Results 1 to 2 of 2

Thread: Security group warns of flaw in wireless protocol

  1. #1
    AO French Antique News Whore
    Join Date
    Aug 2001
    Posts
    2,126

    Security group warns of flaw in wireless protocol

    The Australian Computer Emergency Response Team issued an advisory Thursday warning companies that their wireless networks could be disrupted by an attacker with a handheld device.
    A vulnerability in the most common wireless networking protocol, the 802.11 standard established by the Institute of Electrical and Electronic Engineers (IEEE), allows a device to essentially jam other devices on a network using a low-power signal.

    "Previously, attacks against the availability of IEEE 802.11 networks have required specialized hardware and relied on the ability to saturate the wireless frequency with high-power radiation, an avenue not open to discreet attack," AusCERT said in its advisory. "This vulnerability makes a successful, low-cost attack against a wireless network feasible for a semiskilled attacker."

    The flaw affects the clear channel assessment (CCA) procedure, which attempts to minimize the probability that two devices will broadcast on the same frequency. The attack can cause all devices in range to wait to transmit until the attack has halted.


    The attack is considered a denial-of-service tactic and, as such, is not rated a critical problem. However, AusCERT warns that emergency response networks should move to wireless technologies that are not vulnerable to jamming.

    Vulnerable devices include any that support the 802.11, 802.11b and low-speed 802.11g wireless standards. Devices that use 802.11a or high-speed 802.11g, above 20mbps, are not vulnerable, the organization said.
    Source : http://zdnet.com.com/2100-1105_2-5212088.html
    -Simon \"SDK\"

  2. #2
    Senior Member
    Join Date
    Apr 2004
    Posts
    1,024
    I read about that yesterday on Security Focus...

    Some pretty scary stuff for any large business or corporation using Wireless to transfer critical data... But that's a bad idea in the first place, so in a way it's their own fault...

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •