Saturday, June 02, 2007

My Router

Belkin Router. Model number doesn't really matter the security hole is of my own making, not the routers fault.

I set up my router the way we set up the customers router at work. We use a 64 bit wep key , and the key is the mac address(last 10 digits) of the router, which is written on the back or bottom of the router. Works great , can't lose the key without losing the router, and can't steal the key without physically being in the house. Sounds very secure.

Got a call from a windows vista customer the other day to set up their wireless connection. During the process , it seems that windows vista wireless will tell you the Mac address of what it's trying to connect to. The customer actually read to me the mac and I could see on my screen it was the same as the one for the router I was trying to connect her to.

Oh oh.

Got home, checked the security logs on my router. Yup ! Some bugger (only one so far) was bumming a free ride on my router ! (through the router and into my cable modem and voila ! They have free high speed internet at my expense) They'd figured out to put in the mac id as the security key. I changed it immediately.

My goodness. We have so many customers that use the mac id for their security key ... this is going to be a serious problem when this leaks.

No comments: