Password Security

2009-02-17 by Administrator, tagged as fun

This is just too crazy. Right now I am sitting in a hotel room of a hotel chain which offers WLAN services itself (a software called “HotSpotCenter” from Dr. Eckhardt + Partner GmbH) and through Swisscom.

Both solutions are far too expensive and I usually do not depend on such things since I have a UMTS flatrate. But for some reason I do not get a connection in my hotel room and so I looked for unsecured wireless networks and of course I found one right away with the hotel name as SSID. Connecting to it and opening a web browser I was presented with a welcome page asking me to present my credentials.

Hotel WLAN Login

I then figured they have some kind of MAC authentication and wanted to sniff wireless traffic a little bit and see if I could capture a MAC address of an allowed client. So I started MS Netmon and shortly after I had a MAC address to try out. But then my wireless network driver would not let me change my MAC address and with no Internet access I was chasing my own tail.

Wirless Driver Settings

“What the heck let’s try some passwords” I thought and my first try was the hotel name as user and password. Doing so I found myself confronted with the administrative interface of the HotSpot Software.

Hotel WLAN Admin

Playing around a little but I finally printed myself a nice little voucher and now I am writing this post.

Hotel WLAN Voucher

Now this is password security the way I like it.