[00:00.900 --> 00:01.700] All right. [00:02.520 --> 00:04.560] We will get this started. [00:04.920 --> 00:05.460] There we go. [00:05.600 --> 00:05.940] Thank you. [00:06.740 --> 00:15.300] This is the future of wireless pen-testing with Dragorn, who, if you've been to previous cons, seems to be at every one of them as well. [00:17.040 --> 00:18.140] He's number 39. [00:18.920 --> 00:24.640] Thorn, the gentleman in the middle, will be known as 45 from this moment forward. [00:24.640 --> 00:30.980] And RenderMan, who is known as number 112 or guy in the fedora. [00:32.760 --> 00:33.600] You guys ready? [00:34.620 --> 00:35.460] Take it away. [00:36.380 --> 00:36.620] All righty. [00:38.000 --> 00:38.800] Hi, everybody. [00:39.140 --> 00:39.940] Glad you could make it today. [00:41.580 --> 00:43.220] Do you want to make your customary comment? [00:43.740 --> 00:44.160] No. [00:44.260 --> 00:44.440] No? [00:44.540 --> 00:44.700] Okay. [00:44.700 --> 00:45.840] There's just a lot of you out there. [00:46.220 --> 00:47.720] And Mike had noticed that before. [00:48.920 --> 00:53.160] We're going to talk today about the future wireless penetration testing. [00:53.380 --> 01:03.580] But obviously, to talk about the future of it, we've got to kind of take a picture of what we did in the past and what we're currently at. [01:04.040 --> 01:09.760] So I'm going to talk first about the history just a little bit and then we're going to bounce around on different topics for today. [01:11.860 --> 01:20.480] Back in the late 1990s, right around 2000, a lot of technology started to come together with the wireless stuff. [01:20.480 --> 01:30.600] The big push came when, in about 2001, 802.11 got extremely affordable by everybody, at the consumer level, at least. [01:31.120 --> 01:35.280] And at that point, wireless pen-testing really started to take off. [01:37.380 --> 01:47.460] The first kind of programs that came out about it were from Pete Shipley had done an early script in San Francisco back in 2001. [01:48.200 --> 01:51.580] Net Stumbler was written also in 2001. [01:51.900 --> 01:56.440] And in late 2001, Dragorn wrote the first version of Kismet. [02:04.020 --> 02:06.000] Thank you for the many hours of entertainment. [02:08.680 --> 02:18.120] So, at that point, people started to become aware of this stuff being available and that it was kind of open and out there. [02:18.320 --> 02:20.960] And the whole thing really started to take off. [02:22.520 --> 02:26.340] I did my first war drive in about September 2001. [02:27.140 --> 02:30.200] And in five miles, I came up with about five networks. [02:30.780 --> 02:38.340] In comparison to that today, I think there's something on the order of about 300 networks in that same five miles. [02:45.020 --> 02:49.860] So, that kind of brings us up to today that we've got this big jump. [02:49.860 --> 02:50.880] It's out there. [02:51.100 --> 02:53.060] Everybody's starting to get involved in it. [02:53.760 --> 03:01.980] And we're going to talk about the rest of the panel or the session today is we're going to talk about what are we going to do in the future. [03:02.560 --> 03:05.660] So, with that, I'm going to turn it over to Dragorn. [03:08.300 --> 03:11.920] I figured we'd touch a little bit briefly on what Kismet will be doing in the future. [03:12.820 --> 03:18.320] The major rewrite has been in works for a little over two years since just before the last HOPE. [03:18.880 --> 03:22.300] I wish I could say it was done for release today, but I can't. [03:22.420 --> 03:24.840] But you can get it from Subversion in the state it's in currently. [03:25.360 --> 03:30.140] The main things useful for pen-testing that will be in that release is Kismet finally supports plug-ins. [03:30.460 --> 03:34.580] So, every time I say, I'm not going to put that in there, someone else can with a plug-in now. [03:35.300 --> 03:37.160] You can do injection through it. [03:37.620 --> 03:44.900] There will be smarter drones so that you can treat remote captures like a Linksys connected to a Windows machine as a local card. [03:46.420 --> 03:49.480] And plug-ins can do anything that Kismet can do now. [03:49.620 --> 03:51.180] So, you can add new GPS systems. [03:51.580 --> 03:55.160] There might even be a plug-in to handle Bluetooth built into the system. [03:57.140 --> 03:59.440] And we'll take some more questions on that after. [03:59.860 --> 04:02.880] But I'll turn it over to RenderMan for some 802.11 stuff. [04:03.840 --> 04:04.280] Okay. [04:06.000 --> 04:11.800] Basically, with the future of wireless, there's a couple of different areas we're seeing as big. [04:12.340 --> 04:13.900] 802.11 is here to stay. [04:14.060 --> 04:15.400] We're not getting rid of it. [04:16.640 --> 04:18.420] Bluetooth is coming up big. [04:18.980 --> 04:20.780] That's going to be another huge thing in the future. [04:20.920 --> 04:21.620] And RFID. [04:21.880 --> 04:22.700] It's wireless. [04:23.080 --> 04:24.900] We're all going to have to deal with it at some point or another. [04:26.300 --> 04:28.300] Starting with the 802.11 stuff. [04:29.240 --> 04:34.080] 802.11i, the new wireless security spec coming out. [04:34.400 --> 04:35.980] Usually, everybody calls it WPA2. [04:36.080 --> 04:39.080] Even though that's not the actual ratified version. [04:40.300 --> 04:44.520] I don't know what the IEEE working groups are thinking on these things. [04:44.520 --> 04:45.960] But I don't know. [04:46.040 --> 04:50.220] I just see some severe problems with 802.11i coming out. [04:50.960 --> 05:02.160] Reason being is if you actually look through the spec, there's this wonderful little statement in there saying there's a function called the Michael countermeasure, message integrity check. [05:02.160 --> 05:15.920] Basically, if an access point running 802.11i receives two messages that have bad checksums on the packets, it will shut down the radio and recompute all the keys and renegotiate everything. [05:16.260 --> 05:18.280] It shuts down the radio for 60 seconds. [05:18.820 --> 05:29.800] When it does this, it sends out a deauthentication packet to all the clients saying, I'm going down because something went wrong and I'm recalculating things. [05:29.800 --> 05:41.760] Within the spec, there's this wonderful line that says, because we can't verify the authenticity of this deauthentication packet from the access point as being actually from the access point. [05:41.880 --> 05:43.020] We know it can be spoofed. [05:43.160 --> 05:48.460] We're just going to ignore it and continue trying to connect to that same SSID and MAC address. [05:49.460 --> 05:56.380] So, I send two packets to the radio with bad message integrity checks. [05:56.700 --> 05:58.240] The radio turns off. [05:58.940 --> 06:03.680] And now I can slide in my own access point with the same SSID and MAC address. [06:07.220 --> 06:09.420] This is going to be interesting. [06:10.820 --> 06:16.120] I don't know what the 802.11 groups in the IEEE are thinking with these things. [06:17.200 --> 06:24.940] They just don't seem to really be catching on that there are problems and they have the ability to address them when they're designing the specs. [06:25.600 --> 06:28.700] They just don't seem to be doing anything sane. [06:29.760 --> 06:30.560] Any thoughts? [06:30.560 --> 06:42.520] On a similar note, the 802.11 W spec is going to address finally some of the access point authentication measures to keep it from being so easy to knock everyone off the network. [06:42.720 --> 06:47.620] Except they don't address most of the management frames that you can use to knock people off the network. [06:49.160 --> 06:52.740] And even that, they're saying, is like two years away from being ratified. [06:52.740 --> 06:55.860] So, we're kind of stuck in the meantime here. [07:00.040 --> 07:07.520] And to add to that whole thing, too, is that a lot of stuff is getting unplugged and getting thrown out into the same spectrum. [07:08.560 --> 07:16.840] For instance, just something I learned last night is, I'm sure you're all aware of a lot of burglar alarms that are going wireless. [07:17.600 --> 07:20.960] A lot of those things are basically... and fire alarms. [07:21.140 --> 07:28.360] They're basically just kind of out there going, I'm not in an alarm state, and I'm not, I'm not, and then, oops, I'm in an alarm state. [07:30.940 --> 07:42.080] And that's not a big deal until you realize that some of their devices are directly actionable on the outside of the building. [07:42.220 --> 07:48.720] For instance, there are things that are known as Knox boxes that carry the keys to buildings. [07:49.060 --> 07:53.520] These are designed so the fire department can gain access to the building in case of an emergency. [07:53.780 --> 07:57.420] They usually see this on apartment buildings, a little FD logo on the thing. [07:57.420 --> 07:59.360] Yeah, they're usually a little triangle, that type of thing. [08:00.100 --> 08:18.260] But those things, if they get triggered off, will actually start to open on some alarm systems now, allowing anybody, hopefully the fire department, but if anybody has spoofed the alarm system, you can gain access to the building physically by the building has just handed you the key. [08:19.140 --> 08:23.600] Some of the bigger ones will actually give you blueprints, so you can have blueprints and a key. [08:24.980 --> 08:27.910] So there's a lot of things like that that are getting unplugged. [08:28.640 --> 08:45.880] So as things are changing and evolving with pen-testing in general, we're going strictly from kind of beyond the whole idea of the information into physical access to the buildings at the same time. [08:46.800 --> 08:57.360] People are just taking a lot of things and saying, well, it's real easy to unplug it, and they're not thinking about what the ramifications are as they go along. [08:57.760 --> 08:59.460] For instance, a security camera. [08:59.660 --> 09:05.380] So now you can check to make sure no one's in that part of the building before you unlock it. [09:06.320 --> 09:19.640] Yeah, cameras are a real good example because those things are completely unplugged, they're completely unsecure, and because they're based on the regular television signals, they're specifically not encrypted. [09:20.120 --> 09:29.280] So anybody, if you know what the frequency is for a given camera, can just tune into the camera and see what's going on up there. [09:30.760 --> 09:34.360] How many of you remember the opening scene from the movie Sneakers? [09:36.380 --> 09:42.040] For those of you who don't, basically they set off a smoke bomb inside of a bank in a safe deposit box. [09:42.200 --> 09:49.720] Smoke goes up, sets off the fire alarm, and automatically all the emergency fire doors open up, which allows the guys to run in the back. [09:50.120 --> 09:52.980] You know, security guard's there, alarm's going off, he doesn't know what to do. [09:53.180 --> 09:57.520] Gets a phone call saying, oh yeah, we've been having all sorts of problems with the alarm, it'll shut off in a minute. [09:57.520 --> 09:58.740] Oh, it does. [09:59.460 --> 10:00.960] But now, everybody's in. [10:01.300 --> 10:07.660] So, you can imagine a situation where, with this alarm system, you trigger it, oh, no fire. [10:07.880 --> 10:09.020] Trigger it, oh, no fire. [10:09.400 --> 10:13.820] You do this enough times, people are going to think, oh, something's busted, something's shorted, whatever. [10:14.480 --> 10:20.260] You trip it the next time, you just walk up and take the keys, because you know the fire department's probably not going to be called, because, oh, it's just an error. [10:25.030 --> 10:25.670] Now what else? [10:28.150 --> 10:28.950] Client attacks. [10:30.650 --> 10:34.710] How many of you run firewalls normally on your laptops when you're connected onto wireless? [10:36.930 --> 10:39.110] Okay, there should be a hell of a lot more hands than that. [10:40.950 --> 10:45.050] The people who couldn't see, that was probably about 10 to 15 percent raised their hands. [10:47.430 --> 11:00.510] New tools coming out, I know that there's going to be some interesting stuff coming out of DEFCON about 802.11 fuzzing, and attacks to drivers for wireless cards. [11:01.610 --> 11:06.870] For a long time, everybody's been focusing on attacking the access point, gaining access to the network that way. [11:07.310 --> 11:17.310] There's been more and more research coming out about attacking the clients themselves, and either getting them to come over to another access point, or just doing nasty things to their data. [11:19.250 --> 11:20.290] What are some of the tools? [11:21.610 --> 11:23.170] The evil twin... [11:23.170 --> 11:23.750] Oh, yeah. [11:25.450 --> 11:26.770] The evil twin concept. [11:28.910 --> 11:41.190] I think that there's going to be a lot more focus on getting access to those clients, because we've all seen the businessman that's in the airport doing his spreadsheets or whatever, and you never know who's on that flight next to you. [11:42.470 --> 11:43.270] Sometimes it's me. [11:44.770 --> 11:53.190] For anyone who's ever fired up a sniffer and noticed how many networks the Windows machines are probing for near you, how easy is it to create one of those networks? [11:54.770 --> 11:57.170] How likely is it that they have a firewall turned on? [11:57.830 --> 11:59.670] And according to this room, not very wrong. [12:01.490 --> 12:11.450] And it's really easy to just spoof something like Linksys, and all of a sudden you're an access point that you think you're connecting to, and it's actually him. [12:12.650 --> 12:13.710] How many people... [12:14.530 --> 12:20.910] I'm not saying anybody here does it, because it would be a felony, but how many people do we know that take advantage of the Linksys global network? [12:22.410 --> 12:26.450] How do you know that is actually a Linksys access point? [12:26.450 --> 12:30.110] and not just somebody doing man in the middle or whatever? [12:32.070 --> 12:34.130] Because you could never spoof that, right? [12:43.030 --> 12:45.050] Quick question, just quick hands up. [12:45.410 --> 12:51.050] How many of you on your access points at work or home have the SSID broadcast turned off? [12:53.050 --> 12:53.450] Why? [12:57.420 --> 12:58.960] Oh, nobody can see you. [13:02.600 --> 13:05.380] There's just so much bad information out there. [13:05.820 --> 13:10.400] And I mean, we were guilty of it to a certain degree, because for the longest time we were saying turn off SSID broadcast. [13:11.940 --> 13:18.540] But there's so many IT people out there that will read, you know, a book that will say you do all of these things and you're going to be fine. [13:19.040 --> 13:24.740] Well, half the time, if you turn off the SSID broadcast, you're going to have more problems connecting than if you don't. [13:26.140 --> 13:31.820] So, there's just going to be more and more problems with people just not understanding the instructions. [13:34.440 --> 13:35.920] RTFM goes a long way, believe me. [13:37.460 --> 13:49.460] Towards the end of replicating networks, the Karma tool is a modification of the Mad Wi-Fi drivers for Etheros, which will automatically create a network for every probe request it sees. [13:50.540 --> 13:52.520] You don't even have to clone the network anymore. [13:52.740 --> 13:54.780] It will just bring up the access. [13:55.000 --> 13:58.980] It will automatically respond to any probe request and attach them to your network. [14:03.690 --> 14:07.310] Another thing in the realm of client vulnerabilities is firmware vulnerabilities. [14:07.310 --> 14:16.850] I haven't seen any yet, but an Etheros card is basically an ARM 7 chip running a fairly complex piece of software in the firmware. [14:17.710 --> 14:21.090] If you ever find a bug in that firmware, how often do you update that? [14:23.410 --> 14:25.750] I haven't seen many firmware updates come out. [14:25.990 --> 14:31.030] If there's a bug in that, you've got executability on a device attached to your PCI bus. [14:31.030 --> 14:35.590] That means you've got a device that you control attached to someone's memory system. [14:36.710 --> 14:38.330] Forget the operating system controls. [14:38.570 --> 14:40.290] You can scan their memory right out from underneath it. [14:40.370 --> 14:42.130] If anyone ever exploits the firmware. [14:43.190 --> 14:43.910] Who knows? [14:55.980 --> 15:04.220] In regards to some of the stuff we've talked about a few minutes ago, a lot of this stuff is all taking part in the same spectrum, too. [15:04.220 --> 15:06.440] You've got cameras like the X10s. [15:06.940 --> 15:09.740] I mean, those things are all over the place. [15:10.380 --> 15:16.160] You've got, obviously, 802.11 B and G in the same space. [15:16.920 --> 15:20.820] And some of these things are coordinated together in some of them, such as me and G. [15:21.060 --> 15:22.020] Some of them are not. [15:22.420 --> 15:29.220] You put in a camera and an access point in close proximity, you get problems. [15:30.000 --> 15:34.440] Basically, the whole spectrum in a lot of places is really getting overcrowded. [15:36.100 --> 15:51.140] It's not uncommon in some places to actually have someone kind of be an ad hoc coordinator for the spectrum in their building, just because it's getting so crowded or in the neighborhood, because it's getting so crowded. [15:53.480 --> 15:55.460] And it's only going to get worse, people. [15:56.660 --> 16:11.960] So one of the things to do with the pen-testing is you're going to be taking kind of a look at the whole gamut in a given spectrum area, as to what kind of things are in there, what's vulnerable, what isn't. [16:12.580 --> 16:14.140] It's not just going to be B. [16:14.340 --> 16:16.040] It's not going to just be G. [16:16.340 --> 16:18.060] It's going to be things like cameras. [16:18.300 --> 16:24.480] It's going to be things like burglar alarms, which are also in the 2.4 megahertz spectrum, or gigahertz spectrum. [16:28.510 --> 16:32.290] It also means that you'll have to consider things that are no longer within that spectrum. [16:33.990 --> 16:39.050] Ubiquity Networks now has a 900 megahertz, a Theros-based 802.11 card. [16:39.170 --> 16:40.190] It's not truly 802.11. [16:41.850 --> 16:47.710] Most IDS systems that are detecting if someone's plugged an unauthorized access point into their network, they're not looking at 900. [16:48.650 --> 16:51.250] Bluetooth access points, they exist. [16:51.430 --> 16:53.670] I believe Kensington makes one or Belkin makes one. [16:54.310 --> 17:02.350] Most IDS systems aren't looking for a Bluetooth access point, but it still means it's there and that you can connect to it and possibly gain access to the network via that. [17:04.510 --> 17:09.970] Speaking about Bluetooth, just a show of hands, how many people have Bluetooth telephones on them today? [17:11.770 --> 17:12.290] Okay. [17:13.730 --> 17:18.470] And I've got one, but I keep the Bluetooth off on a lot of the functions. [17:19.990 --> 17:24.550] Just of that, how many of you are running in discoverable mode? [17:25.770 --> 17:27.290] That would be 37. [17:29.330 --> 17:33.130] For the record, one person in the back raised their hand that I could see. [17:33.130 --> 17:33.510] Yeah. [17:35.310 --> 17:38.310] How many know that you have it in discoverable mode? [17:38.430 --> 17:39.530] That may be, okay, it's one. [17:39.970 --> 17:42.210] This is not the device you're looking for. [17:42.510 --> 17:43.750] Blackberry 8700. [17:45.290 --> 17:45.830] Shoned. [17:47.310 --> 17:49.250] Is there a Brian Ventura in the audience? [17:51.370 --> 17:52.730] Well, there is. [17:53.110 --> 18:00.130] I mean, this is just a quick sample of a group of people who should know exactly what their devices are doing. [18:01.710 --> 18:10.530] Now, how many executives in that are going to fully understand the problems with leaving their Bluetooth phone enabled? [18:11.210 --> 18:16.170] This is something that I think is going to really turn around and bite as more and more data ends up on these devices. [18:16.630 --> 18:21.470] You know, if they're walking around and they keep discoverability on because, oh, it makes their headset easier to use. [18:22.530 --> 18:25.870] You know, they could be exposing all sorts of fun things. [18:26.290 --> 18:26.690] Yeah. [18:26.850 --> 18:36.650] And I mean, and not even connected to the corporate network, but all sorts of, like, on Windows handheld devices, you've got Outlooks, you've got all their emails and all this other stuff. [18:38.230 --> 18:43.410] Just, the problem is no longer just contained within the building that you're having to control. [18:43.530 --> 18:46.830] You're not going to worry about all these guys running around, around the world, signing contracts. [18:47.090 --> 18:52.790] And you've got to chase after them and hold them down when they're in the office and beat it into them that there's a problem here. [18:52.950 --> 18:54.290] You might want to take care of this. [18:56.030 --> 18:56.430] Yeah. [18:56.650 --> 19:00.910] And a lot of these things, too, this, you know, just the physical security of the devices. [19:01.450 --> 19:06.490] You know, let's face it, how many people have put things like passwords on PDAs? [19:08.130 --> 19:13.850] You know, you lose the PDA, you've just given to whoever finds it your list of all your passwords. [19:15.170 --> 19:25.350] And if a PDA talks via Bluetooth and Wi-Fi to other devices around it, are you creating bridging that you never even suspected? [19:25.970 --> 19:28.070] Maybe not, but there's a possibility. [19:28.310 --> 19:40.950] And again, if you're going to be doing any kind of penetration testing, you've got to be aware of these things and at least be thinking along the lines of, can we go from device A to device B to device C and into the infrastructure? [19:42.750 --> 19:48.290] Or can you go into device A and leave something that when they connect to the infrastructure gets you in? [19:48.910 --> 19:51.210] This would be what we would consider a device B. [19:52.950 --> 19:55.510] This teddy bear has an access point built into him. [19:56.910 --> 19:59.870] How many people would it be rogue hunting for a teddy bear? [20:01.690 --> 20:02.670] Probably not a lot. [20:04.110 --> 20:09.690] One thing with the 802.11 stuff you're going to see is access points are getting smaller and smaller. [20:10.350 --> 20:12.850] You're not dealing with a big Linksys box anymore. [20:14.150 --> 20:17.790] Thorne here says there's a D-Link one that's like the size of a USB stick. [20:18.870 --> 20:19.810] It's a little bit bigger. [20:19.910 --> 20:21.070] It's about an inch and a half square. [20:22.410 --> 20:24.210] But it's a great little device. [20:24.330 --> 20:26.570] I carry one around for going to different places. [20:26.810 --> 20:29.170] And it's literally about this big. [20:29.710 --> 20:33.750] You won't notice it as an access point unless you know what you're looking for. [20:33.750 --> 20:36.170] A big pair of rabbit ears sitting on top of a filing cabinet. [20:36.430 --> 20:37.150] Kind of easy to spot. [20:37.410 --> 20:39.250] But something like this plugged into the back of a PC. [20:40.750 --> 20:43.290] You're going to have to start searching really high and low for that stuff. [20:44.070 --> 20:48.070] Or a battery pack and delivery of flowers to the secretary. [20:48.870 --> 20:49.990] Dude, don't give away all my secrets. [20:55.360 --> 20:56.680] How many people have Bluetooth headsets? [20:59.220 --> 21:03.080] How many people have the Bluetooth pin of four zeros? [21:03.560 --> 21:04.160] Or five zeros? [21:05.660 --> 21:07.540] How many of you wear them all the time? [21:09.080 --> 21:16.460] How many of you have seen people on buses, subways, standing on a street corner looking absolutely schizophrenic? [21:16.680 --> 21:18.020] You know, talking to themselves. [21:18.440 --> 21:21.020] You can probably go up front of the hotel in here and see that. [21:22.640 --> 21:24.540] Default pins on all these things. [21:24.920 --> 21:25.980] And it's always four zeros. [21:26.880 --> 21:27.880] No matter what model. [21:28.020 --> 21:28.960] It always seems to be four zeros. [21:29.380 --> 21:30.520] Or one, two, three, four. [21:33.120 --> 21:36.960] Any time you have a default like that you can't change on a lot of devices. [21:37.300 --> 21:40.940] Like I got a Motorola M500 headset and it's hard coded in there. [21:41.920 --> 21:43.400] Phone phreaking over Bluetooth. [21:43.860 --> 21:44.440] What's that? [21:44.620 --> 21:46.060] Phone phreaking over Bluetooth. [21:46.180 --> 21:47.180] Phone phreaking over Bluetooth. [21:47.180 --> 21:57.540] Where I see a problem and one thing I actually want to see happen, all of these people who are on subways or movie theaters now with their headsets on all the time. [21:58.640 --> 22:02.140] Somebody needs to find a way to broadcast into all those things. [22:03.100 --> 22:09.980] We need to introduce like an omission voice into the back of them, you know, into their heads and say, you know, I know what you did. [22:10.140 --> 22:11.140] I have the pictures. [22:12.900 --> 22:14.580] Somebody needs to do this. [22:22.760 --> 22:26.120] Yeah, they can do it with some cars with a program called Car Whisperer. [22:26.240 --> 22:28.220] But I think you need to do this on a more personal level. [22:28.980 --> 22:33.320] I mean, it's nice to be able to reach out and say, you know, hey, jackass, you just cut me off. [22:33.540 --> 22:33.820] What? [22:34.500 --> 22:35.300] Where's that come from? [22:36.420 --> 22:38.460] You know, backseat driver from a distance. [22:38.720 --> 22:44.160] But, you know, I think you need to get more personal and start, you know, scaring the living daylights out of these people. [22:45.180 --> 22:48.520] Or to invert that, open up the microphone. [22:51.240 --> 22:54.340] And then broadcast it to other people on other headsets. [23:11.200 --> 23:12.900] So, we're just kind of making this up as we go. [23:13.080 --> 23:15.360] We've got a few notes, but... [23:16.960 --> 23:20.780] RFID is something that, I mean, there was a couple of really good talks this morning on it. [23:21.920 --> 23:29.620] Something that is all around us, whether or not you want it to be the XM mobile speed pass, proximity cards, credit cards. [23:29.800 --> 23:30.400] It's everywhere. [23:32.260 --> 23:34.360] Why are a lot of these... [23:35.260 --> 23:38.020] Why is RFID being used in all of these cases? [23:39.000 --> 23:41.160] There are so many examples. [23:42.060 --> 23:44.180] One of which, the passports. [23:44.760 --> 23:51.920] You know, August of this year, the U.S. is going to start putting RFID chips in their passports to be read, you know, when you go across the border. [23:53.300 --> 23:55.140] Why do they need to be read at a distance? [23:55.640 --> 24:00.820] Like, is there bulletproof glass or something that prevents them from, you know, going from this far away to this far away? [24:00.940 --> 24:03.320] Like, there are so many contact-based systems. [24:03.940 --> 24:06.220] It's a solution looking for a problem. [24:07.140 --> 24:20.080] And you introduce so many problems into this, and most people don't seem to understand that when you, you know, introduce RFID, you're introducing levels of complexity that can fail on you. [24:20.720 --> 24:27.840] If your inventory control system is based on RFID, well, what's the life cycle of these things? [24:27.940 --> 24:30.560] Well, the manufacturer says that they're, you know, good for 100,000 reads. [24:31.100 --> 24:34.280] Well, drive a Mack truck over it, and then see if you can read it. [24:34.460 --> 24:35.900] You know, these sort of things happen. [24:36.460 --> 24:39.440] You know, if you're depending on this, it's going to fail you. [24:40.960 --> 24:58.300] Yeah, and, you know, going back to the idea of the pen-testing with this is that if you're going to be doing a lot of pen-testing, and there's an RFID element into the building, for instance, access cards, it's just one more area where you're actually going to be unwired, [24:58.340 --> 25:02.700] but you're going to be kind of penetration testing on the whole system. [25:08.120 --> 25:14.080] Jonathan Westhughes was talking this morning about the lady with the implanted Verichip in her arm. [25:14.640 --> 25:16.700] His little... he has a project. [25:17.680 --> 25:24.900] It's just a little credit card size circuit board, two switches, one button reads, the other broadcasts. [25:26.260 --> 25:32.420] So all you have to do is just walk up to somebody, hit one button, swipes their... it activates and swipes their... [25:33.040 --> 25:39.160] the access codes for their RFID proximity card, hit the other button, and it just rebroadcasts it and lets the end. [25:39.960 --> 25:45.480] You know, this is something that can easily be done on a crowded elevator, subway, escalator, or just walking past. [25:46.060 --> 25:51.860] You know, the keys to the kingdom are being broadcast on a small radio out of your executive's pockets. [25:51.860 --> 25:53.500] This is... [25:54.180 --> 25:55.300] I believe U.S. [25:55.380 --> 25:56.900] passports last for 10 years. [25:57.260 --> 25:57.860] Is that valid? [25:58.660 --> 25:58.780] Correct. [25:59.020 --> 25:59.180] Right. [25:59.920 --> 26:00.920] So it's encrypted. [26:01.280 --> 26:04.700] How much crypto was developed 10 years ago, which has been broken since? [26:06.220 --> 26:07.120] Most of it. [26:07.680 --> 26:09.240] Does anybody remember WEP? [26:13.140 --> 26:13.420] No. [26:13.700 --> 26:14.580] Or even MD5. [26:17.100 --> 26:23.420] So what's the likelihood of this technology surviving in your passport for 10 years in a way that's going to be secure? [26:23.980 --> 26:24.880] We don't know. [26:25.320 --> 26:25.360] Not high. [26:26.420 --> 26:32.080] And the thing is, they aren't releasing any of these passports to the public for testing. [26:32.880 --> 26:34.100] And the chips are made in Malaysia. [26:34.200 --> 26:35.740] And the chips are made in Malaysia, he says. [26:36.520 --> 26:38.780] But, you know, I would love to get my hands on these things. [26:39.220 --> 26:42.700] You know, they integrated a tinfoil hat in the front and the back. [26:43.160 --> 26:44.900] You can't read it when the book is closed. [26:45.100 --> 26:48.360] Well, you dump enough RF energy in there and you're probably going to get something out of it. [26:48.360 --> 26:50.340] So, you know, this is something that needs to be tested. [26:50.540 --> 26:55.080] But, for some strange reason, the State Department doesn't like sending sample passports to foreign nationals. [26:55.340 --> 26:56.120] I don't know why. [27:00.210 --> 27:00.820] Q&A? [27:01.140 --> 27:01.300] Yeah. [27:02.060 --> 27:02.160] Okay. [27:02.500 --> 27:05.120] We're going to open it up to questions and answers. [27:05.280 --> 27:11.320] And they asked us to remind people, if you do want to talk to us, ask a question, please come up and use the microphones. [27:11.320 --> 27:13.500] And any ideas you have in the future, too? [27:14.840 --> 27:16.400] I've got two questions for you. [27:16.520 --> 27:19.440] The first one was about Flash BIOS updates. [27:19.760 --> 27:28.340] Have you guys heard anything solid on whether they've actually started exploiting that weakness or possible weaknesses? [27:28.660 --> 27:33.600] And the second thing I wanted to ask you is, what did you use on your laptop to scan for those Bluetooth devices? [27:35.220 --> 27:37.040] I haven't heard of anything. [27:37.660 --> 27:43.420] Well, there was the Chernobyl, I had to remember, virus a while ago. [27:43.420 --> 27:43.500] CIH. [27:43.620 --> 27:45.820] Or CIH, which would nuke your BIOS. [27:46.000 --> 27:47.360] I don't see any reason. [27:47.580 --> 27:52.700] It would be difficult to match the correct BIOS to flash into your system. [27:52.880 --> 27:56.320] But I see no reason that you couldn't flash a malicious BIOS into a system. [27:56.580 --> 27:59.680] It's a level of development that most people aren't doing right now. [27:59.680 --> 28:04.800] But if there were a reason with enough money behind it, I don't see any reason why it wouldn't be possible. [28:05.080 --> 28:07.820] The same would go for flashable access points. [28:08.080 --> 28:15.460] Or even downloadable firmware with like a spoofed driver update that did download new firmware from the client machine. [28:15.860 --> 28:19.880] Like in a Theros card or pretty much anything else that uses hot pluggable firmware now. [28:20.060 --> 28:24.500] There's no reason that they couldn't download some malicious firmware that did something. [28:24.500 --> 28:29.440] Either terrible, overtly, or covertly monitor your data. [28:30.720 --> 28:33.040] Okay, that's the last time I send you my DEFCON presentation. [28:34.360 --> 28:34.840] Sorry. [28:35.120 --> 28:37.060] Actually, I don't think I saw your DEFCON. [28:37.140 --> 28:37.280] Oh. [28:38.200 --> 28:41.540] One of the things I'm going to be talking about there, I'm still working on it. [28:41.760 --> 28:42.240] Hopefully. [28:44.080 --> 28:51.300] Basically, with a lot of consumer off-the-shelf access points, they're running Linux with a flashable firmware. [28:52.300 --> 28:58.480] But there's no way to verify that the firmware that's actually running on there is the one that's supposed to be there. [28:59.140 --> 29:02.780] Yeah, you can log in and see this nice Linksys web interface and everything like that. [29:02.920 --> 29:04.920] But do you actually know what's running under the hood? [29:05.540 --> 29:06.360] How do you write? [29:06.480 --> 29:09.040] How do you do an antivirus scan on your router? [29:10.180 --> 29:14.340] This is something that I think is going to turn around and bite in the near future here. [29:15.040 --> 29:26.800] Oh, and in relation to this, the Bluetooth scanning, Linksys, you know, USB adapter, class one, nothing particularly fancy, and network chemistry's blue scanner. [29:27.060 --> 29:29.660] I mean, this is not anything terribly scary. [29:29.800 --> 29:33.180] This is just a quick test we decided to do just before the talk here. [29:34.140 --> 29:45.800] Also for Linux, there's a T-Bear and a few other similar scanners that just list all of the cards that are open for Bluetooth connectivity. [29:46.260 --> 29:47.820] Just a curiosity question. [29:48.040 --> 29:54.780] How many of you, when you're looking for rogue access points in your businesses or consulting, how many of you are also scanning for Bluetooth? [29:55.540 --> 29:56.260] Just a curiosity. [29:57.220 --> 29:57.840] Okay, not many. [29:58.060 --> 29:58.820] About a half dozen. [30:00.950 --> 30:02.840] I think the person in front was next. [30:03.240 --> 30:03.400] Yeah. [30:03.500 --> 30:04.620] Yeah, I didn't have a question. [30:04.740 --> 30:06.620] I had more of a, like a comment or a statement. [30:06.980 --> 30:07.100] Go for it. [30:07.100 --> 30:12.400] I think they build stuff like RFID and all this crap because it creates new markets and they try to get people interested in it. [30:12.760 --> 30:13.800] Solutions looking for a problem. [30:13.800 --> 30:16.800] And then when it breaks, they introduce another market to fix it. [30:16.960 --> 30:22.240] And like, that's exactly what software, and you know, I do security for a living like probably a lot of people. [30:22.950 --> 30:30.660] And don't you see all the products out there and all the money and all this crap you keep buying and you buy more crap that's broken so you can get more crap to fix the crap that's broken. [30:30.680 --> 30:33.880] You get a consultant to fix the crap that broke because you don't know how it's broken. [30:34.630 --> 30:36.640] And all it is is just a bunch of shit. [30:36.640 --> 30:37.280] Excuse my language. [30:37.380 --> 30:38.100] But that's what it is. [30:38.180 --> 30:41.620] And it just is perpetuating and it's all on purpose. [30:42.120 --> 30:44.460] It's all on purpose to create markets. [30:44.760 --> 30:45.300] Well said. [30:45.300 --> 30:45.320] Good. [30:47.660 --> 30:55.740] How many of you have seen installations of wireless where they'll spend, and godly, I want some money fighting, you know, for Spectrum and they can't figure out how to keep this thing running and everything. [30:55.800 --> 30:59.020] It's like, okay, a hundred bucks and I'll drop a wire over here. [30:59.240 --> 31:00.700] You're not moving from this location. [31:00.820 --> 31:02.340] Why do you need wireless? [31:04.000 --> 31:04.940] The person in the middle? [31:07.000 --> 31:13.160] I personally encountered that Mick checks something where it turns the radio off for 60 seconds. [31:13.680 --> 31:14.420] So I decided that... [31:14.420 --> 31:15.420] The Michael countermeasures? [31:15.640 --> 31:15.740] Yeah. [31:15.880 --> 31:16.120] Yeah. [31:16.760 --> 31:17.760] That you were talking about earlier. [31:18.180 --> 31:21.860] So I determined that WPA is broken and we all know WEP is broken. [31:21.980 --> 31:28.160] So is it possible to run a Wi-Fi network that has any encryption on it? [31:29.500 --> 31:33.340] WPA, done right, can be moderately acceptable. [31:34.980 --> 31:46.620] What I prefer for my own networks, like not in a business and whatnot, would be to sometimes even just turn off WEP entirely, leave the network open, and then use layer three encryption like a VPN tunnel. [31:47.400 --> 31:49.180] OpenVPN is dead simple to set up. [31:49.320 --> 31:55.480] I believe it runs on OSX, Windows, Linux, and there you go. [31:55.480 --> 32:03.920] You just firewall off your access point subnet from the rest of your network, only allow the VPN ports to the VPN server, and then tunnel everything over from there. [32:05.240 --> 32:09.300] Just another kind of question out to you people in general, show of hands. [32:09.400 --> 32:15.020] How many people are actually running any kind of firewall that's separating the wired portion from the wireless portion? [32:16.660 --> 32:17.560] It's not too bad. [32:17.600 --> 32:18.360] It's more than I expected. [32:22.340 --> 32:29.860] So how long is it going to be before I can throw out my cow patty, my aircrack, and all the rest of those, and they're finally integrated into Kismet? [32:30.040 --> 32:33.120] How much interest are you seeing in people to do that? [32:33.580 --> 32:34.400] Write a plug-in. [32:35.320 --> 32:37.240] Yeah, the easy answer is write a plug-in. [32:37.600 --> 32:44.020] The harder answer, cow patty would actually be something that would be reasonable to do as a plug-in, because it's more of a real-time thing. [32:45.400 --> 32:51.360] Aircrack builds a large database of packets and then does lots of scary math on them. [32:52.020 --> 33:06.080] I don't think that's really a run-time app as much as a post-processing, because every time you added a new packet, you probably have to start recalculating all of your data that you've run so far, and that could be a couple days' worth of work in some cases. [33:06.500 --> 33:09.480] Are you seeing any really interesting proposals for plug-ins? [33:11.580 --> 33:13.300] I haven't seen too many yet. [33:14.800 --> 33:24.700] Mainly I'm hoping that I can turn the API loose and people will think of things I didn't, and for things where I didn't want to integrate it into the source. [33:25.180 --> 33:27.260] One of the things I'm trying to do is keep Kismet passive. [33:27.540 --> 33:31.640] It just makes my life much simpler that I can say to people, it's not going to attack your network. [33:31.840 --> 33:34.140] They might do something with it and attack your network. [33:34.780 --> 33:41.660] So in this case, when I have things I don't want to integrate into code, I can have people write them as plug-ins. [33:42.360 --> 33:43.200] Share the blame. [33:43.560 --> 33:45.220] Yeah, share the blame, pass the buck. [33:46.180 --> 33:58.060] It should also allow it to be much easier to port it to Windows, and if there are any drivers in the future for Windows that allow capture, it should be possible to do a complete capture source in Windows as a plug-in. [33:58.460 --> 33:58.880] Cool. [34:00.980 --> 34:01.460] Thanks. [34:08.360 --> 34:09.060] Go ahead. [34:09.580 --> 34:10.060] Okay. [34:10.980 --> 34:23.920] I recently read somewhere about an attack involving sending packets that exploited the actual driver of the network card, so that you don't actually have to be accepting connections or probing to get hacked. [34:23.920 --> 34:26.020] Yeah, that's going to be the talk at Black Hat. [34:26.160 --> 34:28.000] I don't believe the details on that have been released yet. [34:28.000 --> 34:30.520] I think he's talking about Simple Nomad stuff from Shmikami. [34:30.520 --> 34:30.900] No. [34:31.540 --> 34:33.680] Are you talking about the recent one that's going to be at Black Hat? [34:34.680 --> 34:34.920] Yeah. [34:35.240 --> 34:36.560] Do you have any thoughts on that? [34:36.560 --> 34:38.300] They haven't released many details on that yet. [34:38.380 --> 34:38.460] Okay. [34:39.020 --> 34:44.380] Basically, for those of you who might not know what we're talking about, at Shmikami, Simple Nomad gave a talk. [34:44.700 --> 34:46.720] It was entitled Hacking the Friendly Skies. [34:46.880 --> 35:00.740] Everybody thought it was about trying to hack an airplane and make a crash or something, but what it was was he had figured that, you know, he's sitting back in cattle class and, you know, Mr. Executive's up front there, you know, sitting there with his champagne working on his laptop. [35:01.340 --> 35:04.060] You're in an environment where there's no other access points. [35:04.400 --> 35:08.900] Well, you know, there's that whole big spiel in the front saying, you know, please turn off all your wireless devices. [35:09.120 --> 35:12.020] Well, most executives probably don't even know how to do this. [35:12.020 --> 35:14.260] You can tell I've got a really high opinion of executives. [35:15.740 --> 35:19.640] So they leave, you know, Bluetooth, or they leave their Wi-Fi running. [35:20.260 --> 35:30.300] Well, Simple Nomad basically figured a way to get that, to connect his laptop to theirs without them having to configure anything. [35:31.140 --> 35:40.340] And he was sitting in backing cattle class and, you know, poking through shares and everything and just seeing all sorts of interesting stuff because you're in a contained environment that people don't expect to be attacked over wireless. [35:41.260 --> 35:54.640] And this other one is going to be released at Black Hat and it's basically 802.11 fuzzing, just throwing all sorts of crap at wireless drivers and watching them fail in interesting and, in one case, a fairly spectacular way. [35:55.540 --> 35:58.700] No details yet, but we'll see you in about a week. [35:58.960 --> 36:16.240] From the publicly released stuff that was, I believe, on the Black Hat page in Slashdot, it sounds like it's a bug at the driver level, basically in the Windows kernel, which, would let you send a couple frames and own Windows at the kernel. [36:17.360 --> 36:20.760] But, you'll have to wait for their Black Hat presentation for that one. [36:21.780 --> 36:27.740] The interesting thing about driver attacks in the future is that, so what if you're running a firewall? [36:28.120 --> 36:31.400] It just got owned at the wireless layer before it passed it to the IP layer. [36:31.400 --> 36:33.140] Assuming it was even a data frame. [36:35.160 --> 36:36.220] Did I answer the question? [36:36.700 --> 36:37.500] Yeah, thank you. [36:39.320 --> 36:40.080] Anyone else? [36:40.320 --> 36:40.760] Don't be shy. [36:42.980 --> 36:44.560] You look like you've got something down there. [36:51.680 --> 36:54.120] Is the API on CBS yet? [36:54.740 --> 36:57.180] Yeah, the plug-in API is in Subversion. [36:57.460 --> 37:00.240] The whole new development is in Subversion. [37:00.380 --> 37:01.220] It's publicly accessible. [37:02.580 --> 37:06.380] It's actually the plug-in API is part of what's running the access points here this year. [37:06.640 --> 37:13.800] So, the access point control mechanism to configure them all from the NOC is actually a plug-in to Kismet, which configures radios. [37:15.600 --> 37:16.340] Nice toys. [37:17.720 --> 37:23.000] So, I remember last year there was some talk about USB devices and exploiting USB drivers. [37:23.000 --> 37:25.720] I know this kind of came back again, but over wireless. [37:26.180 --> 37:30.240] Has anybody figured out how to write exploit code that runs on a PCI bus yet? [37:31.040 --> 37:35.080] At ShmooCon, Hickory had a talk, or Hickory. [37:35.480 --> 37:36.580] I'm angling his name. [37:36.800 --> 37:37.080] Hickory. [37:37.240 --> 37:42.540] Had a talk briefly about using the PCI bus to do reverse DMA mapping. [37:44.040 --> 37:50.160] There's also mention there, what you're talking about with the USB, I believe, is not actually a USB driver hack. [37:50.160 --> 37:51.880] It's a USB hardware hack. [37:52.280 --> 38:12.000] If you confuse the USB bus sufficiently, you can gain DMA access to the system, which allows your device plugged into the USB bus to map system memory starting at byte zero, out from underneath Windows or whatever operating system is running, and then modify it. [38:13.540 --> 38:15.520] So, it's a slightly different attack factor. [38:15.860 --> 38:16.700] Can you lean forward a little? [38:16.900 --> 38:18.780] It was a slightly different attack factor. [38:18.780 --> 38:20.300] Yeah, that would be a physical attack factor. [38:20.500 --> 38:22.720] I believe there's a similar one announced in FireWire. [38:22.940 --> 38:23.220] Okay. [38:24.600 --> 38:26.580] I'm sure if you Google it, you can find more on them. [38:27.360 --> 38:37.640] I don't see any theoretical reason why you couldn't perform a similar attack with a firmware exploit to a card bus or mini PCI card. [38:38.080 --> 38:39.680] But I haven't seen it done. [38:41.700 --> 38:42.500] Maybe we will. [38:42.500 --> 38:42.540] Maybe we will. [38:43.060 --> 38:45.260] It would be very complex to do. [38:45.660 --> 38:50.140] But that hasn't stopped previous very interesting attacks from happening. [38:50.720 --> 38:50.880] Okay. [38:51.160 --> 38:51.440] Thanks. [38:53.240 --> 39:02.160] I just want to say, just looking at 802.11 security over the last couple of years, you know, we've gone from WEP where they're saying, oh, it's just, you know, 40-bit WEP is okay. [39:02.540 --> 39:05.440] I think we've gone from hiding your SSID to 40-bit WEP. [39:05.440 --> 39:05.720] Yeah. [39:06.500 --> 39:11.080] Well, I mean, there was a point where a 40-bit WEP was all you could get because of the export restrictions. [39:11.300 --> 39:12.120] And then we went to 128. [39:12.880 --> 39:14.800] And then, you know, that was found to suck. [39:15.020 --> 39:16.240] So we went to WPA. [39:16.580 --> 39:17.800] You know, that had problems. [39:17.920 --> 39:19.100] Now we're going to WPA, too. [39:19.980 --> 39:21.520] And that's even got some problems. [39:21.720 --> 39:30.700] I mean, you start looking at the Michael County measures and even little issues that will be revealed at DEFCON, but WPA isn't even bulletproof. [39:32.020 --> 39:39.060] Somewhere along the line, we're probably going to catch up, but time will have moved on and we'll be way ahead of that. [39:39.720 --> 39:46.520] There just seems to be no sane way of running 802.11 right now short with just what's packaged with it. [39:46.580 --> 39:50.080] You're having to go to VPNs or other products on top of it. [39:50.080 --> 40:00.780] And I just think that the IEEE working groups really need to get their act together and realize they need to keep pace with everybody else. [40:02.040 --> 40:09.540] And how many of you have businesses that you support or even at home that your gear is still only WEP capable? [40:10.240 --> 40:13.200] You know, you got an old WAP 11 or something like that. [40:13.640 --> 40:14.320] A number of you. [40:14.760 --> 40:20.700] So many businesses will invest in the infrastructure and they'll get a security auditor to come in and say, yep, you're secure. [40:20.820 --> 40:22.260] You've got, you know, WEP on and everything. [40:22.500 --> 40:23.320] Everything's good now. [40:24.080 --> 40:26.480] Well, how many of them are keeping up on this? [40:27.360 --> 40:29.300] The Internet moves at the speed of light here. [40:31.260 --> 40:34.320] Changes in policy don't move at the speed of light. [40:34.660 --> 40:39.340] There's so many cases where a business policy is, oh, you know, remote offices have to run WEP. [40:40.100 --> 40:41.840] Well, they'll revisit that 18 months. [40:41.840 --> 40:46.180] Well, the next three layers of security have been blown out of the water by then. [40:46.340 --> 40:47.840] So they're so far behind the curve. [40:48.440 --> 40:57.020] You really need to have somebody on your staff with their ear to the ground that has the ability to make policy changes on the fly. [40:57.300 --> 40:59.680] Saying, okay, yesterday WEP was sufficient. [40:59.860 --> 41:00.760] Today, it's not. [41:01.520 --> 41:03.520] You know, okay, we're going to have to invest in new infrastructure. [41:03.700 --> 41:06.840] This is just a nature, this is a reality. [41:10.220 --> 41:11.160] Yeah, go ahead. [41:11.440 --> 41:11.760] Hi. [41:11.760 --> 41:11.780] Yeah. [41:12.560 --> 41:14.280] I have a less technical question. [41:14.460 --> 41:14.900] Lean forward. [41:15.300 --> 41:15.920] Can you hear me? [41:16.160 --> 41:16.300] Yeah. [41:17.080 --> 41:21.920] What can we do as people and consumers about retarding the adoption of RFID? [41:22.940 --> 41:23.060] Right? [41:24.100 --> 41:24.660] Nothing? [41:24.880 --> 41:25.980] There's nothing that can be done? [41:26.540 --> 41:30.640] You could boycott Walmart if they enforce that. [41:30.920 --> 41:31.140] I know. [41:31.140 --> 41:35.080] Because nobody shops at Walmart and I'm sure we can all keep it from... [41:35.080 --> 41:35.520] No. [41:35.660 --> 41:36.160] No, we can't. [41:37.520 --> 41:37.860] No. [41:37.860 --> 41:39.380] Dude, there's like the fifth largest economy. [41:40.200 --> 41:40.980] Kind of hard to avoid them. [41:41.260 --> 41:45.600] Um, I think, it depends what level of RFID you're talking about. [41:45.680 --> 41:47.380] I mean, if you're talking about like... [41:47.380 --> 41:48.920] Well, for instance, when I get a bank card... [41:48.920 --> 41:49.560] Lean forward, you're not anything. [41:49.560 --> 41:51.280] ...when I get a bank card from my bank... [41:51.420 --> 41:55.580] ...and they've decided to put RFID in my new debit card... [41:55.580 --> 41:55.700] Yeah. [41:55.860 --> 41:56.960] ...whether or not I want it. [41:57.080 --> 41:58.440] It pisses me off a lot. [41:59.260 --> 41:59.380] Yeah. [41:59.380 --> 42:01.060] Uh, do you have a microwave? [42:01.600 --> 42:02.000] Yeah. [42:02.420 --> 42:03.540] I mean, but do I... [42:03.540 --> 42:05.740] That doesn't stop a hundred other people from... [42:05.740 --> 42:07.400] Who don't know what RFID is. [42:08.000 --> 42:10.040] You know, from getting those cards and using them... [42:10.040 --> 42:10.620] Yeah. [42:10.700 --> 42:11.240] ...and having stuff happen. [42:11.520 --> 42:12.840] Invite them to use your microwave. [42:13.460 --> 42:14.680] I could have a microwave party. [42:14.680 --> 42:16.820] The suggestion was to invite them to use your microwave. [42:17.080 --> 42:17.200] Yeah. [42:18.300 --> 42:20.240] I guess that's the best we got right now. [42:20.420 --> 42:20.520] Yeah. [42:20.780 --> 42:22.680] You know, a lot of this stuff too is... [42:22.680 --> 42:24.380] It's just getting pervasive. [42:24.380 --> 42:27.760] I mean, how many people drive Fords? [42:27.980 --> 42:28.360] Or Ford... [42:28.360 --> 42:29.560] Ford-related products? [42:30.900 --> 42:31.340] Um... [42:31.340 --> 42:33.440] Ford Explorer is the most popular vehicle in the U.S. [42:34.900 --> 42:35.780] Since, uh... [42:35.780 --> 42:39.480] The old 2004 model, I think the keys are all been RFID. [42:41.220 --> 42:41.660] Um... [42:41.660 --> 42:41.880] Uh... [42:41.880 --> 42:42.480] Implanted. [42:42.600 --> 42:42.800] A transponder. [42:42.960 --> 42:43.140] Yeah. [42:43.200 --> 42:44.420] There's a transponder in the key. [42:46.140 --> 42:46.580] Um... [42:46.580 --> 42:46.860] And... [42:46.860 --> 42:47.460] And that... [42:47.460 --> 42:48.260] That is broken. [42:48.420 --> 42:50.640] It was based on a 40-bit encryption and... [42:50.640 --> 42:51.500] Proprietary algorithm. [42:51.740 --> 42:51.940] Yeah. [42:52.820 --> 42:53.260] They... [42:53.260 --> 42:53.660] Uh... [42:54.140 --> 42:54.980] A year ago. [42:55.300 --> 42:55.700] Uh... [42:55.700 --> 42:56.340] 18 months ago now. [42:57.200 --> 42:57.640] Uh... [42:57.640 --> 42:59.600] You can duplicate those keys on the fly. [43:00.840 --> 43:02.640] I think it's also just a matter of, uh... [43:02.640 --> 43:04.060] Social education catching up. [43:04.600 --> 43:05.620] I mean, uh... [43:05.620 --> 43:05.780] Uh... [43:05.780 --> 43:06.380] RFID is new. [43:07.240 --> 43:07.680] Uh... [43:07.680 --> 43:09.220] A lot of people don't even... [43:09.220 --> 43:11.380] I mean, I don't want to say everybody's dumb. [43:11.620 --> 43:12.880] Although I do often say that. [43:13.160 --> 43:14.700] But, uh... [43:14.700 --> 43:15.580] I mean, a lot of... [43:15.580 --> 43:21.180] People that go out and buy a cell phone don't necessarily understand, you know, how radio wave propagation and whatnot works. [43:21.180 --> 43:25.360] And we're expecting them to understand that a little chip in their credit card could be dangerous to them. [43:25.860 --> 43:30.000] I mean, how long have we been talking about RFID credit cards now? [43:30.060 --> 43:30.720] Maybe two years? [43:30.980 --> 43:38.180] It's probably gonna be another three or four years before, you know, there's enough doom and gloom danger stories on the media to, uh... [43:38.180 --> 43:39.520] Have that pick up. [43:39.700 --> 43:40.780] I mean, we're still getting... [43:40.780 --> 43:45.760] We're still now seeing stories about how dangerous it is to have an unencrypted wireless network. [43:45.880 --> 43:46.380] And, you know... [43:46.380 --> 43:49.600] About every two weeks, some local news station does an expose about... [43:49.600 --> 43:54.160] They got, you know, the local long-haired kid with a black t-shirt in the neighborhood to drive them around. [43:55.720 --> 43:56.520] And, uh... [43:57.120 --> 43:57.520] Terrify... [43:57.520 --> 43:58.720] Gotta have a Pringles can. [43:59.380 --> 44:03.040] To terrify all the people in their town about the dangers of an open wireless network. [44:03.040 --> 44:04.460] We're still seeing that happening now. [44:04.560 --> 44:05.980] So what's gonna be in two years from now? [44:06.060 --> 44:07.040] It's not gonna be RFID. [44:07.260 --> 44:07.540] Yeah. [44:07.720 --> 44:10.340] He's saying so in two years from now, it's probably not gonna be RFID yet. [44:10.940 --> 44:14.380] That's just gonna be another aggregated nuisance. [44:14.540 --> 44:15.800] Another aggregated nuisance. [44:16.380 --> 44:16.640] Uh... [44:16.640 --> 44:16.740] Yeah. [44:17.200 --> 44:17.600] Could be. [44:17.820 --> 44:18.160] Could be. [44:18.180 --> 44:19.380] I think we have another question. [44:21.280 --> 44:21.680] So... [44:21.680 --> 44:30.260] With the current configuration of many access points with all of their vulnerabilities running Linux, why do you think we've not seen an entirely AP-based worm yet? [44:30.260 --> 44:34.020] That's just exploiting firmware-to-firmware-to-firmware in your urban environment. [44:36.240 --> 44:37.440] You're hoping we have... [44:37.440 --> 44:39.000] You have read my DEFCON talk, haven't you? [44:39.820 --> 44:40.020] Yeah. [44:40.220 --> 44:41.620] We actually, uh... [44:41.620 --> 44:45.900] Two years ago, came up with a proof of concept for doing that kind of thing. [44:46.640 --> 44:47.160] Um... [44:47.880 --> 44:48.400] And... [44:48.400 --> 44:49.180] It's... [44:49.180 --> 44:52.060] It's entirely possible that that could happen. [44:53.680 --> 44:54.200] Um... [44:54.200 --> 44:54.760] The... [44:54.760 --> 45:06.160] There's a couple of things that make it a little bit more difficult, at least on the surface, in that you actually have to probably stop for a couple of minutes, make a connection, um... [45:06.160 --> 45:06.820] You know, get... [45:06.820 --> 45:07.600] Get some transfer. [45:08.380 --> 45:08.820] I... [45:08.820 --> 45:15.900] We haven't seen anything that would actually go where you could just drive down the road and be connecting and actually get a worm to go across. [45:16.360 --> 45:25.520] Now, there's nothing to say that if there wasn't an exploit for one of these firmwares, I mean, how many consumers upgrade the firmware on their Linksys router outside, you know, once they've taken it out of the box? [45:26.080 --> 45:26.780] Not a lot. [45:27.140 --> 45:28.360] If it ain't broke, don't fix it. [45:28.520 --> 45:30.440] Most people don't even set passwords, so... [45:30.440 --> 45:30.460] Yeah. [45:30.460 --> 45:31.760] We're not even talking about exploits here. [45:31.880 --> 45:34.680] We're just talking about, you know, log in, upload new firmware. [45:34.900 --> 45:35.220] Thank you. [45:36.840 --> 45:39.720] There'll be limitations with memory, uh... [45:39.720 --> 45:40.740] Use the microphone! [45:41.180 --> 45:54.520] There'll be limitations with memory, he's saying, but even then, all you need to do is just, say, open up Telnet or something like that, or just, you know, an open spam relay or something like that, as long as the user still sees the Linksys front end, [45:55.320 --> 45:57.580] everything's, you know, all nice and peachy, as far as they're concerned. [45:58.140 --> 46:00.060] Back to my original point, how do you check? [46:01.020 --> 46:04.160] There's no method I know of so far, especially on a consumer gear. [46:04.160 --> 46:10.660] You can't pull your drive and throw it in another machine and empty five some things from an unowned kernel at that point. [46:14.970 --> 46:30.030] In reference to people who, I guess, aren't technically adept, like just the random person that walks into Best Buy and says, I want a notebook, you know, it's gotta be wireless, you know, and they bring it home, there's no encryption, even though, you know, [46:30.090 --> 46:32.330] most of the stuff out there isn't that good anyway. [46:32.330 --> 46:46.650] Do you think the people that a technology isn't a hobby to are gonna catch on and say, you know what, you know, this is only a computer, but I really need to, you know, look into the manual or look into, you know, what I'm doing on this is gonna affect, [46:46.890 --> 46:50.110] you know, my finances, you know, anything about my life? [46:50.210 --> 47:04.850] Because most people, in reference to anything, cars, technology, they usually just use it as a tool, like a hammer, and just throw it back into the box where, you know, if it's a hobby, you'll tend to fall over, you know, the problems of a certain technology and hopefully try to fix them. [47:04.990 --> 47:05.650] I think... [47:06.430 --> 47:11.930] That's been the bane of tech's existence from the beginning, is getting people to read the friggin' manual. [47:12.330 --> 47:15.770] It just... that's one of those insurmountable problems. [47:17.150 --> 47:29.730] Making people aware that, you know, they are personally vulnerable to this, you know, unfortunately, Fox News seems to be the king of that, of just scaring the daylights out of people with these big, huge articles they do on TV. [47:31.150 --> 47:32.990] I actually have to applaud Microsoft. [47:33.390 --> 47:34.330] I never thought I'd say that. [47:34.910 --> 47:41.150] When they were producing hardware, wireless hardware, their setup wizard, actually, you had to physically... [47:41.150 --> 47:43.990] you had to click and say, no, I don't want to use a web key. [47:44.730 --> 47:53.490] So that little action of not being open by default led to a lot of networks being secured that probably wouldn't have otherwise. [47:53.830 --> 47:59.150] That's not saying that people didn't just turn it off anyways, but it was leading people down the right path. [47:59.670 --> 48:05.790] And that's where I think a lot of manufacturers need to do, is they need to kind of, like, steer the cattle down this way, not the other way. [48:06.250 --> 48:08.650] I think also the awareness is rising in general. [48:08.870 --> 48:13.870] I mean, five years ago, how many people downloaded Elf Bowling? [48:13.870 --> 48:17.830] I mean, not a show of hands here, but, I mean, in general, how many people downloaded Elf Bowling? [48:18.290 --> 48:19.030] A whole lot. [48:19.090 --> 48:20.930] How many people heard of malware in Trojans? [48:21.450 --> 48:22.490] Probably not that many. [48:23.010 --> 48:26.250] Now you watch TV, Citibank commercials, Earthlink commercials. [48:26.750 --> 48:28.990] Citibank has identity theft recovery services. [48:29.810 --> 48:32.670] Earthlink's talking about their Trojan blockers and antiviral stuff. [48:33.090 --> 48:34.390] I mean, that reaches people. [48:34.510 --> 48:36.090] They're beginning to get more educated about it. [48:36.090 --> 48:43.330] So, I think the awareness of what, of that, you know, the average person would need to protect themselves is rising. [48:44.170 --> 48:48.850] I think they'll probably also be not that many people necessarily targeting the average person. [48:48.970 --> 48:51.950] I mean, they'll be the guy in your neighborhood who needs Internet, who doesn't want to buy a cable modem. [48:52.530 --> 48:54.190] We'll look for the next open access point. [48:54.550 --> 49:01.810] There may, in the future, be people who write scrapers that go through the neighborhood or, like, a worm activity or something like that to scrape the personal data. [49:01.810 --> 49:05.970] But, I mean, generally, most people aren't that interesting and it's not worth breaking into their computers. [49:06.590 --> 49:13.270] The threat comes when that becomes automated and it spreads and turns into a worm or something like that. [49:15.790 --> 49:16.870] A couple things. [49:17.130 --> 49:25.490] One, as you mentioned, the Windows kernel being owned by attacking the firmware on the wireless device. [49:25.630 --> 49:25.910] Driver. [49:26.970 --> 49:27.490] Driver. [49:27.930 --> 49:30.690] Is there any way, say, to write out... [49:30.690 --> 49:35.630] For instance, with Linux, to write a kernel module, they would be able to detect that sort of thing. [49:36.350 --> 49:39.670] You should be able to just do it with, like, Kismet or even a tcpdump filter. [49:41.250 --> 49:49.230] Once the data becomes public, if that packet is known, then, I mean, whatever it is has to be in that packet payload. [49:49.430 --> 49:53.350] So if you're in monitor mode, you should be able to sniff it and write some detector. [49:53.530 --> 49:55.490] I mean, you could just do it with tcpdump and grab it. [49:55.650 --> 49:57.050] But you'd have to have it on all the time. [49:57.210 --> 49:58.130] Right, you'd have to be watching. [49:58.450 --> 49:59.530] And by the time you detect it, it would be too late. [49:59.530 --> 50:03.650] Which is why you need the wireless IDS system to know when somebody is shooting at you. [50:03.970 --> 50:04.030] Right. [50:04.650 --> 50:09.150] The other thing is, what if you exported the configuration on a modified firmware AP? [50:09.810 --> 50:11.970] Is there, I mean, I imagine... [50:11.970 --> 50:15.350] I would think that the configuration would change in some way. [50:16.130 --> 50:17.730] Not guaranteed, but... [50:17.730 --> 50:19.710] My research was in WRT54Gs. [50:20.510 --> 50:26.910] All of their settings, you know, channel, SSID, things like that, that were all stored in VRAM, which survives during a flash. [50:28.190 --> 50:32.950] So, as far as the user sees, you know, at 3 o'clock in the morning, they're rather hiccuped. [50:33.090 --> 50:34.250] Oh, you know, now it's back. [50:34.350 --> 50:35.590] Same SSID, same channel. [50:36.310 --> 50:37.750] Everything looks the same. [50:39.310 --> 50:44.510] Yeah, I've reflashed a lot of devices over the years. [50:44.510 --> 50:50.230] And I haven't seen one that you actually had to go back and reprogram the SSID or the channel or any of that. [50:50.390 --> 50:51.590] It all stays behind. [50:51.590 --> 51:04.750] So, if that becomes a real possibility, then I don't see an end user who's relatively clueless about it being tipped off because of the fact that something changed, because it won't. [51:04.750 --> 51:06.090] It's as simple as that. [51:06.690 --> 51:10.090] And if they didn't set a password, do you think they're going to notice if it changed the channel? [51:10.330 --> 51:10.470] Yeah. [51:11.890 --> 51:14.070] Hey, it still links us as the SSID. [51:15.610 --> 51:24.050] I guess something I want to point out as more of a comment, too, is it's amazing how many organizations actually use wireless in default mode without passwords and actually use it as key parts of their organization. [51:24.690 --> 51:30.550] I've seen one that actually used a data center and had a wireless access point that went two miles to where their offices were. [51:31.390 --> 51:32.510] And it was amazing. [51:32.510 --> 51:39.930] It went over a toll booth where any moron could basically grab any of their key data, including basically breaking out their VoIP system. [51:40.350 --> 51:40.910] I believe. [51:41.130 --> 51:44.910] And I've seen this actually quite often in, you know, what I used to do. [51:44.910 --> 51:48.070] So, it's just amazing how many of these organizations are actually doing this. [51:48.070 --> 51:51.290] I believe there's a talk tomorrow that, in fact, covers some of that exactly. [51:52.950 --> 51:53.390] Okay. [51:53.490 --> 51:58.110] We probably have time for one or maybe two questions if they're quick and then we're getting flashed. [51:58.150 --> 51:58.990] Just a comment. [51:59.190 --> 52:15.930] As far as telling if your firmware has been hacked or not, for the WRT54Gs, if you're running any of the Linux, or any of the Linux firmwares, for example, OpenWRT, you can compile and run OSIRIS on it, which is the firmware or host integrity monitor. [52:16.170 --> 52:24.250] But that, of course, only applies if you're technically savvy and care enough to watch in the first place, in which case you're probably not going to be exploited. [52:24.670 --> 52:25.070] Exactly. [52:25.350 --> 52:25.430] Right. [52:25.570 --> 52:27.610] But, I mean, if it does get owned, how would you check it? [52:27.670 --> 52:29.890] Because you can't look at it directly. [52:30.090 --> 52:34.230] You can't pull the drive and examine it under something that's not booting the kernel that's potentially owned. [52:34.230 --> 52:40.510] Well, what a Cyrus will do is they'll go through and actually do MD5's checksum on it, et cetera. [52:40.610 --> 52:50.850] But if the only way to do that would be to get the file from the machine over SCP where it's served by the kernel that may be owned, or to get the file locally served by the kernel that may be owned, which may lie to you. [52:51.250 --> 53:01.930] If you're just going to a configuration utility and looking at a box that says, you know, the checksum for your firmware is, it's kind of hard, easy to put a real Linksys, what are the real Linksys? [53:01.930 --> 53:04.050] What happens is you've got a server and the client component. [53:04.310 --> 53:08.890] So the server's got the known hashes of it and then actually checks from the client. [53:09.050 --> 53:16.670] And the thing is you'd have to have a, I guess, malicious kernel that is looking out for that in order to subvert OSIRIS. [53:17.990 --> 53:22.770] Like you said, if you're that sophisticated, you're probably not going to be worried about that in the first place. [53:23.030 --> 53:24.970] You're not going to be that vulnerable to it. [53:25.030 --> 53:26.250] Or you're just not running Linksys gear. [53:27.770 --> 53:29.490] I think that's about it for our time. [53:29.670 --> 53:31.610] We'll be around if people want to talk to us after. [53:31.950 --> 53:32.670] Thank you.