Windows XP system wireless network security

  

Win XP has been quite popular, but for Win XP system, how to set up wireless network security, we may not understand, then how to set up?

Although the early wireless networks have not been carried out for special reasons, they have not been able to attract network attention for quite a long time. Now, with the shift of wireless prices, it has entered the homes of ordinary people, and more and more netizens have used wireless networks. Wireless security has drawn increasing attention from all walks of life.

The objective cause of the instability of wireless network security is still viruses and malicious users. It: service theft, data theft, data corruption, and the normal use of wireless networks. The following steps will be answered for the reader!

Or the above sentence: "Simple is synonymous with insecurity", the biggest factor of XP's wireless security risk, it is the easiest from XP Easy-to-use function ——"Wireless zero configuration" (WIRELESS? ZERO? CONFIGURATION), since the access point can automatically send and receive signals, the XP client can automatically enter the coverage of the wireless network signal once it is available. Establish a connection. If the signal coverage of multiple wireless networks is entered, the system can automatically contact the nearest access point and automatically configure the network card to connect. After the completion, the established connection will appear in the “Available Network”. SSID, because many vendors use the half MAC address of the network card to name the SSID by default, so the SSID default name can be speculated. After the attacker knows the default name, at least the network connected to the access point is a breeze.

There are three main measures:

1. Enable the non-broadcast function of the wireless device without spreading the SSID.

This function needs to be found in the options of the hardware device. When enabled, the network will be closed.

At this time, the person who wants to connect to the network must provide an accurate network name instead of the XP system. Network name.

2. Use an irregular network name and disable the default name.

If you don't broadcast, the attacker can still connect to the network by guessing the network name, so it is necessary to change the default name.

The irregularities here can be borrowed from the password setting technique, and the network name with sensitive information is not set.

3, client MAC address filtering

Set only the client with the specified MAC can connect to the access point, you can further check the connecter.

The above three methods are only the primary settings of XP wireless security. Don't expect to set aside these three steps to be able to sit back and relax. From the current security settings, although you can guard against some wireless attacks, However, since no encryption is applied to the data in the transmission, as long as the attacker uses some specific wireless LAN tools, it can capture various data packets in the air, and through the content analysis of these data packets, The various information, including the SSID and MAC address, so the first three methods are ineffective for this kind of attack. The next step we face is the encryption problem of wireless transmission---WEP.

This is a very controversial topic. Therefore, in order to avoid getting into the misunderstanding, we will not explain the strengths and weaknesses of this issue in detail, only one sentence: “WEP provides wireless LAN From data security, integrity to data source authenticity, comprehensive security, but WEP's key is easy to get attackers. Although the current manufacturers have strengthened this, Microsoft has released related upgrade packages (KB826942, support.microsoft.com/default.aspx?scid=kb;zh-cn;826942), but this problem cannot be solved fundamentally. .

WEP runs on the access point. If we enable WEP on 2000, we must use the shared key provided by the client software. If it is XP, it will not be needed, and the system will be at first. When the secondary access is enabled for WEP, you can continue the following configuration after entering the key:

1. Open “network connection", click the properties of the wireless network card.

2. Select “Preferred Network", select or add an entry, then click Properties.

3, open the "wireless network properties", then do the following:

1) modify the "network name"

2) will "data encryption" ( WEP)”Tick

3)Tick "Network Authentication" to check

4) Select the "Key Format" for matching access points (ASCII or hexadecimal) System) and "key length" (40 or 104).

5) You need to enter the correct "network key"

6) Do not select “automatically select the key”.

4, save off.

OK, the settings for WEP under XP are basically completed, but in order to make the wireless network more stable, let us look at other security measures that need attention:

1. In the network Include as much as possible an authentication server.

Configuring the network to all connection requests must first pass the verification of the authentication server, which will greatly improve the security of the wireless network.

2, modify the WEP key once a month

Because WEP has a record defect, it is best to modify the WEP key every once in a while.

3, to avoid wired and wireless network interconnection.

Wireless networks should be independent. To avoid mutual involvement and avoid increased security risks, separate wired and wireless networks, at least between them.

4, establish VPN authentication

Add a VPN server between the access point and the network, so that an attacker may be able to connect to the access point, but only a dead crab Only, can't enter the network, can't make any damage to the network.

5, regular maintenance

The maintenance content is to check the network and audit logs, check the network can use some scanning tools to attack the wireless network, Netstumbler (.netstumbler.com/">www .netstumbler.com)

Kismet www.kismetwireless.net

The focus of the review log is to review account login events.

Finally, check the list of Ed Bott's wireless network:

1. Set a strong password for the access point.

2. Disable the remote management function of the access point.

3. The firmware of the wireless network device (FirmWare) is kept up to date.

4. Modify the default name of the network name of the access point.

5, use MAC filter control

6, enable WEP and set a strong password.

Copyright © Windows knowledge All Rights Reserved