Bulding the Wired Home: Elk M1 Home Security System

Written by Anonymous on 12:33 AM

In some sense, home security systems suffer the same fate as mobile phone handsets. Most people, if they have one, have the one that a security monitoring company installed, and their only interaction with it is to turn it on or off. But some people want more than just a security system. Some people want a security system that can be expanded to perform almost any kind of home monitoring and automation task. You know, lunatics. Lunatic geeks. Enter the Elk M1.

At their heart, security systems are relatively simple circuit board with a lot of inputs and outputs for various sensors and accessories, and some kind of programable, scriptable capability. When a sensor detects a condition that the installer has determined to indicate a break-in (door opens, motion sensor activates, etc), then the system initiates a series of events, according to the scripts: alarm sounds, police is called, etc. For most security systems, this is the end of the story. But there's no reason you need to restrict the inputs to only intrusion sensors, and there's no reason you need to restrict the outputs to alarms and dialers. If you make the programming and scripting capabilities sophisticated enough, there's no limit to what a system like this could do.

As part of OSNews' ongoing series on home technologies, we worked with a homebuilder to instal an Elk M1 system in a new home in Park City, UT. Like all of the stories in this series, our goal was to take generally-available computing devices and bring them together in a way to solve problems that homeowners face, without spending a lot of money. In this case, we wanted to centralize all of the home's monitoring and automation tasks into one reliable device. Even though we had put a lot of thought into ways that a commodity PC could be used as a home's "nerve center," we didn't want to have to depend on a PC for such mission-critical monitoring, and wanted to be able to turn off or hibernate the home server when it's not needed, etc.

This article will cover the home security and monitoring aspects of our M1 installation, and we'll cover more home automation in a future article once we have completed more of that work.

We started way back when the house was still bare studs, right after the main electrical wiring had been installed, by specifying where wire needed to be run. Though many security systems are installed in existing homes using wireless sensors, for various reasons, not least of which is the necessity for wireless sensors to have batteries replaced, it's always better to hard-wire when possible. We chose to wire every door and window (including garage doors) for contact sensors, motion sensors covering the home's main thoroughfares, and a glass break sensor in an area in the back with lots of windows. Most importantly, we installed wire for monitored smoke and CO detectors in every area of the home that's required by building code. Lastly, we wired for the alarm sounders, strobes, and speakers that were to be part of the system's alert and notification outputs. All of these cables were coiled up into a metal wiring box in the utility room, until much later in the construction process.


After the wallboard and painting was done, it was time to install the various sensors and outputs. Doors and windows generally use a magnetic contact that breaks (or completes) a circuit when a magnet is pulled too far from the sensors. The various other sensors and detectors are all more sophisticated, but work on the same principle, breaking or completing an electrical circuit. And there are other sensors you can install: water sensors, heat sensors to detect fires, temperature sensors which can trigger events at a temperature threshold, doorbell and phone ring detectors, vibration sensors, pressure sensors, rain sensors that can be used to trigger sprinklers to be disabled, car detectors that can sense a car passing the driveway, etc.

At the most basic, the first priority was for intruders and fires to be detected, and the appropriate alarm to be sounded. Let's just say that the Elk M1 handled these issues with aplomb. Because there are sensors on all the doors and windows, the system can also report which of them is open when you try to arm it, and you can make your decision whether you want to go close an upstairs window or just set the alarm anyway. The smoke alarms are set so that if one goes off, they all sound the alarm, and since there's one in each bedroom, it makes it much more likely that sleeping home occupants will evacuate before the fire gets too big. One of my favorite features are the RFID proximity keyfobs that can be used to arm and disarm the alarm, so you don't have to key in a code. The system can also be configured to be armed and disarmed with a radio frequency keyfob, like a car alarm. The alarm install technician who helped us with the install mentioned that he had even set the external alarm horn on his house to chirp when he hit the alarm button, just like a car, until his wife got annoyed and made him deactivate that feature.

Normally, programming of the M1 can be done either by navigating through the menus in the keypad (which can be pretty daunting unless you just have a few things to configure) or by hooking up the panel to a computer with a serial connection and using Elk's Remote Programming software. We installed Elk's ethernet module, which not only allowed me to program it from a computer anywhere in the house, but if I were to get my router configured correctly, from anywhere on the internet. I could, for example, remotely deactivate the alarm if a friend needed to get into the house while I was away, and not have to give them my code.

And of course, no lunatic geek would be satisfied unless this kind of remote management could be done through a mobile device. Thanks to an intrepid iPhone developer named Jayson Callaway, there's an app for that! The Elk network module relies on Java for its web interface, so that's no go on the iPhone and many other mobile platforms, but eKeypad M1 is an iPhone app that provides an interface to the networked Elk M1 system. It lets me arm and disarm the system, check the status of the zones, monitor status of inputs, such as temperature sensors, adjust networked thermostats, and even control lighting and other home automation functions.


For people still living in the 20th century, the M1 can be configured to answer the phone, enabling control of the system with the phone keypad. One related feature that I wired for that I haven't configured yet is the "listen in" feature, that would enable someone to call into the system and speak to the inhabitants of the house over a loudspeaker, and hear what they have to say through a microphone. This is would be used to allow the monitoring company to speak to whoever's in the building before they call the police, or just listen for commotion, or for someone to check in on children or an elderly relative.

One fun feature of the Elk M1 is its voice status indicators. When an alarm goes off, a voice announces the particulars over a loudspeaker, such as "Fire! Fire!" or "Zone Violated: Motion Sensor Loving Room!" so it gives you some kind of idea of what's going on.

The one big home automation task that I have set up is an automatic water cut-off feature. I had the plumber install a motorized water valve on the home's main water line. We then ran cable to the utility and storage rooms, where an appliance might leak or a burst pipe would spray water. We put inexpensive water sensors in those areas, and programmed the Elk M1 to cut off the main water whenever those sensors went off. It is also set to speak an alert: "Water alarm, water valve off" when the script trips. The F6 button on the keypad turns the water back on. This way, the homeowner can have peace of mind that even in the event of a burst water heater or wintertime heating system failure, damage will be minimized, even during vacations.

My future plans for this system, which will be covered in a subsequent article are to complete the lighting control setup, with support for one-touch lighting themes, and integration with the alarm system that will turn all lights on during an alarm and even use the security sensors to turn on lights, such as turning on exterior lights when the garage door opens or the hall lights when a motion sensor is tripped. Also, I plan to integrate the home's nine thermostats with the Elk M1, allowing a vacation setback, wherein the house could be set to a cool-but-not-freezing temperature while you're away, but you could call up the house the day before you return and tell it to be all warmed up when you get home. Stay tuned.

If you'd like to buy the Elk M1, it's available at Amazon. Also see the Elk web site.

Posted by David Adams


Securing Wi-Fi for Hackers

Written by Anonymous on 11:51 PM

Is the Black Hat network a hostile network? Wireless vendor Aruba isn't so sure.

How do you secure a wireless network for a convention of hackers?

That's the question that wireless networking vendor Aruba Networks has been answering for the last four years as the wireless service provider for the Black Hat security conference.

Black Hat takes place this week in Las Vegas, and Aruba is providing the wireless network. And that means it has its work cut out for it: Aruba's Wi-Fi network is under constant assault during the event, with users attempting denial of service (DoS) attacks, scanning for open ports and deploying rogue access points.

Aruba isn't intimidated by the Black Hat crowd -- on the contrary, Aruba execs note that they learn from the event in order to make wireless access more secure.

"The posture that we take at Black Hat is much more defensive than it is for a regular public conference," Mike Tennefoss, Aruba's head of strategic marketing, told InternetNews.com. "The way we set up wireless in the early years was to have an open Wi-Fi network and we saw all sorts of attacks take place."

"A lot of these people have gone to Black Hat training [sessions] first, and there are wireless hacking classes that are taught," he added. "So a lot of the stuff we saw last year happened during the training where people tried to try out new attacks."


Tennefoss said that last year, Aruba took the step of turning on WPA (define) encryption by default for the Black Hat network.

"What we saw as a result of turning on WPA was a drastic reduction in the amount of 'screwing around' that people did on the network," Tennefoss said. "Most of the other conferences that we do, like Interop, they don't want to turn on WPA. For usability reasons, they want an open network."


With an open network, data is sent unencrypted in the clear. Even though it's less secure, organizers of some conferences see a benefit in that it's easier to log on to, since a WPA password is not required.

But Tennefoss noted that there is also a misconception in the marketplace that works against WPA -- that it causes an impact on wireless performance. According to Tennefoss, Aruba's wireless gear does not suffer from a performance hit as a result of turning the encryption.

One security feature that the Black Hat Wi-Fi network will not have is network access control (NAC). Tennefoss explained that Aruba has a NAC endpoint compliance system that validates the health of an endpoint -- that is, it ensures it has working security software. According to Tennefoss, the Black Hat organizers have chosen not to take advantage of that capability.

Tennefoss said endpoint compliance is more popular with corporate deployments, and trade shows don't tend to use the technology. The chief concern is that if NAC is turned on, it will decrease the network's ease of usability, as users may or may not be able to comply with the network policy.

Going rogue

One of the most common types of attacks seen at Black Hat is when attackers set up their own access points with the name "Black Hat". Such a rogue access point could potentially trick users into connecting to it, and then the attacker could see all of the users' traffic.

But Aruba is striking back, courtesy of a technology called RFprotect. Integrated into Aruba's controller and management software, RFprotect seeks out and helps to identify rogues on the network, Tennefoss said.

Aruba can also physically locate where potential rogue access points might be set up, enabling staffers to confront the hackers responsible.

"We set our access points up in such a way that every room is covered by at least three access points," Tennefoss said. "So we can triangulate location based on signal strength."

Tennefoss explained that all three access points would see any rogue signal. The data is fed into Aruba's management system, which then enables the company to pinpoint a rogue's location in a room.

Aruba also keeps the access point logs from the event and analyzes all the traffic after Black Hat to see if any new types of attacks are emerging.

But is it safe?

Users of the Black Hat Wi-Fi network have traditionally been first greeted by a terse warning that the network is hostile -- that is, if you use it, you might be prone to hacking.

But to Aruba, that doesn't mean that the Wi-Fi network isn't safe for most users.

"Given the level of protection we have in place, it's relatively safe," Tennefoss said. "The larger point for the warning is that the entire conference should be considered hostile overall. So don't do your online banking or transmit passwords in the clear over the network because someone could potentially intercept you."

The Black Hat event runs an effort called the Wall of Sheep, which anonymously posts on a wall users that are connecting to services without the appropriate security -- for instance, transmitting data in the clear.

Tennefoss noted that the Wall of Sheep is about education and not specifically about the insecurity of the Black Hat Wi-Fi network.

"I think it's a safe network to use," Tennefoss said. "You're not going to turn on your notebook and suddenly be infected. It's more about being conscious of what sort of things you're doing on the network."

By Sean Michael Kerner


New security system to prevent small craft and outboard thefts

Written by Anonymous on 1:58 AM

When Itchenor Sailing Club suffered the theft of four outboard engines, club member Richard Lang, who runs a £6 million company specialising in wireless security products, decided to develop a new system specifically to combat this growing problem.

The recession was always going to mean that the persistent problem of outboard engine theft would become worse. Having studied previous recessions and downturns and their effect on crime, The Home Office has issued blunt warnings that the credit crunch will see an overall rise in crime figures. Sure enough, marine insurance companies have seen a marked increase in claims not just for outboard engines but RIBs (Rigid Inflatable Boats) and other small “trailable” craft. The recent theft of four outboard engines and RIBs in Chichester Harbour prompted Itchenor Sailing Club to take action. It so happens that one of the club’s long standing members, Richard Lang, is Managing Director of Tag Guard Ltd, one of the UK’s biggest names in building and construction site security.

Richard Lang briefed his in-house R & D team and they developed a bespoke new system that should enable clubs, marina operators, boat yards and small craft boat dealers or brokers to adopt this new, low cost but highly effective security.

Richard Lang comments, “The new system we designed is now in use at my own club – it’s simple to set up and should prove highly effective in preventing boats and their engines from being taken from moorings or even hardstanding areas.

“One system can protect several boats and the first system now in operation in Chichester Harbour is securing 10 boats and their engines at the same time.

“The equipment can easily be extended to provide effective security to external and internal areas of clubs and marine premises that are left unoccupied and unsecured such as storage sheds, boatyards, workshops and other buildings – it can even incorporate fire detection as part of the overall system.

“The alarm system is wireless and based on the proven products that have been developed over many years to withstand the rigours of the building and construction sector where Tag Guard is best known.

“Any unauthorised movement of the boats or engines triggers an alarm that is received by our own remote monitoring centre, which is manned 24/7 throughout the year.

“In the event that an alarm is triggered, mobile guard response can then be dispatched and key holders immediately notified; the system also sets off an audible alarm and security lights to ensure that the thieves cannot continue unnoticed.

From Bym news


How to be a (safe) Wi-Fi warrior

Written by Anonymous on 12:42 AM

(Fortune Small Business) -- Wireless technology makes it easier than ever to work from the road. But laptops get stolen and Wi-Fi networks at airports, coffee shops and hotels can expose users to increasingly sophisticated forms of cybercrime.

"You're insecure if you're on any publicly available network," says Ken Silva, chief technology officer at Internet security firm VeriSign (VRSN). Silva adds that basic measures, like installing a firewall and antivirus software, are no longer enough to protect your data. What's a telecommuter to do?

First, Silva recommends investing in e-mail and hard-drive encryption software and backing up critical work before you travel. If you must use public Wi-Fi, he says, scrutinize the sites you visit and send data only through certified secure and encrypted pages, indicated by a lock-shaped icon and https: at the beginning of the URL.

Yankee Group analyst Phil Hochmuth suggests setting up a virtual private network (VPN), which lets you use your business network and its security applications from remote locations. If you're not using a VPN, he says, think twice before sending sensitive information such as Social Security or credit-card numbers.

Log in to only one network at a time and disable any file- and network-sharing features on your device, even if you do use a VPN, adds Devin Akin, chief technology officer at CWNP, a firm that certifies IT professionals working with wireless networks. Otherwise, uninvited guests can easily sift through your files, install malware on your hard drive and gain access to your company or home network.

Akin also warns of "evil twins": Wi-Fi decoys that resemble legitimate services but are set up by hackers who use them to gather passwords and other vital information from unsuspecting users. To avoid them, connect only to Wi-Fi networks that display certified-secure and encrypted log-in pages.

Finally, don't ignore the low-tech risk of over-the-shoulder snoops. Install a privacy filter on your laptop (made by 3M and other vendors) to shield your screen in close quarters.

By Lora Kolodny


5 steps to securing your corporate wireless network in 2009

Written by Anonymous on 11:48 PM

Unlike Ethernet, wireless networks don’t stop at your front door. With open source tools like Kismet and penetration testing CD’s like Backtrack, it’s easier than ever to find and compromise Wi-Fi networks. When we designed the Napera N24, wireless security was a frequent area of concern for customers, and it continues to be a key driver for network access control deployments.

In the spirit of holiday list making, here are five guidelines based on our experience in the field to help IT managers tighten wireless security in 2009.

1. Have a wireless security policy before you deploy

I opened a dinner presentation at MIT once with a gag where I asked the audience to start writing their security policy on their napkin. The sad truth is that those folks bearing napkins with one or two bullet points are generally ahead of the curve. Many smaller companies lack written security policies.

A policy need not be long and complex. The important point is that it exists, you gave some thought to it and it is communicated clearly. A good policy evolves over time to support the objectives of the business and mitigate potential risks.

Write a clear policy on the use of wireless and circulate it to your users. At a minimum, identify who and what is permitted on your wireless network. Mandate a standard for strong wireless encryption and authentication, and spell out how guest access is supported.

Once company laptops are equipped with wireless, IT managers should be proactive in advising staff on the proper use of public hotspots, and the security implications of doing company business over wireless networks. Well designed applications have encryption built in, but there are plenty of legacy systems which are vulnerable to snooping. Don’t be a sheep!

2. Secure the infrastructure when you deploy it

Most access points ship with well known default admin credentials and a default SSID, which is a red flag to wireless intruders . Change them! I’m constantly amazed at how many wireless deployments neglect this important step.

3. Avoid WPA-PSK shared passwords if possible

I’ve blogged on the weaknesses of WPA-PSK shared passwords extensively. Any password that is shared between many employees and guests tends to lack complexity (because of the need to share it) and can be brute forced with off the shelf software. Shared passwords are insufficient to protect commercial wireless networks. If an employee leaves or a laptop goes missing, WPA-PSK passwords should be changed. Even when managed well, there is no easy way to audit who is using a WPA-PSK protected network. Unless you really don’t have anything of value on your network, it’s simply not good enough.

WPA Enterprise is the best solution to this problem, because it allows individual usernames and passwords for wireless access. Traditionally WPA Enterprise has been painful to deploy because of PKI and RADIUS requirements. With the Napera N24, we made deploying WPA Enterprise easy, because the N24 was designed with a RADIUS server and a valid certificate built in. Even better, you can use your Active Directory to authenticate users, and you can allow guests restricted access via wireless.

4. Don’t rely on outdated security features like WEP, MAC access controls or hidden SSID’s

Some features offered by access points are simply security by obscurity. They may be fine for grandma, but they add nothing to corporate IT security.

WEP hasn’t been secure for years. Don’t use it. If you absolutely must use WEP, assume all of your communications will be in the clear and anyone can access your network. You should probably put your WEP access points outside your firewall. Even better, put them on Craigslist and buy new access points that support WPA2.

Restricting wireless devices by MAC address is futile, because it provides only a trivial obstruction and adds a large administrative burden. Any moderately skilled intruder can bypass MAC filtering by monitoring wireless traffic and forging their own. It’s not worth the administrative effort.

Turning off the SSID beacon may make you feel more secure, but only makes your network invisible to average users (and less useful to everyone, especially guests). Kismet will reveal the ‘hidden’ SSID.

5. Make sure your laptops are protected and kept up to date

Now that you are deploying Wi-Fi laptops, they will be exposed to wireless networks outside of your office. Make sure those laptops are protected with desktop firewalls, antivirus and the latest operating system patches, and kept up to date. And make sure you check these devices when they return to the office, so they don’t bring anything unpleasant back to home base.

Bonus tip- Use WPA2 with AES encryption, not TKIP.

Per my blog post last month, using WPA with TKIP encryption is looking problematic, and one hack has been published. In my experience, where there is smoke, there is fire, and we will see more TKIP hacks in coming months.

Beat the rush and deploy WPA2 with AES-CCMP encryption, regardless of whether you use WPA-PSK or WPA Enterprise. Most modern clients and access points support WPA2, and you should be able to migrate smoothly. If your access points don’t support WPA2, think about upgrading them in 2009.

What’s your tip?

Most users love wireless, and the mobility and price points offered by Wi-Fi are tough to beat. There are plenty of security issues to consider and it’s easy to lose sight of the goal amongst all the hype and acronyms. I’m sure I’ve overlooked some great ideas, so feel free to post them below.

Start 2009 on a positive note by making sure you’ve reviewed this list, and I’ll keep blogging on more ways to keep your wireless secure.

From napera


Researchers Find More Flaws in Wireless Security

Written by Anonymous on 12:24 AM

WPA Networks Open to Limited Attack

Wireless networks that use a popular form of security known as Wi-Fi Protected Access (WPA) are vulnerable to an attack that could compromise certain communications in less than 15 minutes, two researchers plan to tell attendees next week at the PacSec 2008 conference in Tokyo.

Martin Beck and Erik Tews - two graduate students at technical universities in Germany - found a combination of techniques that allow an attacker to decrypt limited communications protected with the lesser of two WPA security protocols, known as the Temporal Key Integrity Protocol or TKIP. Using the techniques, attackers could also recover a special integrity checksum and send up to seven custom packets to clients on the network, sources told SecurityFocus.

The attack does not allow the key protecting the communications to be recovered, one of the researchers stressed .

"The new attack on WPA is not a complete key recovery attack," Tews said in an email to SecurityFocus. "It just allows you to decrypt packets and inject packets with custom content. But there is only a single short-term key recovered during the attack."

The research describes the latest weakness in wireless networks' security. In 2001, three researchers found a way to reliably break the previous wireless security protocol, known as Wired Equivalent Privacy (WEP), in less than two hours. By 2007, the latest refinement in attacks against WEP - found by Tews and two other researchers - reduced the time to recover a WEP key to less than a minute of calculations.

In 2002, after seeing WEP thoroughly broken, the industry alliance responsible for setting standards for wireless access points created the Wi-Fi Protected Access (WPA) protocol. Two years, later the firms created a stronger version of the standard known as WPA2.

Tews and Beck's attack appears to be the first practical, albeit limited, break of WPA encryption.

The duo's attack on WPA's Temporal Key Integrity Protocol (TKIP) uses a similar technique to an attack on WEP found in 2004, according to a copy of Beck's and Tews' presentation obtained by SecurityFocus. The WEP attack, known as chopchop, could decipher a packet of data without knowing the key by guessing each byte and using the access point as a check on each guess: If the packet is accepted by the access point, then the attacker knows the plaintext guess is correct.

The Temporal Key Integrity Protocol (TKIP) adds several countermeasures to foil attacks that would have succeeded against WEP. The protocol adds a message integrity check, or MIC, to protect against header and message alterations and uses replay counters to prevent replay attacks.

The researchers, however, found that the countermeasures only made the attack take longer: a wrong guess would cause the packet to be dropped by the access point, while a correct guess would cause a MIC failure and require the attacker to wait 60 seconds. In the case of an important type of networking data known as an Address Resolution Protocol (ARP) packet, only 14 bytes are not known. In less than 15 minutes, an encrypted ARP packet could be deciphered, including the secret MIC data, according to the researchers' presentation.

The attack also allows a limited amount of data to be sent on other channels using the same keystream - an end run around the replay-attack protection of TKIP.

While the security vulnerabilities are limited, the techniques could be used in a denial-of-service (DoS) attack, the researchers stated in their presentation, by using ARP injection to overwrite entries in the ARP table or potentially attack a local network's domain servers. The technique could also be used to channel data through a corporate firewall, they added.

In an email to a security mailing list, PacSec conference organizer Dragos Ruiu recommended that wireless-network administrators move to WPA2 or use the improved WPA security mode, known as Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP). In the latter case, the access point should not allow clients to revert to TKIP for communications with legacy systems, Ruiu said.

"If you aren't given the option to disable this, you might want to think about getting a different Access Point or Wi-Fi Router," he said.

According to Tews, an experimental implementation of the researchers' attack has been introduced into a development version of the aircrack-ng tool.

Beck and Tews plan to discuss their findings at the PacSec conference in Tokyo next week.

Copyright © 2008, SecurityFocus


Motorola Enhances Wireless Network Security

Written by Anonymous on 1:51 AM

Motorola has enhanced wireless network security by providing a built-in, hardware-based wireless intrusion prevention system sensor in its enterprise-grade wireless LAN access points. The integrated product debut follows Motorola's acquisition of AirDefense, a WLAN security provider.

According to Motorola, the multi-radio Motorola AP-5131 (802.11 abg) and AP-7131 (802.11abgn) with integrated, hardware-based wireless intrusion prevention system (WIPS) provides enterprises with a new option that does not require the traditional three-layer solution of wired, followed by overlay wireless followed by overlay WIPS.

Motorola AirDefense 5131 and 7131 APs with WIPS use dedicated radios for sensing and avoid the performance-challenged, time-slicing technique currently available from other wireless infrastructure vendors.

Sujai Hajela, vice president and general manager of enterprise WLAN at Motorola enterprise mobility business, said: "Worldwide, business demand for seamless security in all-wireless enterprise environments is steadily increasing. Motorola and AirDefense have already hit the ground running and are ready to offer our customers around the world streamlined secure enterprise networks at the lowest total cost of ownership."

Enterprise WLAN is part of Motorola’s portfolio of wireless broadband systems and services that complete IP networks. Delivering IP coverage to all spaces both indoors and outdoors, it includes fixed broadband, mesh and Enterprise WLAN for private and public networks.

By Samuel Abraham


Don't Have Security Nightmares

Written by Anonymous on 4:30 AM

How worried should we be about net security scares, asks Bill Thompson.

Anyone concerned about the security of their computers and the data held on them might sleep a little uneasily tonight.

Over the past few weeks we've heard reports of serious vulnerabilities in wireless networking and chip and pin readers, and seen how web browsers could fall victim to "clickjacking" and trick us into inadvertently visiting fake websites.

The longstanding fear that malicious software might start infecting our mobile phones was given a boost when the Information Security Center at US university Georgia Tech outlined how phone software could be hijacked to create "botnets" and allow handsets to be remotely controlled.

And now a group of researchers at the Security and Cryptography Laboratory at Ecole Polytechnique Federale de Lausanne in Switzerland have shown that you can read what is typed on a keyboard from 20m away.

It takes some sophisticated equipment to do it, but with the right antennae and a bit of luck it seems you can detect the radio emissions coming from the wires that connect keyboards to computers and tell just what someone is typing.

Data leaks

Web addresses, usernames and passwords are all visible, as well as the content of letters, e-mails and Facebook updates.

These aren't wireless keyboards, which are clearly vulnerable to snooping, but the good old USB or PS/2 keyboards we all use every day.

And even though the kit you need isn't the sort of stuff that your average credit-card skimmer is going to have lying around their flat, it shows that there are many unexpected vulnerabilities to be discovered.

The researchers suspect that cheaper keyboards with poor shielding are to blame, so government departments and hospitals may have to find a better supplier if even more of our sensitive data is not to leak out.

This is a good example of how lack of foresight can lead to security problems when faster hardware catches up with the assumptions made by system designers, and it also lies behind the newly-emerged vulnerability that affects secure wireless networks.

Internet apocalypse

Many encryption tools are susceptible to brute force attacks, for example, where a program simply tries all the possible keys until it finds the right one.

The developers believe that this will take too long for it to be useful, ideally some significant proportion of the age of the observable universe.

However, the latest version of a password recovery tool from Elcomsoft takes advantage of the astonishing processing power of the latest range of Nvidia graphics processing units (GPUs) to crack the WPA and WPA2 wireless security protocols in a matter of hours or even minutes, rendering most commercial wireless networks open to attack.

Since it was a wireless vulnerability that allowed criminals to break into the corporate network of TK Maxx's parent company and steal details of 45 million credit cards, this is a threat to be taken seriously.

A few years ago these problems would only have been reported in the computer trade press or in the technology sections of the more serious newspapers, where they were unlikely to bother the majority of network users.

Now they get more widespread attention and are often presented as marking an imminent internet apocalypse.

It is, of course, important that all net users appreciate the importance of protecting their computer and know how to avoid malicious websites, phishing scams and other attempts to subvert their online activities, but it can go too far.

Reasonable concerns

Last week I gave a talk to a group of people in Blockley, Gloucestershire, where I was trying to persuade those who were somewhat sceptical about the usefulness of the internet in their lives that the network has opened up new and incredibly beneficial opportunities for sharing, interaction and education.

It was one of the increasingly rare occasions when I can lower the average age of those present by entering the room, and I wanted to convince those present that it was worth spending time online.

There was a lot of concern over inappropriate content and how we ensure that children are kept safe, but I also had to field questions about the security of online banking and how to protect computers from viruses and other malware.

These concerns are reasonable, but not if they stop people going online or using the net to the full.

The dangers that face us, both the ones we know about already and the ones being discovered by security researchers every day, are not a reason to stay offline, they are a reason to be cautious when going online.

When Nick Ross presented Crimewatch on BBC television he would conclude his litany of tales of crime, violence and disorder by exhorting viewers not to have nightmares.

Perhaps we need something similar to accompany the growing number of warnings over net fraud, wireless security and broken encryption. It may be bad out there, but it isn't quite broken.

Bill Thompson is an independent journalist and regular commentator on the BBC World Service programme Digital Planet.


Trend Micro Internet Security Pro v2

Written by Anonymous on 12:14 AM

Firewall Toughening Up

Trend Pro's firewall comes preconfigured with four distinct profiles for different situations. I used the strict "Direct internet connection" profile for firewall testing since that test system indeed has a direct connection. Profiles are available for wireless, home, and office networks as well. Each profile activates its own complete set of firewall configuration settings, and Trend Pro can automatically change profiles when you connect to a different network.

I attacked the firewall using port-scan tests and other Web-based attacks. It passed every test and put all the system's ports in Stealth mode. The attacking programs couldn't see a thing.

A personal firewall should also make sure that no program misuses the Internet or network connection. Some firewalls put the user in charge, asking whether each program should be allowed access the first time it tries to connect. Trend Pro's firewall is smarter than that. Like Kaspersky, Panda, and Norton it automatically eliminates known bad programs and grants access to known good programs. It relies on its behavioral monitoring to handle unknown programs. If they try anything sneaky they'll get smacked down.

So does the behavioral protection work? I tried running a dozen leak tests, programs that demonstrate techniques malware programs use to evade old-style program control. I disabled the real-time protection, leaving just behavioral blocking. Trend Pro blocked 10 of the 12, a good result. Norton and Panda don't try to block these because they're just demonstrations with no actual malicious payload. That's a reasonable stance, but I like the fact that I can see Trend succeeding with these tests.

Trend Pro's multilayer protection was also effective when I attacked the test system using exploits generated by the Core Impact penetration tool. These attacks try to gain control of the protected system by exploiting vulnerabilities in the operating system, browser, or applications. Some attacks failed because the system wasn't vulnerable; Trend Pro blocked the rest in one way or another. The utility's battle with one exploit did slow the system to a crawl, but a reboot fixed that. It doesn't identify the exploit by name the way Norton does, but it gets the job done.

I always try to break a suite's protection using techniques that malware could manage programmatically. Last year's Trend Pro suite didn't do so well—I killed it off by tweaking the Registry and by turning off its essential services. This year's suite is much tougher. When I tried to change a Registry value to disable the firewall it not only prevented the change, it reported an attack. Likewise it reported my attempts to kill its process using Task Manager as an attack. And its essential services are configured so they can't be stopped by me or by malware. I did manage to kill it off by setting each service's start-up type to Disabled and crashing the computer, but that's a pretty far-fetched attack. Trend Pro is toughening up!

By Pcmag


New PCI DSS Details Released

Written by Anonymous on 12:38 AM

Online traders could breathe a sigh of relief when the next Payment Card Industry Data Security Standard is released in October.

The industry-wide standard for all firms which store credit card data has had a mixed response since its launch in 2006.

But the new version will implement much of the feedback gleaned in the past two years, and aims to introduce more clarity, according to Bob Russo, general manager of the PCI Security Standards Council.

"Rather than releasing a totally new and updated standard this is a revision of 1.1, so there are no major changes to the way people have to comply with it, " he said.

"In the future, as we move to standard 2.0, there will more than likely be pretty major changes but [in this version] we've come up with a lot more clarity and consolidated a number of sub-requirements."

The only noticeable revisions to the standard are an explicit requirement to strongly encrypt all wireless transmissions of cardholder data across public networks according to industry best practice standards.

There is also a further prescription that any antivirus software applies to all operating system types and addresses all types of malware.

Russo added that there will be "no bumps in the road" between the two versions, so firms currently implementing 1.1 do not need to worry about changing their plans to accommodate the new standard.

Current proposals for DSS 1.2 are still being considered and a final version will be released in early October.

Written by Phil Muncaster


Configuring Wireless Networking in Windows Vista

Written by Anonymous on 12:29 AM

Wireless Network:
A wireless network provides all the functions of a wired network with an advantage of roaming within your radio-signal network with still connected to your network.

Prepare:
Once you have identified the hardware needed like Hi-Fi Wireless networking card, and Wireless Router/ Access Point (Detailed information available on Windows XP page referred above), you are almost ready to connect to the network. If you are using a laptop which comes with an in-built wireless card, it may have a special function key or a button mostly in the front of the laptop to turn it on and off (Check with your computer manufacturer for information).

A following similar picture should be available near to the Wireless On/off button:

Figure 1: Wireless Symbol





Wireless network configuration methods:

You can configure connections to wireless networks, known as wireless profiles, for a computer running Windows Vista with the following methods:

  • Connect to a network dialog box
This is the common method by which individual users will configure connections to wireless networks.
  • Group Policy
Network administrators can use Group Policy settings in an Active Directory directory service environment to centrally configure and deploy wireless network settings and automatically configure domain member computers. More information here
  • Command line
Network administrators can use commands in the new netsh wlan context of the Netsh.exe tool to manually configure wireless networks and their settings. There are Netsh commands to export an existing wireless profile to an XML file and then import the wireless profile settings stored in the XML file on another computer. Learn about the syntax and use of the complete set of netsh wlan commands that you can use to manage 802.11 wireless networks in Windows Vista.

Connecting to Wireless network using Connect to a network dialog box:

1. Click Start and in the Search field type Network and Sharing, then select the Network and Sharing Center from the menu when the option appears.

2. In the Network and Sharing Center, select Connect to a network in the left pane. You can access the Connect to a network dialog box from many locations in Windows Vista, including the following:


  • By clicking Start, and then Connect to from the Windows Vista desktop
  • From the Manage wireless connections dialog box
  • From the Connect/Disconnect context menu option of a wireless network adapter in the Network Connections folder
The new Connect to a network dialog box is a redesigned version of the Choose a wireless network dialog box in Windows XP with Service Pack 2 (SP2). This new dialog also supports virtual private network (VPN) and dial-up connections (including Connection Manager and Point-to-Point Protocol over Ethernet [PPPoE]).


3. When the Connect to a network window appears, select Wireless from the drop-down menu to display all detected Wireless Networks. A non-broadcast wireless network appears in the list with the name “Unnamed Network.” (The first time the user connects to a network that does not broadcast an SSID, the user must type the Network Name.) The list of available networks is subject to the allowed wireless networks configured through Group Policy or the command line and the types of wireless networks being detected, such as infrastructure mode or ad hoc mode networks.

The following figure shows the Connect to a network dialog box.


In Show, you can select the following:
  • All Wireless, dial-up, and VPN connections.
  • Wireless Only wireless connections.
  • Dial-up and VPN Only dial-up and VPN connections.
By default, All is selected.




NOTE: If any of the wireless connections in the list are marked as "network cable unplugged" or "disabled," then the wireless adapter is not connected or is not turned on. You will have to make sure that the WiFi router is set up properly and that your adapter is enabled to proceed with that wireless connection.

4. On the Connect to a network window, each wireless network available within range is listed. Right-click the network that you are connecting to and click Connect and proceed to Step 8. If the wireless network you want to connect to is not listed, then you may be out of range of the wireless router or access point. For help in troubleshooting your wireless router or access point, see related links below.

5. If Router / Access Point configuration is setup correctly, and still the wireless network is not listed, try a setting up the network manually. To setup a network connection manually, click Set up a connection or network option found on the bottom left corner of the windows.

6. In the following dialog box, select Manually connect to a wireless network:


7. The next step of the Manually connect to a wireless network wizard would prompt for settings such as Network Name (SSID) and wireless encryption (WEP) settings. Type each in the required fields and click the Next button to proceed to Step 9.


8.
The Connect to a network wizard will ask for the Network Name (SSID) and wireless encryption (WEP) settings. Type each in the required fields. Wireless networks have varying degrees of security. If your wireless network does not require encryption, the settings on this tab will be automatically setup for you. If the wireless network that you are connecting to uses standard encrypted communication, select WEP enabled from the Encryption type drop down menu. Complete the wireless encryption configuration by typing the Network key into Network security key: field. See your network administrator or your wireless router software for the required network key.

9. If your network is unsecured, you will be prompted to confirm the connection. Windows Vista will never automatically connect to an unprotected or ad hoc network, reducing the risk of automatically connecting to a malicious wireless access point.


10. Click OK to return to the Connect to a network window. If the settings you have configured are correct, the network name will be listed in the preferred networks list. Click OK and close your Control Panel. Your notebook should now be connected to the wireless network. You may have to restart your notebook for some changes to take effect.

Configuring your Wireless Network Connection

1. Click Start, right-click Network, and then click Properties.

2. In the task list of the Network and Sharing Center dialog box, click Manage wireless networks in the left pane. From the Manage Wireless Networks dialog box, you can add a new wireless network, remove a selected wireless network, obtain the properties of the wireless network adapter, and choose the type of profile to assign to new wireless networks (applies to all users or the current user).



3. To view or modify the properties of an existing wireless network, in the Networks you can view and modify list, right-click the network name you are connecting to and select Properties.

4. To modify encryption and security settings, in the Wireless Network Properties window, select the Security tab.
Connection Tab

Security Tab with WPA-Enterprise settings

WPA – Personal Settings


5. On the Security tab, you can specify the following security types:

- Security type:
  • No authentication (Open) Open system authentication with no encryption.
  • WEP Open system authentication with Wired Equivalent Privacy (WEP).
  • WPA-Personal Wi-Fi Protected Access (WPA) with a preshared key (also known as a passphrase).
  • WPA-Enterprise WPA with IEEE 802.1X authentication.
  • WPA2-Personal WPA2 with a preshared key.
  • WPA2-Enterprise WPA with IEEE 802.1X authentication.
  • 802.1x IEEE 802.1X authentication with WEP (also known as dynamic WEP).
The choices listed depend on the capabilities of your wireless network adapter that are reported to Windows.

The shared key authentication method is not listed. Microsoft strongly discourages its use because it provides weak security for your wireless network. To configure shared key authentication, select No authentication (Open) here and then select Shared from the Security tab in the properties of the wireless network (described later in this article).

Encryption type: Select the method used to encrypt data frames sent over the wireless network. The choices depend on the selected security type. The three encryption types are WEP (128-bit), Temporal Key Integrity Protocol (TKIP) (128-bit), and Advanced Encryption Standard (AES) (128-bit).


When the No authentication (Open) security type is selected, None is selected.
When the WEP security type is selected, WEP is selected.
When the WPA-Personal security type is selected, you can select TKIP or AES.
When the WPA-Enterprise security type is selected, you can select TKIP or AES.
When the WPA2-Personal security type is selected, you can select TKIP or AES.
When the WPA2-Enterprise security type is selected, you can select TKIP or AES.
When the WEP (802.1x) security type is selected, WEP is selected.


The choices listed depend on the capabilities of your wireless network adapter that are reported to Windows.

- Security Key/Passphrase Type the WEP key (if you selected the WEP security type), the WPA preshared key (if you selected the WPA-Personal security type), or the WPA2 preshared key (if you selected the WPA2-Personal security type).

- Show characters Specifies whether you want to view the value typed in Security Key/Passphrase.

6. Enter the values depending on your network configuration and click Ok. It may take Windows a few minutes to complete the connection.

7. Click OK or Close to exit any open windows or panels.



From Whizblaze


Security researchers hack the London underground train for free ride

Written by Anonymous on 1:11 AM

A group of Dutch security researchers were able to clone the “smartcards” that commuters use to pay fares in the London Underground system, allowing the group to ride for free. This is an interesting attack vector that I actually talked to Adam Laurie about when I was at Black Hat Amsterdam. I’ve spoken about similar hacks with a number of security researchers, and there’s been some interesting ideas proposed on the subject. In fact, I may just try this on the laundry cards used in my apartment complex. I promise a full write up on how it was done if I manage to pull something off.

I originally saw this story commented on in an article on Wired by Alexander Lew, which commented that:

There are more than 17 million of the transit cards, called Oyster Cards, in circulation. Transport for London says the breach poses no threat to passengers and “the most anyone could gain from a rogue card is one day’s travel.” But this is about more than stealing a free fare or even cribbing any personal information that might be on the cards.

Oyster Cards feature the same Mifare chip used in security cards that provide access to thousands of secure locations. Security experts say the breach poses a threat to public safety and the cards should be replaced.

”The cryptography is simply not fit for purpose,” security consultant Adam Laurie told the Telegraph. “It’s very vulnerable and we can expect the bad guys to hack into it soon if they haven’t already.”


For those not familiar, Adam Laurie is a major player in the computer security research field and has done a ton of interesting research on all number of wireless technology. I’m working on getting Adam to write up a guest editorial or two on what he’s been working on lately.

Read on…

Images courtesy of Transport For London

The Wired article continues:

The Dutch government has taken the breach seriously and says it is upgrading the smartcard system that secures its buildings. “It’s a national security issue,” a spokesman for the Dutch Interior Ministry told reporters. “We’re in the process of replacing the cards of all 120,000 civil servants at central government level.”

According to the Times, Radboud University researcher Bart Jacobs and his team used an ordinary laptop to clone an access card to a building in the Netherlands. When that worked, they went to London to test the technique on the Underground.

The hackers scanned one of the Underground’s many card readers to collect the cryptographic keythat purportedly keeps the system secure. The keys were uploaded to a laptop, essentially turning them into portable card readers. The hackers then brushed up against passengers to wirelessly upload the information on their Oyster cars. That information in hand, it was a simple matter of using it to program new cards.

Jacobs says the same technique can clone smartcards that provide access to secure buildings. “An employee can be cloned by bumping into that person with a portable card reader,” he told the Times. “The person whose identity is being stolen may then be completely unaware that anything has happened. At the technical level there are currently no known countermeasures.”


Read that again… “no known countermeasures”. Crazy. Keep your eyes open for a guest editorial from Adam Laurie, hopefully coming soon. We’re negotiating how many beers I’ll owe him at Black Hat Vegas this year.

-Nate

Nathan McFeters is a Senior Security Advisor for Ernst & Young's Advanced Security Center in Chicago. The views and opinions expressed in this article are his own and do not represent the views and opinions of Ernst & Young Advanced Security Center or Ernst & Young, LLP. Nathan has performed web application, deep source code, Internet, Intranet, wireless, dial-up, and social engineering engagements for numerous clients in the Fortune 500 during his career at Ernst & Young and has spoken at a number of prestigious conferences, including Black Hat, DEFCON, ToorCon, and Hack in the Box. He can be found at his Pwn* blog and XS-Sniper, a blog with Billy Rios. See his full profile and disclosure of his industry affiliations.

By Nathan McFeters


Taking Wireless Security into Your Own Hands

Written by Anonymous on 12:08 AM

Some companies are restricting the use of USB ports. In one scam, someone leaves a flash drive on a restroom shelf at a bank. An employee finds it and inserts it into the USB port on his computer to see what's on it. Instantly, the drive installs a malicious code that copies customer data and sends it via the bank's e-mail system to a computer overseas.

Conducting business online via laptop Relevant Products/Services, cell phone or handheld device is productive -- but it can also be risky if the proper wireless security isn't in place.

"The productivity is tremendous, especially with handheld devices that you can use from anywhere," said Jack Vonder Heide, president of Technology Briefing Centers, Inc. "But the potential for catastrophe is great when we look at security breach possibilities. We really need to focus on them and make sure that we plug the holes."

In 2006, a hacker gained access to a financial institution employee's corporate user name and password when the employee accessed the Internet via a Wi-Fi signal in Midtown Manhattan's Bryant Park.

What he didn't know was that the seemingly legitimate wireless signal came from a nearby hacker, who could then track the employee's computer use, according to news reports.

Hotels, libraries, coffee shops and other public places now offer tens of thousands of Wi-Fi "hot spots" around the nation. But use caution when using Wi-Fi access to do any business-related work, Vonder Heide advises.

"I would not recommend anyone accessing anything of a confidential nature from a laptop computer via a non-secured wireless channel. It's just too risky," he said, A better option, he said, is to plug the computer into a phone line.

Better yet, he recommends that any data Relevant Products/Services that leaves the workplace on a laptop computer be encrypted -- in other words, scrambled and locked with a mathematical "key."

Many companies require employees to use a virtual private network (VPN) to access the company system remotely, said Kim Passalugo, a computer support agent with Geek Squad, "it's like a secret tunnel, if you will, through the Internet that nobody else can see," she said.

At the very least, individuals who use wireless Internet at home should make sure their router has been personalized, so it can't be accessed via the default user name and password, Passalugo recommended. Make sure all firewall, antivirus and anti-spyware software is configured to update automatically.

Many companies now have access control logging mechanisms that record when, for how long, and what files are viewed when an employee logs onto the system.

Another way that companies are protecting customer data is to restrict the use of USB ports on workplace computers, Vonder Heide explained. Here's why: In one scam, someone leaves a small flash drive on a restroom shelf at a bank. An employee finds it and inserts it into the USB port on his or her computer to see what's on it. Instantly, the drive installs a malicious code that copies customer data and sends it via the bank's e-mail system to a computer overseas.

Given that many business professionals are now buying their own tech devices, individuals must take time to make sure there are adequate passwords in place -- even on cell phones and handheld devices. (See www.microsoft.com/protect/yourself/password/checker. mspx for password advice.)

Finally, to be absolutely safe and compliant with company requirements, financial professionals should turn to in-house IT staff for assistance and regular updates.

"It's like a game of leapfrog, because when we discover a hole and fix it, it's a very short time before identity thieves and electronic criminals take advantage of another vulnerability," Vonder Heide said.

From Newsfactor


Wireless Security: Did you know?

Written by Anonymous on 12:12 AM

Based on my unscientific quick straw poll, the majority of computer-literate people have no idea how WLAN / wifi / wireless LAN security works and - worse - are actively exposing all their data and passwords to all services, having convinced themselves that they are “mostly” safe or secure.

So what? I’ve been going around gently advising friends, colleagues, and acquaintances that they should make some minor changes that make all the difference and left it at that.

But then I went to a conference run by Sony (of Playstation fame) where they were running an unsecured network right on London’s South Bank, within easy reach of a vast number of cafe-goers and laptop users.

Oh - but they weren’t just running it unsecured, they were pumping out it’s SSID to all and sundry, offering a blatant invitation: they’d named it “DevStation 08″, broadcasting from a large building with 6-foot-high letters and logos on the outside and inside proclaiming the same name and advertising that DevStation was the Sony PlayStation developer conference. Um. Maybe not such a good idea? (and this is far from the first or only conference I’ve been to that’s done this - I’m not criticising the organizers of that conference in particular, it’s just a great concrete example showing that even well-funded orgs are making these very basic mistakes)

I’m posting this in the (possibly vain) hope that it might persuade some more people to stop being foolish and/or lazy and perpetrating embarassingly poor security with their own and other people’s systems. I’m going to (hopefully) blow apart a popular myth. And hopefully get a decent Google ranking for it, which I’ll explain in a moment.

The worst thing…

…is that if you google wireless security you find many many pages and sites that advise on it, the vast majority of which avoid telling people the one thing they need to know - how to secure a wireless network the easy way? - and many of which veer so far clear of telling the truth it’s clear that the people writing them don’t have a clue about wireless security.
Level 2 - hide the SSIDs until actually trying out the various obvious attacks before having the courage to post about it, so I’m reasonably confident I’m not talking crap here :). Hopefully no-one’s going to shoot me down in flames here :).

The first few times I encountered people claiming that their networks were “secure enough” in ways that I found suspicious, I tried googling to confirm/deny what I thought was going on. I must have looked at close to a hundred odd webpages on the topic, and not ever found a straight answer. Argh.

The most important thing you need to know: if you are not using ENCRYPTION KEYS then you are GIVING AWAY ALL YOUR PASSWORDS, no matter what you think you have in place that is making it “not as bad as that”. You’re wrong. Trust me.

Levels of wireless security

Level 1 - switch it on and see if it works

This is really important when you buy a new computer / laptop / wireless router and need to find out if the damn hardware actually works and is all “compatible” with each other. There are many websites talking about things to do to make this work.

Sadly, very few of them (actually, no more than one that I’ve seen so far IIRC), tell you the most important final step:

Immediately disable everything, and start again from scratch with it all encrypted

Level 2 - hide the SSID

This is a good move - it stops your router from actively telling every computer (and - incidentally - many mobile phones (!)) in the area that you have a wireless network, that it’s free, and that they are welcome to use it.

What is an “area”? Well, with modern computers, it’s about 200 metres. That should be long enough to reach the length of your garden, into the garden of the house behind you, and out into the next street over. Quite a long distance. In most cases we’re talking *considerably further* than you could shout or see from your home, far enough that it would take you the best part of a minute just to run to the most distant point your wifi is reaching.

Unfortunately, anyone who knows anything about computers and who wants to get a free network will require approximately 10 minutes with google to find various tools that will give away your network anyway. But … it was a good first step - well done!

For most people, it’s *not worth the effort* of hiding the SSID, because you need to do the other steps anyway, and those “other” steps make you so secure that it doesn’t matter whether people can see your SSID. Many home users keep the SSID on just because it’s a pain in the ass to have it turned off when a friend comes round and wants to use their laptop etc.

Level 3 - force people to use a username and password to “login” before using the network

This is what the Sony conference did. It’s what several other conferences I’ve been to in the last few years have done. It provides … no security at all.

Did you read that correctly? I’m going to repeat:

A webpage with username and password provides NO SECURITY AT ALL to a wireless network

I don’t mean “because someone could guess the username/password” (they’re usually the same as the SSID name, sob).

I also don’t mean “because someone could casually ask anyone at the conference and probably be told straight away the correct answer” (although I’ve noticed that ten times out of ten that works. Easy!)

I actually mean because I verifiably was able to read all the internet traffic of everyone at each of these conferences WITHOUT LOGGING IN. This is using basic tools which are so common and widely used that I have them installed on all machines in the office *automatically* as part of the basic software install for new employees - no-one who does any multiplayer game development or online development (even webserver development!) would go without these tools.

The most common of all is Wireshark, an excellent network diagnosis tool which shows you all the traffic on the local network. Automatically. And … it has a nice feature where you click on some interesting traffic, and if it’s using TCP (note: all web traffic uses TCP) then Wireshark decodes all the information and reconstructs the stream of web-page requests and responses - including ALL THE FORM DATA YOU FILLED OUT, etc. On these “password-protected” wireless networkgs I ran WS just long enough to see that someone was logging in to their webmail (without reading the username and password, I just checked those fields were present), and then shut it down and wiped the data - I don’t want to know anyone else’s passwords, and don’t want to see anyone else’s private data.

Level 4 - turn on MAC authentication: only specific laptops / computers / etc can use the network

OK, so this seems REALLY secure. Several friends of mine use this, believing themselves safe. Um. Ahem. No. Sorry! If the data is not encrypted, then you have a setup that is no better than the one above - your router is still happily broadcasting (that means “shouting at the top of its voice”) all traffic to every wireless device in the immediate vicinity.

This is one of those things I googled extensively - at first, I thought surely routers wouldn’t be dumb enough to broadcast everything to all the EXPLICITLY DENIED wireless computers too? - and had no luck with finding simple answers (I didn’t want to try reading through the detailed hardware specs of wireless networking standards - there are too many of the things :( ).

Of course, unless they are implementing some key-exchange protocol, there’s no way they could stop themselves. And since I’m 99% certain that the MAC authenticated clients are using the same basic wireless protocol as the normal ones, which doesn’t include ANY key exchange, I’m pretty sure that MAC filtering is entirely pointless (from a “keeping your passwords private” point of view).

My friends are happily sending their hotmail passwords and all their private emails (you do realise, don’t you, that if you view an email in hotmail, your wireless router BROADCASTS that email to every wireless computer within a couple of hundred metres of you?) to their neighbours, their neighbours’ neighbours, and even to THEIR neighbours - and of course to every random person sitting in any cafe within a few hundred metres and who has randomly got their laptop out to do some work while they sip their coffee.

Level 5 - Firewall

Some friends feel secure because they have a firewall. Windows Firewall now comes as standard on all Windows XP and Windows Vista machines. Apple computers running OS X have their own firewall built-in, and linux users generally know enough about networking to have implemented their own following one of the surprisingly easy-to-follow HOWTO documents on the web.

These all do … absolutely nothing.

As stated above…(sorry, going to repeat myself here)

if you view an email in hotmail, your wireless router BROADCASTS that email to every wireless computer within a couple of hundred metres of you

The firewall will stop some hacker/cracker from trying to break in to your computer. However, most crackers aren’t stupid enough to waste their time breaking in to your computer if you’ve already given them the password to every online service you ever use, especially your primary email address. Being able to SEND AND RECEIVE email from your inbox is normally enough for them to steal all the passwords to all your other online systems, including important ones like, oh, your bank account.

Worried yet? You should be.

Level 6 - WEP and WPA - encryption key-based, protected wireless network

Here’s the secret: security Levels 1 to 5 don’t really exist. They have practically nothing to do with wifi security. Some of them are very effective … at solving different problems. Unfortunately, too few people realise that there is more than one problem when it comes to security when using a wireless internet card - and that the main problem (can everyone else see your username and password? Can they read all your emails? etc) isn’t being solved by those other solutions.

If your wireless data is not encrypted, then it doesn’t matter whatever else you do - you’re giving away everything.

In case you were wondering how easy it is for people to find your non-secure network, think about this: All Windows and Apple computers automatically show the user which networks in range are secured, and which are unsecured. Yep. They make it *real easy* to find the ones that are crying out “please abuse me”.

What you should do next. Do it. Do it NOW.

Now, if you google, you can actually find many many websites / pages talking about the differences between WEP and WPA, and the comparitive advantage and disadvantages, and advice on how to get them working between, say, a Netgear router, a Linksys network card, a Windows PC, and a Mac Airport device. That’s fantastic - well done, teh interweb! (no seriously - I’m delighted).

Now, please, everyone STOP AVOIDING WEP/WPA. Actually, please just use WPA: it works on *everything*, and there’s a vast number of HOWTO’s, FAQ’s, and troubleshooting guides to get you up and running on every conceivable combination of hardware and software.

And if I’m wrong, if you can’t get it working, please feel free to comment here, and I’ll do my best to help you. Because, frankly, I don’t ever want to fire up OS X again and see in the list of nearby wireless networks any of them without that little padlock icon that tells me they’re using encryption.

By Adam


Wireless Security

Written by Anonymous on 1:57 AM


Security Flaw Found in BT's Home Hub

Written by Anonymous on 1:16 AM

A security flaw in BT’s wireless broadband hub has been exposed by a national newspaper after it became the talk of security experts some months back.

As the installer of the Home Hub wireless network, BT is also said to be aware of the vulnerability, which may allow a hacker to steal sensitive data from the host computer.

It is apparently simple to exploit because the password supplied to ‘secure’ the wi-fi system can reportedly be breached after just a few, rather than countless, permutations.

Armed with a free computer program, IT experts showed the Mail on Sunday, which investigated the flaw, how to gain broadband access via the hub in just five minutes.

Once logged on, they said a criminal would be able to plant software to steal passwords and other sensitive data from the computer hosting the Home Hub.

“I am sure there are people driving round the suburbs with laptops trying to do this today,” Lloyd Brough, principal consultant at NCC Group, told the paper.

Paul Vlissidis, the group’s technical director, reportedly added that security experts had been discussing the weakness in the BT system for months.

But responding to the claims, the telecoms giant said it proved only a “theoretical” attack, as the breach wouldn’t allow its author to steal a hub user’s bank account details.

Under fire for not alerting consumers, BT also told the investigators that not a single customer has been affected by the problem, which it believes won’t affect the majority.

Despite the reassurance, BT has issued some new advice to customers about practical ways they can improve the security of their wireless network device .

Late last year, BT disabled the hub’s ‘remote assistance’ feature after security concerns it gave hackers a window to fully control the system, which had 2m users at the time.

From Contractor UK


Hacking wireless networks with a Pringles tube

Written by Anonymous on 12:12 AM


The wireless gateways to cybercrime

Written by Anonymous on 1:02 AM

Unsecured wireless connections are easily stolen, making increasing numbers of people the victims of crime online



On a hot summer's day two years ago, members of the Washington police force arrived at a building in Arlington County to arrest a suspected paedophile. The detectives were met by an elderly woman who, it emerged, had nothing to do with the crime. The problem was her wireless router. The device was openly allowing access to the internet throughout her apartment building and it is suspected that one of her neighbours was using it to upload child pornography.

A short walk with a Wi-Fi enabled phone or laptop will highlight that stealing wireless internet is easy. In a 2007 online survey of 560 people, more than half admitted to stealing Wi-Fi previously. To test just how easy it was, I recently took a short stroll with a laptop around my neighbourhood in Bristol. I found 127 Wi-Fi networks within a half mile of my home. Ignoring the dozen cafes and hotels, one-fifth (23) of them had no security.

A further quick check at each also showed that all 23 still used the default password to access the administration area of the router - which would enable a cybercriminal to edit details, lock the user out or steal passwords. This is apparently a typical picture; the IT security consultant, Network Box, estimates that 13% of all home networks and 16% of business networks are unsecured. With 30m routers sold worldwide last year alone, that's a lot of access points capable of being exploited.

There are several dangers associated with leaving the administration area open, says Graham Cluney of the firewall and antiviral software vendor, Sophos. "Different routers have different functions but you can generally change some of the [router's] settings and the way it works.

"If you know what you're doing you can make [the router] visit other sites. For example, you can redirect from Google to a replica site that uploads a keystroke recorder to the computer, which is capable of recording bank details."
Under attack
Gunter Ollmann, of IBM's internet security systems division, agrees. He explained how easy it was to change the DNS settings, which translate a web address into something the computer understands. By doing this the attacker can dictate where the home user is browsing.

"Even just controlling the DNS addresses and ensuring that all internet traffic now passes through a proxy server that the attacker controls means that the attacker can capture all passwords and submission details their victims are using." It wouldn't matter that your computer's antivirus software was the best in the world, you'd be sending all your details through another machine monitoring every detail you sent.

Gunter points out that an attacker could also modify settings to ensure the reset button no longer works properly, or just resets to the new operating system the attack installed on it.

Identity theft is not the only problem. Susan Hall, a partner in the law firm Cobbetts LLP and a specialist in IT law, highlights the problem of piggybacking by organised crime, in effect laundering the true IP address of the criminal. Using someone else's internet connection means it is harder to link the act with the criminal, be it fraudulent activity or the viewing of illegal sites. The prosecution needs only to prove the communication came from a particular system. Once this is achieved the onus is on the individual to prove his or her innocence.

As Hall points out: "We've had to argue this for cases of libel and had to try to track it back. It's not at all easy to show it didn't come from you." With it being "just too easy to do", Hall believes that the number of cases in which stolen Wi-Fi has been used for illegal activity will simply spiral.

Following my initial walk with a laptop, I tracked down a user. With permission - because doing it without would be a breach of the Computer Misuse Act - I hacked into and altered my "reasonably tech-savvy" neighbour's router Wi-Fi settings; he explained that he simply hadn't been worried enough to spend the time setting up the security of a password.

Only the router password and ISP (internet provider) login details were changed, preventing the machine from accessing the internet. My neighbour spent more than 40 frustrating minutes trying to access the internet - unsuccessfully.
Simple security
Karen Hanley of the Wi-Fi Alliance, a global industry body, believes that network security should be made as simple as possible if it is to be adopted. It is currently placing its seal of approval on WPA2 encoding for wireless networks. The organisation also recommends changing both the router's password and name.

The need for simplicity is slowly being adopted by the device manufacturers. Linksys' new LELA system, the company claims, will be as simple as selecting from a list of high, medium or low security.

The question, though, is whether enough people will use it - and how you make sure that they change the default password.
Setting your security

The administration area of your wireless router can be found by typing the default gateway address (such as 192.168.1.1) into a web browser. To get the default gateway type ipconfig into a command prompt (start, accessories, command prompt on most Windows machines). On Mac OS X, go to System Preferences/Network.

Say the address is 192.168.1.1 - type http:192.168.1.1 in your browser. You'll be asked for a user name (default is admin) and/or password - usually admin or blank. From this area, the system password can be changed and the level of encryption set. The network name (SSID) can also be altered to improve security further.

The password you set should be unique, secure and very difficult to link to you. It should also be memorable. Several experts suggest selecting an abbreviated, meaningful phrase. For example: "my first holiday was in Wales 1984" becomes MfhwiW1984. Make sure it has no connection to any information placed onto your Facebook, Bebo or MySpace profiles.

From Guardian.co.uk


Telkom modems hacked wirelessly

Written by Anonymous on 11:58 PM

The Telkom Mega 100 and 200 wireless modems have been found to be easy to hack, says Dino Covotsos, CEO of Telspace Systems.

Covotsos demonstrated their vulnerabilities at ITWeb Security Summit 2008, in Midrand, yesterday.

Covotsos showed delegates how easily the Telkom modems could be hacked, and said: “It is so simple, that getting them assessed isn't even considered.”

There are, however, steps that can be taken to secure this wireless security further, said Covotsos. “Telkom does need to urgently address this issue, but there are additional precautions which can keep the user more secure in the meantime.”

Covotsos suggested the modem's WPA key be changed immediately, and that it should be between eight and 64 characters in length.

He explained to delegates that when he tried to alter the passkey on specific models, it was denied, but there may have been changes in the meantime. “There may be new firmware available that allows for the key to be changed and more complex security implemented.”

Covotsos also asked delegates to keep in mind that he only attempted to hack the 100 and 200 models, and is not sure what others may be vulnerable as well.

He said all attempts to contact Telkom about these vulnerabilities have so far proved unsuccessful.

Covotsos feels that when it comes to awareness levels and security, locally we are not where we should be.

“What is especially worrying is those that are not really PC literate,” he said. “They will take for granted that their Telkom modem installation is secure. But Telkom has released this to the public and are putting people at risk.”

BY Ilva PietEerse


Our Hot News

MLL Telecom, which specialises in building and operating broadband wireless networks, today unveiled a new Customer Management Centre (CMC) dedicated to network management, increasing network visibility and proactively identifying and resolving incidents on each customer’s network. Read More..

Want to subscribe?

Subscribe in a reader Or, subscribe via email:
Enter your email here:
Find entries :