Return Homepage: Technology Information
Browse by pages:Technology Information by Pages
Search more in this site:
Google
 
You can also see: Previous Article Next Article

Design flaw in wireless VoIP handsets endanger the enterprise

Author:Posted by George Ou @ 9:44 pm

Date:February 20th, 2008

Source Site:zdnet



February 20th, 2008

Design flaw in wireless VoIP handsets endanger the enterprise

Posted by George Ou @ 9:44 pm

Categories: Zero-day attacks, Cisco, Vulnerability research, Wi-Fi security, Wireless, Passwords

Tags: VoIP, Password, WPA-PSK, Handset, Authentication, Character, Wireless, Flaw, PEAP, Badge

Update 2/23/2008 - Cisco confirms vulnerability in 7921 Wi-Fi IP phone

Security conscious businesses and organizations who implemented 802.1x/EAP enterprise-grade authentication are at risk with certain implementations of wireless LAN VoIP handsets. I have verified that Vocera Communications is one of the vulnerable vendors and I have heard from other security researchers that Ciscos wireless VoIP handsets have this design flaw as well. Im trying to get official responses from Vocera and Cisco. Based on the Voceras own PDF documentation on page 55, we have the following admission.

PEAP is a two-part protocol. In the first part, an authentication server and a client set up an encrypted Transport Level Security (TLS) tunnel. The badge accepts a certificate from the authentication server, but does not validate it because of the processing overhead required.

From a security standpoint, this is a reckless design decision that undermines the whole purpose of using strong EAP authentication with asymmetric cryptography in the first place. By skipping the certificate checking process, it effectively reverts 802.1x PEAP authentication to the insecure level of Ciscos proprietary LEAP authentication. What this means is that a client (the wireless VoIP phone in this case) will assume that the wireless access point and its backend authentication infrastructure is authentic and not check its certificate for authenticity due to processing overhead.

By not validating the server certificate, the clients hashed password would be sent in the clear to an attacker trying to hack the network. Because the strength of hash passwords depend solely on the complexity and length of the password, hashed passwords typically cant withstand a password dictionary attack for more than a few hours. There are some EAP implementations where hashing isnt even used and in those cases the password would immediately be exposed as clear text under this attack. Once the password is cracked and the username is already known due to the fact that it was sent in the clear, an attacker not only has the means to enter a network but they have the user credentials to access all the servers and applications. From a security stand point, this is a worst case scenario. If Domain Admin passwords were compromised in this matter, then the keys to the kingdom would be compromised.

Temporary workarounds:
Do not use 802.1x/EAP authentication on these vulnerable clients that dont perform certificate checks and use WPA-PSK on these vulnerable embedded devices. WPA-PSK mode is also much faster for these computationally-challenged embedded devices which cuts down on startup and roaming times. If you have to use LEAP, certificate-unverified PEAP, or certificate-unverified EAP-FAST mode, you have to assume that the password hash can be exposed to an attacker.

Note: LEAP makes zero effort to protect the hashed password since it is sent in the clear. Many implementations of EAP-FAST are fundamentally weak because they employ anonymous server certificates which can be made up by anyone. PEAP can be secure if its implemented and deployed correctly where the digital certificates signer andsubject field (server name)are properly verified by the client.

If you still have to use these vulnerable clients in this vulnerable EAP implementation, then the password you use has to be a random 32-character alpha-numeric password to achieve roughly 128 bits of entropy. If 64 bits of entropy is enough, then a random 16 character alpha-numeric password will suffice. Special characters are not recommended since it might cause some compatibility problems with some wirelessinfrastructure or devicesand the keypads on mobile devices may not be able to enter them.

If youre using WPA-PSK, you can reasonably use a random10-16 character alpha-numericPSK (Pre-Shared Key)passphrasebecause its extremely time consuming and CPU intensive to run a dictionary attack against WPA-PSK.Onedownside to WPA-PSK is that every client uses the samePSKso if you lose one of those devices configured with the PSK, you have to re-key every client device. The other downsideto WPA-PSK mode is that a compromised PSK allows the attacker to decrypt otherWPA-PSK sessions that use the same key. There is a way to get around these two shortcomings by using Dynamic PSK mode from Ruckus which uses a very practical and effective per-client PSK, but thats only for the Ruckus products.

Conclusion:
Until these design flaws in the client-side PEAP and EAP-FAST implementation are solved, users will not be able to use the reasonably short passwords that they currently use in authentication directories such as Active Directory or the short pins they use with their phones. Even if these flaws are fixed, the computational resources required for certificate validation may make these embedded devices too slow for roaming. Fortunately, the PMK caching and pre-authentication features in the WPA2 standard will permit seamless roaming if your infrastructure and clients support it.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.


This article is: Design flaw in wireless VoIP handsets endanger the enterprise

Tip: We only provide abstract for users. If you want to read the full article, please click the Full Article Link.


You may be interested in these articles:

Financiers question corns day in sun for ethanol

Martin LaMonica   Year:June 20, 2007 12:32 PM PDT   Source Site:newsblog

NEW YORK--To hear money people talk about it, the numbers for investing in corn-based ethanol arent looking as good as they did only a year ago. Biofuels have been the top recipient of investment in a multi-year clean tech, or green tech, expansion. But some indicators show that projects around corn-based ethanol may run into speed bumps, even though the long-term prospects for biofuels are positive, according to speakers at the Renewable Energy Finance Forum here on Wednesday. For one thing, the price of corn is on the rise, as farmers look to capitalize on government incentives that favor domestic fuel production. About a year ago, corn was about 2 dollars a bushel but is now hovering near 4 dollars a bushel. Ethanol can be made from a variety of plant-based "feedstocks," including...
...

Apple issues Apple TV security fix

Robert Vamosi   Year:June 20, 2007 11:40 AM PDT   Source Site:newsblog

Apple today issued an update for its Apple TV device. The update fixes the mDNSResponder buffer overflow vulnerability, CVE-2007-2386. This vulnerability was patched last month in Security Update 2007-05 for desktop and laptop users of Apple Mac OS X 10.4 up to 10.4.9. The Apple TV device will automatically pick up this update during its weekly schedule. Depending on the day that your Apple TV device checks for updates, this process may take up to a week to complete. Should you want the update sooner, it is also possible to force a manual update by using the TV interface, selecting "Settings," then "Update Software." ...
...

And the winner is...diesel?

Candace Lombardi   Year:June 20, 2007 11:32 AM PDT   Source Site:newsblog

Is diesel the answer to more stringent emission standards? Apparently it is, at least from the perspective of automakers. Ford India announced Wednesday that it is launching a diesel version of the Ford Fiesta, the latest in a string of similar announcements in the industry. "(This car) will dramatically change customers perceptions about the traditional diesel vehicle. The car is designed to deliver responsive acceleration, outstanding fuel economy, and reduced emissions consistent with future norms," Scott McCormack, vice president of Ford India, said in a statement. While environmentalists, consumers and politicians continued to discuss ethanol, hydrogen and electricity, the auto industry, it seems, had already decided and has been making plans for its short-term answer to the ene...
...

The Open Source CEO on the CNET Blog Network

CNET News.com Staff   Year:June 20, 2007 11:32 AM PDT   Source Site:newsblog

In a new series, Matt Asay of the CNET Blog Network interviews top CEOs about surprises and challenges theyve faced running open source companies. Check out his interviews with MuleSources Dave Rosenberg, Hyperics Javier Soltero, MySQLs Marten Mickos, Alfrescos John Powell and more at The Open Road. And keep up on open source and other topics in posts from industry leaders, pundits and experts at the CNET Blog Network. ...
...

Getty Images buys music licensing start-up Pump Audio

Caroline McCarthy   Year:June 20, 2007 11:08 AM PDT   Source Site:newsblog

Getty Images, which made a name for itself as a stock photography clearinghouse, announced Wednesday it has purchased Pump Audio, which licenses independent music to advertising and media clients. The price of the acquisition, according to a release from Getty, was $42 million. This is the most recent in a series of moves on Gettys part to expand beyond photography and into the digital media sector. Last month, it launched a new division in the company to license video footage and other multimedia content, and over the past few months has chalked up a string of acquisitions, from amateur photography site Scoopt to smaller competitors like iStockphoto. The Pump Audio buy, however, marks Gettys first foray into music licensing. For Pump Audio, which made a splash at last years OnHoll...
...

Verizon Fios hits 1 million subscriber mark

Marguerite Reardon   Year:June 20, 2007 10:21 AM PDT   Source Site:newsblog

CHICAGO--Verizon has signed up its one-millionth Fios subscriber, CEO Ivan Seidenberg said Wednesday during his keynote speech here at the NXTcomm tradeshow. Verizons been building its Fios all-fiber network throughout its territory for the past three years. The network takes fiber directly to peoples door step, and provides near limitless bandwidth that can be used to deliver a triple play of services including high-speed Internet connectivity, telephone service, and TV. The company already offers Internet service that runs at 50 megabits per second. And its testing service at 100Mpbs. While ATT has opted to only take fiber into the neighborhood and use existing copper lines to deliver service to homes, Verizon believes the all-fiber network will give it the headroom it needs to ensur...
...

United Airlines computer snag delays takeoffs

Candace Lombardi   Year:June 20, 2007 9:23 AM PDT   Source Site:newsblog

United Airlines was forced to temporarily ground all flights on Wednesday morning after experiencing a computer system failure, the Federal Aviation Administration has confirmed. The outage took place between 6 a.m. and 8 a.m. PDT on Wednesday. "It was their system, not ours. It was their decision whether they would go up or not. They are now up and running," an FAA representative said. A total of 24 domestic flights were canceled, and 268 domestic and international flights were delayed by an average of one and half hours, according to United spokeswoman Robin Urbanski Janikowski. "We do not know the cause of the outage, and its something that we will investigate. The computer outage affected the systems that United uses to dispatch flights for departure," Janikowski said in an e-mai...
...

PHP exploit code plants itself in GIF

Dawn Kawamoto   Year:June 20, 2007 9:07 AM PDT   Source Site:newsblog

Security researchers on Tuesday found PHP exploit code embedded in a GIF on a major image hosting site. The exploit code slipped through the proverbial gates with the aid of a legitimate image at the beginning of the file, according to a posting on the Sans Internet Storm Center. "It is a clever way to pass exploit code to others without it setting off alarms or attracting attention all while bypassing network security tools," the Sans security blog noted. Malicious attackers planted PHP coded exploit script within an image file. PHP is often used as a programming language to create dynamic Web sites. Once this type of malicious GIF is uploaded to a server, it can create havoc by remotely allowing more exploits to be deployed on the system, said Johannes Ullrich, chief research office...
...

iPhone to feature special YouTube player

Caroline McCarthy   Year:June 20, 2007 7:53 AM PDT   Source Site:newsblog

(Credit: Apple) Apples made it official: the iPhone will have full-blown YouTube integration. According to the iPhone Web site, the much-anticipated handset will include "a special YouTube player that you can launch right from the home screen." iPhone owners can now load and browse videos from the video-sharing site as well as e-mail them to their friends. This comes less than a month after Steve Jobs announced that the companys Apple TV set-top box would also have built-in integration for the wildly popular YouTube. The iPhone, as we all know by now, hits stores at 6 PM ET on June 29. Thats next Friday! ...
...

Could YouTube, PirateBay and file sharing boost Sicko?

Greg Sandoval   Year:June 20, 2007 4:00 AM PDT   Source Site:newsblog

We could soon learn more about whether illegal file sharing is a friend or foe to a movie debut. Sicko, the documentary about the health-care industry from director Michael Moore is due to be released on Friday. To several thousand fans of YouTube, Google Video and The PirateBay, the movies opening came a week earlier. Thats when bootleg copies began cropping up at those places. Any studio exec will say each illegal download represents a lost ticket sale. Thats food out of the mouths of cinematographers, actors, costumers and best boys, the studio suit will huff. Not so, say those that download. Typically their argument goes something like this: The Internet promotes movies like nothing else. People who really enjoy a film they watch online will often plunk down cash for a DVD or mo...
...

MySpace officially launches instant messaging service

Caroline McCarthy   Year:June 19, 2007 9:00 PM PDT   Source Site:newsblog

MySpace has announced the official beta release of its MySpaceIM instant messaging service which soft-launched informally a year ago. According to a release from MySpace, over 17 million of the social networking sites 180 million members worldwide have installed the downloadable client. MySpace, which was acquired by News Corp. in 2005, used to operate a browser-based instant messaging service, which it has since phased out. Sample screenshots of MySpaceIM (Credit: MySpace) The MySpaceIM service competes with other ubiquitous and well-established instant messaging clients, like Yahoo Instant Messenger, Microsofts Windows Live Messenger, and the formidable AOL Instant Messenger. But MySpaceIM hopes to set itself apart from the pack with tight integration to the sites homepage and ...
...