<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>CWIzatt</title>
	<atom:link href="http://www.lockergnome.com/izatt82/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lockergnome.com/izatt82</link>
	<description>My opinions and views of the world</description>
	<pubDate>Fri, 18 Jul 2008 23:31:31 +0000</pubDate>
	<generator>http://www.lockergnome.com/?v=2.6.1</generator>
	<language>en</language>
			<item>
		<title>You are not safe anymore on TOR</title>
		<link>http://www.lockergnome.com/izatt82/2008/07/18/you-are-not-safe-anymore-on-tor/</link>
		<comments>http://www.lockergnome.com/izatt82/2008/07/18/you-are-not-safe-anymore-on-tor/#comments</comments>
		<pubDate>Fri, 18 Jul 2008 23:10:48 +0000</pubDate>
		<dc:creator>Chris Izatt</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[hacking]]></category>

		<category><![CDATA[hiding on the web]]></category>

		<category><![CDATA[IP]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.lockergnome.com/izatt82/2008/07/18/you-are-not-safe-anymore-on-tor/</guid>
		<description><![CDATA[Read this article (PDF) on how IPs of clients using the Onion router can be found. You might be shocked what you read if you didn&#8217;t already know.
digg story
]]></description>
			<content:encoded><![CDATA[<p>Read <a href="http://www.packetstormsecurity.org/0610-advisories/Practical_Onion_Hacking.pdf">this article</a> (PDF) on how IPs of clients using the Onion router can be found. You might be shocked what you read if you didn&#8217;t already know.</p>
<p><a href="http://digg.com/security/you_are_not_safe_anymore_on_TOR">digg story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lockergnome.com/izatt82/2008/07/18/you-are-not-safe-anymore-on-tor/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wireless Router Security</title>
		<link>http://www.lockergnome.com/izatt82/2008/07/04/wireless-router-security/</link>
		<comments>http://www.lockergnome.com/izatt82/2008/07/04/wireless-router-security/#comments</comments>
		<pubDate>Fri, 04 Jul 2008 04:45:50 +0000</pubDate>
		<dc:creator>Chris Izatt</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[hacking]]></category>

		<category><![CDATA[information security]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[sniffing]]></category>

		<category><![CDATA[wireless routers]]></category>

		<guid isPermaLink="false">http://www.lockergnome.com/izatt82/2008/07/04/wireless-router-security/</guid>
		<description><![CDATA[  
In today’s consumer market people expect certain things from products, such as security. One item that keeps getting more popular is the wireless router. This is a very functional piece of equipment and needs to be optimized for security. The way a wireless router works is it takes your wired internet connection and [...]]]></description>
			<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   &lt;![endif]--><!--[if gte mso 9]&gt;     &lt;![endif]--><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  &lt;![endif]--> <!--  /* Font Definitions */  @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:Calibri; 	mso-fareast-font-family:Calibri; 	mso-bidi-font-family:"Times New Roman";} p.MsoHeader, li.MsoHeader, div.MsoHeader 	{margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	tab-stops:center 3.0in right 6.0in; 	font-size:11.0pt; 	font-family:Calibri; 	mso-fareast-font-family:Calibri; 	mso-bidi-font-family:"Times New Roman";} span.verdana 	{mso-style-name:verdana;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-page-numbers:1; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  &lt;![endif]--></p>
<p>In today’s consumer market people expect certain things from products, such as security. One item that keeps getting more popular is the wireless router. This is a very functional piece of equipment and needs to be optimized for security. The way a wireless router works is it takes your wired internet connection and transmits it like a radio station. Unfortunately these routers do not secure themselves and many people do not understand the risks in leaving them unsecured. I will talk about several things in this essay including, securing your router, how to secure your router, how common unsecured wireless routers are, and the different ways to make sure you keep your information private.  </p>
<p>Many people that have purchased wireless routers simply just plug them in and go. This does work and there is no setup required to make them function. Leaving your router like this could be disastrous. This device takes the internet connection and broadcasts it through a radio frequency signal. So somewhat like a radio station does and you are able to listen in on a radio. The same thing works for a wireless router. Anyone with in a three hundred foot radius can connect to your router. This might seem harmless, but in doing so you are making it entirely too easy for someone to access you and your information from a remote location.  Think about it this way, someone connects to your router in seconds because it is unsecured and gains access to your computer and injects a virus. This whole process would be undetected by you most likely and now your computer is a spamming machine. What I mean by that is, someone was able to use you internet protocol address to do their dirty work and now when they track the spam back, it will come to you and you only. Along with doing that the attacker could copy all your data and be gone before you know it.</p>
<p>In routers sold today the most common two types of encryption are (WEP) or Wired Equivalency Protection and (WPA2) WiFi Protected Access 2. There are some major differences in these two encryptions and their security. WEP was released in 1997 to be used by the 802.11 protocols of wireless access points. In March 2000 there was some weakness found in this encryption. What if I said that if we can intercept a cipher text C, that we could guess the plaintext of that? Maybe this does not look like much, but let me explain further. “Let <em>Z </em>= RC4(key, IV) this will be the whole RC4 key stream or the encrypted output of the router. The main problem with using RC4 is, if the same key stream is used twice it can become very insecure. Since C= P+Z. We can conclude that the RC4 key stream Z is equal to Z<em> </em>= <em>P </em>+ <em>C </em>= <em>P </em>+ (<em>P </em>+<em>Z</em>) like I stated before this is not a problem unless the key stream is reused. To put this in to perspective an eavesdropper can decrypt intercepted cipher texts without knowing the key, this is a major risk. Now that the attacker knows these values he can (Spoof packets) and the router will accept them, because they are no different encryption wise than the others” (Wagner). What is wrong with this?  The attacker can send these packets through the access control and he can attack any computer connected to that network. WEP is better than leaving your router unencrypted, but it is very insecure and can be cracked in a matter of minutes. WPA2 a second generation of WPA, which uses a stronger encryption algorithm called AES (Advanced Encryption Standard). It also uses a preshared key that is used at both ends from the router and on the device gaining access. “WPA2 uses CBC-MAC (Cipher Block Chaining Message Authentication Code) Protocol for authentication and integrity, and CTR (Counter Mode) to encrypt the data and MIC. WPA2&#8217;s MIC is similar to a checksum and provides data integrity for the nonchangeable fields in the 802.11 header, unlike WEP and WPA. This prevents packet replay from being exploited to decrypt the packet or compromise cryptographic information” (Bulk). This is not to say that WPA2 can not be cracked, but with up to a sixty three character pass phrase the number of unique packets needed to be intercepted would be very large. Using a very strong pass phrase is very important with WPA2. Experts have stated that, for personal use WPA2 along with a strong pass phrase would be unpractical to decrypt and very timely. Knowing this you can take one more step towards making your home network more secure.</p>
<p>You have all this information, so how do you encrypt your wireless router? Depending on your wireless router the internet protocol address to access it will differ. You can find these in your manual or if you do not have that the information can be found with your favorite search engine. Generally searching your router brand name and internet protocol address will find this info. Now that you have found that simply type it into your browser just like a website address, for example 192.168.1.1 a box will pop up asking you to login. If you have never done this the username and password are set to default and can also be found on the internet or the manual. The username and password should be changed as well if you have not already done so. Now logged into your router there are a number of things you can do in this menu. What I will be focusing on is the encryption and how to set this up. Since routers menus differ based on brand I will do my best to give you general directions that maybe not be exact. In this menu there should be a tab that says wireless or something to that effect. You may have to look a little to find wireless security, once you have found that move on. In the wireless security tab there might be a number of choices, but I will only be discussing WPA personal and WPA2 personal. These two should be sufficient for your personal network and are more user friendly. You can choose either, but I would recommend WPA2 personal, as it is the most updated. There should be some tabs below for options to choose from, one of them being which algorithms you want to use. In my router I have the option to use both TKIP+AES together which is what I use and what I would recommend. There should also be a box to enter the shared key in to. This pass phrase is what I mentioned before and the need to have a strong one. A few keys to having strong pass phrase are to have characters types of numbers, letters, and symbols. The pass phrase will be strong if it is random and not a word from the dictionary. I mentioned before the need for a longer pass phrase. This is because the longer the pass phrase the more combinations possible. All there is left to do is to hit enter or submit.  When logging into your router you will have to enter the same pass phrase as before, normally your computer will save this and you will only have to do it once. </p>
<p>You now have an encrypted router so all your data is safe right? Not exactly. One attack I want to present is called The Man in the Middle Attack. An attacker is able to intercept packets and retransmit them with his own key. What is happening is that in the middle of a conversation from your computer to a server, the attack replaces the server with a fake one. One way to defeat this type of attack is not to click through error messages that pop up to alert you. When an attacker does this there maybe an error message stating that the server was not authenticated, but if you do not read your error messages you will never know this is happening and that is what the attack relies on. So many people have access to technology and do not educate themselves on it. This makes the life of a black hat hacker very easy. We have access to many defenses, but if we do not educate ourselves on how to use it properly then they can be exploited more easily. </p>
<p>I conducted a security survey of sixty city blocks of Taylorville, IL. This is not a very large area by any means. I found thirty one unsecured wireless access points during this survey, I find this unacceptable. Some of these were near the town square and possibly business’ or maybe government offices. This is just speculation with out doing more research on who owns these routers. I expected to find some unsecured routers during this survey, but not as many I as did find. This survey was not time consuming for me and it would not be to an attacker either. New technology is introduced on a constant basis and people do not take the time to educate themselves. Secure your wireless router and use the strongest possible security available to you.</p>
<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   &lt;![endif]--><!--[if gte mso 9]&gt;     &lt;![endif]--><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  &lt;![endif]--> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  &lt;![endif]--></p>
<p align="center"><strong>Works Cited</strong></p>
<p>Bulk, Frank. &#8220;<a href="http://www.lexisnexis.com.er.llcc.edu:2048/us/lnacademic/results/docview/docview.do?docLinkInd=true&amp;risb=21_T3920199034&amp;format=GNBFI&amp;sort=BOOLEAN&amp;startDocNo=1&amp;resultsUrlKey=29_T3920199037&amp;cisb=22_T3920199036&amp;treeMax=true&amp;treeWidth=0&amp;csi=155287&amp;docNo=1">ABCs Of WPA2 Wi-Fi Security</a>.&#8221; <u>Network Computing</u> 02 Feb 2006 10 Jun 2008.</p>
<p>Cam-Winget, Nancy, Russ Housley, David Wagner, and Jesse Walker. &#8220;Security Flaws in 802.11 Data Link Protocols.&#8221; <u>Communications of The ACM</u> 46 No. 5 (May 2003): 35-39.</p>
<p>Chirillo, John. <u>Hack Attacks Revealed</u>. Second. Indianapolis,  IN: Wiley Publishing, 2002.</p>
<p>Endorf, Carl, Eugene Schultz, and Jim Mellander. <u>Intrusion Detection &amp; Prevention</u>. Emeryville, CA: McGraw Hill/ Osbourne, 2004.</p>
<p>Hardjono, Thomas, and Lakshminath R. Dondeti. <u>Security in Wireless LANs and MANs</u>. Norwood, MA: Artech House, INC, 2005.</p>
<p>Wagner, David. &#8220;<a href="http://www.fcc.gov/realaudio/presentations/2002/042902/wagner.pdf">Wireless Security</a>.&#8221; <u>fcc.gov</u>. University of California, Berkley. 10 Jun 2008.</p>
<p>&#8220;<a href="http://techdir.rutgers.edu/wireless.html">Wireless Security</a>.&#8221; <u>Rutgers Computing Services</u>. 23 Mar 2006. The State University of New Jersey.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lockergnome.com/izatt82/2008/07/04/wireless-router-security/feed/</wfw:commentRss>
		</item>
		<item>
		<title>America&#8217;s economy</title>
		<link>http://www.lockergnome.com/izatt82/2008/04/13/americas-economy/</link>
		<comments>http://www.lockergnome.com/izatt82/2008/04/13/americas-economy/#comments</comments>
		<pubDate>Sun, 13 Apr 2008 16:28:49 +0000</pubDate>
		<dc:creator>Chris Izatt</dc:creator>
		
		<category><![CDATA[Illinois]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[politics]]></category>

		<category><![CDATA[president]]></category>

		<category><![CDATA[economy]]></category>

		<category><![CDATA[oil]]></category>

		<guid isPermaLink="false">http://www.lockergnome.com/izatt82/2008/04/13/americas-economy/</guid>
		<description><![CDATA[The fact of the matter is, our economy is crap. For any one who has had to look for a job any time lately you understand the employment situation. This is really getting out of hand, we have companies now that just run job ads with out there really being a position open. So when you [...]]]></description>
			<content:encoded><![CDATA[<p>The fact of the matter is, our economy is crap. For any one who has had to look for a job any time lately you understand the employment situation. This is really getting out of hand, we have companies now that just run job ads with out there really being a position open. So when you think you are applying for an opening really you are just submitting to a list. Along with that how many of you have called a company and got somebody overseas? I know I have many times. Also business now run the tele voice mail or whatever you want to call the computer you always have to talk to when you call a business. Now what do these have to with the economy, well a lot. Business out source to other counties, no longer want to interact with there customers, and do not hire those people who normally would do those jobs. This turning into a bad cycle of events in my mind big business continue to rake in huge profits while constantly raising prices. Oil companies are the worst, they continue to raise prices even through they are making record breaking profits, who will step in and say enough is enough? In my eyes no one will, the oil companies either have the politicians paid off or on the pay role in some form. Think about this, in a small town close by me in Illinois a power plant was planned to be built after a long wait and process of the company looking for the best spot. The last two towns were the one here in IL and a town in Texas. Illinois got the spot and the people in this region were ecstatic. There just not that much money that gets put into these towns and cities so this was a big deal. A short time after this we here word that President Bush got involved and now some how the plant will be getting built in the Texas town. HHHHHHHHHMMMMMMM, isn&#8217;t he from Texas? Doesn&#8217;t this seems like somebody got paid or owed somebody a favor?</p>
<p>What I feel is the solution is the need to remove and replace the government as a whole. The one we have now is totally corrupt. I think if our government  had other restrictions for politicians it would run a lot better. For example no more contributions, politicians may not be tied to large corporations of any kind, and they only get there pay check from the government while in power and can not make any other money. In some ways this seems unamerican, but at the same time if our officials are always tied to big money how will the common man be heard? </p>
]]></content:encoded>
			<wfw:commentRss>http://www.lockergnome.com/izatt82/2008/04/13/americas-economy/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Present Day Presidents</title>
		<link>http://www.lockergnome.com/izatt82/2008/03/10/the-present-day-presidents/</link>
		<comments>http://www.lockergnome.com/izatt82/2008/03/10/the-present-day-presidents/#comments</comments>
		<pubDate>Mon, 10 Mar 2008 06:49:24 +0000</pubDate>
		<dc:creator>Chris Izatt</dc:creator>
		
		<category><![CDATA[election]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[politics]]></category>

		<category><![CDATA[president]]></category>

		<category><![CDATA[voting]]></category>

		<guid isPermaLink="false">http://www.lockergnome.com/izatt82/2008/03/10/the-present-day-presidents/</guid>
		<description><![CDATA[I am confused on a issue and it has been bugging me for some time now. So i will share it here with you guys on my blog now that I have one.
I thought that our presidents here in the US swore to uphold our constitution? Now the part I am confused about is, some [...]]]></description>
			<content:encoded><![CDATA[<p>I am confused on a issue and it has been bugging me for some time now. So i will share it here with you guys on my blog now that I have one.</p>
<p>I thought that our presidents here in the US swore to uphold our constitution? Now the part I am confused about is, some of the candidates are for banning guns. This very idea goes against the the piece of paper that they will swear to protect if elected. That is the same thing as a cop being hired and then selling drugs. How is this possible? In my opinion the younger generation, my generation has blinders on&#8221;like a horse.&#8221; The only thing they see is what pertains to them right now and do not care about anything else. What can be done to fix it, well take action, vote, voice your opinions, be active in government and make our voices heard, even if you think different than I. This is America.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lockergnome.com/izatt82/2008/03/10/the-present-day-presidents/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Gun Control In Illinois</title>
		<link>http://www.lockergnome.com/izatt82/2008/03/10/gun-control-in-illinois/</link>
		<comments>http://www.lockergnome.com/izatt82/2008/03/10/gun-control-in-illinois/#comments</comments>
		<pubDate>Mon, 10 Mar 2008 06:36:10 +0000</pubDate>
		<dc:creator>Chris Izatt</dc:creator>
		
		<category><![CDATA[Illinois]]></category>

		<category><![CDATA[firearms]]></category>

		<category><![CDATA[guns]]></category>

		<category><![CDATA[second amendment]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[politics]]></category>

		<guid isPermaLink="false">http://www.lockergnome.com/izatt82/2008/03/10/gun-control-in-illinois/</guid>
		<description><![CDATA[Gun control in Illinois is just out of control. I do not want you guys to think that I am some gun nut just crying, i am not. Illinois is one of the most restrictive states in the union. Number one, we have to carry a card with us to transport, buy firearms, and buy [...]]]></description>
			<content:encoded><![CDATA[<p>Gun control in Illinois is just out of control. I do not want you guys to think that I am some gun nut just crying, i am not. Illinois is one of the most restrictive states in the union. Number one, we have to carry a card with us to transport, buy firearms, and buy ammunition! The state has proven that gun control does not work, but they continue to try to take away firearms from law abiding citizens. In 1982 Chicago banned handguns, how has that turned out? Not very good, murders with handguns have been rising for years. A Chicagoan said &#8220;I&#8217;m entitled to defend myself.  I think this law is a life or death matter,&#8221; said the man, who asked not to be identified. (Fox News) People can not defend themselves any more and are told that is what the police are for. Sure that is what the police are there for, but will they be there to save you son or daughter from getting shot in a car jacking? Cops can not and are not every where, sure they do there job, but they are not mind readers. Citizens well they are every where 24 hours a day, all around us. We should be able to protect ourselves and others from such crime, but not in Illinois. What disturbs me the most is, I was in the US Marine Corps and I swore to protect our constitution. Now some politician wants to tell me I can not carry a gun to protect myself! I just want to get this straight, I am good enough to take a bullet so that elected official can speak freely, but I can not carry a gun which is a right given by &#8220;God&#8221; according to our forefathers. I can not see the logic in this, the federal government paid me to protect national assets, but I can&#8217;t help protect people from being victims. If we the people keep letting the government do what they want, that is exactly what all of us including your family will become &#8221; VICTIMS.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lockergnome.com/izatt82/2008/03/10/gun-control-in-illinois/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
