January 23, 2009

WIRELESS NETWORK SECURITY, WEP VS. WPA

In this article I want to discuss which is the better option on securing your wireless network, WEP or WPA?

WEP and WPA is the most commonly used counter measure against unwanted or illegal access on any wireless network, Most of this setup can be found at home, small-scale and even medium-scale businesses.

Using WEP and WPA are the easiest way of securing your wireless network. But nowadays those two encryptions are both hackable, even a noob hacker can crack a WEP or even WPA encryptions.

Here is the most common method that the hacker will do to crack your WEP/WPA keys :

WEP :

1. The hacker will disable first, the monitor mode of his wireless card.
2. After that, he will spoof its mac address to prevent himself for being caught or to pretend as an associate on the target network.
3. The hacker will use the monitor mode again in order to listen to the target network.
4. After the monitor mode, he will collect as many IV’s as possible to increase the chance of cracking.
5. Now he will use the ARP that he collected and use it to crack the WEP key of the target network.
WPA

1. The same procedure are applied, But for a hacker to success in cracking the WPA pass phrase, He must have a good dictionary. (a dictionary is a file that contains a huge number of different possible passwords/pass phrase that can be used by the hacker).
2. If in chance that your WPA pass phrase exist in the hacker’s dictionary, the hacker will surely crack the WPA.

Many software have been released to the public that is capable of cracking any WEP or WPA encryptions like Aircrack , Airsnort, even Backtrack (compilations of different hacking tools) that makes it easier for a noob hacker to crack it. As I’ve mentioned earlier cracking WEP and WPA are possible, but in case of WPA, the hacker must have a huge number of different passwords/pass phrase on his dictionary. So in order to avoid that your WPA pass phrase to be cracked, Use a combination of words and numbers, avoid using simple words, make your pass phrase a little unique that only you can understand. If your pass phrase does not exist on the hacker’s dictionary, there’s no way he can crack your WPA (at least for the noob hackers). But it’s still possible for a REAL and determined hacker to crack your WPA.

Now that you’ve got some ideas on how the cracking works, I’m sure that you can secure more you’re wireless network.

REMINDER
: Please avoid using WEP encryptions even it is 64/128 bit.
: On my next article I will give a step by step methods in cracking a
WEP encrypted network.

My Five Best Apps For Windows

I have a desktop PC at home with Windows XP (SP3) and Linux (Ubuntu Intrepid Ibex 8.10) running on it (dual boot), with a specs of 256mb ram, 32mb of VGA (shared), 900mhz Intel Celeron processor. You might think that this is not the best desktop PC that you will ever had, but for me, this computer is enough to satisfy my computing needs. Now here is my 5 favorite applications running under my Windows box.

RocketDock

RocketDock is a program with the functionality like Mac OS X dock developed by the PunkSoftware. You can add programs, files, folders on the dock for easy access. It lessens your work on using the start button to access different programs or by clicking the icons from the desktop. The dock contains icons that represents programs, folders and others. These features allow us (users) to launch any program at a single click.

RamMedic

RamMedic of Iomatic Inc. is a tool that optimizes the computer system memory. If your suffering from the slowness of your computer due to lack of computer memory then RamMedic is a must have program for you. Like me, who is fortunate enough to have 256mb of ram, multi-tasking was one of my biggest problem. Running multiple applications at the same time can cause slowness for my computer to process. So when I installed the RamMedic on my PC, it dramatically increases the processing speed of my computer. And now I can do some multi tasking without affecting the computer’s speed.

Launchy

Launchy is the most efficient way to open files, folders, websites, and programs on your computer. Nobody likes to hunt through the start menu to find an application, just to find that the application is hidden under some obscure folder named after a company you have never heard of! Instead, Launchy is a smart search program which tries to guess which program or file you are looking for and will launch it when you hit the enter key. It is only visible when you hit the alt+space key combination; otherwise it hides in the background. Once you have used it for a few days, it becomes an indispensable utility for your computer. And it’s free!

Unlocker


Unlocker is a nice program that forces a specific file to rename, delete and move to another directory. Sometimes we encountered some problems on deletion or moving of files, because some other programs are currently accessing your target file. Now Unlocker solves this problem for you, Unlocker basically kills the process of all the programs that are connected to your target file making it free to do specific task such as move, delete and rename.

FireFox Browser

The most popular web browser on earth! Firefox comes up with various add-ons that suits your needs. Because of this large number of add-ons that Firefox holds, it gains popularity by other users.

Sibolsoft.com.ph goes Open-Source


Sibolsoft announces their new project, called as “myDbase” (inspired by mysql with its DBMS capability). Sibolsoft encourage the local programmers (here in Baliuag) to participate/join to this Open-Source/Open Structure Project. Sibolsoft aims to developed a web-based application that can be run on localhost, that will help the user to design their own business program. Normally a desktop application usually offers their own standard design for a specific program, that makes it difficult for the user’s to apply their own business system. The lack of availability of a program routine that will suit the needs of the user is the most common problem that they encounter. Most of the program routines that you will find on “proprietary” software are highly technical which makes it very confusing for the user to comprehend. To overcome this problem, large-scale companies provide funds for the development and customization of the software that they are going to use for their own system. Unfortunately, Only large- scale business companies can afford to provide funding on their own software unlike with the small and medium-scale businesses that will rely on the availability of the software within the market.



Facing these problems, Sibolsoft comes up with the idea of creating application softwares that will allow the user to design/create their own business program from the way they want. Hoping for its rapid development, Sibolsoft decided to make “myDbase” as an “Open-Source” project, which means that the source-code of the program can be freely distributed to others. In effect, different programmers can study and modify the program to achieve a stable program. The goal for this project is to encourage developers to developed programs that will benefit the local community.



MyDbase was the pilot project of Sibolsoft with an Open Source principle, and hopefully the upcoming and existing projects will follow through. Carrying the open source principles.





Sibolsoft Image

DevFest Manila 2008

DevFest (Developer's Festival) was held at the UP Diliman Social Welfare Building. The said event was hosted by Google and sponsored by Globe and Smart Telecommunications. The Google Friends (the guys behind the said event) travels from country to country to encourage programmers like us to develop web apps (mini application) that can be ported to social network (social website e.g. friendster , myspace ) and this is what they called "OpenSocial". Using the google API or I might say their own API you can develop your own OpenSocial Application that can be used by other users through Social Networks,

Pamela Fox who started the talking, explains about this so called OpenSocial, followed by some guys from the Globe, who announces that there will be a GlobeLabs Challenge open for all developers who wants to create programs for sms/mms protocols.

The next guy who caught my attention was from the android team, well, definetly he's not an android xp, I've got interested when I heard about a phone running under a LINUX OS, and that was the ANDROID.Seeing some of his programs and being able to access google maps through that phone was a brilliant idea, but do you think it is enjoyable to view a map from a phone?? a tiny view of the map from a phone?? Seriously I don't like using google maps from a phone BUT this ANDROID still rocks.

The Friendster people talks about the OpenSocial and discuss some ways on how you can port your own application to Friendster itself. Using their API's you can actually create your own application and start making money. In fact in order to promote this OpenSocial Phenomena there will be a contest that will choose 4 winners for every country including the Philippines for the best OpenSocial Application. Other presentor came in like the Drupal guy who uses Drupal to create web apps.Pamela Fox returns at the stage for some presentation and explanation about google map api's and other api's and the last guy who talks about the youtube api.

All in all the event was really fun specially watching the Google friends dance on the floor, and of course a bit excited cause the I.T. development are growing bigger and better making more and more opportunities for I.T. people.
Powered By Blogger

Google News