Showing posts with label wifi. Show all posts
Showing posts with label wifi. Show all posts

Tuesday, July 24, 2007

Cisco Wireless ARP Storm Vulnerabilities


DOS possible in latest released details for Cisco Wireless LAN Controllers. Workarounds and updates available.

The WLC contains vulnerabilities in the processing of unicast ARP traffic where a unicast ARP request may be flooded on the LAN links between Wireless LAN Controllers in a mobility group...
If the client sends a unicast ARP request with a destination MAC address that has not been learned by the Layer-2 infrastructure, that request will be flooded to all ports in the Layer-2 domain after egressing the WLC. This allows the second WLC to reprocess the ARP request and incorrectly reforward this packet back into the network...
If the arpunicast feature has been enabled on the WLC, the WLC will re-forward broadcast ARP packets targeting the IP address of a known client context. This creates an ARP storm if more than one WLC is installed on the corresponding VLAN...
In a Layer-3 (L3) roaming scenario, a wireless client moves from one controller to another where the wireless LAN interfaces configured on different controllers are on different IP subnets. In this scenario, a unicast ARP may not tunneled back to the anchor controller, but may instead be sent by the foreign controller out to a local VLAN...

Link

Thursday, January 11, 2007

WiPhi Testing

I'm currently connected to the WiPhi network. I do live near the corner of Spring Garden. Signal strength is 80 - 95%. Only my local wireless connection is higher. I've obtained an address and its in the 10.2 range. Currently I have 10.2.15.101, netmask of 255.255.252.0 and default router of 10.2.12.1. Its set to channel 11. I'm curious as to how they planned the channels out, if they're only using 1,6 and 11 or if they chose to use 1,4,8 and 11 or if they let the actual AP choose its channel based on signal interference. I see also there is another network named FeatherSecure which is not supported by my PSP. Completely unrelated, I've found an access point named Cisco_CallForAccess2679188524. I'll follow up on that later. All in all it seems to work well from where I'm sitting.

Wednesday, January 10, 2007

Free WiPhi


Wireless Philadelphia is well under way and Earthlink is currently offering a free trial run until January 21st. The map above shows the areas currently covered by Earthlink. To log on to the network "simply click on Feather by Earthlink from your computers list of available networks to get surfing." I'll be trying this out when I get home as I should be blanketed in coverage. After the 21st, the plan is only $17.95 per month. Now if only GMail would go completely SSL.

Link

Wednesday, November 01, 2006

Macbook Wireless Exploit

Proof of concept now available for Apple Airport Drivers via the new Metasploit module we listed below. Apple's security tower is crumbling now that more people are paying attention to it.

The Apple Airport driver provided with Orinoco-based Airport cards (1999-2003 PowerBooks, iMacs) is vulnerable to a remote memory corruption flaw. When the driver is placed into active scanning mode, a malformed probe response frame can be used to corrupt internal kernel structures, leading to arbitrary code execution.
Previously Apple, followed by others, had denied that Maynor and Ellch were actually able to crack a stock Macbook without third party peripherals. The proof is now in the Metasploit.

Link, Metasploit Module (via Kernel Fun)

Sunday, October 29, 2006

FCC Confirms Nokia 870


This appears to be the new Nokia 870 which surfaced earlier this week. Engadget has just uncovered FCC docs somewhat confirming the device but there are no specifics besides a 45 day request for confidentiality. The 770 featured WiFi, Bluetooth, Opera browser and was based off of Debian Linux. This one appears to have a camera, is expected to support VOIP but other details are sketchy.
Link to FCC Docs

Friday, October 27, 2006

WiFi to be Integrated into Metasploit

For all of those interested in security (blackhats or whitehats), Metasploit is adding a wifi module to its software. The module is based off of Johnny Cache Lorcon tool.


Metasploit 3 will integrate kernel-mode payloads to allow users to use existing user-mode payloads for both kernel and non-kernel exploits.

Because the framework provides an easy-to-use interface for connecting vulnerabilities to actual payloads, this Metasploit gives users an avenue to target the most sensitive part of the operating system.

Moore told eWEEK he is collaborating with Ellch on an actual 802.11 exploit. The plan is to use Ellch's LORCON (Loss of Radio Connectivity) hacking tool to send exploits at Wi-Fi bugs that are haunting widely used devices and computers.

Link

Tuesday, October 24, 2006

NOLA Gives Up on Free Wifi Network

The city of New Orleans has decided to unplug its free WiFi network once Earthlink finishes building out its system. Sad to see it go, but having two different systems competing for the same wireless spectrum would have been messy and extemely difficult to maitain.

The wireless network that is run by the city for citizens will be taken down to avoid overlap between the two systems, said Mark Kurt, the city's director of information technology.

"Once EarthLink has deployed their network, we will remove our equipment, and redeploy elsewhere as the situation warrants. The other wireless networks that have been set up by the city for temporary facilities and public safety will continue to be operated by the city as long as they are necessary and funding is available," Kurt said.

Link (via BoingBoing)