I'm going to be taking my CTR350/UM150 on vacation. I'll be staying a condo for a week and don't want to pay the resort's confiscatory rates for wifi access so I'm bringing my own "free" access.

I was thinking about leaving the wireless with no security and allow any of the other guests to use it if they wish. (I won't be using it that much; no skin off my back if they glom a bit of free surfing.)

But I don't want anyone to crack into the CTR web interface or otherwise muck with it. Can I allow open access and not worry?

If I decide to log into the CTR350 could they potentially read my password as I log in to the admin interface wirelessly?
Back to top
View user's profile Send private message
manganos
EVDO User


Joined: 09 Jun 2007
Posts: 52
Location: Dinwiddie, VA

PostPosted: Sun Apr 20, 2008 5:46 pm    Post subject: Reply with quote

If someone can find out the mac address of your router you are SOL. They can really mess ya up Smile Run the basic setup and you will be good to go. Smile
Back to top
View user's profile Send private message
Rottweiler
EVDO User


Joined: 20 May 2006
Posts: 34
Location: Heber Springs, Arkansas

PostPosted: Sun Apr 20, 2008 6:32 pm    Post subject: Reply with quote

manganos wrote:
If someone can find out the mac address of your router you are SOL. They can really mess ya up Smile

Thanks. What can they do by knowing the MAC address?
Back to top
View user's profile Send private message
andy6432668
EVDO User


Joined: 02 Jun 2005
Posts: 50

PostPosted: Sun Apr 20, 2008 7:00 pm    Post subject: Reply with quote

They can turn that router into a paper weight !
Back to top
View user's profile Send private message
tz1
EVDO Junkie


Joined: 29 Sep 2005
Posts: 432
Location: http://kr1gps.dyndns.org:8888/

PostPosted: Mon Apr 21, 2008 7:06 am    Post subject: Reply with quote

Change the administration password to something reasonably strong (that doesn't include the digits of the MAC address like the default password).

That should make it sufficiently secure. (And if it is open, few would bother trying to get into the admin interface).
Back to top
View user's profile Send private message
rally1
EVDO Newbie


Joined: 27 Sep 2005
Posts: 10

PostPosted: Mon Apr 21, 2008 12:18 pm    Post subject: Reply with quote

Yes they can read you password very easily with a free program such as airsnort or similar new ones. Just like when you are sitting in the airport or hotel and using unencrypted wifi.

Will they, probably not.
Back to top
View user's profile Send private message
dario
EVDO Fledgling


Joined: 03 Jan 2008
Posts: 12

PostPosted: Mon Apr 21, 2008 1:17 pm    Post subject: Re: Is the CTR350 secure? Reply with quote

Rottweiler wrote:
I'm going to be taking my CTR350/UM150 on vacation. I'll be staying a condo for a week and don't want to pay the resort's confiscatory rates for wifi access so I'm bringing my own "free" access.

I was thinking about leaving the wireless with no security and allow any of the other guests to use it if they wish. (I won't be using it that much; no skin off my back if they glom a bit of free surfing.)

But I don't want anyone to crack into the CTR web interface or otherwise muck with it. Can I allow open access and not worry?

If I decide to log into the CTR350 could they potentially read my password as I log in to the admin interface wirelessly?


The only thing I would be wary of is....hmmm let say a user wanted to download the anarchist cookbook, download child images or email the whitehouse a bad message...Guess who the government would be coming after. In this day, I would be cautious on leaving your network open. Messing around with my router will be least of my concerns.
Back to top
View user's profile Send private message
Rottweiler
EVDO User


Joined: 20 May 2006
Posts: 34
Location: Heber Springs, Arkansas

PostPosted: Mon Apr 21, 2008 2:39 pm    Post subject: Reply with quote

andy6432668 wrote:
They can turn that router into a paper weight !

How?
Back to top
View user's profile Send private message
rickey318
EVDO User


Joined: 07 Mar 2008
Posts: 87
Location: Shreveport, LA

PostPosted: Mon Apr 21, 2008 3:42 pm    Post subject: Reply with quote

andy6432668 wrote:
They can turn that router into a paper weight !


True!! But who will want to be hacking a router that offers them free internet at a (I bet High Price) resort??? Very Happy
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
manganos
EVDO User


Joined: 09 Jun 2007
Posts: 52
Location: Dinwiddie, VA

PostPosted: Mon Apr 21, 2008 7:13 pm    Post subject: Reply with quote

Point is that you don't want anyone you don't know (even some you do know) using your internet connection to get on the net. Someone at my work just got charged with 30 counts of child porn. Maybe he is guilty or maybe someone sat outside of his home with a laptop and used his connection b/c it was not secure. I don't want to take that chance. Password it and secure it the best you can.
Back to top
View user's profile Send private message
tz1
EVDO Junkie


Joined: 29 Sep 2005
Posts: 432
Location: http://kr1gps.dyndns.org:8888/

PostPosted: Tue Apr 22, 2008 9:47 am    Post subject: Reply with quote

The "password" system CradlePoint implemented uses an encrypted MD5 with salt challenge scheme. It is NOT out in the open so airsnort won't by itself help, but I don't know how strong the mechanism is (and have doubts).
Back to top
View user's profile Send private message
rally1
EVDO Newbie


Joined: 27 Sep 2005
Posts: 10

PostPosted: Tue Apr 22, 2008 11:16 pm    Post subject: Reply with quote

Except that the default password is the easily viewable MAC address.
Back to top
View user's profile Send private message
tz1
EVDO Junkie


Joined: 29 Sep 2005
Posts: 432
Location: http://kr1gps.dyndns.org:8888/

PostPosted: Wed Apr 23, 2008 8:16 am    Post subject: Reply with quote

rally1 wrote:
Except that the default password is the easily viewable MAC address.


Worse, the default ESSID has the last three digits of the MAC address, and the others tend to be patterned.

It is a bit silly to have a default password that isn't blank or something like "default" when it is clearly visible. This is one of the "so smart it's stupid" things I find annoying about CradlePoint.

Security and reliability tend to require simplicity because too often measures can cancel out instead of combining to increase strength.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    EVDOforums.com Forum Index -> CradlePoint CTR350 / CTR500 / PHS300 / MBR1000 EVDO Router Support Forum All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum








Sprint Rev A USB: Compass 597



Sprint Rev A ExpressCard: Merlin EX720


Purchase an V740 Rev A ExpressCard


Sprint U727


CTR350 Router


CradlePoint PHS300


Purchase a MBR1000


Purchase an EVDO Booster Antenna

Purchase a LinkSys 3G Router



Purchase an EVDO Amplifier


Your Mac EVDO Experts









EVDO Antenna Booster





Digg Us :: del.icio.us :: technorati :: furl

4G :: 4G Forums :: PHS300 :: MBR1000 :: KR2