Start networking and exchanging professional insights

Register now or log in to join your professional community.

Follow

Can Wi-Fi security be hacked? What is the best way to protect it?

user-image
Question added by Aamer Al Saiari , Collection Supervisior , National Commercial Bank NCB
Date Posted: 2016/02/14
Mikhail Vaskiyev
by Mikhail Vaskiyev , Director , Panasonic Marketing CIS Rep Office

Any kind of wireless data transmission can be hacked. The matter is just the cost difference of your data data to be protected and the requested efforts to hack them. The best way is to refrain from any wireless data transmission if possible

Mohammed Kaddoura
by Mohammed Kaddoura , Information Technology , Bekai Group

1- Hide your Network SSID

2-USE WPA Security

3-Disable WPS (Commonly used to hack wireless routers)

4-Filter Mac Address's ( Add yours and block all others)

5-Reduce range if possible

6-Use long passwords with numbers and better random (Unique)

 

Ahmad Alsuwaidi
by Ahmad Alsuwaidi , Area Manager , Emirates Global Aluminium (EGA)

Yes.WiFi  can bee hacked and this depends on the properties of the connection and skills of the hacker. For instance, if you are using WEP as the encryption protocol, the hacker could easily use free available software on the internet to hack you. However, if you are using WPA instead of WEP, it requires an experienced hacker with a powerful computer to decrypt the code. A research showed that 95% of hackers are using existing tools and programs to hack, while 5% or less of hackers are real skilled hackers who can develop codes and tools for hacking. In fact, most people get hacked due to silly mistakes made in which they provide the hacker with crucial information about their system. The less information hacker knows bout your system, the harder it is to acj it. As stated by others in previous posts, you can implement measures to help protect your network starting by having a strong password/key and a strong encryption. Despite that, communication security is a culture and there is not bullet proof solution to prevent hackers from jeopardizing your system.

Mohamed Aman Elhelw (MBA-ITIL)
by Mohamed Aman Elhelw (MBA-ITIL) , ICT Service Desk Team Leader , United Gas Derivatives Company

1- Create a unique password on your router

Once you have logged into your router, the first thing you should do to secure your network is to change the default password* of the router to something more secure.

This will prevent others from accessing the router and you can easily maintain the security settings that you want. You can change the password from the Administration settings on your router’s settings page. The default values are generally admin / password.

2- Enable Network Encryption

In order to prevent other computers in the area from using your internet connection, you need to encrypt your wireless signals.

There are several encryption methods for wireless settings, including WEPWPA(WPA-Personal), and WPA2 (Wi-Fi Protected Access version 2). WEP is basic encryption and therefore least secure (i.e., it can be easily cracked*, but is compatible with a wide range of devices including older hardware, whereas WPA2 is the most secure but is only compatible with hardware manufactured

karim marouf
by karim marouf , Team Manager , OASYS

The best way to protect you WIFI network is to personelize it. for example:

1. Include the MAC address in the connexion filtering (which means only devices with these mac address can get connected).

2. Hide you SSID (you do'nt need to broadcast it).

3. Use non regular band frequency. 

4. Ajust your Wireless Access point transmission power to make sure the signal will stayinside your company. So people from the neighboorhood will not even be able to scan it.

Yes it can be hacked.

Most of the points have been covered by other experts.

 

In addition to that

 

1. Some routers may have firewall on it. Enable and configure it.

2. Disable other protocols when not in use.

3. Change wifi password frequently. Have a complex password which is of high complexity.

4. Do not share passwords other than the ones whose devices you are allowing on the network.

Muhammad adnan Qumar
by Muhammad adnan Qumar , IT engineer , Synopsis Solutions Ltd

Step 1. Open your router settings page

First, you need to know how to access your wireless router’s settings. Usually you can do this by typing in “192.168.1.1” into your web browser, and then enter the correct user name and password for the router. This is different for each router, so first check your router’s user manual.

You can also use Google to find the manuals for most routers online in case you lost the printed manual that came with your router purchase. For your reference, here are direct links to the manufacturer’s site of some popular router brands –LinksysCiscoNetgearApple AirPortSMCD-LinkBuffaloTP-LINK3Com,Belkin.

Step 2. Create a unique password on your router

Once you have logged into your router, the first thing you should do to secure your network is to change the default password* of the router to something more secure.

This will prevent others from accessing the router and you can easily maintain the security settings that you want. You can change the password from the Administration settings on your router’s settings page. The default values are generally admin / password.

[*] What do the bad guys use  This is a public database of default usernames and passwords of wireless routers, modems, switches and other networking equipment. For instance, anyone can easily make out from the database that the factory-default settings for Linksys equipment can be accessed by using admin for both username and password fields.

Step 3. Change your Network’s SSID name

The SSID (or Wireless Network Name) of your Wireless Router is usually pre-defined as “default” or is set as the brand name of the router (e.g., linksys). Although this will not make your network inherently* more secure, changing the SSID name of your network is a good idea as it will make it more obvious for others to know which network they are connecting to.

This setting is usually under the basic wireless settings in your router’s settings page. Once this is set, you will always be sure that you are connecting to the correct Wireless network even if there are multiple wireless networks in your area. Don’t use your name, home address or other personal information in the SSID name.

Also see: Change Network Name to Prevent Wi-Fi Theft

[*] What do the bad guys use  Wi-Fi scanning tools like inSSIDer(Windows) and Kismet (Mac, Linux) are free and they will allow anyone to find all the available Wireless Networks in an area even if the routers are not broadcasting their SSID name.

Step 4. Enable Network Encryption

In order to prevent other computers in the area from using your internet connection, you need to encrypt your wireless signals.

There are several encryption methods for wireless settings, including WEPWPA(WPA-Personal), and WPA2 (Wi-Fi Protected Access version 2). WEP is basic encryption and therefore least secure (i.e., it can be easily cracked*, but is compatible with a wide range of devices including older hardware, whereas WPA2 is the most secure but is only compatible with hardware manufacturedsince 2006.

To enable encryption on your Wireless network, open the wireless security settings on your router’s configuration page. This will usually let you select which security method you wish to choose; if you have older devices, choose WEP, otherwise go with WPA2. Enter a passphrase to access the network; make sure to set this to something that would be difficult for others to guess, and consider using a combination of letters, numbers, and special characters in the passphrase.

[*] What do the bad guys use  AirCrack and coWPAtty are some free tools that allow even non-hackers to crack the WEP / WPA (PSK) keys using dictionary or brute force techniques. A video on YouTube suggests that AirCrack may be easily used to break WiFi encryption using a jail-broken iPhone or an iPod Touch.

Step 5. Filter MAC addresses

Whether you have a laptop or a Wi-Fi enabled mobile phone, all your wireless devices have a unique MAC address (this has nothing to do with an Apple Mac) just like every computer connected to the Internet has a unique IP address. For an added layer of protection, you can add the MAC addresses of all your devices to your wireless router’s settings so that only the specified devices can connect to your Wi-Fi network.

MAC addresses are hard-coded into your networking equipment, so one address will only let that one device on the network. It is, unfortunately, possible to spoof a MAC address*, but an attacker must first know one of the MAC addresses of the computers that are connected to your Wireless network before he can attempt spoofing.

To enable MAC address filtering, first make a list of all your hardware devices that you want to connect to your wireless network**. Find their MAC addresses, and then add them to the MAC address filtering in your router’s administrative settings. You can find the MAC address for your computers by opening Command Prompt and typing in “ipconfig /all”, which will show your MAC address beside the name “Physical Address”. You can find the MAC addresses of Wireless mobile phones and other portable devices under their network settings, though this will vary for each device.

[*] What do the bad guys use – Someone can change the MAC address of his or her own computer and can easily connect to your network since your network allows connection from devices that have that particular MAC address. Anyone can determine the MAC address of your device wireless using a sniffing tool likeNmap and he can then change the MAC address of his own computer using another free tool like MAC Shift.

Step 6. Reduce the Range of the Wireless Signal

If your wireless router has a high range but you are staying in a small studio apartment, you can consider decreasing the signal range by either changing the mode of your router to 802.11g (instead of 802.11n or 802.11b) or use a different wireless channel.

You can also try placing the router under the bed, inside a shoe box or wrap a foilaround the router antennas so that you can somewhat restrict the direction of signals.

Apply the Anti-Wi-Fi Paint – Researchers have developed a special Wi-Fi blocking paint that can help you stop neighbors from accessing your home network without you having to set up encryption at the router level. The paint contains chemicals that blocks radio signals by absorbing them. “By coating an entire room, Wi-Fi signals can’t get in and, crucially, can’t get out.”

Step 7. Upgrade your Router’s firmware

You should check the manufacturer’s site occasionally to make sure that your router is running the latest firmware. You can find the existing firmware version of your router using from the router’s dashboard at 192.168.*.

Connect to your Secure Wireless Network

To conclude, MAC Address filtering with WPA2 (AES) encryption (and a really complex passphrase) is probably the best way to secure your wireless network.

Once you have enabled the various security settings in your wireless router, you need to add the new settings to your computers and other wireless devices so that they all can connect to the Wi-Fi network. You can select to have your computer automatically connect to this network, so you won’t have to enter the SSID, passphrase and   other information every time you connect to the Internet.

Your wireless network will now be a lot more secure and intruders may have a tough time intercepting your Wi-Fi signals.

Who is Connected to your Wireless Network

If you are worried that an outsider may be connecting to the Internet using your Wireless network, try AirSnare – it’s a free utility that will look for unexpected MAC addresses on your Wireless network as well as to DHCP requests. Another option is that you open your router’s administration page (using the 192.168.* address) and look for the DHCP Clients Table (it’s under Status > Local Network on Linksys routers). Here you will see a list of all computers and wireless devices that are connected to your home network.

 

 

 

 

*It is also a good idea to turn off the router completely when you are not planning to use the computer for a longer period (like when you are out shopping). You save on electricity and the door remains 100% shut for wireless piggybackers.

**If you ever want to let a new device connect to your network, you will have to find its MAC address and add it to your router. If you simple want to let a friend connect to your wireless network one time, you can remove his MAC address from the router settings when he or she leaves your place.

WiFi are hack able and the security measures to be taken depends on the intentions of the hacker and the intentions of the hacker depends on what the wifi is being used for

for example a hacker in Ur neighborhood would intend to use ur internet for free meanwhile a hacker in airport or in coffee shop intends to to steal personal data and he can can use different attacks for that purpose

A.B.M. Kamrul Ahasan Majumder
by A.B.M. Kamrul Ahasan Majumder , Manager(Head of IT network & Information security) , Bangla Trac Ltd.(Bangla Cat)

the following steps need to follow:

1.use mac address who will be access wifi

2. Hide SSID and SSID name should be unknown. no one donnot understand which company's SSID use.

3.Use WPA2 or WPA2-PSK for encryption.

4.Use non regular brand frequency. not to use auto frequency channel.

5. Always wifi router firmware should be upgraded.

6.randomly use long and complex password for SSID and also use complex user name & password to access wifi router.

7. wifi router firewall need to on IPS firewall

8.always check log file in wireless router.

9. guest user ssid and employee ssid name & password should be different.

 

Faseeh Mohd koya
by Faseeh Mohd koya , IT SUPPORT ENGINEER [L2] , Ministry of Sports and Youth

Yup definitely it can be hacked. Wifi is never be a secured way of connection.

Magdy Tawfik Eskander Ebid Taya
by Magdy Tawfik Eskander Ebid Taya , IT Consultant , 3J

Yes, it can be protected by using  WPA Security with extended character in the password.

More Questions Like This

Do you need help in adding the right keywords to your CV? Let our CV writing experts help you.