Showing posts with label Security By Obscurity. Show all posts
Showing posts with label Security By Obscurity. Show all posts

WiFi Networking And Static IP addresses

When your computer connects to a WiFi access point, one of the first things that it normally does is to request an IP address, so it can connect to the router and / or to the other computers in the LAN. One of the earliest ways to stop intruders from connecting to your LAN, through your WiFi access point, was to restrict access by MAC address. A second way was to disable DHCP, and stop issuing IP addresses automatically.

Such a simple procedure - and so useful (or so thought those who tried it). Not so useful, thought the hackers when they would encounter a WiFi LAN, without DHCP to issue IP addressing. Part of hacking a WiFi LAN involves monitoring the packets for useful MAC addresses, and a small additional effort is then expended in extracting IP addresses. It's just radio.

If your neighbour, who just bought his first wireless computer, can't get an IP address when he connects to your otherwise open LAN, he can't access the Internet through your service. You're safe from him leeching your Internet service.

But what of his son, who hacks as a hobby? Once he gets past your MAC address filter, finding out what IP addresses are being used is trivial. He probably won't even notice that you disabled DHCP. And since he hacks, he's probably got nefarious intent, maybe leeching WiFi so he can hack a distant Internet server, using your service of course.

Maybe the FBI is targeting his activities, so he's borrowing your service. When they see his new IP address (your service), who gets blamed? Probably you.

Oh yeah - if you have DHCP disabled on your LAN, and you carry your laptop to your friends house, how are you going to get an IP address? Are you going to manually setup an address there? Then change it back when you come home again? Have fun. What about to your local hotspot, where DHCP is the only way that you can get an address?

I know who I would worry about, when I assess the dangers associated with Internet connectivity, and with WiFi networking. Static IP Addresses, when used as a security device on a WiFi LAN, are just another form of security by obscurity, plus inconvenience to you. Use WPA / WPA2, not WEP, and properly layered security, and forget about other WiFi security devices. Any hacker who can get through WPA (and that will happen one day) won't be fazed in the slightest by fixed IP addressing.

>> Top

MAC Address Filtering

The Media Access Control, or MAC, Address is one of the most universally present identity features in computer networking. Whether your computer uses Internet Protocol (the default and preferred protocol) or IPX/SPX or NetBEUI (possible alternates), as its Layer 3/4 transport, each networking device on your computer will have a MAC Address. Some devices will even have 2 MAC addresses, and here's where a problem starts. Besides the Universally Administered Address (UAA), which is assigned to a network device when it is assembled at the factory, some devices will be assigned a Locally Administered Address (LAA) by the network administrators, when a network is being setup.

Setting up an LAA is trivial in nature. The hard part is deciding what address to use. Once you decide that, just run the Network Adapter Settings Wizard. Depending upon the vendor, the ability to assign a LAA will be somewhere in the wizard. For 3Com, for instance, the Advanced tab will have a value "Network Address". TYpe in the LAA that you wish to use on the adapter in question, hit the OK buttons a couple times, and you're good to go.

If you change the MAC address of the WAN connection on your NAT router, you're setting a LAA there.

One of the most common security selections, when you setup a router, is the ability to filter by client MAC address, and permit network access to a select few addresses. Like hiding the SSID beacon, filtering by MAC address is just another form of security by obscurity. It's similar in effect to disabling DHCP, and manually issuing IP addresses to all computers.

An attacker who is interested in connecting to your WiFi network has only to learn the MAC address of a device on your network, and assign the observed address. As described above, assigning an address is a trivial exercise; and learning an address is the same. Learning an address is simply a prerequisite in interesting exercises such as a Man In The Middle attack, or WEP cracking.

The bottom line? MAC address filtering is probably the lamest form of WiFi security that you can try. It's easy to do, but easy to bypass too.

>> Top

Security By Obscurity

The principle of Security By Obscurity, or hiding yourself from the bad guys, has been around for quite a few years. The English comedy troupe Monty Python provided a light-hearted, yet not entirely irrelevant, discussion about this issue, How Not To Be Seen.


In this film we hope to show how not to be seen. This is Mr. E.R. Bradshaw of Napier Court, Black Lion Road London SE5. He can not be seen. Now I am going to ask him to stand up. Mr. Bradshaw, will you stand up please? (In the distance Mr. Bradshaw stands up. There is a loud gunshot as Mr. Bradshaw is shot in the stomach. He crumples to the ground.) This demonstrates the value of not being seen.


Years back, folks would claim that they were never online for more than a few minutes, and they turned their computer off when they weren't online.

They would claim safety by using dial-up, and later by using dynamically addressed broadband. Dynamic addressing was thought to be safer, because with a frequently changed IP address, the bad guys could never find you.

One of the selling points of PPPoE, which let the DSL Broadband ISPs oversell their customer base against their IP pools, was the "dial-up experience", as if PPPoE customers wanted a new IP address every day. Some customers actually believed that argument. Remember that Cable Broadband is that way routinely.

Nobody ever talked explicitly about getting a new IP address that had apparently already been noticed by the bad guys. Yet that was always a possibility; any "new" address that you get has probably been used by somebody. In any mature pool of dynamic addresses, most or all have probably been noticed by the bad guys in some way.

A well known and controversial security consultant provides a free scanning service, to check out your computer or router. His service will tell you if your computer or router is providing information to the internet, gratuitously, which would make you visible to those with dishonourable intent.

Steve Gibson's Shields Up! will probe your public ip address, whether your computer or router, checking for open and replying ports. It will then advise you how exposed you are, from observing how many of your ports are open, or are replying to his probes.

To the Shields UP! scanning service, the most secure configuration is a computer or router that does not respond to any probes, simply discards them. This condition is called, by Steve, "Stealth Mode". The idea about "stealth" is that your computer or router shouldn't reply to any connection attempt, to say "no connection available here", which would obviously verify to a bad guy that there is a host at your ip address.

(Cut to another area, however this time there is a bush in the middle.) This is Mr. Nesbitt of Harlow New Town. Mr. Nesbit, would you stand up please. (Nothing happens.) Mr. Nesbitt has learned the first lesson of not being seen - not to stand up. However, he has chosen a very obvious piece of cover. (The bush explodes and you hear a muffled scream).


Unfortunately, if there was no host at your ip address, a router upstream from you would respond, with "Destination address unreachable", to any probes. By not replying to probes at all, you are confirming that your ip address is in use (and the router has been routing the probes to you), but you simply chose not to answer. To a bad guy, this may make you even more interesting.

Also unfortunately, there are many ways to probe your ports. Just because your computer / router doesn't respond to a proper "TCP connect" request doesn't mean that it won't necessarily respond to (or can't be detected from) a SYN, FIN, or UDP scan.

(Cut to another scene with three bushes.) Mr. E.V. Lambert of Homeleigh, The Burrows, Oswestly, has presented us with a poser. We do not know which bush he is behind, but we can soon find out. (The left-hand bush explodes, then the right-hand bush explodes, and then the middle bush explodes). (There is a muffled scream as Mr. Lambert is blown up.) Yes, it was the middle one.


Bad guys, that don't care whether there is anything at your ip address, will attempt to hit you anyway. Security By Obscurity became still less relevant on January 25, 2003, with Slammer!. Slammer didn't check for anything at any given ip address, it just sent itself to randomly chosen addresses. It infected 90% of its potential targets - worldwide - in 10 minutes, by simply not caring what it was invading. By its very simple design, its code became lean, mean, and very fast.

Slammer's target base was fortunately limited, as it was aimed at a special type of server. Even so, it brought down massive portions of the internet infrastructure, with the huge volume of traffic that it had generated, within 15 minutes after it hit the internet.

  • The tiny worm hit its first victim at 12:30 am Eastern standard time.
  • By 12:33 am, the number of slave servers in Slammer's replicant army was doubling every 8.5 seconds.
  • By 12:45 am, huge sections of the Internet began to wink out of existence.

Read more about this milestone in the history of malware, in this fascinating tale by Wired Magazine Slammed! An inside view of the worm that crashed the Internet in 15 minutes.

Blaster, a successor to Slammer, that uses an RPC service vulnerability that was present in Windows NT operating systems (KB823980): until it was patched, continues to infect (unpatched) hosts occasionally. Look at any of the Microsoft.public.*.* Usenet discussion groups. Even now, occasionally somebody asks about their computer shutting down with "NT Authority..." or "RPC Call...".

Sasser, a successor to Blaster, uses an LSASS vulnerability that was present in Windows NT operating systems until it was patched. Sasser was featured on TV in 2005 - in the BBC Video Jacques' Hack Attack. The computer featured in the video was online for less than 30 minutes, because it crashed after loading 3 worms (Sasser being just 1 of the 3), and the resulting network and system traffic overloaded it. The first worm hit that unprotected computer almost immediately after it was connected to the internet.

In typical british melodrama (and to us Yanks, Spencer Kelly, of the BBC, may sound vaguely similar to John Cleese, but the BBC is not Monty Python):

How long would it be before we were hit by something nasty on the net? Hours, minutes? As it turned out - eight seconds!


If your computer is vulnerable to an attack, and a Blaster or Slammer type worm is sent in your direction, you WILL be infected. Stealth or not.

I've been trying to make an anagram out of "security by obscurity", to something evocative, like "botnet membership" - but no luck so far. Anybody out there want to help? I'll send you a t-shirt (and attach a link here to your blog), if you can come up with an interesting anagram.

Regardless of whether it makes an anagram or not, Security by Obscurity, if it's your main protection, will surely lead into botnet membership. Making your computer into yet another distributor of important email - like "Your l0an has been @pproved", "che@p mesdctations", and "V!agra".

>> Top

Disabling the SSID

Many security experts think that broadcasting your SSID, which identifies your WiFi LAN to all of your wireless neighbors, creates a substantial security risk to your LAN. This concept is similar to the justification of stealthing your IP address, as I discussed in Security By Obscurity.

You can disable the broadcast of the SSID in the beacon. This will make your AP invisible, as long as there are no stations associating with it. As soon as any stations (wireless computers) associate with the AP, the SSID will be out there for everybody to see.

Associating with an AP, with SSID beacon disabled, can be done, as long as the SSID is known to the station wishing to associate. But the process is complex, and generates a lot of excess traffic. This traffic exposes your SSID even more than if you had been broadcasting the SSID in the first place.


And, as I said above, you can hide yourself, as long as there is nobody connecting to you. But what's the purpose of having a AP with no clients? And as soon as you have clients, you'll be visible again. Only the truly lame script kiddies don't know about NetStumbler. You won't be invisible to NetStumbler, or similar tools.

Disabling SSID beaconing MAY make you invisible in normal WiFi client manager displays. This is both good, and bad.
  • The upside is that your neighbour, who knows barely enough to find the Ethernet port ("big fat phone plug thingy") on his cable modem, won't know that you're there. You're safe from him trying to hack your WLAN.
  • The downside is that your neighbour doesn't know that you're there. If he picks the same channel that you're using, and your bandwidth suffers because you have to share the channel, you can only blame yourself. Your neighbour will probably end up taking his WiFi Access Point back to the store, because "it doesn't work right". That, too, will be your fault. He won't even know that you're in the area, and come ask for advice, because you're "invisible".
  • A second downside is that you won't be invisible to your neighbour's son, the l33t hax0r. Any script kiddie, or true hacker with any experience, will know about NetStumbler and similar products. He'll scan the channels, and make a list of Access Points, and their SSIDs.
    1. APs with SSID "Linksys", "Netgear", "My Network". Ho hum, so many of those. Check them out when I'm really bored.
    2. APs with obscure SSIDs. Probably well protected - stay away.
    3. And here's an AP with no SSID. This tells Mr L33t Hax0r two things.
      • The owner doesn't want to be seen, so he has something to hide.
      • The owner thinks he can't be seen. If he's that dumb, I'll bet he won't have his AP properly protected either.
      Now we're talking! Let's have some fun with this one.


The reason for having channel number and relative signal strength, in the client manager (WZC and similar products) displays, is to allow your neighbour, when he sets up his WiFi LAN, to pick a channel that is less used. If your neighbour can't see your Access Point on the channel, because you want to be invisible, how is he going to, reliably, pick a less used channel?

Did you ever see the movie The Invisible Man? What were some of the first things that Nick Halloway learned from experience?
  • Don't wear clothes in public, if you want to be invisible.
  • Don't expect folks not to run into you, if you want to walk around in a crowd.

If you think about it, both practices are pretty antisocial. Walking around naked, and walking around invisible, are not keeping to social norms. Neither is using WiFi "naked" (without proper security), or "invisible" (SSID beaconing disabled).

>> Top