Menu

Database

Statistics

Entries: 177
Last 60 days: 1
Users: 1043

News

SANS Institute Sponsors WVE

Sat Apr 19 20:50:43 -0700 2008

We are very excited to announce that the SANS Institute has become an official sponsor of the WVE project. Many of our readers know the SANS Institute as a well-respected, global authority for information security training, certification & research. SANS is widely known for their significant contributions to the information security community through research publications and the Internet Storm Center.

Like WVE, the SANS Institute is dedicated to helping the community with valuable information resources, and we are happy to have them sponsor us. Welcome, SANS Institute!

Wireless Attackers and Honeypot Technology

Tue Apr 15 11:56:22 -0700 2008

Security analyst Raul Siles has developed a paper on the use of wireless honeypot (dubbed "honeyspot") technology to study the skills and capabilities of wireless attackers. Describing the architecture and deployment of a wireless honeypot, Siles' paper is a valuable resource for enhancing the security of wireless networks, either as an attacker skillset and technique analysis tool, or as a deterrent to ward attackers away from other networks (e.g. "Pay no attention to the man behind the curtain"). More information is available on Raul's blog post or you can grab the paper from the Spanish Honeypot website. Thanks Raul!

High Speed Risks in 802.11n Slides Posted

Fri Apr 11 18:57:35 -0700 2008

Following his RSA 2008 presentation titled "High Speed Risks in 802.11n Networks", WVE editor Joshua Wright has posted his slides. New WVE entries pertaining to these issues have also been created. Comments are most welcome. Thanks!

Vulnerabilities in 802.11n

Wed Apr 09 19:13:53 -0700 2008

New entries highlighting vulnerabilities in IEEE 802.11n networks are being added to the database. This is in coordination with WVE editor Joshua Wright's presentation tomorrow at the RSA 2008 conference in San Francisco titled "High Speed Risks in 802.11n Networks". Presentations slides will be posted on Josh's website, and linked here on the News page. If you are at the RSA conference, be sure to catch Josh's presentation at 8:00am on Thursday (WIR-301).

WVE Editors Speaking at SHARKFEST.08

Thu Jan 03 08:24:50 -0800 2008

Two WVE editors, Mike Kershaw and Joshua Wright, have been selected as speakers at the first annual SHARKFEST conference. This Wireshark developer and user event is 3 days of training and discussions on network analysis, troubleshooting, security, Wireshark development, communications dissection and more.

Mike Kershaw is giving a session titled "WLAN Analysis & Security", focusing on security analysis with Wireshark. Joshua Wright is giving a session titled "Leveraging Wireshark for Wireless Network Analysis", focusing on WLAN operational troubleshooting and debugging.

SHARKFEST.08 is on March 31 - April 2 at Foothill College in Los Altos Hills, CA. More information including an agenda for the conference is available on the SHARKFEST website.

Paper: Dispelling Bluetooth Security Misconceptions

Sat Sep 22 08:56:41 -0700 2007

In 2006, the Bluetooth SIG announced that over 1 billion Bluetooth adapters had shipped. Many organizations overlook the threat of Bluetooth technology in their organizations, even though many types of Bluetooth devices can expose organizations to attack.
The paper "Dispelling Common Bluetooth Misconceptions" examines several threats commonly overlooked when working with Bluetooth technology. Comments are most welcome.

"I Can Hear You Now", Eavesdropping on Bluetooth Headsets

Tue Sep 18 10:19:27 -0700 2007

WVE editor Joshua Wright has posted a video on YouTube, describing an attack against a Bluetooth headset. Using a standard Linux workstation, he shows how headset devices can be exploited as audio bugs from significant distances, recording and inject arbitrary audio through the headset device. You can check out the clip at http://www.youtube.com/watch?v=1c-jzYAH2gw. Please direct comments or questions to Josh directly.

Paper: Five Wireless Threats You May Not Know

Thu Sep 13 12:26:15 -0700 2007

WVE Editor Joshua Wright has published a paper to help organizations understand the risks associated with modern WLAN deployments. While many organizations have turned to strong encryption mechanisms such as TKIP or CCMP, and strong authentication mehchanisms such as PEAP and EAP/TLS, it does not satisfy several remaining threats in wireless security. "Five Wireless Threats You May Not Know" is available on the author's website.

Cracking Cisco LEAP with ASLEAP for Win32

Fri Jun 01 11:51:28 -0700 2007

WVE editor Devin Akin has created a video showing how to crack a LEAP protected network by utilizing ASLEAP2 under Windows. In the video Devin shows how to capture the authentication exchange, convert it to Pcap format, and then how to use ASLEAP. Check out the preview.

Securing a RADIUS server

Fri Jun 01 11:43:48 -0700 2007

In the latest installment of our wireless security column at NetworkWorld , WVE editor Andrew Lockhart, responds to a reader's question about how to protect a RADIUS server.

Next page

Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...