On TechRepublic: 12 tech terms that make you sound old
BNET Business Network:
BNET
TechRepublic
ZDNet

January 19th, 2006

Windows Wi-Fi 'vulnerability' not a vulnerability

Posted by George Ou @ 3:01 am

Categories: Mobile/Wireless, Networking, Security

Tags:

[Updated 1/20/2006 2:00 AM:  I had a chat with Mark Loveless after he contacted me after reading this blog and we cleared some issues up.] We’ve had two stories this week by Tom Espiner declaring a new Wi-Fi vulnerability in Windows XP with SP2 and that a fix wasn’t available for another year or more.  The first story claimed that there was a new vulnerability discovered in Microsoft’s Windows XP wireless network client loosely based on researcher Mark Loveless’ claims that he found a new Windows Wi-Fi vulnerability.  [Upadated: Mark Loveless didn't actually use the word "vulnerability" but he rated this Windows behavior with a severity of "high" along with the qualification that the risk was "albeit lame".]  The second story stated that Microsoft admitted to this vulnerability and that they wouldn’t patch it for another year or more.  We may as well rip out our wireless LAN adapters from our PCs… [Update: Since Loveless technically never used the word "vulnerability", he didn't stretch anything.  But I can see how his severity rating of "high" can easily be misinterpreted as a "vulnerability"] The problem is that Loveless this is really stretching the definition of a "vulnerability" if it can even be considered a vulnerability at all and Microsoft never acknowledged this as a vulnerability.  I checked with a Microsoft spokesperson and they confirmed that Microsoft Security Research Center states that this is not a security vulnerability.

This is what I suspected all along because by definition, a software vulnerability is when software can be made to do something it wasn’t designed to do.  This "vulnerability" that Loveless Espiner’s story raised is actually a feature designed into every wireless "supplicant" (that’s IEEE speak for "client") software in the world because it is a fundamental and critical feature of the IEEE 802.11 protocol.  The name of this feature that Loveless Espiner’s story is concerned about is "SSID probe requests", but the feature is critical if a wireless client computer wants to find an access point or ad-hoc wireless peer computer that suppresses its SSID beacons.  Someone obviously has to reach out to the other party first if there is to be a wireless LAN connection at all.

[Updated: For the record, Loveless' report is actually concerned about a behavior in Windows that doesn't distinguish between ad-hoc networks and infrastructure networks if their SSID happens to be the same.  Loveless also found an a recommendation in RFC 3927 section 5 paragraph 3 coauthored by a Microsoft employee that an automatic addressing scheme shouldn't be used in Wireless LANs so he is criticizing Microsoft for failing to follow this recommendation.  For me, restricting the use of automatic IP addressing in any kind of Wireless LANs is silly because it shouldn't be used as a substitution for real protection in the first place.  Loveless is also complaining about Windows advertising SSIDs and establishing Wi-Fi connections to these SSIDs without explicit user consent just because the SSID had be used before in an unsecured manner.  I still don't have a problem with this because it's a basic usability feature and I don't want Windows bugging me with pop-ups every time just because it's connecting to an unsecured SSID that I've already willingly connected to before.  Anyone afraid of unsecured network connections shouldn't make them in the first place or make sure they take the appropriate precautions if they do.  This was the case I made in this original blog and I'm sticking to it.]

A normal access point will beacon (broadcast) its SSID about 10 times per second to let wireless users know of its presence.  When this SSID broadcast feature is disabled because some network administrator thinks it’s such a great security feature, the only way a client computer can establish a connection with that access point is if it goes out and probes for that access point by its SSID.  It essentially has to shout out to the access point  (figuratively speaking) "HEY ARE YOU THERE!" until the access point replies "YES I AM!" before it can continue negotiating a wireless connection session.  Loveless Espiner’s story is complaining that by broadcasting this SSID in the probe request to the public airwaves, you are essentially giving away what SSID to hackers who can potentially endanger you with Wi-Fi evil twins that pose as legitimate hotspots or peers so that you will establish a Wireless Ethernet connection to them.  The problem with this train of thought is that if you suppressed all SSID broadcasts, you are essentially breaking a fundamental mechanism in 802.11 wireless networking.  Taking this to its logical conclusion, we may as well rip out our wireless LAN adapters from our PCs and be done with it.

Just the act of using a wireless hotspot itself will put you in even more danger because the hacker doesn’t even need to bother putting up an evil twin because he can attack your computer in that hotspot because he is on the same LAN as you.  If the hacker did want to put up an evil twin to perform man-in-the-middle attacks on you, he wouldn’t bother with your "vulnerable" probe requests because the hotspot access point will already have been announcing it 10 times a second.  If you really think about it, it’s even more dangerous to hook up a broadband connection because you’re not just vulnerable to hackers within a 150 foot radius but to hackers all over the world!

But is this really the end of the world?  Of course not!  That’s what firewalls are for and just about any firewall will do, even the free built-in Windows XP firewall.  Corporate IT departments can easily enable the Windows XP SP2 firewall on every PC they own by setting firewall policies in Active Directory Group Policy.  Once users have a personal firewall enabled, they will be relatively safe when they connect to any public unsecured network whether it was a wireless hotspot or wired broadband connection.

If anyone is paranoid about ad-hoc wireless LAN connections, they can simply set their wireless supplicant software to only connect to "infrastructure networks."  Any IT administrator can do the same thing globally to all Windows PCs in their domain by configuring the wireless security settings in their Windows 2003 Active Directory Group Policy.  The dangers of SSID probe requests that Loveless Espiner’s story describes is nothing new and classifying this feature as a vulnerability on Microsoft or any other wireless supplicant software maker is just plain silly.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 75 Talkback(s)
Learn the definition of "ad hoc" when applied to networking.
You should quit while you're behind. George is absolutely right. The term "ad hoc" has a definite meaning when referring to networking. Look it up.... (Read the rest)
Posted by: Furiousrog Posted on: 01/26/06 You are currently: a Guest | | Terms of Use
Good One / Infrastructure Only  D. T. Schmitz | 01/19/06
Instead of ssl  balsover | 01/19/06
Compression  D. T. Schmitz | 01/19/06
One More Nattering Point  D. T. Schmitz | 01/19/06
Typo  D. T. Schmitz | 01/19/06
I am familiar with the protocols.  balsover | 01/19/06
Elaborate  D. T. Schmitz | 01/19/06
VPN and SSL hacking...  cburgess-iPALADIN | 01/19/06
VPN hacking / What  D. T. Schmitz | 01/19/06
He doesn't know what he's talking about  george_ou | 01/19/06
Thanks George  D. T. Schmitz | 01/20/06
Not so fast George  cburgess-iPALADIN | 01/20/06
Just stop. You don't even understand basic cryptography.  george_ou | 01/20/06
RSA is very obsolete  cburgess-iPALADIN | 01/20/06
You don't even know what RSA is  george_ou | 01/20/06
Thanks, George  Real World | 01/19/06
OEMs could help...  dragontiger | 01/19/06
Very well said...but...  JJ_z | 01/19/06
Every one at fault here  george_ou | 01/19/06
Good Article George, But What About Avg Joe Home User?  itanalyst | 01/19/06
The router vendors should take some blame too  Michael Kelly | 01/19/06
A little off topic but good question  george_ou | 01/19/06
Have you ever heard of a LAN Party?  cburgess-iPALADIN | 01/19/06
Have you been to a LAN party? You don't use wireless for gaming  george_ou | 01/19/06
Respectable gamers?  cburgess-iPALADIN | 01/20/06
Being blind and ignorant of basic crypto technology is worse  george_ou | 01/20/06
Asymmetric Numerical Dynamics...  cburgess-iPALADIN | 01/21/06
Stop cutting and pasting things you don't understand  george_ou | 01/21/06
George; why the insults?  nizuse | 01/21/06
No insults, just calling it like it is  george_ou | 01/22/06
You teach an IT Security course?  itanal | 01/20/06
Not Isolated to Home Users...  cburgess-iPALADIN | 01/22/06
Who's "clueless"?  george_ou | 01/24/06
I don't think you know the definition of "ad hoc".  el1jones | 01/25/06
This isn't english class, it's WLANs  george_ou | 01/25/06
Learn the definition of "ad hoc" when applied to networking.  Furiousrog | 01/26/06
One small thing to point out  Sabz5150 | 01/19/06
It's not a flaw  george_ou | 01/19/06
MS thought the same with WMF format...  cburgess-iPALADIN | 01/19/06
No, better usage of existing protocols sorely needed  george_ou | 01/19/06
Please give us a break  Richard Flude | 01/19/06
So what?  george_ou | 01/19/06
Time to throw away the shovel and  Richard Flude | 01/20/06
And what is the difference?  george_ou | 01/20/06
You still don't get it  Richard Flude | 01/21/06
Nope, no problems  george_ou | 01/21/06
Great Link  Richard Flude | 01/22/06
Knoppix Hacks / Hack #44  D. T. Schmitz | 01/19/06
Ou wee! credibility = 0  Reverend MacFellow | 01/19/06
This may not be a "vulnerability" but it is a big problem - here's why.  nicholasmiller | 01/20/06
You're right about the shameless self promotion  george_ou | 01/20/06
I respectfully disagree  nicholasmiller | 01/20/06
And you think this is a good PR strategy?  george_ou | 01/20/06
You know what they say about PR  nicholasmiller | 01/20/06
I didn't fault you for selling a product  george_ou | 01/20/06
SP2 doesn't fix the security issue  cburgess-iPALADIN | 01/22/06
Bad definition of Vulnerability  rpmyers1 | 01/20/06
WMF *was* a really bad design from Win3.x  george_ou | 01/20/06
Design  rpmyers1 | 01/20/06
It's "lame", get over it.  george_ou | 01/20/06
rpmyers1 you're right  Richard Flude | 01/20/06
I stand by my position on this "lame" advisory  george_ou | 01/20/06
usability vs security  barsteward | 01/20/06
And what's your point?  george_ou | 01/20/06
the point is..  barsteward | 01/20/06
The point is that it's lame  george_ou | 01/20/06
Red flag waving  rmerts@... | 01/20/06
the point....  barsteward | 01/21/06
the point 2...  keitme | 01/21/06
Security Nonsense  X41 | 01/22/06
Yes the method is lame.  Hrothgar - PCLinuxOS User | 01/25/06
and before you start  Hrothgar - PCLinuxOS User | 01/25/06
This is just getting weirder and weirder  george_ou | 01/26/06
Dude what happened to the article?  spinits | 01/22/06
Try reading before you reply george  Hrothgar - PCLinuxOS User | 01/26/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    Click Here