Re: IEEE spectrum article on Wifi Worms

Irving Popovetsky <[email protected]> Wed, 23 Jan 2008 14:52:17 -0800
Newsgroups gmane.network.wireless.portland.general
Message-ID <[email protected]>
2 comments:

1.   Last I checked,  almost all Linksys devices allow themselves to be 
flashed via wireless by default, via the web interface.    Experience 
shows that most Linksys owners use open wireless, and leave the password 
as the default.  Most folks change the ESSID these days, but not much 
else.  I'm sure this is the case for most other major consumer-focused 
wireless vendors as well.  I'm fairly certain I could put together a 
proof of concept script in Perl and LWP without much effort.
It would actually be harder to figure out how to ROUTE and differentiate 
between all of these devices that are all IP'ed as 192.168.1.1/24.   The 
rest is easy.

2.  To address Russell's point:    Exploits are generally developed 1 
target at a time, starting with the most popular devices.  Even exploits 
need to be QA'ed.   In the above example you would ID each device as you 
access the web interface,  auto exploit the ones you know about and 
catalog the rest for later exploitation.

-Irving



Russell Senior wrote:
>>>>>> "Keith" == Keith Lofstrom <[email protected]> writes:
>>>>>>             
>
> Keith> http://www.spectrum.ieee.org/jan08/5877
>
> Keith> The article doesn't explain how it is possible to inject new
> Keith> firmware into a wifi router without a hardwire link; the APs I
> Keith> know about are normally managed over the user-side hardwired
> Keith> ethernet ports.
>
> If there is a vulnerability (always a possibility), it might be
> possible to remotely reflash a device.  However, it seems to me this
> would be fairly challenging, in that you'd have to have a version of
> firmware to reflash that is right for each device (there is
> considerable variablility between devices, how they are flashed, etc.
> you'd need to know exactly which device you were on and have a version
> specifically adapted to it) and you'd need a way to flash it.
> Furthermore, it seems like a dumb thing to worry about, since lots of
> hosts are connected over much more reliable media, namely wires.
>
> I guess I am glad that academics are thinking about various potential
> problems, but this one sounds particularly academic to me.
>
>
>   


-- 
-Irving Popovetsky                         Principal Consultant
ProStructure Consulting             http://www.prostructure.com
Network and Security Consulting      phone: (503) 288-1566 x201
            "Crafting Connectivity that Matters"

-- 
The Personal Telco Project - http://www.personaltelco.net/
Donate to PTP: http://www.personaltelco.net/donate
Un/Subscribe:  http://lists.personaltelco.net/mailman/listinfo/general/
Archives:  http://news.gmane.org/gmane.network.wireless.portland.general/
Etiquette: http://www.personaltelco.net/index.cgi/MailingListEtiquette