internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It


  About Us l Contact Us l Privacy
Home News Business Software Hardware Online Marketing Web Management The Basics
Product Watch Buyer's Guide Small Business Essentials Online Forums Glossary Images Events

Search SBC

Search internet.com


Small Business Computing Product of the Year Awards
Winners Announced!


internet.commerce
Be a Commerce Partner
Compare Prices
Online Shopping
Career Education
Condos For Sale
Holiday Gift Ideas
Send Text Messages
SMS Gateway
Corporate Gifts
Logo Design Custom
Hurricane Shutters
Compare Prices
Logo Design
Phone Cards
Shop Online

Free Newsletters
Small Business Computing

Ecommerce Guide Daily

Webopedia

E-mail Offers

Newsletter Address Changes
Webopedia Glossary
Enter a Term:

internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

Get Started with Oracle on Windows DVD
Learn how Oracle gives you the power to grow by providing a scalable, easy-to-use platform for running your business at a price you can afford. Request your free copy of this DVD, containing Oracle Database 11g software, whitepapers, tutorials, etc. Register now! ;
Guide to Oracle 11g and Database Migration
Oracle Database 11g includes more features for self-management and automation, which makes it easier for customers to cost-effectively manage their data. Download this Internet.com eBook for an overview of some of the new features in 11g and for an overview of the issues you need to consider as you prepare for a database migration. ;
Innovate Faster with Oracle Database 11g
Read this in-depth analysis of 56 customers, which shows significant differences between the value software vendors Oracle and SAP deliver to midsize companies. ;
Oracle Business Intelligence Standard Edition One
Find out how Newport Beach, CA-based Mobilitie is shaking up the telecom industry by leveraging technology to provide an entirely different financial model for deploying, upgrading, and owning wireless and wireline network assets. ;
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Quickly implementing an ERP software solution can be of tremendous benefit; however, companies often struggle to balance the benefits of reducing implementation time and cost with the risks of an accelerated deployment. Read this white paper to learn about easy-to-follow best practices for achieving a successful accelerated implementation. ;
Making the Case for Oracle Database on Windows
Users benefit as vendors reduce enterprise complexity and deliver integration. ;



Hot Topics
Driving Business from Bloggers
Demystifying Search Engine Optimization: Part 2
Last Call: Vote Today!


Small Business Essentials
Networking Fundamentals
Be it wired or wireless, building a network can take your small business to new heights in Internet communications, real-time collaboration, webhosting and e-commerce — or simply be setup to connect a series of workstations with a shared printer. Learn how to leverage today's networking technologies at your small business.
[ more ]


Related Articles
Demystifying a Small Business Network
Demystifying a Wireless Network for Small Business Owners
Get the Most From Your USB WLAN Adapter


Is secure, available data a challenge? Symantec Online Backup can help with an easy to use, secure, web-based solution for your business. Sign up and get your first 30 days free.
Hardware & Equipment
A Tale of Two Passwords
By Joseph Moran
February 29, 2008

There's no two ways about it—passwords can be a pain in the... well, you know. Most people would avoid dealing with them if they could and thus engage in some bad password habits, like creating overly simplistic passwords (plus using the same password for everything) and failing to change default passwords.

On your broadband router, there are two passwords in particular, that when set improperly, can leave your network vulnerable.

Router Administration Password
This is a password that's commonly overlooked. Given that people may seldom need to access the router's settings beyond an initial configuration, many either inadvertently or intentionally leave the password at its factory default value, which is usually the manufacturer's name, "password", "1234" or sometimes even no password at all.

A router's admin password provides access to critical settings that govern both your Internet connection and personal wired and/or wireless network, and leaving it unchanged can leave you vulnerable to a specific kind of attack known as drive-by pharming.

Last year, some security researchers effectively invented and documented this kind of attack. In a nutshell, code embedded in a Web page or e-mail message is used to remotely log into a router using a known default password. (The default password for almost any brand and model of router is easily looked up online. See for yourself at Routerpasswords.com, which is just one site among many.)

In drive-by pharming, once granted access to the router an attacker can then configure it to use the attacker's own DNS servers — not unlike how we configured a router to use OpenDNS a few weeks back — and from there exercise total control over which sites the user is taken to. (For a narrated animation describing how a drive-by pharming attack works, check out this Symantec Web page

What was once a theoretical risk has (perhaps inevitably) become a very real one. According to Symantec security researcher Zulfikar Ramzan—one of the researchers who originally discovered and documented the attack— drive-by pharming has now just been spotted "in the wild", which means it's actually been done in the real world as opposed to just in a computer lab. It was in Mexico, to be specific, where it was used to redirect folks using a specific router to a faux Web site posing as that of a major bank. (Read a detailed description on Ramzan's blog.)

Long story short, if you forgot to change your router's password or didn't think you needed to, now is an excellent time to log on to your router and correct that mistake. If you don't know your router's default password offhand, you'll very likely find it on the site mentioned above.

WPA Password
Another router-based password that you'll want to take a close look at is the one you use to WPA-encrypt your wireless network. Those in the know wisely choose WPA over WEP because of the superior security it can provide, but this isn't automatic— the password you create will directly affect the level of protection you receive.

Case in point: a WPA password can be as short as eight characters or as long as 63, but as with all passwords, there's a tendency to use the shortest and easiest to remember WPA password possible. People commonly set up WPA passwords that are dictionary words or proper names of family members or pets, because it must be typed into every device on their wireless networks.

One of the reasons WEP is so weak is because it uses a static encryption key which can eventually be decoded if you monitor the network long enough—often for just hours or minutes. WPA is better because it uses the password you specify to generate a constantly-changing series of encryption keys. But all those keys are still derived from that single WPA password (also known as the Pre-Shared Key, or PSK), so a longer and more complex password will produce keys that are stronger and harder to decode. Put another way, a lengthy WPA password made up of random characters is far preferable to something like "samandmary".

If you're using such a short-and-simple WPA key, it's highly advisable that you change it. Don't despair about having come up with a long complicated password, though, because there are Web sites that can help. You can head over to Passpub.com to grab an instant 52 character key, or generate a custom-length password at Kurtm.net. (The former site sends your key over an SSL-encrypted connection, while the latter generates it directly on your computer, so there's no danger of eavesdropping.)

And yes, you will have the inconvenience of entering your newly long and cumbersome key at each of your wireless computers. But you'll only have to do it once, and it's a small price to pay for better security. These days, you can't be too careful.

Adapted from PracticallyNetworked.com, part of the EarthWeb.com Network.

Do you have a comment or question about this article or other small business topics in general? Speak out in the SmallBusinessComputing.com Forums. Join the discussion today!

Tools:
Add smallbusinesscomputing.com to your favorites
Add smallbusinesscomputing.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed

eBook: Evaluating Software as a Service for Your Business. Sponsored by Webroot
Flash Demo: Learn how IBM Information Server Blade is easy to manage, highly scalable and efficient.
Learn about expanding business opportunities for the reseller channel. Visit IT Channel Planet.
Is secure, available data a challenge? Try Symantec Online Backup free for 30 days.
Whitepaper: Enterprise Information Integration--Deployment Best Practices for Low-Cost Implementation



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES