Searching_ _ _
April 24th, 2009, 07:55 PM
-{ Quote: " This type of attack typically begins with a remote exploit on a Windows machine visiting an infected Website, which then uses the machine as a "wireless drone," he said. "That lets the attacker turn on the machine's wireless interface, look around, and exploit it," Skoudis said. "This is a tremendously useful attack for bad guys."
The good news is that this type of attack is tough to execute in Windows XP. But not so for Vista or Windows 7, where the API calls make it relatively simple to write code that talks to the wireless interface, according to Skoudis.
Tools such as Vista Rfmon, which puts Vista into monitoring mode, can be used to sniff wireless traffic to and from the infected client. "The attacker uses the command shell to turn the wireless interface on to install Vista Rfmon to sniff all that's going on wirelessly with the client...and that can be done [from] halfway around the world."
And if the victim's machine has access to other wireless access points, the attacker can hop from AP to AP, he said.
" }-
Dark Reading (http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=217100332&subSection=Vulnerabilities+and+threats)
The good news is that this type of attack is tough to execute in Windows XP. But not so for Vista or Windows 7, where the API calls make it relatively simple to write code that talks to the wireless interface, according to Skoudis.
Tools such as Vista Rfmon, which puts Vista into monitoring mode, can be used to sniff wireless traffic to and from the infected client. "The attacker uses the command shell to turn the wireless interface on to install Vista Rfmon to sniff all that's going on wirelessly with the client...and that can be done [from] halfway around the world."
And if the victim's machine has access to other wireless access points, the attacker can hop from AP to AP, he said.
" }-
Dark Reading (http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=217100332&subSection=Vulnerabilities+and+threats)