Welcome!

Mobile IoT Authors: Liz McMillan, Elizabeth White, Pat Romanski, Janakiram MSV, Shelly Palmer

Related Topics: Mobile IoT

Mobile IoT: Article

Drive-by Hacking?

Drive-by Hacking?

How can your corporate network possibly be susceptible to drive-by hacking if your IS department hasn't set up or authorized any wireless LANs? Easily! A significant number of employees are setting them up on corporate campuses...without authorization. Read on for tips on how to protect your company.

To define "drive-by hacking," let's first define a related term, "war driving." War driving is a popular hacker slang term for the act of roaming around (generally in a car), sniffing out wireless networks using a laptop and some necessary peripherals. Drive-by hacking is the crime of then gaining unauthorized access to a wireless network that has been discovered.

There are no solid numbers on frequency of occurrences of drive-by hacking; we aren't likely to see any. According to Scott Crenshaw, CEO, NTRU, "People who are attacked have every incentive to keep the information quiet, for internal reasons, for credibility with shareholders, and especially for credibility with customers and business partners."

Highly confidential partner and customer data entrusted to an enterprise is exposed during a wireless break-in. Financial institutions are prime targets and may represent the only public cases we are likely to hear of.

Don't think you're not a target just because you're not a bank. If you have a wireless 802.11b network you are a potential target to those seeking free Internet access. Worse yet you could be an entry point to the Internet for those who want to hack other networks while covering their tracks and getting away scot-free ­ meaning their attacks will be traced back to you.

Prevalent Insecurity
"We did a survey in 2001 of several hundred clients (which tend to be larger companies)," says John Pescatore, research director for Internet security, Gartner Inc. "We asked whether they were planning on buying 802.11b wireless LAN systems, and based on our research only 20% of them had plans to do so in 2001. But our estimate was that 60% of them already had wireless LANs in use within their company. So while only 20% of them were even talking about planning to buy them, we think that for close to two-thirds of them, their users had already gone out and deployed wireless LANs without going through the procurement system.

"A second related number is based on an informal survey we did of our clients and, of the ones using wireless LANs already, 60% hadn't even turned on the basic WEP level of security. They are basically just using it out of the box with no security turned on." So a resultant figure of 36% is arrived at, or about one third of all companies surveyed, that have WLANs running with no security at all.

Profiling the War Driver
Who gets involved in war driving? "There is a category of people who do this sort of thing who are not criminals, strictly speaking. They are what you might call Œtourists.' There is another element in which the person is an industrial spy or someone who does have criminal intent. For them it's just another way of getting on the network, one that may be easier than trying to break in through an Internet connection, a phone line, or by physically jacking into the network," says Scott Blake, VP of information security, BindView Corporation.

Motives
Once on the network, hackers can do anything they would with any other type of network entry. In this case, they also get free wireless broadband to the Internet. Other rewards include the challenge of the hack itself, corporate espionage, data theft, credit card theft, and data destruction. Some drive-by hackers will attempt to gain entry to your network in order to hack other networks, assured that their tracks are covered since the last traceable network entity will be your wireless network, which gave them access without asking that they even be identified.

Where the Legal Risks Lie ­ for the Hacker and for You
When hackers are caught tapping into a network protected by WEP it's definitely a computer crime, according to Chris Wysopal, director of R&D, @stake. But how do you catch them? If they establish a pattern of attack (against the same network and from the same location) @stake has services that can determine the physical location of the attacker. If WEP security isn't turned on, however, drive-by hacking may not be illegal, as the court system has not approached the issue of whether hackers should know that an open network is not necessarily a public one that is freely available.

So Simple a 'Script Kiddie' Can Do It
Why are even the less sophisticated hackers (referred to as "script kiddies") able to hack your wireless LAN? According to Crenshaw, of NTRU, "The development cycles for new technologies are several years, and the attacks we're seeing right now are on technology that was developed 3­5 years ago."

Earlier WLAN technologies weren't designed to be terribly secure and hackers and script kiddies alike have had ample time to figure out their security holes, not that they needed it. All you really need to perform a drive-by are a laptop, an 802.11 wireless LAN card, a directional antenna, and some software. A cylindrical potato chip can, used for its shape as the antenna, can boost a signal by up to 15 decibels, greatly expanding this setup's capability of finding wireless LANs.

There are numerous freely available choices in software for use in discovering WLANs. NetStumbler, AirSnort, and WepCrack are just three of the popular choices. Why is such software allowed on the market? Because the hackers can claim the programs are there just to test networks to see if they are vulnerable. There's no crime in that.

As Matthew Caldwell, chief security officer and co-founder, GuardedNet, puts it, "Listening to the airwaves to see who has an unsecured wireless network in the area is a passive activity, as is listening in to enough network traffic to gain the key to a secured network. What is against the law is trying to use that knowledge to log onto these systems without authorization."

It's Not Only Rogue WLAN Setups That Are Vulnerable
According to Dave Juitt, CTO, Bluesocket, "Enterprise wireless networks are often thought of as a cable replacement for their wired counterparts. There's an educational component that should go along with deploying a WLAN since these networks are a different animal. For starters, you are broadcasting your network outside of your building walls. You have no idea where your packets are flying off to."

Additionally many network admins find WEP management to be difficult at best and don't use it.

Laying Out the Problem Technically...
WEP or no WEP, the 802.11 standard was never designed for broad campus, highly confidential, or mission-critical uses because it is not that secure, nor was it designed to be. According to Dr. John McEachen, Department of Electrical and Computer Engineering, Naval Postgraduate School:

Compared to wireless telecommunications standards, the IEEE 802.11 standard is very simple and straightforward ­ which is what the IEEE 802.11 subcommittee has hoped for to encourage vendor interest. Consequently, it's pretty easy for someone who is technically savvy to go in and see how an IEEE 802.11 network is supposed to respond to certain signals/messages. The downside is that hackers can use this to their advantage to insert certain signals to get the response they want as well, such as "turn off."

Although this may seem trivial, another barrier of significance is the cost of the standard itself. The IEEE 802.11 standard is free on the Internet (http://standards.ieee.org/getieee802/download/802.11-1999.pdf). Compare this to some of the wireless telecommunications standards such as IS-95, IS-136, Mobitex, and UMTS, which cost anywhere from $500 to thousands. (An interesting exception is CDMA2000, which is being given away for free on an experimental basis ­ clearly they feel some economic pressure from 802.11).

Wireless networks broadcast their IDs, known as the Service Set Identifier ­ the Service Set ID or SSID ­ which identifies a WLAN as being available and in the area. So the WLAN will appear in the list of available wireless networks on the laptop being used. These WLANs are open to anyone within range. Almost any corporation with a wireless 802.11 LAN is a target. These systems are generally sold with the security turned off by default because it makes them easier to set up (improving the sales of the hardware in the first place). Because they are easily set up, they can be installed by end users and not just IT professionals.

In most cases the appropriate security questions are never asked. Wireless networking hardware is often configured to automatically hand out Internet Protocol (IP) addresses and user identifiers, right out of the box, to any user device joining the network. In this mode, the device gives out IP addresses as a DHCP server (Dynamic Host Configuration Protocol), meaning they are automatically assigned, just as many dial-up Internet customers are automatically assigned an IP address. By using this identifier, you can join the network and get access to all the services without confronting any authentication process.

At the End of the Day...
You can secure your wireless network appropriately by installing a wireless gateway or VPN. 3COM and others have also addressed the 802.11 holes with new security measures in new 802.11 hardware.

Solutions
Here are some solutions from Matt Caldwell, of GuardedNet, and Al Potter, manager of Network Security Labs, ICSA Labs:

  • Use application-layer encryption methods like Secure Sockets Layer.
  • Use a TCP/IP layer encryption like IPSec.
  • Encrypt all traffic that crosses the wireless network.
  • Use secure authentication. Require users to authenticate before their traffic is accepted or gatewayed over to the wired LAN.
  • Use appropriate antennas. Don't boost your signal needlessly.
  • Consider shielding external walls near access points.
  • Power down wireless access points when not in use.
  • Turn on WEP.
  • And take a walk through company property actually looking for wireless access points so you know whether you have WLANs attached to your network.

More Stories By David Geer

David Geer is a contributing writer to WBT, a journalist, and a computer technician. He graduated from Lake Erie College in 1993 with a BA in psychology and has worked in the computer industry and in the media since 1998.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
SYS-CON Events announced today that Datera, that offers a radically new data management architecture, has been named "Exhibitor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Datera is transforming the traditional datacenter model through modern cloud simplicity. The technology industry is at another major inflection point. The rise of mobile, the Internet of Things, data storage and Big...
"DX encompasses the continuing technology revolution, and is addressing society's most important issues throughout the entire $78 trillion 21st-century global economy," said Roger Strukhoff, Conference Chair. "DX World Expo has organized these issues along 10 tracks with more than 150 of the world's top speakers coming to Istanbul to help change the world."
SYS-CON Events announced today that DXWorldExpo has been named “Global Sponsor” of SYS-CON's 21st International Cloud Expo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Digital Transformation is the key issue driving the global enterprise IT business. Digital Transformation is most prominent among Global 2000 enterprises and government institutions.
While the focus and objectives of IoT initiatives are many and diverse, they all share a few common attributes, and one of those is the network. Commonly, that network includes the Internet, over which there isn't any real control for performance and availability. Or is there? The current state of the art for Big Data analytics, as applied to network telemetry, offers new opportunities for improving and assuring operational integrity. In his session at @ThingsExpo, Jim Frey, Vice President of S...
"We provide IoT solutions. We provide the most compatible solutions for many applications. Our solutions are industry agnostic and also protocol agnostic," explained Richard Han, Head of Sales and Marketing and Engineering at Systena America, in this SYS-CON.tv interview at @ThingsExpo, held June 6-8, 2017, at the Javits Center in New York City, NY.
"We are focused on SAP running in the clouds, to make this super easy because we believe in the tremendous value of those powerful worlds - SAP and the cloud," explained Frank Stienhans, CTO of Ocean9, Inc., in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
DX World EXPO, LLC., a Lighthouse Point, Florida-based startup trade show producer and the creator of "DXWorldEXPO® - Digital Transformation Conference & Expo" has announced its executive management team. The team is headed by Levent Selamoglu, who has been named CEO. "Now is the time for a truly global DX event, to bring together the leading minds from the technology world in a conversation about Digital Transformation," he said in making the announcement.
"We've been engaging with a lot of customers including Panasonic, we've been involved with Cisco and now we're working with the U.S. government - the Department of Homeland Security," explained Peter Jung, Chief Product Officer at Pulzze Systems, in this SYS-CON.tv interview at @ThingsExpo, held June 6-8, 2017, at the Javits Center in New York City, NY.
The financial services market is one of the most data-driven industries in the world, yet it’s bogged down by legacy CPU technologies that simply can’t keep up with the task of querying and visualizing billions of records. In his session at 20th Cloud Expo, Karthik Lalithraj, a Principal Solutions Architect at Kinetica, discussed how the advent of advanced in-database analytics on the GPU makes it possible to run sophisticated data science workloads on the same database that is housing the rich...
SYS-CON Events announced today that Massive Networks will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Massive Networks mission is simple. To help your business operate seamlessly with fast, reliable, and secure internet and network solutions. Improve your customer's experience with outstanding connections to your cloud.
Everything run by electricity will eventually be connected to the Internet. Get ahead of the Internet of Things revolution and join Akvelon expert and IoT industry leader, Sergey Grebnov, in his session at @ThingsExpo, for an educational dive into the world of managing your home, workplace and all the devices they contain with the power of machine-based AI and intelligent Bot services for a completely streamlined experience.
Internet of @ThingsExpo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 21st Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The Internet of Things (IoT) is the most profound change in personal and enterprise IT since the creation of the Worldwide Web more than 20 years ago. All major researchers estimate there will be tens of billions devic...
"The Striim platform is a full end-to-end streaming integration and analytics platform that is middleware that covers a lot of different use cases," explained Steve Wilkes, Founder and CTO at Striim, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
SYS-CON Events announced today that Calligo, an innovative cloud service provider offering mid-sized companies the highest levels of data privacy and security, has been named "Bronze Sponsor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Calligo offers unparalleled application performance guarantees, commercial flexibility and a personalised support service from its globally located cloud plat...
"MobiDev is a Ukraine-based software development company. We do mobile development, and we're specialists in that. But we do full stack software development for entrepreneurs, for emerging companies, and for enterprise ventures," explained Alan Winters, U.S. Head of Business Development at MobiDev, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
SYS-CON Events announced today that DXWorldExpo has been named “Global Sponsor” of SYS-CON's 21st International Cloud Expo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Digital Transformation is the key issue driving the global enterprise IT business. Digital Transformation is most prominent among Global 2000 enterprises and government institutions.
In his opening keynote at 20th Cloud Expo, Michael Maximilien, Research Scientist, Architect, and Engineer at IBM, discussed the full potential of the cloud and social data requires artificial intelligence. By mixing Cloud Foundry and the rich set of Watson services, IBM's Bluemix is the best cloud operating system for enterprises today, providing rapid development and deployment of applications that can take advantage of the rich catalog of Watson services to help drive insights from the vast t...
SYS-CON Events announced today that EnterpriseTech has been named “Media Sponsor” of SYS-CON's 21st International Cloud Expo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. EnterpriseTech is a professional resource for news and intelligence covering the migration of high-end technologies into the enterprise and business-IT industry, with a special focus on high-tech solutions in new product development, workload management, increased effic...
SYS-CON Events announced today that Massive Networks, that helps your business operate seamlessly with fast, reliable, and secure internet and network solutions, has been named "Exhibitor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. As a premier telecommunications provider, Massive Networks is headquartered out of Louisville, Colorado. With years of experience under their belt, their team of...
SYS-CON Events announced today that Cloud Academy named "Bronze Sponsor" of 21st International Cloud Expo which will take place October 31 - November 2, 2017 at the Santa Clara Convention Center in Santa Clara, CA. Cloud Academy is the industry’s most innovative, vendor-neutral cloud technology training platform. Cloud Academy provides continuous learning solutions for individuals and enterprise teams for Amazon Web Services, Microsoft Azure, Google Cloud Platform, and the most popular cloud com...