Re: [Full-Disclosure] wireless sniffing question

From: Cedric Blancher (blancher_at_cartel-securite.fr)
Date: 12/04/04

  • Next message: Owned You: "[Full-Disclosure] secret message time"
    To: question question <john68945@gmail.com>
    Date: Sat, 04 Dec 2004 15:25:35 +0100
    
    

    Le samedi 04 décembre 2004 à 03:09 -0500, question question a écrit :
    > Lets say I have a Linksys (or whichever brand you like) wireless
    > router with a wireless host using 128 bit WEP encryption, and a wired
    > host connected to the same device. Obviously it is possible for the
    > wired box to do various arp attacks on the switch to view other wired
    > hosts traffic. But does the same apply for the wireless host?

    Yes, most probably.
    Most WiFi routeurs act as a bridge between internal wired network and
    wireless network. The routeur part occurs between internal network (WiFi
    +LAN) and WAN port. Thus, ARP attacks can occurs between the two
    networks, meaning a wireless station can attack a wired one and
    vice-versa.

    > Can the wired host trick the switch on the Linksys into forwarding the
    > wireless clients packets to him via the regular wire?

    As shown above, definitly yes.
    Then it can deploy cleartext attacks against WEP, as an example...

    -- 
    http://www.netexit.com/~sid/
    PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE
    >> Hi! I'm your friendly neighbourhood signature virus.
    >> Copy me to your signature file and help me spread!
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Owned You: "[Full-Disclosure] secret message time"

    Relevant Pages

    • Re: ICS; Wireless Host with Dialup Internet
      ... disconnected LAN port, a connected wireless LAN port and a connected ... I turned off the firewall on the wireless host and I now have ... ICS will be set up on the dial-up connection. ...
      (microsoft.public.windowsxp.network_web)
    • Re: Wireless problem...pls help
      ... also you could try removing all but yours in the preferred networks in the ... wireless settings and not allowing it to connect to unpreferred networks ... We have setup a wireless router in our office and it works fine. ... to our wireless host and ignore other available wireless hosts? ...
      (microsoft.public.windowsxp.general)
    • TidBITS#785/27-Jun-05
      ... Jeff Carlson continues his exploration of computerized poker ... and Adam examines both the Canary Wireless ... Rogue Amoeba's Audio Hijack Pro ... A Canary in the Network ...
      (comp.sys.mac.digest)
    • Re: Linksys NAS200 Network Storage adapter
      ... The only two wireless network settings that are of any consequence are the SSID and the encryption method and password. ... either click the "Print Network Settings" button on the final screen of the Wizard or simply access the appropriate XML file and get at them that way and then use the information to configure the router manually as I explained earlier. ... I've read thru some of the MS web site on that product and it appears to do everything a NAS will do plus other cool features, such as, with an xbox360 with the wireless adapter, I can stream my video/pics to my TV for family viewing. ...
      (microsoft.public.windowsxp.network_web)
    • [NMRC Advisory] Microsoft Windows Wireless Exposure on Laptops
      ... Application: Wireless Network Connection ... This advisory documents an anomaly involving Microsoft's Wireless Network ... If a laptop connects to an ad-hoc network it can later start ... This is known as a Link-Local address, and by default Link-Local is turned on on all Windows platforms on all interfaces, including wireless interfaces. ...
      (Bugtraq)