New User, Welcome!     Login

Next Page >>

wireless network

hack.lu 2011 CFP

  * Software Engineering and Security
  * Honeypots/Honeynets
  * Spyware, Phishing and Botnets (Distributed attacks)
  * Newly discovered vulnerabilities in software and hardware
  * Electronic/Digital Privacy
  * Wireless Network and Security
  * Attacks on Information Systems and/or Digital Information Storage
  * Electronic Voting
  * Free Software and Security
  * Assessment of Computer, Electronic Devices and Information Systems
  * Standards for Information Security

Call for Papers Hack.lu 2009

- Software Engineering and Security
- Honeypots/Honeynets
- Spyware, Phishing and Botnets (Distributed attacks)
- Newly discovered vulnerabilities in software and hardware
- Electronic/Digital Privacy
- Wireless Network and Security
- Attacks on Information Systems and/or Digital Information Storage
- Electronic Voting
- Free Software and Security
- Assessment of Computer, Electronic Devices and Information Systems
- Standards for Information Security

Cisco Security Advisory: Cisco Wireless Control System Conversion Utility Adds Default Password

Cisco WCS systems that have not been converted from a CiscoWorks WLSE using the
conversion utility are not affected by this problem. Additionally, Cisco WCS
systems that have been converted from a CiscoWorks WLSE using the conversion
utility for version 4.2 or later are not vulnerable.

For more information about Cisco Unified Wireless Network Software Release 4.2,
visit:

http://www.cisco.com/en/US/products/ps6973/prod_bulletin0900aecd806b7f8a.html

No other Cisco products are currently known to be affected by this

Hack.lu 2008 CfP

* Software Engineering and Security
* Honeypots/Honeynets
* Spyware, Phishing and Botnets (Distributed attacks)
* Newly discovered vulnerabilities in software and hardware
* Electronic/Digital Privacy
* Wireless Network and Security
* Attacks on Information Systems and/or Digital Information Storage
* Electronic Voting
* Free Software and Security
* Assessment of Computer, Electronic Devices and Information Systems
* Standards for Information Security

Aruba Networks Advisory ID: AID-102609 - Malformed 802.11 Association Request frame causes Denial of Service condition on an Access Point

A Denial of Service (DoS) vulnerability was discovered during standard
bug reporting procedures. A malformed 802.11 association request frame
causes a crash on the Access Point (AP) causing a temporary DoS
condition for wireless clients. Prior successful security association
with the wireless network is not required to cause this condition. The
AP recovers automatically by restarting itself.


AFFECTED ArubaOS VERSIONS


Aruba Advisory AID-070611 Cross Site Scripting vulnerability in ArubaOS and AirWave Administration Web Interfaces

 

DETAILS

ArubaOS and AirWave maintain information on all wireless network SSIDs
and APs visible
on the wireless network and the general vicinity. This information is
used for security
and reporting purposes. An attacker could plant an AP with maliciously
crafted SSID and

Hack.lu 2010 CfP

  * Software Engineering and Security
  * Honeypots/Honeynets
  * Spyware, Phishing and Botnets (Distributed attacks)
  * Newly discovered vulnerabilities in software and hardware
  * Electronic/Digital Privacy
  * Wireless Network and Security
  * Attacks on Information Systems and/or Digital Information Storage
  * Electronic Voting
  * Free Software and Security
  * Assessment of Computer, Electronic Devices and Information Systems
  * Standards for Information Security

[Announcement] ClubHACK Magazine Issue 17-June 2011 released

Direct Download: http://chmag.in/issue/jun2011.pdf

Articles in the magainze:- 

Tech Gyan - Pentesting your own Wireless Network
Tool Gyan - Wi-Fi tools
Mom's Guide - Wireless Security - Best Practices
Legal Gyan - Copyrights and cyber space
Matriux Vibhag - Forensics with Matriux Part - 2
Poster of the month - Can you cage a Wi-Fi signanl ?

Re: Android wireless accepts fake response (No interaction requires) (Vulnerability ?)

>> :: Description ::
>>
>> I have found Android device's behavior which I deem it is inappropriate.
>> I am not sure if it can be classified as a vulnerability. The problem
>> appears when an Android device have connected to hidden SSID wireless
>> networks. The default behavior of most OSes is to shout out to see if
>> there is an expected hidden SSID over there. A legitimate access point
>> would reply with a probe response. However, a rouge access point could
>> also reply with a fake probe response and continue further negotiation
>> until it captures WPA handshake. Android devices will automatically and
>> gratefully accept the fake response while other OSes, including Windows,

Android wireless accepts fake response (No interaction requires) (Vulnerability ?)

:: Description ::

I have found Android device's behavior which I deem it is inappropriate.
I am not sure if it can be classified as a vulnerability. The problem
appears when an Android device have connected to hidden SSID wireless
networks. The default behavior of most OSes is to shout out to see if
there is an expected hidden SSID over there. A legitimate access point
would reply with a probe response. However, a rouge access point could
also reply with a fake probe response and continue further negotiation
until it captures WPA handshake. Android devices will automatically and
gratefully accept the fake response while other OSes, including Windows,

hashdays 2011 - Call for Papers (#days CFP)

Scope
-----
In particular, we are looking for topics in the following domains:
* Operating system and application security
* Wired and wireless network security
* Mobile communication security
* Forensics and anti-forensics
* Digital privacy and anonymous communication
* Reverse engineering of software and hardware
* Malware collection and analysis

Linksys WRT54G - read router password from file placed on FTP

    2046    Dec-24-2001  00:02:42   calibra.dat       

lftp 192.168.1.1:~> 


It is possible to download igwpricf.dat file (and another) where plain-text password to web access and wireless network are keeping.


rafal@localhost ~ $ strings igwpricf.dat
Linksys
IntotoSoft

Aruba Mobility Controller - multiple advisories: DoS and authentication bypass

A Denial of Service (DoS) vulnerability was discovered during standard
bug reporting procedures. A malformed 802.11 probe request frame causes
a crash on the Access Point (AP) causing a temporary DoS condition for
wireless clients. Prior successful security association with the
wireless network is not required to cause this condition. The AP
recovers automatically by restarting itself.


AFFECTED ArubaOS VERSIONS


OS X 10.6.5 kernel crash upon wlan roaming with disabled mandatory MCS

During the buildup at the CCC 27c3 congress in Berlin we noticed several Apple Macbooks kernel paniced while connected to the wireless network. We identified the cause of this issue and we are able to reproduce this as well.

It seems to be limited to the aluminum unibody Macbooks, running OS X 10.6.5 with the following Broadcom wireless chip:

 Card Type:            AirPort Extreme  (0x14E4, 0x8D)
 Firmware Version:     Broadcom BCM43xx 1.0 (5.10.131.36.1)

The problem occurs when 802.11n MCS0 (Modulation and coding scheme) is disabled on a Cisco Wireless Controller. This scheme is mandatory according to the IEEE standard (802.11n-2009, page 265). Deselecting this MCS is available through the web interface (both WCS and WLC) and the console without a notification about the fact that it is mandatory:

 (Cisco Controller) >config 802.11a disable network

Ruxcon 2010 Final Call For Papers

   * Code Analysis
   * Forensics and Anti-Forensics
   * Embedded Device Security
   * Web Application Security
   * Network Traffic Analysis
   * Wireless Network Security
   * Cryptography and Cryptanalysis
   * Social Engineering
   * Law Enforcement Activities
   * Telecommunications Security (SS7, 3G/4G, GSM, VOIP, etc)


[DCA-00014] Dlink WBR-2310 Wireless Router DoS

 - The D-Link RangeBooster G™ WBR-2310 with enhanced 108 features the
industry’s first default 108Mbps* “Dynamic Mode” that allows clients
to always operate at the highest possible speeds while automatically
identifying and recognizing other D-Link RangeBooster G™ products for
highest performance capability and seamless access to the wireless
network in a homogeneous environment.

[Bug Description]

 - The Embedded Web Server does not sanitize correctly a crafted GET
request leading to Denial-of-Service.

Online Binary Planting Exposure Test

whether your computer or network can be attacked from the Internet (using any one of
the known or unknown binary planting bugs).

You should also know that any network-based countermeasure (such as blocking SMB and
WebDAV at the perimeter) will stop protecting you when you connect your computer to
another network, such as a hotel-provided or public wireless network. Running the
test in various setups you're using might therefore be a good idea.

Additional information here:
http://blog.acrossecurity.com/2010/08/online-binary-planting-exposure-test.html.


[ GLSA 200901-01 ] NDISwrapper: Arbitrary remote code execution

Background
==========

NDISwrapper is a Linux kernel module that enables the use of Microsoft
Windows drivers for wireless network devices.

Affected packages
=================

    -------------------------------------------------------------------

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

A privilege escalation vulnerability exists only in WLC software version
4.2.173.0, and could allow a restricted user (i.e., Lobby Admin) to gain
full administrative rights on the affected system.

Note: Wireless network users are not affected by this vulnerability.

This vulnerability is documented in Cisco Bug ID CSCsv62283 and has
been assigned the Common Vulnerabilities and Exposures (CVE) identifier
CVE-2009-0062.


[ MDVSA-2011:171 ] networkmanager

 Security issues were identified and fixed in networkmanager:
 
 GNOME NetworkManager before 0.8.6 does not properly enforce the
 auth_admin element in PolicyKit, which allows local users to bypass
 intended wireless network sharing restrictions via unspecified vectors
 (CVE-2011-2176).
 
 Incomplete blacklist vulnerability in the svEscape function in
 settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME
 NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, when

[SECURITY] [DSA 1731-1] New ndiswrapper packages fix arbitrary code execution vulnerability

CVE Id         : CVE-2008-4395
Debian Bugs    : 504696


Anders Kaseorg discovered that ndiswrapper suffers from buffer overflows
via specially crafted wireless network traffic, due to incorrectly
handling long ESSIDs. This could lead to the execution of arbitrary
code.


For the oldstable distribution (etch), this problem has been fixed in

Proxy bypass vulnerability & plain text passwords in LevelOne AMG-2000

"AMG-2000 is an AP Management Gateway dedicatedly designed for small to
medium-sized network deployment and management, making it an ideal solution
for easily creating and extending WLANs in SMB offices. With its user
management features, administrators will be able to manage the whole process
of wireless network access. In addition, Access Point (AP) management
functions allow administrators to discover, configure, update, and monitor all
managed APs from a single secured interface, and from there, gain full control
of entire wireless network."



Airscanner Mobile Security Advisory #07122001: Eye-Fi Multiple Vulnerabilities

Spoof Eye-Fi listener on local or remote network.

In addition to these issues, there are several wireless related risks associated 
with the Eye-Fi sending out probe requests. Using Karma like programs, a rouge
wireless network can be setup, through which the Eye-Fi card will automatically pass
the images, allowing them to be capture.

More details on this program and the vulnerabilities are located at:

http://www.informit.com/articles/article.aspx?p=1174944

[ GLSA 200904-12 ] Wicd: Information disclosure

information.

Background
==========

Wicd is an open source wired and wireless network manager for Linux.

Affected packages
=================

    -------------------------------------------------------------------

[SECURITY] [DSA-1996-1] New Linux 2.6.26 packages fix several vulnerabilities

CVE-2009-4027

    Lennert Buytenhek reported a race in the mac80211 subsystem that
    may allow remote users to cause a denial of service (system crash)
    on a system connected to the same wireless network.

CVE-2009-4536 & CVE-2009-4538

    Fabian Yamaguchi reported issues in the e1000 and e1000e drivers
    for Intel gigabit network adapters which allow remote users to

Ruxcon 2012 Call For Papers

    o Code Analysis
    o Forensics and Anti-Forensics
    o Embedded Device Security
    o Web Application Security
    o Network Traffic Analysis
    o Wireless Network Security
    o Cryptography and Cryptanalysis
    o Social Engineering
    o Law Enforcement Activities
    o Telecommunications Security (SS7, 3G/4G, GSM, VOIP, etc)


[ MDVSA-2010:030 ] kernel

 
 An issue was discovered in 2.6.32.x kernels, which sets unsecure
 permission for devtmpfs file system by default. (CVE-2010-0299)
 
 Additionally, it was added support for Atheros AR2427 Wireless
 Network Adapter.
 
 To update your kernel, please follow the directions located at:
 
   http://www.mandriva.com/en/security/kernelupdate
 _______________________________________________________________________

Ruxcon 2010 Call For Papers

    o Code Analysis
    o Forensics and Anti-Forensics
    o Embedded Device Security
    o Web Application Security
    o Network Traffic Analysis
    o Wireless Network Security
    o Cryptography and Cryptanalysis
    o Social Engineering
    o Law Enforcement Activities
    o Telecommunications Security (SS7, 3G/4G, GSM, VOIP, etc)


Level-One WBR-3460A Grants Root Access

4. Or they could download a backup copy of the configuration file for the device (the same file can be obtained by viewing the contents of  "/tmp/nvram"); by viewing that file one can easily extract the ADSL account logins or any other information is curious about, as everything is stored in plaintext - once again)

IV Vulnerability Exploited Successfully:
========================================
1. While we were connected through the Ethernet interface, and
2. While we were connected via the security-enabled (WPA2-PSK) wireless network we had setup (and our wireless NIC's MAC address was in the list of the trusted MACs)

V Proof of Concept:
===================
tasos@nyx:~$ telnet 192.168.0.1
Trying 192.168.0.1...

Ruxcon 2011 Final Call For Papers

    o Code Analysis
    o Forensics and Anti-Forensics
    o Embedded Device Security
    o Web Application Security
    o Network Traffic Analysis
    o Wireless Network Security
    o Cryptography and Cryptanalysis
    o Social Engineering
    o Law Enforcement Activities
    o Telecommunications Security (SS7, 3G/4G, GSM, VOIP, etc)


Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!