Wireless Infidelity II: Airjacking.
This article assesses the extent of the security risks involved in wireless networking technology by considering three possible scenarios demonstrating vulnerabilities. The Service Set ID (SSID) is a 32 byte or less network name of a service set. This name is used by other network devices to initiat...
| Published in: | Communications of the ACM Vol. 47; no. 12; pp. 15 - 21 |
|---|---|
| Main Authors: | , |
| Format: | Article |
| Published: |
Association for Computing Machinery
Dec2004
|
| Subjects: | |
| Online Access: | View this record in EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=15278909&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 15278909 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Dec2004 vid: 47 iid: 12 pid: 68 pub: Association for Computing Machinery artinfo: ui: 15278909 10.1145/1035134.1035149 ppf: 15 ppct: 6 formats: tig: atl: Wireless Infidelity II: Airjacking. aug: au: Berghel, Hal Uecker, Jacob affil: Professor and the director, University of Nevada, Las Vegas School of Computer Science. Director of the University's Center for Cybermedia Research. Co-director of the National Identity Theft Financial Fraud Research and Operations Center. Research Assistant, University of Nevada, Las Vegas Center for Cybermedia Research. su: Wireless communications Wireless Application Protocol (Computer network protocol) Computer security Computer operating systems Computer network protocols sug: subj: Wireless communications Wireless Application Protocol (Computer network protocol) Computer security Computer operating systems Computer network protocols ab: This article assesses the extent of the security risks involved in wireless networking technology by considering three possible scenarios demonstrating vulnerabilities. The Service Set ID (SSID) is a 32 byte or less network name of a service set. This name is used by other network devices to initiate a connection. Wireless Application Protocols (WAP) may be configured as "open" or "closed." In the open mode, the WAP broadcasts its SSID to the world, while in closed mode, it does not. A computer with a WiFi card set to SSID=ANY will attempt to authenticate with the open WAPs with the strongest signals. This is called association polling and is built into Windows XP by default when wireless is enabled. The goal of Wired Equivalent Privacy (WEP) was to bring some of the security available in wired networks to WiFi. Unfortunately, the designers bungled the job. WEP suffers from two fundamental deficiencies — it was poorly designed and it was poorly implemented. Other than that, it's fine. A key WEP vulnerability results from the implementation of the RC4 symmetric stream cipher algorithm. INSET: URL Pearls. pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2004 holdings: @attributes: islocal: N |
|---|