Wireless Network Protocols and Standards
Home > Security News
Security News:
EMAIL THIS

Microsoft confirms Windows Wi-Fi flaw

By Bill Brenner, Senior News Writer
17 Jan 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Microsoft said Tuesday that under certain circumstances, attackers could exploit an anomaly in how Windows 2000, XP and Windows 2003 systems establish wireless connections. But users can take simple steps to neutralize the threat.

Mark "Simple Nomad" Loveless -- senior security researcher for Mountain View, Calif.-based Vernier Networks Inc.'s Vernier Threat Labs and a self-described hacker -- released details of the glitch last weekend at the ShmooCon 2006 hacker conference in Washington, D.C. In his written findings, Loveless said, "If a laptop connects to an ad hoc network it can later start beaconing the ad hoc network's SSID as its own ad- hoc network without the laptop owner's knowledge. This can allow an attacker to attach to the laptop as a prelude to further attack."

The problem is essentially a configuration error that spreads virus-like from laptop to laptop, Loveless said in his written findings. In field tests, numerous ad hoc SSIDs such as "linksys," "dlink," "tmobile," "hpsetup" and others have been documented, he said.

A Microsoft spokesman said via e-mail Tuesday that the vendor investigated Loveless' findings and determined that "customers who have connected to an 'ad hoc' wireless network in the past that was not protected with wireless encryption could be lured into connecting to a malicious advertised 'ad hoc' wireless network under limited circumstances." But, he added, "Customers that are using a firewall and a fully updated system are at reduced risk from attack following this connection."

More on Microsoft

Experts fear big implications for Windows flaw

Expert: Microsoft TNEF flaw could lead to superworm

Customers can also neutralize the threat by configuring their systems to only connect to "infrastructure" networks in the advanced wireless configuration settings, the Microsoft spokesman said. "Due to the design of this feature," the spokesman added, "the most appropriate method for adjusting the default behavior is in a future service pack or update rollup."

Washington Post cybersecurity expert Brian Krebs said in his Security Fix blog that Loveless gave him a personal demonstration of how the flaw could be exploited:

"I set up an ad hoc wireless network connection on my Windows XP laptop named 'hackme' [and] within a few seconds of hitting 'Ok' to create the network, my laptop was assigned a 169.254.x.x address," Krebs said. "A few seconds later, Loveless could see my computer sending out a beacon saying it was ready to accept connections from other computers that might also have the 'hackme' network pre-configured on their machines. Loveless then created an ad hoc network with the same name, and told his computer to go ahead and connect to 'hackme.' Voila! His machine was assigned a different 169.254.x.x address and we both verified that we could send data packets back and forth to each other's computer."

What's more disturbing, he said, was that "no more than five minutes after I had deleted the 'hackme' network ID from my laptop, Loveless and I spotted the same network name being broadcast from another computer that didn't belong to either of us. Turns out, someone else at the hacker conference was trying to join the fun."

Tags: Wireless Network Protocols and StandardsApplication Attacks (Buffer Overflows, Cross-Site Scripting)Wireless LAN Design and SetupWeb Server Threats and CountermeasuresWeb Application and Web 2.0 ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Wireless Network Protocols and Standards
Wireless network guidelines for PCI DSS compliance
Best Wireless Security Products
MMS messaging spoof hack could have global ramifications
PCI group releases wireless security guide
802.1X Port Access Control: Which version is best for you?
Wireless Security Lunchtime Learning
A wireless network vulnerability assessment checklist
How to configure VLANs with 802.1X for WLAN authorization
Risky Business: Understanding WiFi threats
Lesson 1 quiz: Risky business

Application Attacks (Buffer Overflows, Cross-Site Scripting)
Quiz: How to build secure applications
Black box and white box testing: Which is best?
Adobe warns of critical update for Reader, Acrobat 9.1.3
9 Ways to Improve Application Security After an Incident
Developers Need Help with Security Errors
Buffer overflow tutorial: How to find vulnerabilities, prevent attacks
SQL injection protection: A guide on how to prevent and stop attacks
Experts rebuke programmers who use SQL injection as feature
SANS: Application threats, website flaws pose biggest security threats
Mozilla helps Adobe push out faster patches
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

Wireless LAN Design and Setup
Wireless network guidelines for PCI DSS compliance
Best Wireless Security Products
How to prevent wireless DoS attacks
Lesson 4 quiz: How to use wireless IPS
Wireless intrusion prevention systems: Overlay vs. embedded sensors
Rogue AP containment methods
How to monitor WLAN performance with WIPS
The role of VPN in an enterprise wireless network
Wireless AP placement basics
Lesson 3 quiz: Who goes there?
Wireless LAN Design and Setup Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Wired Equivalent Privacy  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts