Community discussions

MikroTik App
 
pixelkop
newbie
Topic Author
Posts: 40
Joined: Mon Apr 30, 2012 5:44 pm

Is mikrotik is secured ...

Sat Apr 20, 2013 1:24 pm

We are suggesting radio link for one Bank. but customer is saying Wireless is not secured. hacking is possible. so can you describe what type of security we are using when we are doing point to point link with router boards. any wiki ??? so we can give to customer. Thanks in advance.
 
Lakis
Forum Veteran
Forum Veteran
Posts: 703
Joined: Wed Sep 23, 2009 7:52 pm

Re: Is mikrotik is secured ...

Sat Apr 20, 2013 3:54 pm

Ok I have p2p link , 2 units lets say 2xSXT in bridge There are mounted on the roof, no encryption

How can anyone hack in my network?
 
User avatar
EMOziko
Member Candidate
Member Candidate
Posts: 129
Joined: Mon Aug 23, 2010 9:42 pm
Location: Georgia

Re: Is mikrotik is secured ...

Sat Apr 20, 2013 3:59 pm

Use wpa2\aes or wpa\aes. Use strong passwords. Use management frame protection and no one will be able to hack your network.

p.s. Banks must have PCI DSS standard implemented in there network.
 
User avatar
tomaskir
Trainer
Trainer
Posts: 1162
Joined: Sat Sep 24, 2011 2:32 pm
Location: Slovakia

Re: Is mikrotik is secured ...

Sat Apr 20, 2013 6:38 pm

If you are using WPA2 encryption for the link, the only way to hack is a dictionary attack or bruteforcing the password.
Against both, if you have a good PSK, its pretty much impossible. Make sure its atleast 12 characters, containing capital letters, normal letters, numbers and special characters, and is not based on any words.

As mentioned before, use management protection to avoid de-auth attacks.
 
User avatar
nickshore
Long time Member
Long time Member
Posts: 524
Joined: Thu Mar 03, 2005 4:14 pm
Location: Suffolk, UK.
Contact:

Re: Is mikrotik is secured ...

Sat Apr 20, 2013 6:57 pm

Use an extra layer of strong encryption.

Run WPA2 or NV2 encrytion on the wifi, and then run IPSEC over that

Nick.
 
Lakis
Forum Veteran
Forum Veteran
Posts: 703
Joined: Wed Sep 23, 2009 7:52 pm

Re: Is mikrotik is secured ...

Sat Apr 20, 2013 8:07 pm

So noon has answered my question

I have 2xSXT in bridge p2p that run nv2

tomaskir How on earth can u do dictionary attack or bruteforcing from ur PC that run Linux or Windows

and even if u find password what next how can u Hack in to a bank network - first u mast be connected to one SXT to have access to bank network
Last edited by Lakis on Sat Apr 20, 2013 8:20 pm, edited 1 time in total.
 
User avatar
tomaskir
Trainer
Trainer
Posts: 1162
Joined: Sat Sep 24, 2011 2:32 pm
Location: Slovakia

Re: Is mikrotik is secured ...

Sat Apr 20, 2013 8:13 pm

Assuming its a WPA2 secured network, using Linux, its simple:

You use a deauth attack on one end. Then capture the re-auth of the client using airodump-ng. You then use aircrack-ng to bruteforce the aepol auth process.
Of course, if its a secure password, its gonna take a long time. But if you use a dictionary attack, and the password is word-based, its not that hard to crack.
 
angboontiong
Forum Guru
Forum Guru
Posts: 1136
Joined: Fri Jan 16, 2009 9:59 am

Re: Is mikrotik is secured ...

Sat Apr 20, 2013 8:30 pm

create an EOIP Tunnel or implement MPLS on your wireless link as most bank lease line go with MPLS...
 
User avatar
cbrown
Trainer
Trainer
Posts: 1839
Joined: Thu Oct 14, 2010 8:57 pm
Contact:

Is mikrotik is secured ...

Sun Apr 21, 2013 7:41 am

Use an extra layer of strong encryption.

Run WPA2 or NV2 encrytion on the wifi, and then run IPSEC over that

Nick.

Agreed.
 
0ldman
Forum Guru
Forum Guru
Posts: 1465
Joined: Thu Jul 27, 2006 5:01 am

Re: Is mikrotik is secured ...

Wed Apr 24, 2013 6:52 am

Ok I have p2p link , 2 units lets say 2xSXT in bridge There are mounted on the roof, no encryption

How can anyone hack in my network?
That is quite easy. SXT don't have very tight beamwidth or much shielding. All anyone needs is a decent antenna and near line of sight.
 
hebeda
newbie
Posts: 36
Joined: Sat Jun 17, 2006 8:12 pm
Location: Leipzig, Germany
Contact:

Re: Is mikrotik is secured ...

Wed Apr 24, 2013 1:48 pm

encrypt the datastream with IPSEC VPN , no need for wpa2 or anything ...
 
CelticComms
Forum Guru
Forum Guru
Posts: 1765
Joined: Wed May 02, 2012 5:48 am

Re: Is mikrotik is secured ...

Wed Apr 24, 2013 2:27 pm

encrypt the datastream with IPSEC VPN , no need for wpa2 or anything ...
Good security is layered. Using both WPA2 and IPsec is more secure than IPsec alone.
 
User avatar
ohara
Member
Member
Posts: 387
Joined: Mon Jun 13, 2011 11:30 pm
Location: Warsaw

Re: Is mikrotik is secured ...

Sat Apr 27, 2013 11:23 am

In addition to the above, I think that if you can get on to a frequency which is non standard, you will make it more difficult for other devices to detect your radio link. If you want to use MT, then a 6Ghz link can be a strong argument while you're negotiating terms of service with somebody who is security conscious. 6Ghz hardware is more expensive, therefore less popular, and it lets you hide from devices that are using other frequencies.

EDIT: access list, connect list, max station count, proprietary wireless protocol like nv2 are additional security options.
 
pixelkop
newbie
Topic Author
Posts: 40
Joined: Mon Apr 30, 2012 5:44 pm

Re: Is mikrotik is secured ...

Wed May 01, 2013 11:14 pm

Thanks for all reply. now i can do this project very cool.... we are installing 10 radio link for one banking client.
 
stormeporm
newbie
Posts: 44
Joined: Sun Dec 30, 2012 12:39 pm

Re: Is mikrotik is secured ...

Fri May 03, 2013 11:11 am

If your going to add ipsec dont do it with a pre shared key but use a certificate.
Ms chap is compromised
http://msmvps.com/blogs/harrywaldron/ar ... ccess.aspx