On BNET: How to get permission to work at home
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner
Posted on ZDNet News: Jan 16, 2006 9:55:00 PM

A Windows feature that automatically searches for Wi-Fi connections can be exploited by hackers, a security researcher has warned.

The feature is part of Windows XP and 2000 and was exposed as being vulnerable at hacker conference ShmooCon on Saturday by vulnerability researcher Mark Loveless.

Loveless claimed that hackers can take advantage of the feature to include a user's PC in a peer-to-peer network, giving them access to information on its hard drive.

When a PC running Windows XP or Windows 2000 boots up, it will automatically try to connect to a wireless network. If the computer can't set up a wireless connection, it will establish an ad hoc connection to a local address. This is assigned with an IP address and Windows associates this address with the SSID of the last wireless network it connected to.

The machine will then broadcast this SSID, looking to connect with other computers in the immediate area.

The danger arises if an attacker listens for computers that are broadcasting in this way, and creates a network connection of their own with that same SSID. This would allow the two machines to associate together, potentially giving the attacker access to files on the victim's PC.

Security experts contacted by ZDNet UK on Monday confirmed that the flaw exists, but said that it should not be a problem for those using firewalls.

Paul Wood, security analyst at MessageLabs indicated that users will probably be unaware that their computers have connected to the peer-to-peer network in such a way.

MessageLabs believes that users running Windows XP Service Pack 2 (SP2) are not at risk.

"This yet again is a wake-up call for those who haven't installed SP2. Any machines running a copy of XP without SP2 are saying 'Come and get me', as there are so many gaping threats," said Mark Sunner, chief technology officer at MessageLabs.

Get some protection
Experts recommended companies deploy a security policy, if one isn't already in place: "Any organization deploying a Wi-Fi network needs to implement a company security policy," said Sunner. "The potential victims are the road-warrior community. Does the in-house security department have a mechanism to check the visibility of remote machines?"

MessageLabs also recommended that individual telecommuters be given personal firewalls.

Individuals can also protect themselves by disabling Wi-Fi when not using it, said Greg Day, security analyst at McAfee.

MessageLabs advised the following:

"Users with Wi-Fi can disable the peer-to-peer facility by going to "Wireless Network Properties | Advanced | Network Access Point | Choose Infrastructure Networks Only," said Wood. "We recommend people only connect to infrastructure points, although some users may want to use peer-to-peer for head-to-head gaming and file sharing."

MessageLabs pointed out that system administrators can also mitigate the problem by blocking ports 135, 137, 138 and 139--which in Sunner's words "should be nailed shut already"--from accepting NetBIOS connections.

Day downplayed the potential of the attack: "Hackers are trying to class this as virus-like. You become part of the problem because your machine is now broadcasting on a peer-to-peer network. However, all this gives hackers is the ability to see other machines--they still have to write exploits. But if the user is patched or has a firewall, they are protected."

Sunner echoed those feelings: "I'm a purist, and for me the (virus) analogy is not rooted in reality. Could it be self-replicating? It's not really within the realms of possibility," said Sunner.

Criminal gangs were unlikely to target this flaw as it would be too labor-intensive to exploit, predicted MessageLabs, saying that it was "really a threat from script kiddies".

Microsoft did not immediately respond to a request for comment.

Tom Espiner of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 38 Talkback(s)
R.I.M. patent infringement.....
I would disagree with the posters who claim that it is entirely RIM's fault. First of all: NTP did not develop the technology that they are "protecting". They bought the rights to the patent much as a... (Read the rest)
Posted by: rickhal Posted on: 02/14/06 You are currently: a Guest | | Terms of Use
Rep told us not to worry...  Mike Cox | 01/16/06
How much do you weigh?  TheCrow_z | 01/16/06
Why bother questioning Mike?  Grayson Peddie | 01/16/06
guess his weight...  linuxoverwindows | 01/17/06
Nothing discovered here  george_ou | 01/16/06
Question about this "vulnerability"  NonZealot | 01/16/06
Any kind of authentication would defeat it  george_ou | 01/17/06
using my wireless ap as a reference point...  linuxoverwindows | 01/17/06
time was estimate...  linuxoverwindows | 01/17/06
Thanks for that info! (NT)  NonZealot | 01/17/06
Try a distributed Beowolf setup  cburgess-iPALADIN | 01/21/06
And they can still be heard apologising  Richard Flude | 01/17/06
interesting article.  linuxoverwindows | 01/17/06
True so true  I'm Ye, the MS SHILL . | 01/17/06
true  linuxoverwindows | 01/17/06
My laptop is already secure by now.  Grayson Peddie | 01/16/06
I'm glad I don't use wi-fi.  HypnoToad | 01/16/06
I can't believe how much press this is getting  toadlife | 01/16/06
Fly in the soup  cburgess-iPALADIN | 01/21/06
Wi-Fi  ipfresh@... | 01/17/06
Windows is a gaping security hole  Chad_z | 01/17/06
There's a gaping hole, allright...  John Zern | 01/17/06
Re: Gaping Hole  BXLE | 01/17/06
should be more like...  linuxoverwindows | 01/17/06
smashed  Shelendrea | 01/17/06
Funny thing is...  SGT_Spam | 01/17/06
Oh, really?  Chad_z | 01/17/06
I bet you don't have Norton in your computer.  Grayson Peddie | 01/18/06
The Chicken Little Syndrome  Wolfie2K3 | 01/17/06
SP2  SGT_Spam | 01/17/06
Wi-Use Windows Wi-FI?  IT_Guy_z | 01/17/06
OEM Utility  SGT_Spam | 01/17/06
Not entirely new but none the less a serious problem  nicholasmiller | 01/20/06
Very good  cburgess-iPALADIN | 01/21/06
RIM  garryg24 | 01/24/06
Stopping Bogus Software Patents  roedy | 01/24/06
Patent Vultures  datadoc_z | 01/24/06
R.I.M. patent infringement.....  rickhal | 02/14/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
advertisement
Click Here