Re: IEEE spectrum article on Wifi Worms

Tyler Booth <[email protected]> Wed, 23 Jan 2008 15:19:19 -0800
Newsgroups gmane.network.wireless.portland.general
Message-ID <[email protected]>
> 2 comments:
>
> 1.   Last I checked,  almost all Linksys devices allow themselves to  
> be
> flashed via wireless by default, via the web interface.    Experience
> shows that most Linksys owners use open wireless, and leave the  
> password
> as the default.  Most folks change the ESSID these days, but not much
> else.  I'm sure this is the case for most other major consumer-focused
> wireless vendors as well.  I'm fairly certain I could put together a
> proof of concept script in Perl and LWP without much effort.
> It would actually be harder to figure out how to ROUTE and  
> differentiate
> between all of these devices that are all IP'ed as 192.168.1.1/24.    
> The
> rest is easy.

If your exploit is already re-flashing the device, there would be no  
problem flashing it
with a derivative of roofnet to take care of routing, your exploit  
could very easily target
a vendor based on the BSSID/MAC of the device.

> 2.  To address Russell's point:    Exploits are generally developed 1
> target at a time, starting with the most popular devices.  Even  
> exploits
> need to be QA'ed.   In the above example you would ID each device as  
> you
> access the web interface,  auto exploit the ones you know about and
> catalog the rest for later exploitation.
>
> -Irving
>
>
>
> Russell Senior wrote:
>>>>>>> "Keith" == Keith Lofstrom <[email protected]> writes:
>>>>>>>
>>
>> Keith> http://www.spectrum.ieee.org/jan08/5877
>>
>> Keith> The article doesn't explain how it is possible to inject new
>> Keith> firmware into a wifi router without a hardwire link; the APs I
>> Keith> know about are normally managed over the user-side hardwired
>> Keith> ethernet ports.
>>
>> If there is a vulnerability (always a possibility), it might be
>> possible to remotely reflash a device.  However, it seems to me this
>> would be fairly challenging, in that you'd have to have a version of
>> firmware to reflash that is right for each device (there is
>> considerable variablility between devices, how they are flashed, etc.
>> you'd need to know exactly which device you were on and have a  
>> version
>> specifically adapted to it) and you'd need a way to flash it.
>> Furthermore, it seems like a dumb thing to worry about, since lots of
>> hosts are connected over much more reliable media, namely wires.
>>
>> I guess I am glad that academics are thinking about various potential
>> problems, but this one sounds particularly academic to me.
>>
>>
>>
>
>
> -- 
> -Irving Popovetsky                         Principal Consultant
> ProStructure Consulting             http://www.prostructure.com
> Network and Security Consulting      phone: (503) 288-1566 x201
>            "Crafting Connectivity that Matters"
>
> -- 
> The Personal Telco Project - http://www.personaltelco.net/
> Donate to PTP: http://www.personaltelco.net/donate
> Un/Subscribe:  http://lists.personaltelco.net/mailman/listinfo/ 
> general/
> Archives:  http://news.gmane.org/gmane.network.wireless.portland.general/
> Etiquette: http://www.personaltelco.net/index.cgi/MailingListEtiquette
>

-- 
The Personal Telco Project - http://www.personaltelco.net/
Donate to PTP: http://www.personaltelco.net/donate
Un/Subscribe:  http://lists.personaltelco.net/mailman/listinfo/general/
Archives:  http://news.gmane.org/gmane.network.wireless.portland.general/
Etiquette: http://www.personaltelco.net/index.cgi/MailingListEtiquette