sharing folders

rh71

No Lifer
Aug 28, 2001
52,844
1,049
126
WINXP SP1...

How safe (from the outside world) is it to share folders on a home LAN 24/7 ? I have a Netgear wireless access point (SSID not broadcast, MAC filtered to 1 PC Card, WEP 128bit) and I leave the shares open on my main rig for a hardwired XBOX (so no logon for it). The router is pretty locked down except for a few ports I have forwarded for misc apps.

I'm primarily concerned about leaving shares open because of the wireless capability and someone can sniff out my signal since they have all day, everyday to do it - then they can get into my shares. Can someone sniff this out (MAC address info, WEP key, SSID) only when I'm using the PC Card (on the laptop) to connect to it, which isn't all that often, or can they get it just from the router at any time ?

In the past, I've heard of "experts" saying to disable windows file sharing because of its inherent vulnerabilities. Should we still be concerned or have routers/firewalls taken this concern away ?
 

Woodie

Platinum Member
Mar 27, 2001
2,747
0
0
I would say it's reasonably safe...but it's a risk management thing.

I leave my server up 24/7 w/ a wireless LAN available 24/7...but...All shares require authentication, and the accounts w/ write privileges have strong passwords, my WLAN is pretty hard to get to (in the basement, I live in the woods, so poor outside signal). It's acceptable risk for *me*.

If you don't need file sharing, then of course disable it. You're probably pretty safe from the Internet side, as NAT along w/ the SPI firewall is pretty solid. From the wireless side, it sounds like you've done the right things. Can you lock down the shares to read only for the XBOX? That's the only thing I would add.
 

phatrabt

Senior member
Jan 28, 2004
238
0
0
I have shares that I leave on 24/7 with my wireless network, but my shares are empty folders that are only for the other machines to use. If I have to give them files I copy the files into the dir that the others can see and go from there. You could also go the router of Read on your folders with stuff in them and RW to a blank folder. That way someone can't change anything in the folders that you have stuff in but still have access to a folder for storage.

You say that you've got WEP on, but in this day and age WEP isn't good enough.
With the right tools and some time someone COULD break into your network. It all depends on a lot of variables... Are you in a densely populated area? Are there a lot of AP's around? If possible, I would use WPA and sleep easier. Just some thoughts...