Community discussions

MikroTik App
 
piatthi
newbie
Topic Author
Posts: 32
Joined: Tue May 05, 2009 10:56 am

Hotspot Bypass

Tue May 18, 2010 7:19 pm

hi all,

since there is a know security issue in hotspot feature :

suppose a letigimate user PCA with MAC A is already authenticated in hotspot server.

an attacker who know MAC of PCA, can fixe it on its PCB ( MAC spoofing), and get automatically IP of PCA, and then begin to browse without need authentication.

is there any countermesure solution on Mikrotik Os ?

thanks for your reply
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: Hotspot Bypass

Tue May 18, 2010 9:45 pm

On switched platforms use edge security (DHCP snooping, ARP snooping, 802.1x, port security on Cisco), on wireless platforms use the equivalents (WPA etc.) - the Hotspot servlet cannot possibly tell the difference as the client looks absolutely legitimate as it has the same MAC and IP address. You either prevent the customer from spoofing at all or must accept that the Hotspot cannot defend against spoofed connections.

Who is online

Users browsing this forum: flintham12, TomSvitana and 61 guests