Karlnet
[Top] [All Lists]

Re: [Karlnet] RE: [isp-wireless] Re: DSSS security hole anounced

To: Karlnet Mailing List <karlnet@WISPNotes.com>
Subject: Re: [Karlnet] RE: [isp-wireless] Re: DSSS security hole anounced
From: Chris Conn <cconn@abacom.com>
Reply-to: Karlnet Mailing List <karlnet@WISPNotes.com>
Date: Thu, 13 May 2004 15:00:00 -0400
List-post: <mailto:karlnet@WISPNotes.com>


Dan Metcalf wrote:

Chris,

I wasn't thinking about the DOS, but rather the ability of karlnet to
change the DSSS code to completely remove that possibility and maybe
prevent it from being sniffed using kismet

Dan

Hello,


Have you actually tried Kismet? It will show perhaps 5-10% tops of the traffic (still enough for the patient people). Anyway, turn wep on and you will get rid of the Kismet problem since it waits for weak (unencrypted) WEP IVs, and it is my understanding that Karlnet does not send the IVs in the clear. On top of that, if you are using an Orinoco radio, it does not send weak IVs...

Chris



-----Original Message-----
From: karlnet-bounces@WISPNotes.com

[mailto:karlnet-bounces@WISPNotes.com] On


Behalf Of Chris Conn
Sent: Thursday, May 13, 2004 1:55 PM
To: Karlnet Mailing List
Subject: Re: [Karlnet] RE: [isp-wireless] Re: DSSS security hole

anounced


Of course I still monitor the list, we still utilise Karlnet

extensively!


Probably right Mr Metcalf that the PHY layer can be denied service

using


this method.  That is assuming that the Turbocell protocol actually
defers eternally, although I believe Karlnet has put a maximum radio
deferral time way back in version 3.75 =)  It may slow things down a

bit


perhaps.  I don't really consider the Karlnet MAC to be very compliant
with any real standard.

Chris


Support wrote:



Thanks for the reply Chris, nice to know you are still monitoring

the list.


RLM

-----Original Message-----
From: karlnet-bounces@WISPNotes.com
[mailto:karlnet-bounces@WISPNotes.com]On Behalf Of Chris Conn
Sent: Thursday, May 13, 2004 1:35 PM
To: Karlnet Mailing List
Subject: Re: [Karlnet] RE: [isp-wireless] Re: DSSS security hole
anounced


This vulnerability requires the device to use Carrier Sense Multiple Access with Collision Avoidance, the key here being the Collision Avoidance. Karlnet does not use CA since it is based on a polling

MAC


and therefore does not utilize CSMA/CA.

So sleep easy, if actually you are to believe that someone would

truly


want to try this.


Dan Metcalf wrote:




I wonder if karlnet code could change the DSSS code




-----Original Message-----
From: Ivan Korshun [mailto:ivan@vector.kharkov.ua]
Sent: Thursday, May 13, 2004 2:14 PM
To: isp-wireless@isp-wireless.com
Subject: [isp-wireless] Re: DSSS security hole anounced

Barry,

It is known already more than 3 years ...
I have termed it a "sterilizer"

Solution of a problem "sterilizer":
- change one bit in firmware PC card (Prism 2.5 e.t.s.)
or
- possibility to change the code DSSS by the user,
the code DSSS could be changed in firmware till 1997

OFDM (802.11a/g) has much more problems than DSSS...

-Ivan




Hello WISP,

http://www.auscert.org.au/render.html?it=4091

Affects DSSS systems. Also on slashdot......

--
Best regards,
Barry                          mailto:isplists@whywait4wires.com

___________

The ISP-WIRELESS Discussion List ___________



To Join: mailto:join-isp-wireless@isp-wireless.com
To Remove: mailto:remove-isp-wireless@isp-wireless.com
Archives: http://isp-lists.isp-planet.com/isp-wireless/archives/
To unsubscribe via postal mail, please contact us at:
Jupitermedia Corp.
Attn: Discussion List Management
475 Park Avenue South
New York, NY 10016

Please include the email address which you have been contacted

with.


--
[This E-mail scanned for viruses by Declude Virus]





_______________________________________________
Karlnet mailing list
Karlnet@WISPNotes.com
http://lists.wispnotes.com/mailman/listinfo/karlnet

_______________________________________________
Karlnet mailing list
Karlnet@WISPNotes.com
http://lists.wispnotes.com/mailman/listinfo/karlnet

_______________________________________________ Karlnet mailing list Karlnet@WISPNotes.com http://lists.wispnotes.com/mailman/listinfo/karlnet -- [This E-mail scanned for viruses by Declude Virus]





_______________________________________________
Karlnet mailing list
Karlnet@WISPNotes.com
http://lists.wispnotes.com/mailman/listinfo/karlnet

<Prev in Thread] Current Thread [Next in Thread>