Configuración conexión inalámbrica en Windows XP Profesional con seguridad WPA-PSK.

La seguridad en redes inalámbricas mediante conexiones abiertas y encriptadas con cifrado WEP son de un nivel realmente bajo, El nivel de seguridad en este caso dependerá del tipo de contraseña que el usuario de a los equipos, aquí ya no vale la cantidad de trafico capturado sino uno en concreto,si configuramos una contraseña un poco particular y la cambiamos muy a menudo, las posibilidades que nos roben la conexión es totalmente nula,De hecho estadísticamente el numero de redes con encriptación WPA es mínimo, Con esta configuración ya eliminamos el peligro de la conexiones wireless y este solo se centrara en la conexión a Internet . Partimos de la base que vamos a operar con un router inalámbrico que soporte WPA, aunque también puede valer un punto de acceso, pero esta claro que la conexión a Internet no la da el punto de acceso sino el modem o el router. No vamos a diseñar una gran red de una gran corporación o empresa, simplemente necesitamos establecer una conexión inalámbrica entre un router y un ordenador para poder pasear libremente por la casa si tener que llevar siempre encima un cable de conexión y disfrutar libremente de nuestra ADSL allí donde queramos . Cuando me refiero a un ordenador pueden ser varios siempre que la conexión del router a Internet lo permita. Cuando llegue el momento Windows establece un apartado para grabar los datos y simplemente mediante una llave de memoria usb podamos introducirla en otro ordenador y este quede configurado de forma automática,así que además de la configuración del router cuando configuremos el ordenador será siempre de forma manual, y si tenemos varios ordenadores pues repetimos el proceso para cada una. la conexión física aunque sea través de ondas de radio entre tarjetas y router, para la asociación es decir el proceso de obtención de IP, de puerta de enlace y de DNS es lo mismo que para cualquier red cableada (ethernet). La única diferencia que radica entre estos dos grupos de redes locales corresponde exclusivamente al proceso de establecer la comunicación o sea al medio físico,todo el protocolo de conexión es exactamente el mismo. Si habéis pasado a este punto, es que tenéis ya instalada correctamente vuestra tarjeta wireless aunque esta no este operativa, y tampoco es importante saber en estos momentos de que forma esta trabajando, con saber que esta el driver puesto y es el correcto con esto bastara. Recuerden la aspa roja que nos indicaba que el sistema había detectado una o mas redes wireless disponibles, o quizás ninguna si todavía no hemos preparado el router inalámbrico.

O en el caso de que no haya ninguna:

Pero en ambos casos la tarjeta ya esta preparada para trabajar, respecto a lo que a nivel de driver se refiere. Si tu punto de acceso o router inalámbrico no soporta WPA mejor podés dejar de leer. Respecto a las tarjetas tienen que ser realmente viejas como para que no puedan operar de esa forma. Cada tarjeta tiene su aplicación personal para poder ser configurada, pero como no podemos establecer un manual para cada aplicación,lo haremos siempre con el sistema operativo,visto esto nos dará una idea correcta de trabajar para cada aplicación. Pero con los pasos aquí explicados y a no ser que sean tarjetas un poco especificas el problema esta mas que resuelto. Por lo tanto pasemos a configurar el router inalámbrico y la conexión del ordenador a dicho router. Un grave error que todo el mundo comete es ponerse primero a configurar la tarjeta, pero esto nunca debe de hacerse en primer lugar, lo primero es configurar el router o el punto de acceso, una vez hecho esto, no olvidamos de el y pasamos a configurar las tarjetas. Porque esto es tan importante, muy sencillo, si estamos trabando con una conexión ya cableada el orden casi no importa, pero si estamos trabajando con una conexión inalámbrica ya establecida entre router y tarjeta sea del modo no protegido o sea del modo con seguridad WEP, si cambiamos la configuración de la conexión lógicamente perderemos la conexión al router y no podremos configurarlo. Por lo tanto, primero siempre se debe de configurar el router, la conexión también se perderá pero en este caso ya la recuperamos cuando cambiemos la configuración en el ordenador, pero si lo hacemos al revés, y no tenemos red cableada para ajustar el router tendremos que poner los valores iniciales y el trabajo habrá sido en vano. De la misma forma si estamos operando ya en WPA y queremos cambiar la contraseña primero se debe de cambiar el router y posteriormente en los ordenadores. Y sobre todo si tenemos que configurar varios apartados como es el caso que nos ocupa partiendo de una conexión wireless ya establecida, nunca cambiaremos las dos cosas a la vez, por ejemplo en el caso que nos ocupa, primero modificaremos el apartado de autentificación pero no el del nombre de red y el de canal, puesto que si lo hacemos perderemos la conexión, tendremos que ajustar de nuevo los valores en el ordenador y volver a establecer la conexión al router para modificar el tipo de seguridad en el router y luego vueltas a empezar en el ordenador. si es una red wifi abierta que queréis pasar a encriptada, modificar solo el apartado de seguridad, luego ya podremos modificar el apartado de canal y nombre de red. Todo depende del manejo que tengamos y de la configuración por defecto del router o la que estemos usando antes de iniciar la configuración WPA-PSK. Solo aconsejo configurar tu red wireless con seguridad WEP para analizar los pocos seguras que son, y previo camino para entender la seguridad WPA. Intentar usar el WEP lo menos posible, aunque siempre es mejor que nada. Cada router es especifico pero siempre se mantienen las mismas secciones principales para gestión de las redes inalámbricas. Para acceder a el usar el mismo navegador y poner la ip que se fijo en la puerta de enlace Acceder al Router es uno de los básicos para el router inalámbrico, que corresponde a la autentificación de seguridad, establecemos que la autentificación sea requerida, el protocolo de seguridad corresponde a WPA-PSK y ponemos una contraseña. En este caso es lo que diferencia una conexión segura de otra que no lo es. En el análisis de la seguridad WPA y mediante captura y ataque de desautentificación pudemos encontrar la clave ya que era muy fácil para un diccionario, pero mira en este caso la cantidad de símbolos (caracteres especiales) que he puesto, lógicamente no hay ningún diccionario que soporte esto, y mira que estuve probando para genera un súper diccionario con un mínimo de 9 dígitos pero el ordenador se quedaba sin memoria ,si le ponemos mas de nueve como es este caso. En el caso que la configuración del router no acepte todos estos símbolos pues lógicamente poner aquello que si son posibles. Si al aplicar sale un error
Esto es debido a que venimos de una conexión con seguridad WEP y antes de nada hay que deshabilitarla. Pero que pasara, pues que si estamos con conexión wifi con WEP perderemos la conexión al router, Para inhabilitar la WEP:
No es necesario vaciar los valores en Key1-4, pero tampoco esta de mas.
Y dejarlo como queremos:
Y el segundo punto importante que se relaciona con conexión wireless en el router sea cual sea el tipo de seguridad corresponde
Recorda si usás una conexión wireless para configurar el router y esta ya esta establecida tanto sea abierta , wep o wpa (para solo modificar la contraseña puesto que lógicamente ya estará todo bien configurado), no toqués nada de este apartado, solo del otro. En un futuro si te da por cambiar el canal y el nombre de red wireless, pues ya podés venir a este apartado y cambiarlo, y por supuesto después en los ordenadores. Habilitamos la conexión wireless, se supone que si el acceso fue mediante conexión wireless, este ya estará establecido, pero si es por acceso de red cableada quizás lo mas normal es que no lo este. Poner un nombre de red wireless (ESSID), elegimos el canal que queramos y si queremos ocultar el ESSID para que no lo emita pues lo hacemos y si no pues no. cualquier herramienta básica de captura te lo intenta comunicar, pero como trabajamos en Windows nos puedé dar problemas si el nombre de la red inalámbrica esta oculto, por lo tanto yo lo dejaría visible, es decir "No a ocultar ESSID", Nota: como ves estas 2 ventanas siempre están relacionados y cualquier cambio en una afecta a la otra. Ahora pasaremos a configurar las tarjetas. O bien "Inicio" - "Todos los programas" - "Accesorios" - "Comunicaciones" - "Configurar red inalámbrica". O bien: en "Conexiones de red e Internet" en "Configurar red inalámbrica". Con lo que lanzara el "Asistente para redes inalámbricas".
luego Seleccionamos la opción de configura una nueva red inalámbrica, y si esta ya esta establecida y solo queremos modificar pues seleccionamos "Agregar nuevos equipos". Pero aconsejo siempre usar la primera opción, aunque ya partamos de una conexión inicial.
Ponemos el Nombre de red al igual que en el router y cambiamos algunas cosas y luego en siguiente.
Introducimos la contraseña para el cifrado, podemos esconder los caracteres o no, según creas.
Pasamos de la unidad USB y seleccionamos "Configurar una red manualmente".
Y luego en "Siguiente". Al cabo de casi nada el asistente nos indica que la configuración finalizo correctamente. A mi nunca me salio un error con problemas en la configuración así que no tengo captura de ello. En cualquier momento podemos cancelar e iniciar el asistente mas tarde.
Podemos imprimir la configuración por si tenemos mala memoria, sobre todo de las contraseña utilizada. Y simplemente pulsamos "Finalizar".
Vemos que la conexión ya es real, y se pone de manifiesto en un icono de la Área de notificación de la barra de tareas. Aun así para comprobarlo, pinchamos sobre ese icono. Y si ese icono no saliera podemos hacerlo mediante acceso al panal de control y en conexiones de red y veras fácilmente el icono que caracteriza a este tipo de conexión inalámbrica, pues simplemente pinchás en el y también te saldrá las misma pantalla. Pero siempre sale el icono a menos que este ocultado por nosotros.
Si el nombre de red wireless hubiera sido configurado como oculto.
Recorda que si es la primera vez que configurás una red wireless con seguridad WPA-PSK es mejor no ocultar el nombre de red, una vez que se haya finalizado el proceso y comprobemos que nuestra conexión a Internet esta establecida podemos volver al router y ocultar el nombre, recorda en el caso que estamos viendo y con este súper router seria: "Hide ESSID" debe de estar seleccionado. En el supuesto que la conexión no se produzca de manera automática, en esta ventana vemos que podemos actualizar la lista de redes, conectar y desconectar nuestro equipo de cualquier red, así como cambiar a configuración avanzada y gestionar todo el protocolo de comunicación TCP/IP. En este caso la conexión se produzco de manera automática pero esta captura se hizo después de haber desconectado la red para que pudieras ver el botón "Conectar" y como debe de hacerse por si no se ha conectado a la primera. Pues ya esta es que no hay mas. Si querés lo vemos con el Netstumbler y el airodump
En esta caso el NetStumbler no acierta ni a la de dos. Por eso Kismet (GNU/Linux) y airodump (Windows/Linux) es mejor, además que no te da los clientes, pero si es el mejor para analizar los problemas de señal. Podemos analizar la conexión y la cobertura.
Es bastante buena. Incluso si hacemos un test de velocidad nos daría un resultado similar a una red cableada. Lo analizamos con el airodump, siempre que tengamos otra tarjeta que acepte el modo monitor en Windows, nunca con la misma que usamos para la conexión normal con seguridad WPA-PSK:
En este caso el airodump si acierta con el tipo de seguridad. Además podemos comprobar que los clientes que hay son solo los nuestros. Si esta captura la paso por el aircrack me daría el famoso "trafico deseado" , ya que aunque no tenemos tantas posibilidades en Windows como en linux de realizar desautentificación mediante "Ataque 0" si podemos tener todo el día el airodump funcionando hasta esperar que se proceda al intercambio de claves en el inicio de la conexión entre el router wireless (AP) y el ordenador (tarjeta wireless). Si analizamos o analizan el trafico después de ese momento de intercambio de claves no servirá para nada. Y aunque consigas el intercambio de claves tampoco te servirá para nada, ya que si me has hecho caso y as puesto una contraseña con caracteres especiales (si lo soporta vuestro router) números y letras y de una longitud que no sea la mínima permitida y exigida, difícilmente esta contraseña estará soportada por cualquier diccionario de claves por muy bueno que sea. Con el airodump se analizan los clientes inalámbricos, pero para mas seguridad podemos usar "el Look@LAN" y comprar todos los clientes asociados que pueda haber en la red. En este caso vemos que nadie mas esta asociado a nuestra red.
Solo esta el router (NOT WIN) y mi ordenador (WINDOWS). Y ya de paso analizamos el router y nos vale para entender como funciona este programa. También se complementa este programa con el "IP Scanner" que incluso te dan nombres de trabajo y de equipos, pero siempre para elementos conectados en la misma red, o sea autentificados y asociados.
También de paso observamos la información que nos da del router. Solo presento la ventana principal, pero pinchando con el ratón en cualquiera de ellas se obtiene mucho mas información. La configuración y el manual para WPA en Windows XP profesional con Service Pack 2 acabo mucho antes, pero hemos intentado aprovechar para añadir algunos elementos extras mas, y ver algunas herramientas que muchos usan para conocer información de nuestro equipo, pero esto, esta claro que solo se puede hacer si estas autentificado y asociado, cosa difícil de conseguir que nos hagan si estamos con seguridad con WPA-PSK, con una matización, siempre que hayamos puesto una clave muy difícil y rara. Y además podemos usar esta herramientas para nuestro propio análisis de comprobación de seguridad y comprobar que no hay ningún parásito en nuestra conexión wireless. por lo tanto con el mismo trabajo tenemos una seguridad mucho mas alta.


....................................................................................


Security in wireless networks using open connections and encrypted with WEP encryption is a really low level, the level of security in this case depends on the type of password that the user of the equipment here is not worth the amount of traffic captured but one in particular, set a password if a particular bit and change too often rob us of the possibilities is absolutely no connection, in fact statistically the number of networks with WPA encryption is minimal with this setup and eliminate the danger of wireless connections and this just focus on your Internet connection. On the basis that we will operate with a wireless router that supports WPA, but can be worth a point, but it is clear that the Internet connection is not the access point but the modem or router. We will not design a network of a large corporation or large company, we simply need to establish a wireless connection between a router and a computer to be able to walk freely around the house if you have to wear over a cable connection and enjoy our free ADSL there where we want. When I refer to a computer can be more if the router's Internet connection allows. When it comes time Windows establishes a section to record the data and simply using a USB memory key can enter it on another computer and this is configured automatically, so in addition to configuring the router setup when the computer is always manually and if we have multiple computers then repeat the process for each one. although the physical connection via radio waves between card and router, so the association is the process of obtaining IP, gateway and DNS is the same as for any wired network (ethernet). The only difference lies between these two groups of local networks is solely for the process of communication or the physical environment around the connection protocol is exactly the same. If you come to this point is that you have already installed your wireless card, although this is not operational, nor is it important to know at this point that it is working with the driver know that this post and this is correct enough . Remember the red X indicates that the system had detected one or more wireless networks available, or perhaps none if we have not yet developed the wireless router.

Or in the case that there is no:

But in both cases the card is ready to work, on what level of driver is concerned. If your access point or wireless router does not support WPA best you can stop reading. Regarding the cards have to be really old and they can not operate that way. Each card has a personal application to be configured, but we can not establish a manual for each application, we will always be with the operating system, seen this will give us a correct idea of working for each application. But with the steps outlined here and to be a little cards that are specific to the problem is more settled. So let's set the wireless router and connect the computer to the router. A big mistake that everybody is committed to first configure the card, but this should never be done first, you must first configure the router or access point, once done, do not forget him and move to configure the cards. Because this is so important, very simple, if you're locking in a wired connection and order almost does not matter, but if you're working with a wireless connection already established between the router and card is not protected mode or Safe mode WEP, if we change the configuration of the logical connection to the router will lose connection and can not configure it. Therefore, first you should always configure the router, the connection is lost but in this case and recover when changing the settings on your computer, but if we do the opposite, and we have no wired network to set the router will Set the initial values and work have been in vain. In the same way if we are operating now and we want to change the WPA password is necessary to first change the router and then into computers. And especially if we have to set up several paragraphs as is the case on a wireless connection already established, will never change two things at once, such as in the case, modify the first paragraph but not authentication the network name and the channel, because if we do lose the connection, we will have to adjust to new settings in the computer and re-establish the connection to the router to change the type of security on the router and then re - start on the computer. if an open wifi network you want to pass encrypted, just change the heading of security, then we can modify the section of channel and network name. Everything depends on the management that we have and the default router or that we are using before starting the setup WPA-PSK. Just advise your wireless network setup with WEP security to analyze the few that are safe, and after way to understand the WPA security. Try to use WEP as little as possible, although it is always better than nothing. Each router is specific but always keep the same sections for managing wireless networks. To access it use the same browser and put the ip is fixed in the Access Gateway Router


is one of the core for the wireless router, which corresponds to the authentication security, the authentication is required, the security protocol is WPA-PSK and set a password. Here is what differentiates a secure connection that otherwise is not. In the WPA security analysis and attack and capture by desautentificación pudemos find the key because it was very easy for a dictionary, but look at this case the number of symbols (special characters) that I have, of course there is no dictionary support this and look I was trying to generate a super dictionary with a minimum of 9 digits but the computer runs out of memory if you put more than nine as in this case. In the event that the configuration of the router does not accept all these symbols that make it logically, if possible. If you get an error in the application of this type:


This is because we have a connection with WEP security and before there is nothing to disable. But what will happen, because even if we are with wifi connection with WEP lose connection to router to disable the WEP:


No need to empty the value in Key1-4, but neither is worth. And in this case after applying and we can go to:


And we leave it as:


The second important point relates to the wireless router is the kind of security is usually this:



Remember if you use a wireless connection to configure the router and this is already established that it is open, WEP or WPA (just to change the password because logically everything is already configured), do not touch anything in this section, only the other. In the future if you change the channel and the wireless network name, and then you can come here and change it, and then of course in computers. Enable wireless connection, it is assumed that if the access was via wireless connection, this will already be established, but it is wired for network access is perhaps more normal not. Put a wireless network name (ESSID), we choose the channel you want and if we want to hide the ESSID is not broadcast as we do and if not, no. any basic tool tries to capture what you communicate, how we work in Windows but can give us problems if the wireless network name is hidden, so I no longer visible, ie "No to hide ESSID" Note: As you see these 2 windows are always connected and any change in one affects the other. Now we will configure the cards. Or the "Start" - "All Programs" - "Accessories" - "Communications" - "Configure Wireless Network". Or in "Network and Internet Connections" under "Configure Wireless Network". So he launched the "Wireless Wizard".



then



Select the option to configure a new wireless network, and if this is already established and just want to modify it select "Add new hardware". But I advise always using the first option, but already part of an initial connection.


We put the network name as in the router and change some things such as:



then follows.


Enter the password for encryption, we can hide the characters or not, as you create.


We went from the USB drive and select "Configure network manually."


And then "Next." After almost nothing the wizard indicates that the configuration completed successfully. I never went wrong with my problems in the configuration so I do not catch it. Anytime we can cancel the wizard and start later.


We can print an account if you have bad memory, especially the password used. And just click "Finish."



We see that the connection is real, and shows an icon in the Notification Area of the taskbar. Yet to check this, click on this icon. And if this icon, we do not go through the honeycomb of access control and network connections, and easily see the icon that characterizes this type of wireless connection, then simply click on it and also leave you the same screen. But always get the icon unless concealed by us.


If the wireless network name was set to hidden. It would look like this:




Remember that if you're setting up a wireless network with WPA-PSK security is better not to hide the network name, once you have completed the process and see that our Internet connection is established we can go back to the router and hide the name, remember the case and we're seeing with this super router would be: "Hide ESSID" must be selected. In the event that the connection does not occur automatically, in this window we see that we can update the list of networks, connecting and disconnecting any of our network and switch to advanced settings and manage the communication protocol TCP / IP . In this case the connection takes place automatically, but this capture was made after having disconnected the network so that you could see the button "Connect" and should be done if you have not connected to the first. Well now there is no more. If you want to see it with Netstumbler and airodump


In this case the NetStumbler not right or the two. So Kismet (GNU / Linux) and airodump (Windows / Linux) is better, that does not give you the customers, but it is best to analyze the problems of signal. We analyze the connectivity and coverage.


It's pretty good. Even if you do a speed test would give us a result similar to a wired network. We look with airodump, provided we have another card to accept monitor mode in Windows, not with the same one used for normal connection with WPA-PSK security:




In this case, airodump if the right type of security. We can see that there are customers who are just our own. If this captures the way through the aircrack give me the famous "desired traffic," because although we do not have many options in Windows and Linux by making desautentificación "0 attack" if we can have the whole day running airodump to wait for andalusia appropriate key exchange at the beginning of the connection between the wireless router (AP) and computer (wireless card). If we study and analyze the traffic after that point key exchange it will be useless. And while getting the key exchange will not serve for nothing, as if I've gone and given as a password with special characters (if your router supports it) and numbers and letters in length than the minimum allowed and required hardly be supported by this password key for any dictionary that is very good. With airodump discusses wireless clients, but for more security we can use the "Look @ LAN" and buy all customers who may have partners in the network. In this case we see that nobody else is associated with our network.


You're just the router (NOT WIN) and my computer (Windows). And incidentally, we analyze the router and uses it to understand how this program. It also supplements the program with the "IP Scanner" that even give you names and teams, but always connected to elements on the same network, or authenticated and associated.


We also note in passing that gives us information on the router. Only presents the main window, but clicking the mouse on any of them get much more information. The configuration and the manual for WPA in Windows XP Professional with Service Pack 2 out sooner, but we tried to take some items to add more extras, and view many tools used to find information about our team, but this, it is clear that can only be done if the authenticated and associated difficult thing to get us to where we are with WPA-PSK security with a qualifier, provided that we have put a very difficult and rare key. And we can use this tool for our own analysis of security check and verify that no parasite in our wireless connection. hence with the same work have a much higher security.

No hay comentarios:

Protected by Copyscape Original Article Checker