<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:iweb="http://www.apple.com/iweb" version="2.0">
  <channel>
    <title></title>
    <link>http://www.willhackforsushi.com/Home/Home.html</link>
    <description> </description>
    <generator>iWeb 2.0.3</generator>
    <item>
      <title>Nerdy 802.11n Threat Podcast</title>
      <link>http://www.willhackforsushi.com/Home/Entries/2008/7/18_Nerdy_802.11n_Threat_Podcast.html</link>
      <guid isPermaLink="false">4671d543-754e-415d-bb46-cfccf7d79390</guid>
      <pubDate>Fri, 18 Jul 2008 13:14:39 -0400</pubDate>
      <description>The good people at Network World called the other day and invited me to do a quick podcast about my work on identifying 802.11n threats.  This follows &lt;a href=&quot;http://www.airwave.com/media/webcasts/%253Ffile%253Dairwave-webcast-new-risks-in-80211n-07-08%2526ver%253Dhome&quot;&gt;a webcast I did for Airwave&lt;/a&gt; (registration required) and an article by &lt;a href=&quot;http://www.networkworld.com/newsletters/wireless/2008/071408wireless2.html&quot;&gt;Joanie Wexler in Network World&lt;/a&gt;.&lt;br/&gt;&lt;br/&gt;&lt;a href=&quot;http://www.networkworld.com/podcasts/newsmaker/2008/071808nmw-wright.html&quot;&gt;Check out the 11 minute podcast on the Network World site.&lt;/a&gt;  &lt;a href=&quot;../About.html&quot;&gt;Comments&lt;/a&gt; are always welcome.&lt;br/&gt;&lt;br/&gt;-Josh</description>
    </item>
    <item>
      <title>BTfind Sneak Peek - Bluetooth Device Locating</title>
      <link>http://www.willhackforsushi.com/Home/Entries/2008/6/12_BTfind_Sneak_Peek_-_Bluetooth_Device_Locating.html</link>
      <guid isPermaLink="false">76d85131-f99d-4d2f-a5f0-544fd906c5b7</guid>
      <pubDate>Thu, 12 Jun 2008 13:59:56 -0400</pubDate>
      <description>&lt;a href=&quot;http://www.kismetwireless.net/&quot;&gt;Mike Kershaw&lt;/a&gt; and I have been working on a tool for the discovery and analysis of Bluetooth devices.  Spawned by an assessment of the current tools available for Bluetooth analysis, we were disappointed to learn that there were no tools available to help an administrator both enumerate Bluetooth devices and locate them using RSSI analysis.  Initially we looked at adding this functionality to the &lt;a href=&quot;http://labs.arubanetworks.com/project/bluescanner&quot;&gt;BlueScanner&lt;/a&gt; tool that I maintain for Windows XP systems.  Unfortunately, none of the Bluetooth stacks from Microsoft, Widcomm/Broadcom, BlueSoleil or Toshiba support RSSI reporting of discovered devices (Widcomm does partially, but not in a way that is particularly useful for device locating analysis).  So we started over again from scratch, developing a tool using the Linux BlueZ stack.&lt;br/&gt;&lt;br/&gt;</description>
    </item>
    <item>
      <title>RSA2008 - 802.11n Risks Presentation</title>
      <link>http://www.willhackforsushi.com/Home/Entries/2008/4/11_RSA2008_-_802.11n_Risks_Presentation.html</link>
      <guid isPermaLink="false">f3c8c035-9617-4e08-9060-1a84fe91d751</guid>
      <pubDate>Fri, 11 Apr 2008 08:44:33 -0400</pubDate>
      <description>Yesterday morning I had the opportunity to present my research on the threats introduced with 802.11n networks to the early-morning crowd at the RSA2008 conference.  This was my second year presenting at RSA, and the second time I got the 8:00 am crowd.  I enjoy this speaking slot for three distinct reasons:&lt;br/&gt;&lt;br/&gt;I get to set the bar for other speakers by being first of the day;&lt;br/&gt;If people come to the session after a night of parties, they must *really* want to hear what I have to say;&lt;br/&gt;People are usually eating, which means fewer questions (just kidding).&lt;br/&gt;&lt;br/&gt;In the presentation I did a quick review of how 802.11n is revolutionizing wireless LAN deployments, making it possible to supplant wired deployments altogether with an 802.11n wireless network.  This is possible not only through the performance benefits we get with 802.11n, but also with the increased reliability with the use of MIMO and other physical-layer enhancements.  Next, I examined several threats that I see in 802.11n:&lt;br/&gt;&lt;br/&gt;Dramatic lack of useable spectrum in the 2.4 GHz band with 40 MHz transmitters;&lt;br/&gt;Extended range with MIMO vs. SISO (single input, single output) transmitters, exacerbated with the need to deploy MIMO networks in locations that support backward-compatibility with SISO clients;&lt;br/&gt;Increased difficulty and reduced likeliness that channel-hopping WIDS systems will detect a short-lived attack with the explosion of 2.4 GHz and 5 GHz channels that need to be monitored at 20 and 40 MHz independently;&lt;br/&gt;WIDS rogue AP evasion through leveraging high-throughput Greenfield Mode that cannot be detected by existing 802.11a/b/g WIDS sensors;&lt;br/&gt;A new built-in denial-of-service vulnerability against 802.11n and block acknowledgement;&lt;br/&gt;New 802.11n client and AP driver flaws from the increased complexity in frame handling.&lt;br/&gt;&lt;br/&gt;My sincere thanks to everyone who attended the presentation.  I've &lt;a href=&quot;http://www.willhackforsushi.com/presentations/rsa2008-wright.pdf&quot;&gt;posted the slides&lt;/a&gt; on the &lt;a href=&quot;../Publications.html&quot;&gt;Publications section&lt;/a&gt; of the site.  The &lt;a href=&quot;http://www.metasploit.org/&quot;&gt;Metasploit&lt;/a&gt; fuzzing tools I wrote for testing 802.11n-specific features are posted in the &lt;a href=&quot;../Offensive.html&quot;&gt;Offensive&lt;/a&gt; security section.&lt;br/&gt;&lt;br/&gt;I'm hoping to return to RSA again next year, hopefully presenting on some research I have been doing on using software-defined radios for new attacks against wireless protocols.  As always, &lt;a href=&quot;../About.html&quot;&gt;I welcome questions/comments/concerns&lt;/a&gt;.&lt;br/&gt;&lt;br/&gt;-Josh</description>
    </item>
  </channel>
</rss>
