Tampilkan postingan dengan label tech-experience. Tampilkan semua postingan
Tampilkan postingan dengan label tech-experience. Tampilkan semua postingan

2011/06/26

Understanding WEP - WAP


Understanding WEP
Wireless security with the methods of Wired Equivalent Privacy (WEP)
WEP is a security & encryption standard first used on the wireless, WEP (Wired Equivalent Privacy) is a method of securing wireless networks, also called Shared Key Authentication. Shared Key Authentication is the authentication method that requires the use of WEP. WEP encryption uses a key that is inserted (by the administrator) to a client or access point. This key must match the given access point to the client, with the included client to authenticate to the access point, and has a standard 802.11b WEP.

Shared Key Authentication Process:
1. Client has asked the association to the access point, this step is the same as the Open System Authentication.
2. Access point sends challenge text to the client transparently.
3. Client will respond by encrypting the challenge text using the WEP key and sends back to the access point.
4. Access point responded to client feedback, access point will perform to decrypt encrypted responses from the client to verify that the encrypted challenge text using the appropriate WEP key. In this process, the access point will determine whether the client has given the appropriate WEP key. If the WEP key provided by the client are correct, then the access point will respond positively and directly to the client authentication. However, if the client entered the WEP key is incorrect, then the access point and client may respond negatively to will not be authenticated. Thus, the client will not be authenticated and not associated.

WEP has many flaws, among others:
1. The problem of weak keys, the RC4 algorithm used can be solved.
2. WEP uses a static key
3. Problem initialization vector (IV) WEP
4. Problem of message integrity Cyclic Redundancy Check (CRC-32)
WEP consists of two levels, namely 64 bit key, and 128 bits. Actually, the secret key in the WEP key 64 bit only 40 bit, 24bit is an Initialization Vector (IV). Likewise, the 128-bit WEP, 104bit secret key consists of.
WEP weaknesses include:
1. The attack on the weaknesses of the initialization vector (IV), often called the FMS attack. FMS stands for the third name the inventor of weakness IV Fluhrer, Mantin, and Shamir. This attack was done by collecting a weak IV as much as possible. The more weak IV is obtained, the sooner discovered the key that is used

2. Get a unique IV data obtained through the packet to be processed for WEP key cracking process more quickly. This method is called chopping attack, first discovered by h1kari. This technique only requires a unique IV thus reducing the need for IV are weak in WEP cracking.

3. Both of the above attacks require considerable time and packet, to shorten the time, the hackers usually do traffic injection. Traffic Injection is often done by collecting the ARP packet and then sends back to the access point. This resulted in the collection of initial vectors is easier and faster. Unlike the first and second, to attack traffic injection, required specification of tools and applications that start rarely found in stores, ranging from chipsets, firmware version, and versions of drivers, and not infrequently have to do the patching of drivers and applications.

Excess WEP
When users want to connect the laptop, the user does not change any settings, everything is automatic, and when you first about browsing, the user will be prompted to enter a username and password
Almost all wireless components already support this protocol.







Understanding WPA
Wireless Apliccation abbreviated protocol WAP is an open international standard for applications that use wireless communication. The main objective for building applications that can access the Internet from mobile phones or PDAs.

Abbreviated as WAP.
Standard protocol for wireless applications (such as those used in mobile phones). WAP is a protocol or a technique messaging service that allows a digital phone or a mobile terminal having a WAP facility, see / read the contents of a site on the internet in a special text format. This web site should be a site with a WAP facility.

This technology is the result of cooperation between industries to create an open standards (open standards) and based on Internet standards, as well as several protocols that have been optimized for wireless environments.

This technology works in text mode with a speed of about 9.6 kbps. Later also developed the GPRS protocol which has several advantages over WAP.

Wireless Application Protocol is a protocol development of wireless protocol data already exist. Phone.com created a version of the standard HTML (HyperText Markup Language) Internet protocols specifically designed to transfer information between mobile networks efficiently. Wireless terminal with HDML (Handheld Device Markup Language) microbrowser, and Handheld Device Transport Protocol (HDTP) from Phone.com connected with UP.Link Server Suite is so connected to the Internet or intranet where the information needed to be. The technology was later known as WAP.

Wireless security with the methods Accsess WI-FI Protected (WPA)
Is common knowledge if WEP (Wired Equivalent Privacy) is no longer able to be relied on to provide a wireless connection (wireless) are safe from nosy people act or want to take advantage of what we have-known hackers jargon. Not long after the development process of WEP, the fragility of the cryptography aspects emerge.
Various studies have been conducted on WEP and obtained the conclusion that although a wireless network protected by WEP, third parties (hackers) can still be breaking into. A hacker who has a makeshift wireless equipment and software equipment used to collect and analyze enough data, can know the encryption key used.
Addressing the weaknesses that are owned by WEP, has developed a new security technique known as WPA (WiFi Protected Access). WPA technique is a model compatible with the IEEE 802.11i draft standard specification. This technique has several goals in its design, the sturdy, interoperates, can be used to replace WEP, can be implemented on a home or corporate user, and is available to the public as quickly as possible. The existence of WPA "replace" WPE, is it true feeling of "calm" is obtained? There are many pros and cons comments about it. Some say, WPA has a stronger encryption mechanism. However, there are pessimistic because of the communication path used is not safe, where the engineering man-in-the-middle can be used to outsmart the process of sending data. In order for WPA goal is achieved, at least two major security development done. WPA technique was established to provide development data encryption WEP is a weak point, and provides user authentication, which seems lost on developing the concept of WEP.
WPA technique was designed to replace WEP security method, which uses static security key, using TKIP (Temporal Key Integrity Protocol) which can be dynamically changed after 10,000 packets of data transmitted. TKIP protocol will take the primary key as a starting point which is then regularly changed so there is no encryption key is used twice. Background process is automatically carried out without being noticed by the user. By performing encryption key regeneration approximately every five minutes, the WiFi network that uses WPA has been slowing hackers who try to make key cracking earlier.
Although using the standard 64 and 128 bit encryption, like those of technology WEP, WPA TKIP making becomes more effective as an encryption mechanism. However, the problem of decrease in throughput as complained by the users of such wireless networks do not meet the standard answer from the documents sought. Therefore, the problems associated with the throughput is very dependent on the hardware you have, the more specific is the chipset used. The assumption at this time, if the throughput reduction occurs in the implementation of WEP, the rate of decline will be much greater if the WPA and TKIP implemented although some products claim that the decline in throughput has been overcome, of course, with greater use of the chipset capabilities and capacity.
WPA authentication using 802.1x and EAP (Extensible Authentication Protocol). Taken together, these implementations will provide a solid framework on the user authentication process. Framework will be done utilizing a centralized authentication server, such as RADIUS, to authenticate users before joining the wireless network. Also introduced mutual authentication, so users of wireless networks did not knowingly join another network that might steal its network identity.
Mechanism AES encryption (Advanced Encryption Standard) is likely to be adopted WPA with a user authentication mechanism. However, AES is apparently not necessary because the predicted TKIP encryption is able to provide a framework that is very tough, although not yet known for how long the tough can survive.


Target users (authentication key distribution)

• WPA-Personal: Also referred to as WPA-PSK (pre-shared key) mode. Designed for home and small office network and does not require server authentication. Each wireless network device to authenticate with the access point using 256-bit keys are equal.

• WPA-Enterprise: Also referred to as WPA-802.1x mode, and sometimes only WPA (as opposed to WPA-PSK). Designed for corporate networks, and requires a RADIUS authentication server. This requires a more complicated setup, but provide additional security (eg protection against dictionary attacks). An Extensible Authentication Protocol (EAP) is used for authentication, which come in different flavors (eg EAP-TLS, EAP-TTLS, EAP-SIM).
Posted on 21.24.00 / 0 comments / Read More

2011/05/30

Privacy Policy

1. technology-experience.co.cc respect user privacy and does not collect users' personal information without prior notice. Web statistics are the sole property and personal technology-experience.co.cc and only used for troubleshooting purposes.
The information we collect
2. technology-experience.co.cc generally collects personally identifying information with your specific knowledge and consent. When you register to become a member and Faisalcarper.com subscribe to our services, you will be asked to provide information, such as your e-mail address, name and / or other information.

Use of this information
3. technology-experience.co.cc use this information to provide you with services you have requested. For example, if you subscribe to one of our newspapers, we may use your e-mail address to send confirmation notices.
4. We also may use this information to communicate with you about new features, products or services, or to improve the services we offer by tailoring them to your needs.
5. We may allow access to our database by third parties that provide us with services, such as technical repair or forums and job search software
, But only for the purpose and extent necessary to provide those services. technology-experience.co.cc bears no responsibility for the actions or policies of third parties.

Cookie
6. technology-experience.co.cc may use cookies to store some information that are placed by a Website in a storage area on your own computer. We use cookies to control the display of ads, to track usage patterns on the site, to deliver editorial content, and to record registration and personalization information. Our cookies may contain personal data and cookies can be shared with our affiliated companies.
7. Some of our advertisers occasionally serve you cookies as well. We do not have control over cookies placed by advertisers. As a result of your visit to our site, ad server companies may collect information such as your domain type, your IP address and clickstream information.
8. If you do not want cookies stored on your computer, your Web browser probably will include options that allow you to not accept cookies. However, if you set your browser to refuse cookies, some Faisalcarper.com may not function properly.

Ad Server
9. To try and bring you offers that interest you, we have relationships with other companies like Google (www.google.com / adsense) that use of the DART cookie allows, Chitika, etc. that place ads on our web site. As a result of your visit to our site, ad server companies, with the help of cookies, may collect information such as your domain type, your IP address and clickstream information. For more information, consult the privacy policies of each website. Google's Privacy Policy and how to opt out of the DART cookie users is available on the Google ad and content network privacy policy.
10. While your personal information is protected as outlined above, we reserve the right to use aggregated anonymous data about our users as a group for business purposes, such as analyzing usage trends and seeking compatible advertisers and partners.

Child
10. technology-experience.co.cc not intended for use by minors or children, especially under the age of 18. No one under the age of 18 are allowed to provide personal information or use our public discussion areas, forums, and / or chat. Children between the ages of 13 and 17 must get permission from their parent (s) or legal guardian (s) before using our services, including registration and / or subscription to our services offered by this site.
11. If your children disclose information about themselves in public places our discussions, they may get unsolicited messages from other parties. technology-experience.co.cc not responsible for any action by your children when using our service, with or without your consent.

Links to other Web sites
12. This web site contains links to other websites. Please note that when you click one of these links, you move to another website. We encourage you to read the privacy statements of related sites as their privacy policies may differ from us.

Revisions to this Privacy Policy
13. This Privacy Policy may be modified from time to time without prior notice to the visitors. Continued access of technology-experience.co.cc by you will constitute your acceptance of any changes or revisions to the Privacy Policy. This is the purpose technology-experience.co.cc to carry information tailored to your individual needs and, at the same time, protect your privacy.

Contacting Us
14. This is the website technology-experience.co.cc You can contact us at the contact page. If you feel that this site is not following the policy of other information, you can contact us at the address above.
Posted on 01.53.00 / 0 comments / Read More

Contact Us

Please contact us in yudiirawan24@gmail.com
Posted on 01.36.00 / 0 comments / Read More

Tech More

 
Copyright © 2011. Tech-eXperience . All Rights Reserved
Home | Contact Us | Privacy policy | Term of use | Widget | Site map