Windows 2000/XP Vulnerability for Wireless Laptops

WashingtonPost.com is reporting that a new vulnerability was made public at ShmooCon yesterday for Windows 2000/XP laptops that have integrated wireless adapters.

For those who are unfamiliar with how Windows handles network (wired or wireless) connections, I’ll give a brief rundown.  Assuming DHCP is enabled on the network that you’re connecting to, your computer will be assigned an IP address automatically.  If your computer cannot find the DHCP server, then Windows will instead assign you a local/private IP address of 169.254.*.*.  This is where the vulnerability comes into play.

If you are trying to connect to a wireless network and the DHCP server is not found, then Windows will assign you the private IP as noted above.  At the same time, however, Windows will also tell your laptop to allow adhoc (PC-to-PC) wireless connections and to broadcast the SSID of the last wireless network that you connected to.

This means that regardless of your network’s security, anyone could come along and connect to that SSID in ad-hoc mode.  Since your laptop is not on the network, the hacker would actually be connected straight to your computer.

So if you’ve got a secure wireless network, always make sure that your laptop is actually on the network.  Otherwise, the security is completely pointless because of this vulnerability.  Hopefully we’ll see a patch for this in next month’s Windows security updates, but I’m not holding my breath.

Source: WashingtonPost.com

If you like this post, please share it with someone...
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google
  • blogmarks
  • BlogMemes
  • Furl
  • Live
  • NewsVine
  • SphereIt
  • Spurl
  • StumbleUpon
  • Technorati

Get Mobility Site via Email

You can also participate in other conversation in our active forums with 200,000 other Members. It only takes 2 minutes to sign up one time for free in the forums. Thanks for reading.

Leave a Reply

You can use these XHTML tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>

You Should Also Check Out These Posts:

More Active Posts:

About Mobilitysite

Mobilitysite.com is a site covering Mobility News, Reviews, and Discussion. Our coverage focuses on Windows Mobile Phones and PDAs, but extends on past that as well. Tablet PC, UMPC, and Personal Media Players like the Zune and iPod are loosely covered as well. To learn more about Mobilitysite and/or Aximsite, read here. Also take time to register in our forums too. There is a wealth of information to be found inside and registering yourself in the forums also registers you with the blog portion of the site.

Mobilitysite - Aximsite - Hard Reset Guide - AT&T Tilt Site - Got Zune

Contact Us - About Us - Privacy Policy - Advertise - News Archives - Forum Archives - Donate - Top