Skip this advertisement >
Please wait while the page is being loaded
Friday | 16 May, 2008
ARN

News

Australian cities exposed in war driving exercise
Sandra Rossi (Computerworld) 29 November, 2005 08:22:10

ARN Directory | Distributors relevant to this article
Related Stories
  • +

    NetComm hits the road with SME offering 03 August, 2006 11:35:19

    NetComm is hitting the road to drum up support for its new range of SME networking products and is hoping to pick up some partners along the way.
  • +

    IPL brings on new reseller for VoIP push 08 November, 2006 13:45:00

    TSA Communication Solutions will take on IPL's Alcatel equipment
    Hardware distributor, IPL Communications, has struck an agreement with communication reseller, TSA Communication Solutions, as part of its push to secure a select band of national, VoIP-savvy partners.
  • +

    Friends of Ed toast a decade in distribution 15 November, 2006 14:08:57

    Champagne glasses were raised high at Sydney's Shangri La Hotel last month in honour of Express Data's 10th birthday.
  • +

    Gizmo provides home Wi-Fi services for AAPT 06 December, 2006 12:21:28

    Sydney-based technical support business, Gizmo, has partnered with AAPT to offer a new home network support bundle to the telco's Wi-Fi customers.
  • +

    Security unlocked 03 November, 2004 15:43:49

    As the security market continues to mature, services continue to become a more important piece of the puzzle. ARN, in conjunction with Lan Systems, brought together some of the industry's leading figures to talk about where the market is headed and what resellers should be doing in order to make the most of opportunities. Taking part in the roundtable discussion were (pictured below, from left): ARN editor, Brian Corrigan; Volante's national security manager, Ajoy Ghosh; Check Point Australia's managing director, Scott Ferguson; Lan Systems' general manager, Wendy O'Keeffe; Cisco A/NZ's security partner manager, Bruce Munro; Lan Systems' security business development manager, Rohan Wilkinson; and Nortel's security product marketing manager, Matthew Syme.

A state-by-state war driving exercise undertaken in October across Australia's capital cities identified the risk of corporate network intrusions through weak Wireless Local Area Networks (WLAN).

It found an alarmingly high number of organisations are making their corporate networks easy targets for hackers.

The inaugural Altiris/SpectroTech 2005 IT Security Vulnerability Report covered the central business districts of Adelaide, Brisbane, Canberra, Hobart, Melbourne, Perth and Sydney. As connecting to a corporate network is illegal, SpectroTech used passive tools to blindly capture and collate the data.

"These results were a big surprise to us because everyone is at risk," said SpectroTech principal consultant Mark Morgan. "You would be shocked if you heard the names of the major Australian organisations that we picked up."

The results showed 18 percent of CBD based organisations are using default configuration settings for their wireless access points. Melbourne was at the highest risk with 18 percent followed by Hobart (14 percent) and Canberra (13 percent).

"Either companies don't have the knowledge and expertise to design or configure secure solutions or there are rogue devices running rampant on these networks," Morgan said.

Rogue devices are intrusions on networks that are implemented either internally or externally without permission from network administrators. The only way to ensure a network's security is to perform audits and threat analyses in threat environments, said Morgan.

Laura Chappell, IT security expert and FBI consultant, said default settings, which include usernames and passwords, are easily found on the Internet.

"From here, a hacker can simply go in and gain access to your corporate network," she said.

Nearly 30 percent of companies made no attempt to protect their business information at all with no encryption keys used to access the wireless network. "This means that clear-text communications over the wireless network can easily be intercepted and read," Chappell said.

"Adelaide's CBD-based companies are the biggest offenders at 36 percent. This figure is extremely high. If confidential information is crossing the wireless network in plain text, then that's handing corporate secrets to the competition on a platter."

However, Morgan warned that encryption statistics can be misleading and do not necessarily indicate an insecure system.

"Just because data is encryption disabled does not necessarily mean that it is insecure. Many companies do not need to be concerned with the confidentiality of the data they send," he said.

Regardless of the needs of corporate encryption, the report found that an estimated 70 percent of companies within the CBD of all major Australian cities rely on the rudimentary security mechanism, Wired Equivalent Privacy (WEP) to provide authentication and encryption.

Developed as an industry standard and used primarily for encryption, WEP is riddled with flaws and can be cracked in a matter of seconds said Morgan.

"There are a lot of misconceptions about the inherent technology in wireless networks," Morgan said. "Because it's a rapid growth technology, a lot of people sell but few people focus on the design, implementation and support elements."

Only 13 percent of companies were found to be using Temporal Key Integrity Protocol (TKIP), an enhanced version of WEP.

"It all comes down to education. The report shows that the reliance on default configurations and outdated industry standards is leaving corporate networks wide open for attack," Morgan said.

Spectrotech plan to host a national road show early next year to re-educate CIOs and network administrators on the dangers of insecure networks. The vendor neutral consultancy group will provide live hacking demonstrations and offer security solutions from its partners.

(Additional reporting by Mitchell Bingemann.)

ARN Directory | Distributors relevant to this article
Market Place

ARN Member Login

 
Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play
ARN news
Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

V/Line and Oakton use Microsoft SQL Server 2008 to develop an Executive HR Dashboard

With the help of Oakton, V/Line - Victoria’s regional public transport provider - utilised Microsoft SQL Server 2008 to develop an Executive HR Dashboard report.

Sponsored Links