Showing posts with label Wi-Fi security. Show all posts
Showing posts with label Wi-Fi security. Show all posts

Security holes in Apple Time Capsule, AirPort Base Station

Apple has released a firmware update with fixes for three documented security vulnerabilities affecting its Time Capsule and AirPort Base Station products.

The vulnerabilities could lead to denial-of-service or information disclosure attacks via specially crafted packets. Details on the vulnerabilities:

  • CVE-2008-2476 - The IPv6 Neighbor Discovery Protocol implementation does not validate the origin of Neighbor Discovery messages. By sending a maliciously crafted message, a remote user may cause a denial of service, observe private network traffic, or inject forged packets. This update addresses the issue by performing additional validation of Neighbor Discovery messages.
  • CVE-2008-0473 - An out-of-bounds memory access issue exists in the handling of PPPoE discovery packets. By sending a maliciously crafted PPPoE discovery packet, a remote user may be able to cause an
    unexpected device shutdown. This update addresses the issue through improved bounds checking.
  • CVE-2008-3530 - When IPv6 support is enabled, IPv6 nodes use ICMPv6 to report errors encountered while processing packets. An implementation issue in the handling of incoming ICMPv6 “Packet Too Big” messages
    may cause an unexpected device shutdown. This update addresses the issue through improved handling of ICMPv6 messages.

Apple says the update (firmware version 7.4.1) is installed into Time Capsule or AirPort Base Station with 802.11n* via AirPort Utility provided with the device.

[Source: zdnet]

GPU-Accelerated Wi-Fi password cracking goes mainstream

Elcomsoft Wireless Security AuditorNo weak password can survive a GPU-accelerated password recovery attack. Last week’s released Wireless Security Auditor is prone to shorter the time it takes for a network administrator to pen-test the strength of the WPA/WPA2-PSK passwords used on the wireless network. Its core functionality of shortening the wireless password recovery time up to a hundred times based on the GPU used, is naturally going to empower unethical wardrivers with the ability to easily guess the no longer considered secure 8 character passwords.

What’s particularly interesting about the Wireless Security Auditor is that it attempts to accomplish the password recovery in an offline/stealth mode, instead of the noisy direct router brute forcing approach :

“Elcomsoft Wireless Security Auditor works completely in off-line, undetectable by the Wi-Fi network being probed, by analyzing a dump of network communications in order to attempt to retrieve the original WPA/WPA2-PSK passwords in plain text. Elcomsoft Wireless Security Auditor requires a valid log of wireless communications in standard tcpdumptcpdump. The tcpdumptcpdump format is supported by all commercial Wi-Fi sniffers. In order to audit your wireless network, at least one handshake packet must be present in the tcpdump file.”

Meanwhile, pen-testing companies have once again urged IT managers and end users to go beyond the 8 character password strength myth, and anticipate the risks posed by the increasingly efficient password recovery solutions hitting the market :

“David Hobson said: “It’s a wake-up call to IT managers, pure and simple. IT managers should now move to 12 and even 16 character keys as a matter of urgency. It’s not very user-friendly, but the potential consequences of staying with eight character keys do not bear thinking about.”

As previously discussed, best practices wake-up calls remains largely ignored prompting radical solutions in countries like India for instance, which recently announced that a Wardriving police unit will be locating insecure wireless networks and notifying the owners in order to “prevent the commission of a cognizable offense”.

[Source: zdnet]

CSRF vulnerability allows Twitter ‘follow’ abuse

Twitter vulnerability opens door to gaming systemLast week, TechCrunch’s Jason Kincaid wrote about an obvious Twitter vulnerability that allowed a user called “johng77536″ to game the popular micro-blogging service to add thousands of followers (subscribers) in a short period of time.

The “johng77536″ account has since been disabled but a security researcher tracking Twitter security flaws and weaknesses has discovered a new vulnerability that lets users easily game the “follow” system.

Aviv Raff has launched a new Web site called TwitPwn.com with basic details of his discovery:

Twitter suffers from a vulnerability which allows an attacker to force his victim to follow him automatically.

Twitter security team was notified on 31-July-2008.

Technical details will be added as soon as this vulnerability [is] fixed.

Raff showed me a proof-of-concept exploit that took advantage of a CSRF (cross site request forgery) bug to trick me into following his Twitter account by simply clicking on a rigged Web site. A spammer or phisher could abuse this vulnerability to gain thousands of “followers” and attempt social engineering attacks.

Twitter’s security team has promised a fix within 24 hours.

Raff’s discovery isn’t the first. He has assisted Twitter with fixing another bug that could be abused to send spam mails with malicious links. Several Twitter cross-site scripting bugs have also been found and fixed.

[Source: zdnet]

Apple caught neglecting iPhone security

Apple neglecting iPhone security?If you’re waiting on iPhone 2 to standardize your business on the awesome new device (yeah, I’ll be on line to buy one), you might want to pay attention to the conspicuous absence of iPhone security patches over the last four months.

As WaPo’s Brian Krebs reports, the iPhone runs a stripped down version of Mac OS X but, even though OS X security updates are coming fast and furious, the iPhone has been neglected.

This means that there are multiple serious iPhone code execution flaws — including the CanSecWest Safari contest bug — that remains unpatched.

Krebs writes:

In seeking confirmation of this, I spoke recently with Charlie Miller, one of the foremost OS X and iPhone security researchers. Miller confirmed that the iPhone updater tells users that if they have version 1.1.4 installed then they are running the most current version. The problem is that this update does not include fixes for a slew of security holes in the Safari Web browser and other OS X components upon which the iPhone relies heavily.

“Apple should either update their software like they do with the core operating system, or otherwise don’t advertise the fact that the iPhone checks for updates every week,” Miller said. “Right now, an iPhone user is going to think they’re up-to-date because there’s no patch available, but the reality is that users are only as secure as they were back in February.”

Even more worrisome, Miller has created a tool to exploit the Safari vulnerability on an iPhone.

Using the exploit, an attacker who convinces an iPhone user to click on a malicious link could steal the victim’s call records or contacts, send text messages or read the user’s sent and received messages, and make outgoing calls, among other things.

There’s also an iPhone zero-day floating around out there.

So, if you love your iPhone like I do, consider sending Apple a note () and let them know that this neglect is unacceptable.

* Image source: oskay’s Flickr photostream (Creative Commons 2.0).

[Source: zdnet]