WARning

Bryan Irvine <[email protected]>
Newsgroups gmane.network.wireless.seattle.general
Message-ID <[email protected]>
I was recently out wardriving during a lunch break at work, to see if
Eavesdrop would pick up anything.  It didn't, so I tried to connect to
a couple of the networks to see.  I noticed some netbios traffic.  I
figured what the heck and decided to try and connect.  The system
asked for a username and password, which I expected.  Not figuring it
would work, I typed in "administrator" for the username, and left the
password blank. lo and behold it worked!!!  I left a message on the
system for the owner to fix it, and telling them how the message got
on there.  I didn't browse around anywhere else, just left the
message.

Just for kicks, and to see the extent of the problem, I repeated this
over and over for over an hour.  I was able to successfully mount
about a dozen drives (only 2 systems all day didn't let me in using
administrator/no password).  I left messages on them all.

One particularly scary system was a local dentist office that has it's
entire patient database shared out!!

Whoa!  I think a lot of people have a false sense of security because
the marketing departments push these things as having a built-in
firewall.  Of course they don't warn people that anyone connected to
their wireless router will ahve access to everything as if it
wasplugged in.


Scary scary stuff.  I've nicknamed this process of putting messages on
these machines WARning.


--Bryan
_______________________________________________
Talk mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.