Showing posts with label wi-fi security. Show all posts
Showing posts with label wi-fi security. Show all posts

Wi-Fi networks under virus risk


Indian computer security analysts have detected and alerted Wi-Fi users in the country against a possible virus attack that could lead to crashing and hacking of secure networks.


The Indian Computer Emergency Response Team (CERT-In), country’s national agency to respond to computer security incidents, has found that the “Wi-Fi Protected Setup (WPS) contains a design error that could allow a weaker-than-expected defence against brute-force attacks, which could allow an attacker to gain unauthorised access to the affected system.”
A brute-force attack, in computer terminology, is a programme that is used to crack and stealthily enter into an encrypted and password protected system while WPS is a popular method for setting up a new wireless router for a home network.
“The virus is streaming in the Indian Internet networks with a high severity. The combat mechanisms are being deployed,” a computer security analyst with a government agency said.
“An un-authenticated, remote attacker within range of the wireless access point could use the PIN (password) to gain unauthorised access to the device to retrieve the password for the wireless network or change the configuration of the device.
“Failed attempts to exploit the vulnerability could lead to a denial of service condition,” the CERT-In said in its alert to Wi-Fi users.
The agency also said that reports (with the agency) indicate that some WPS devices “do not implement any kind of lockout policy for brute-force attempts, which greatly reduces the time to perform a successful attack.”
Searching Tag:-virus,wi-fi security,hackers,virus security,computer security,

Cross site scripting


Cross site script is most common web attack.it basically attacks on application layer of web.
.its basically hits html and javascipt.
  cross site scripting arises when web application take data from form of site and include in it
web page without properly validating the data.XSS vulnerabilities allow an attackers to execute arbitrary commands and display arbitrary content in a victim users browsers. when XSS attacks became a successful attack it take control of victim browser or victim web application.  the potency of an XSS attack lies in the fact that thr malicious code executes in the context of the victim's session,allowing the attackers to bypass normal security restriction

Types of Cross Site Scripting Attacks :-

Reflective Cross Site  Scripting :-
 
In this XSS attacks attacker send the victim a misleading mail with the link containing malicious
javascript,if the victim click the link ,the http request is intiated  from the victim browsers
 and sent to the vulnerable web application.Thw malicious javascript is then reflected back to the victim's browsers,where it is executed int the
context of  of victim users session
 

Persistent Xss

Consider a Web application that allows users to enter a user name which is displayed on each user’s profile page. The application stores each user name in a local database. A malicious user notices that the Web application fails to sanitize the user name field and inputs malicious JavaScript code as part of their user name. When other users view the attacker’s profile page, the malicious code automatically executes in the context of their session.


 

Pharming Security

PHARMING-- BY request of one my reader,i am trying to explain what is Pharming.Due to short of time i cant explain all about pharming.
Pharming is the exploitation of a vulnerability in the DNS server software that allows a hacker to acquire the domain name for a site, and to redirect that website's traffic to another web site. DNS servers are the machines responsible for resolving internet names into their real addresses - the "signposts" of the internet.


If the web site receiving the traffic is a fake web site, such as a copy of a bank's website, it can be used to "phish" or steal a computer user's passwords, PIN or account number. Note that this is only possible when the original site was not SSL protected, or when the user is ignoring warnings about invalid server certificates.


For example, in January 2005, the domain name for a large New York ISP, Panix, was hijacked to a site in Australia. In 2004 a German teenager hijacked the eBay.de domain name.


Secure e-mail provider Hushmail was also caught by this attack on 24th of April 2005 when the attacker rang up the domain registrar and gained enough information to redirect users to a defaced webpage.

Firefox spoofing flaw reported

Mozilla’s Firefox web browser is vulnerable to spoofing attacks, according to an Israeli security researcher. Aviv Raff reported on his blog on Wednesday that Mozilla Firefox v2.0.0.11 allows information presented in a basic authentication dialogue box to be spoofed, opening up the possibility of users being redirected to a malicious website. Earlier versions of the browser may also be affected.

According to Raff, when a web server returns a 401 status code, it causes Firefox to display an authentication dialogue box. The 401 status code is returned by the web server when it recognises that the HTTP data stream sent by a browser or bot is correct, but access to the URL requires further user authentication.

The authentication dialogue box displays the server URL in what is called the WWW-Authenticate header field. This URL is in part defined by the realm value and, according to Raff, it is possible for an attacker to create a specially crafted realm value that will look as if the authentication dialogue came from a trusted website. This is due to Firefox failing to sanitise single quotes and spaces in the WWW-Authenticate header field, after a legitimate realm value enclosed in double quotes has been given.

At least two possible attack vectors are opened by this reported flaw, according to Raff. Man-in-the-middle attackers could create a web page with a link to a trusted website such as a bank. When a victim clicks on the link on the malicious page, the trusted web page would be opened in a new window. A script would be executed to redirect the newly opened window to the attacker’s web server, allowing username and password details to be compromised.

Alternatively, an attacker could embed an image in an email or web page which, when clicked on, would return a specially crafted dialogue login from the attacker’s web server, again allowing authentication details to be compromised.

President of Mozilla Europe, Tristan Nitot, told ZDNet.co.uk that Mozilla is in the process of investigating the report, and so could not comment further at this time.

“We take security seriously,” said Nitot. “We are taking this report seriously, and are investigating.”

computer security

Computer security is the process of preventing and detecting unauthorized use of your computer. Prevention measures help you to stop unauthorized users (also known as "intruders") from accessing any part of your computer system. Detection helps you to determine whether or not someone attempted to break into your system, if they were successful, and what they may have done.

We use computers for everything from banking and investing to shopping and communicating with others through email or chat programs. Although you may not consider your communications "top secret," you probably do not want strangers reading your email, using your computer to attack other systems, sending forged email from your computer, or examining personal information stored on your computer (such as financial statements).
   Intruders (also referred to as hackers, attackers, or crackers) may not care about your identity. Often they want to gain control of your computer so they can use it to launch attacks on other computer systems.

Having control of your computer gives them the ability to hide their true location as they launch attacks, often against high-profile computer systems such as government or financial systems. Even if you have a computer connected to the Internet only to play the latest games or to send email to friends and family, your computer may be a target.

Intruders may be able to watch all your actions on the computer, or cause damage to your computer by reformatting your hard drive or changing your data.

Unfortunately, intruders are always discovering new vulnerabilities (informally called "holes") to exploit in computer software. The complexity of software makes it increasingly difficult to thoroughly test the security of computer systems.

Also, some software applications have default settings that allow other users to access your computer unless you change the settings to be more secure. Examples include chat programs that let outsiders execute commands on your computer or web browsers that could allow someone to place harmful programs on your computer that run when you click on them.

HOW to Track and Recover Your Lost/Stolen iPhone

iPhone is the world’s best smart phone available today without any doubt. People carry their phones everywhere they go, and hence there is always a chance of them forgetting their iPhone somewhere or the iPhone getting stolen. Learn how to track, message, erase and recover your lost or stolen iPhone.

1. Track your iPhone via MobileMe
Apple has announced a new service called Find My iPhone that will allow iPhone owners to remotely locate their lost or stolen iPhones using the iPhone’s GPS. The service will be available as part of Apple’s MobileMe online subscription service.

Find My iPhone will pinpoint the iPhone’s current location using Google Maps and let owners send and display a message on the iPhone even if it’s locked, presumably to provide information on how to return the phone to the finder of the phone.
2. iPhone anti-theft solution – iLocalis
iLocalis has the following uses-

    * Never lose you iPhone: If it is missing just log onto the iLocalis site and you’ll know where it was located last.
    * Retrieve a stolen iPhone: If your iPhone is stolen you can log into the site and check out where it’s at. Extra features built into iLocalis allow you to send text messages or make calls on your iPhone when you don’t even have it with you. If you iPhone is stolen log in and send yourself a text message. If the thief changed the sim card you’ll have their phone number!
    * Allow your family and friends to know where you are: iLocalis will send a message to your friends when you are near by. You can also set it up to allow your friends to locate you. If your friend also has iLocalis you can send messages to each other for free. No txt messaging charges.
    * iLocalis can also be used for a business that needs location services for their employees. Employees carrying iPhones with iLocalis can be tracked via the web site easily.

Computer Security Threats--Backdoor Trojan

A backdoor Trojan(security threat) allows someone to take control of another user’s
computer via the internet without their permission.
A backdoor Trojan(security threat) may pose as legitimate software, just as other Trojan horse programs
do, so that users run it. Alternatively – as is now increasingly common – users may
allow Trojans onto their computer by following a link in spam mail.
Once the Trojan is run, it adds itself to the computer’s startup routine. It can then
monitor the computer until the user is connected to the internet. When the computer
goes online, the person who sent the Trojan can perform many actions – for example,
run programs on the infected computer, access personal files, modify and upload files,
track the user’s keystrokes, or send out spam mail.
Well-known backdoor Trojans include Subseven, BackOrifice and, more recently,
Graybird, which was disguised as a fix for the notorious Blaster worm.
To avoid backdoor Trojans, you should keep your computers up to date with the latest
patches (to close down vulnerabilities in the operating system), and run anti-spam
and anti-virus software. You should also run a firewall, which can prevent Trojans from
accessing the internet to make contact with the hacker.Backdoor trojan computer security threat is one of
danger security attack.so be aware about this security threat.

Hardware Security


Security should be intertwined with every part of system; the hardware is no exception. The interaction between hardware and software must be carefully planned. In doing so, the security of the entire system is strengthened.

Trusted Computing

Systems rely on Operating Systems and hardware. This collection of components comprises the core of the Trusted Computing Base (TCB). Systems fundamentally trust all actions that take place within the TCB. As Operating Systems become increasingly more complex, they are prone to faults and vulnerabilities. Hence, researchers seek to shrink the TCB.
Recently, a consortium gathered to create an open trusted framework. The Trusted Computing Group'sTrusted Platform Module (TPM) has received much attention. While vendors such as Dell have announced the deployment of TPMs, privacy concerns remain. Such concerns must be addressed before wide-spread acceptance occurs. (TCG)
Our current research efforts aim to discover novel uses for the TPM while maintaining the privacy of users.

Securing Non-Volatile Main Memory


We propose a Memory Encryption Control Unit (MECU) to address the vulnerabilities introduced by non-volatile memories. The MECU encrypts all memory transfers between the level 2 cache and main memory. The keys used to encrypt memory blocks are derived from secret information present on removable authentication tokens, e.g., smart card, or other similar secure storage devices. This provides protection against physical attacks in absence of the token.
We evaluated a MECU-enhanced architecture using the SimpleScalar hardware simulation framework on several hardware benchmarks. The performance analysis shows that we can secure non-volatile memories with minimal overhead---the majority of memory accesses are delayed by less than 1 ns, with limited degradation subsiding within 67 us of a system resume. In effect, we provide zero-cost steady state confidentiality for main memory

uAndroid's Security Framework


                            uAndroid's Security Framework
The Google Android mobile phone platform is one of the most anticipated smartphone operating systems. Android defines a new component-based framework for developing mobile applications, where each application is comprised of different numbers and types of components. Activity components form the basis of the user interface; each screen presented to the user is a different Activity. Service components provide background processing that continues even after its application loses focus. Services also define arbitrary interfaces for communicating with other applications. Content Provider components share information in relational database form. For instance, the system includes an application with a Content Provider devoted to sharing the user's address book upon which other applications can query. Finally, Broadcast Receiver components act as an asynchronous mailbox for messages from the system and other applications. As a whole, this application framework supports a flexible degree of collaboration between applications, where dependencies can be as simple or complex as a situation requires.

Common mobile viruses:Mobile Security Threat



How they spread and what are the effects:

Cabir: When this virus infects  your mobile then  message 'Caribe' will be displayed  at each  time you switch off and  on the mobile. These worms are generally  spread through blue tooth signals from surroundings  mobiles. 
Duts: A parasitic  file infector virus .its alos  known as Pocket PC. It try to infect all EXE files which are more than 4kb present in the directory where it saved. 
Skulls:  it is a Trojan horse. Means a piece of code will be  downloaded  on your mobile nad then the virus called Skull replaces your phone desktop into  image of skull as icon.it is very dangerous as  It is usually  transferred with all phone applications and also with SMS and MMS. 
Comm warrior: It's also spread through MMS  and  unsecured blue tooth  to other devices. It has more impact on devices running under OS Symbian Series 60. This virus launches The executable worm file and the worm  hunt for gaining access to your blue tooth devices and sends the infected files under various different  name to various random device.

Bluetooth Security Risks:MOBILE SECURITY



Bluetooth Security Risks
1. The first step in using any Bluetooth device is to turn on the Bluetooth feature in it. The default state of Bluetooth in any device is “Off” mode. 
2. Once Bluetooth is turned on, it is in active but dormant state. In order to use it, it needs to be put in to “Discoverable” state. In theory when a device is in “non discoverable” state it should not be visible to other devices but in reality the device is still discoverable to those devices it has made a connection before using MAC address. A hacker seeing the Blue LED can use Brute Force address discovery process to record the MAC address and hack the device using software such as RedFang.


3. During communication process also Bluetooth technology exposes itself to security breach as the address itself is not encrypted although the message may be encrypted. Technique such as frequency hogging provides some protection but is not completely secure.
4. There are devices available in the market which can capture a Bluetooth signal from the air and analyze. At present cost is prohibitive for casual hackers to acquire some of these devices but still a professional hacker can use those devices and hack vital information.
5. Many owners leave the Bluetooth device in the discoverable mode after actual use due to ignorance or simply forget to turn off “discoverable” mode which gives hackers easy opportunity to pair with their device and hack.
6. Pairing two Bluetooth devices usually does not require any authentication, however using a service like file transfer or data/video/voice exchange require some authentication by entering PIN. Once PINs are entered a link key is generated and stored in the device’s memory. This process is not required for next time onwards.
7. Many vendors do not implement authentication and authorization process correctly allowing hackers to steal information or use one’s phone or use it for making calls or SMS.

BLuebugging:Can Breach YOUR Mobile Security



BLuebugging was somewhat like bluesnarfing but the difference is that it is more harmful to your mobile from the prospective of security of your mobile. It was first invented in 2004 by German scientist. In the initial phase, it was necessary to pair devices via Bluetooth before the security breacher  try to breach your mobile with the bugger, but now a days its not needed to pair up the devices.[sintuhack]. It can also possible to break you mobile security via the Bluetooth enabled headset which is used to take call as per to free your hands.[sintuhack]

At early stage it was done with laptop but now a days such powerful PDA and mobile phones are available  in the market that it can be done without laptops .[sintuhack]. you may be happy that your mobile Bluetooth has only a small range so its not easy to pair up your device hence you mobile is secured. But did you know that in market antenna’s are available which can send and receive weak signal s and hence data can be transferred from range of even 200 meters.[sintuhack]

Bluesnarfing:Mobile Security Breach

Bluesnarfing refers to a the method in which one has gained access to data, which is stored on a Bluetooth enabled phone of other people.
Literally Bluesnarfing can be described as unauthorized access of information from a wireless device through a Bluetooth connection. The level of access depends from case to case, but, in general, it involves pretty much anything that's stored on the user's mobile device.
Bluesnarfing allows the using person to make phone calls, send and receive text messages, read and write phonebook contacts, eavesdrop on phone conversations, and connect to the Internet. he can also download the material in his mobile from the victim mobile.
The good news is, bluesnarfing requires advanced equipment and much advanace expertise


In this field. As bluejacking can be done at the range of 10 meters, in bluesnarfing the intruder must be present within a 30 ft. range.
If the phone is in non-discoverable mode, then its not true that you cant be a victim of this.
Its adds only some problem and makes it little bit more difficult for intruders to bluesnarf your phone.


It can be possible from phone and laptop both to bluesnarf a mobile. By just using some bluesnarfing tools (Bluesnarfer, Blooover)

on mobile phone or laptop, anyone can detect and access those vulnerable mobile phones to view and download entire phonebook, calendar, real time clock, business card and other important private data without alerting the phone owner(you).




There's little info on whether Bluesnarfing is possible without the targeted phone being paired with the computer running the aforementioned software application, but anyone cannot completely rule out this possibility, either.


So that’s all about bluesnarfing. Wait till next post to know about other mobile security breach methods………….

10 tips for safer electronic banking and protecting yourself under the EFT Code

The Electronic Funds Transfer Code (EFT Code) protects consumers who use electronic banking such as ATMs and EFTPOS, or telephone and internet banking, to transfer funds.
Here are some important tips to remember about your rights and obligations under the code.

1. There are a number of situations where, under the EFT Code, you will get all of your money back if there was an unauthorised transaction on your account. For example:

* If a forged, expired or cancelled PIN or card was used;
* If there was fraudulent conduct by employees of your account institution or merchant;
* If the transaction took place before you received your card, PIN or code;
* If a merchant incorrectly debited your account more than once;
* If the transaction took place after you told your account institution that your card had been lost or stolen or that someone else may know your PIN or password; or
* If it’s clear that you haven’t contributed to the loss.

2. You won't get your money back from unauthorised transactions however if:

* You acted fraudulently or didn't keep your PIN or password secret:
* You unreasonably delayed telling your account institution that your card had been lost or stolen or that someone else may know your PIN or code.

Even in these circumstances though the amount you are liable for is subject to certain caps.
3. Liability will be split between you and your financial institution where a PIN or code was needed to perform the unauthorised transaction and none of the circumstances in 6 or 7 apply. In these circumstances your liability will be capped at $150 or any lower figure set by your account institution.
4. Under the code, your account institution is normally liable for any failure of their equipment or system. Also, your account institution can’t avoid their liability just because another party involved in the transaction, such as the merchant, caused the problem. You don’t have to make the complaint to one of these other parties, you can simply take your complaint to your account institution and require them to follow it up.
5. If you have a complaint about an electronic funds transfer you should start by raising the matter with your account institution. The EFT code sets our rules for dealing with these complaints.


6. Read your terms and conditions document. It will tell you your rights and obligations and things such as which accounts can be accessed with your card and/or PIN or code; any restrictions that apply, such as limits on how much money you can withdraw in a day and how to report the loss, theft or unauthorised use of the card or PIN.
7. Always check your statements to ensure there are no unauthorised transactions. Some transactions that look unfamiliar may appear that way because the merchant’s banking is done under another name.
8. Tell your account institution immediately if your card is lost or stolen or someone else may know your PIN or password. Also tell them immediately if you find an unauthorised transaction on your statement.
9. Never tell your PIN or code to anyone, including a friend or family member. Don’t record it on your card or with something you keep with your card.
Most unauthorised transactions happen because a person gave someone else their PIN or code. Safeguarding the secrecy of your PIN is the best way to protect yourself from unauthorised transactions.
10. You should avoid using your birth date or a recognisable part of your name as your PIN or code as this is easy for others to guess.

Fix your 10 common Wi-Fi problems(last five)

6. Which wireless channel should I use?
Wireless 802.11b and 802.11g routers have at least 11 channels, and most routers come set to channel 6 as the default. If you experience interference--from a neighbor's router, for instance--you can change your channel to solve the problem. Channels 1, 6, and 11 are non-overlapping channels; other channels overlap a bit. So if your neighbor's network uses channel 6, change your router to 1 or 11. You'll typically find channel settings on the router's basic wireless settings page. Just click the drop-down menu and select an alternate channel, then save the settings.

7. How do I share files on a wireless network?
First, you'll need to set up a workgroup and make sure that all PCs are assigned to the same workgroup. Next, enable file sharing in Windows. First, right-click on the folder you want to share, choose Sharing and Security from the right-click context menu, then click the Sharing tab. Put checks in the boxes labeled "Share this folder on a network" and "Allow network users to change my files" to enable others to modify the documents. Finally, click OK.

8. Should I allow other people to access my Wi-Fi service? What are the dangers?
Some users see no harm in sharing the Wi-Fi love, giving neighbors and even total strangers free access to the Internet. Others maintain that piggybacking can open their networks to potential danger. The decision is yours, but if you choose not to encrypt, make sure to disable file sharing. Assuming you have your hardware firewall turned on, the worst that probably will happen is that your throughput will drop if your piggybacking neighbors crank up BitTorrent every evening. If you want to determine whether others are using your unsecured network, most routers have a page that lists all the wireless clients currently connected.

Most people, however, are not comfortable with the idea of allowing just anyone to use their wireless service. In theory, the practice can make your network vulnerable to hackers, since anyone who uses your wireless signal is on your home network. Malevolent users, for instance, could release nasty viruses or hijack your PC. That's not terribly likely, but you should avoid the possibility by using WPA to protect yourself and keep others off your network.

9. Should I worry about packet sniffers grabbing my information when I browse the Web at public hotspots?
Yes, you should at least consider this possibility, although whether you do anything about it depends on the sensitivity of your data and your level of paranoia. Anyone can install packet-sniffing software that will enable him or her to eavesdrop on what you do at a public hotspot. These snoops can read your emails and see what Web sites you visit, but they will not have access to the files on your laptop, unless you have file sharing enabled. Also, they cannot see any messages or Web pages sent over the secure server connections typically used by banks and e-commerce sites. (Look for https:// in the URL.)

If you use a VPN to access your corporate network, you can use it at hotspots to encrypt all transmissions and shield them from packet sniffers. If you don't have a corporate VPN but frequently use public hotspots, you might consider a consumer VPN service such as the PersonalVPN from Witopia (US$39.99 per year, www.witopia.net) or BlowFish from HotSpotVPN (US$10.88 to US$13.88 per month, www.hotspotvpn.com). These employ powerful 128-bit encryption to protect your data as it is transmitted.

10. What is a hardware firewall? If my router has one, do I need to run the Windows firewall or other third-party firewall software?
Most wireless routers have a hardware firewall that safeguards the network by providing both incoming and outgoing protection. A hardware firewall will include network address translation (NAT) capabilities that make your PC invisible to anyone trying to attack it. If you enable the hardware firewall, you probably don't need a third-party software firewall. You should still run the Windows firewall, however, because it keeps a low profile and will stop basic worms if your PC gets hit by a drive-by downloader.

Fix your 10 common Wi-Fi problems

1. I cannot connect to my router. How do I resolve this?
This is a wide-open problem with an almost limitless range of causes and solutions, but here are several actions that might do the trick. First, make sure your router is configured for Dynamic Host Configuration Protocol (DHCP). If it is, try disabling and re-enabling the DHCP function. If that doesn't work, disable wireless security and see if you get a connection; sometimes a mismatched Wired Equivalent Privacy (WEP) key can drop the IP address. You should also check for electrical interference from competing devices such as cordless phones, baby monitors, alarm systems, and microwave ovens. Disable all suspect devices, then recheck your Wi-Fi connection. If all else fails, reboot the router and all computers on your network.

2. What steps should I take to secure my Wi-Fi network?
Routers typically offer at least two common forms of security: WEP, and Wi-Fi Protected Access (WPA) encryption. Both are easy to enable, although you'll get maximum protection from WPA. To activate security, go to your router's browser-based administration tool (the default address for most routers is http://192.168.0.1 or http://192.168.1.1) and look for the wireless security area. WPA requires you to enter a simple security phrase (eight to 63 characters), or, with some routers, a more secure (but much harder to remember) 64-digit key. Similarly, WEP demands that you choose from 64-bit or 128-bit encryption, and enter an alphanumeric hex phrase, with some routers giving you the option to enter a simpler ASCII phrase. In addition to enabling wireless security, you can also disable the broadcasting of the Service Set Identifier (SSID, or network name). Doing so can make the network more difficult for hackers to see. Also, make sure to enable the router's hardware firewall (more on that later), and change the router's default password. And do not enable file sharing, unless you really use it. This will safeguard your personal files from interlopers.

3. How do I open ports on my router?
Certain functions and applications--personal Web servers, IP Webcams, home FTP servers, and online games--require that you open ports on your router to allow outside requests to be sent to an internal computer on a home network. This procedure, called port forwarding, is pretty straightforward. First, you'll need to find out which ports you need to open for your particular application or service. Then, you'll open those ports on the router. All models vary slightly, but the process is similar. Open your router's configuration tool, and find a tab labeled Port Forwarding. Enter the service or software name, then type the Start Port and End Port numbers. If you're opening one port, enter the same number in both fields. Select TCP as the protocol, then click OK. Check your router's Web site for instructions for your specific brand or take a look at Port Forward, for help.

4. How do I extend the range of my wireless signal?
Improving a wireless signal is an inexact science that's part voodoo, part trial and error. No two homes are alike, and no two solutions will work for everyone, but here are some common guidelines. First, position your antenna on a high perch clear of obstructions. (The wireless signal radiates down.) Keep in mind that certain things will interfere with the signal: Objects with high water content, metal, and dense building materials such as brick, stucco, and concrete. So avoid blocks of liquid (fish tanks and water coolers), and metal pipes and construction.

If antenna positioning doesn't help, you can get an extender (or "repeater"), such as the Linksys Wireless-G Range Expander WRE54G. Devices like this will boost your range from 50 to 75ft, but they can be tricky because they require setup and configuration. A somewhat easier (if visually less elegant) approach is Wireless Garden's Super Cantenna. This tripod-mounted, high-gain antenna connects to your router and can be pointed at a specific area to amplify the signal. It's easy to set up, but it ain't pretty.

5. How do I automatically connect to a Wi-Fi network without having to manually connect the first time?
If you just want to connect fast to any available network, you can set your notebook to do so automatically. Go to Control Panel > Network Connections and right-click your current wireless network. Then click Properties > Wireless Networks > Advanced. Make sure the radio button next to "Any available network (access point preferred)" is on, then check the box "Automatically connect to non-preferred networks."

next five will be posted on next blog...