Page 1 of 1

Is mikrotik is secured ...

Posted: Sat Apr 20, 2013 1:24 pm
by pixelkop
We are suggesting radio link for one Bank. but customer is saying Wireless is not secured. hacking is possible. so can you describe what type of security we are using when we are doing point to point link with router boards. any wiki ??? so we can give to customer. Thanks in advance.

Re: Is mikrotik is secured ...

Posted: Sat Apr 20, 2013 3:54 pm
by Lakis
Ok I have p2p link , 2 units lets say 2xSXT in bridge There are mounted on the roof, no encryption

How can anyone hack in my network?

Re: Is mikrotik is secured ...

Posted: Sat Apr 20, 2013 3:59 pm
by EMOziko
Use wpa2\aes or wpa\aes. Use strong passwords. Use management frame protection and no one will be able to hack your network.

p.s. Banks must have PCI DSS standard implemented in there network.

Re: Is mikrotik is secured ...

Posted: Sat Apr 20, 2013 6:38 pm
by tomaskir
If you are using WPA2 encryption for the link, the only way to hack is a dictionary attack or bruteforcing the password.
Against both, if you have a good PSK, its pretty much impossible. Make sure its atleast 12 characters, containing capital letters, normal letters, numbers and special characters, and is not based on any words.

As mentioned before, use management protection to avoid de-auth attacks.

Re: Is mikrotik is secured ...

Posted: Sat Apr 20, 2013 6:57 pm
by nickshore
Use an extra layer of strong encryption.

Run WPA2 or NV2 encrytion on the wifi, and then run IPSEC over that

Nick.

Re: Is mikrotik is secured ...

Posted: Sat Apr 20, 2013 8:07 pm
by Lakis
So noon has answered my question

I have 2xSXT in bridge p2p that run nv2

tomaskir How on earth can u do dictionary attack or bruteforcing from ur PC that run Linux or Windows

and even if u find password what next how can u Hack in to a bank network - first u mast be connected to one SXT to have access to bank network

Re: Is mikrotik is secured ...

Posted: Sat Apr 20, 2013 8:13 pm
by tomaskir
Assuming its a WPA2 secured network, using Linux, its simple:

You use a deauth attack on one end. Then capture the re-auth of the client using airodump-ng. You then use aircrack-ng to bruteforce the aepol auth process.
Of course, if its a secure password, its gonna take a long time. But if you use a dictionary attack, and the password is word-based, its not that hard to crack.

Re: Is mikrotik is secured ...

Posted: Sat Apr 20, 2013 8:30 pm
by angboontiong
create an EOIP Tunnel or implement MPLS on your wireless link as most bank lease line go with MPLS...

Is mikrotik is secured ...

Posted: Sun Apr 21, 2013 7:41 am
by cbrown
Use an extra layer of strong encryption.

Run WPA2 or NV2 encrytion on the wifi, and then run IPSEC over that

Nick.

Agreed.

Re: Is mikrotik is secured ...

Posted: Wed Apr 24, 2013 6:52 am
by 0ldman
Ok I have p2p link , 2 units lets say 2xSXT in bridge There are mounted on the roof, no encryption

How can anyone hack in my network?
That is quite easy. SXT don't have very tight beamwidth or much shielding. All anyone needs is a decent antenna and near line of sight.

Re: Is mikrotik is secured ...

Posted: Wed Apr 24, 2013 1:48 pm
by hebeda
encrypt the datastream with IPSEC VPN , no need for wpa2 or anything ...

Re: Is mikrotik is secured ...

Posted: Wed Apr 24, 2013 2:27 pm
by CelticComms
encrypt the datastream with IPSEC VPN , no need for wpa2 or anything ...
Good security is layered. Using both WPA2 and IPsec is more secure than IPsec alone.

Re: Is mikrotik is secured ...

Posted: Sat Apr 27, 2013 11:23 am
by ohara
In addition to the above, I think that if you can get on to a frequency which is non standard, you will make it more difficult for other devices to detect your radio link. If you want to use MT, then a 6Ghz link can be a strong argument while you're negotiating terms of service with somebody who is security conscious. 6Ghz hardware is more expensive, therefore less popular, and it lets you hide from devices that are using other frequencies.

EDIT: access list, connect list, max station count, proprietary wireless protocol like nv2 are additional security options.

Re: Is mikrotik is secured ...

Posted: Wed May 01, 2013 11:14 pm
by pixelkop
Thanks for all reply. now i can do this project very cool.... we are installing 10 radio link for one banking client.

Re: Is mikrotik is secured ...

Posted: Fri May 03, 2013 11:11 am
by stormeporm
If your going to add ipsec dont do it with a pre shared key but use a certificate.
Ms chap is compromised
http://msmvps.com/blogs/harrywaldron/ar ... ccess.aspx