Re: IEEE spectrum article on Wifi Worms

Russell Senior <[email protected]> 23 Jan 2008 14:36:46 -0800
Newsgroups gmane.network.wireless.portland.general
Message-ID <[email protected]>
>>>>> "Keith" == Keith Lofstrom <[email protected]> writes:

Keith> http://www.spectrum.ieee.org/jan08/5877

Keith> The article doesn't explain how it is possible to inject new
Keith> firmware into a wifi router without a hardwire link; the APs I
Keith> know about are normally managed over the user-side hardwired
Keith> ethernet ports.

If there is a vulnerability (always a possibility), it might be
possible to remotely reflash a device.  However, it seems to me this
would be fairly challenging, in that you'd have to have a version of
firmware to reflash that is right for each device (there is
considerable variablility between devices, how they are flashed, etc.
you'd need to know exactly which device you were on and have a version
specifically adapted to it) and you'd need a way to flash it.
Furthermore, it seems like a dumb thing to worry about, since lots of
hosts are connected over much more reliable media, namely wires.

I guess I am glad that academics are thinking about various potential
problems, but this one sounds particularly academic to me.


-- 
Russell Senior, Secretary
[email protected]

-- 
The Personal Telco Project - http://www.personaltelco.net/
Donate to PTP: http://www.personaltelco.net/donate
Un/Subscribe:  http://lists.personaltelco.net/mailman/listinfo/general/
Archives:  http://news.gmane.org/gmane.network.wireless.portland.general/
Etiquette: http://www.personaltelco.net/index.cgi/MailingListEtiquette