Slashdot Mirror


Windows Wireless Networking Flaw Identified

An anonymous reader writes "Washingtonpost.com is reporting from the 2nd annual Shmoocon hacker conference about the release of a previously undocumented vulnerability in Windows. The flaw takes advantage of a feature on Windows laptops that have wireless cards built-in. Security researcher Mark Loveless found that Windows laptops which cannot find a wireless connection are configured to broadcast the name of the last SSID they associated with. They assign themselves an ad-hoc 'link local' (think 169.254.x.x.) address, and an attacker can configure his machine to broadcast an SSID of the same name. Thus, the attacker associates with that 'network' and communicates directly with the victim's machine. The funny part from the Post blog entry is that Microsoft helped author the RFC for link local."

1 of 225 comments (clear)

  1. Time by MBHkewl · · Score: 0, Offtopic

    I guess being "loveless" gave "Mark Loveless" all the time in world, aih? Heh, poor nerd..
    Oh, wait...

    --
    Mod points are a dangerous tool. Abuse them wisely.