* Dr. Internet columnist Steve Blass offers advice on how to locate a Web site visitor via their IP address * Wireless Security columinst Tim Cranny discusses how insecure WEP is
* Geo-locating IP addresses
By Steve Blass
Q: Can I find where a Web site visitor is located by their IP address?
A: It’s sometimes possible to determine the location of an IP host. The brute force approach is to perform a reverse DNS lookup of the domain containing the IP address and extrapolating from the whois information to create an educated guess about where the host is located.
To read Steve’s response in its entirety, please click here.
* Is WEP ever appropriate?
By Tim Cranny
Q: How insecure is Wired Equivalent Privacy?
A: The short answer is that Wired Equivalent Privacy (WEP) is badly broken and only fit for a few low-security uses. Wireless communications are, for obvious reasons, far more susceptible to eavesdropping and unauthorized access than wired communications, and WEP was intended to provide a cryptographic ‘wrapper’ around the communications channel to protect it. Unfortunately, both the design and implementation of WEP were badly flawed, and attackers are able to crack open the encryption and listen in on – or modify – the ‘real’ data without much effort. To make matters worse, these attacks have been turned into ‘script-kiddy’ tools, so the skill level needed to crack WEP is now close to zero. As the final nail in the coffin, these attacks grow faster and simpler with every increase in bandwidth and CPU speed.
To read Tim’s answer in its entirety, please click here.




