Follow Us

Windows 7 tool can turn laptop into rogue Wi-Fi access point for hackers

SoftAP feature in the new OS could threaten enterprise security

Microsoft Windows 7 contains software that can turn a laptop into a rogue Wi-Fi access point that masks the entry of hackers onto the corporate network, according to an engineer.

Windows 7 contains a "SoftAP" feature, also called "virtual Wi-Fi" that allows a single PC to function simultaneously as a Wi-Fi client and as an AP to which other Wi-Fi-capable devices can connect.

The capability is handy when users are wearing their consumer hats and want to share music and play interactive games during their off hours.

But it also can allow onsite visitors and parking-lot hackers to piggyback onto the user's laptop and "ghost ride" into the corporate network unnoticed.

So says Gopinath KN, director of engineering at AirTight Networks, a wireless intrusion-prevention system (WIPS) and service company that has analysed the SoftAP capability. He says a Windows 7 device performs Port Address Translation, allowing a single public IP address to be used by many LAN devices (and exposing only certain Layer 4 port numbers).

So devices that associate with the Windows 7's virtual AP will be bridged into the wired network unseen because they will be hidden behind the "master" IP address.

The issue is more dangerous than Wi-Fi's peer-to-peer, or ad hoc, mode, says AirTight Vice President of Product Management Sri Sundarilingam. In peer-to-peer mode, the only data exposed are the local files and applications on participating users' laptops - not the whole corporate network.

AirTight, of course, has a vested interest in discussing the SoftAP vulnerability. WIPS products such as AirTight's and those from competitors such as AirMagnet and Motorola AirDefense scan the airwaves for unauthorised devices in the airspace - such as a Windows 7 SoftAP - and flag them as rogues that clients are not permitted to associate with.

So using WIPS is one protective option. Another is to provision the laptop with the SoftAP capability turned off and deny all Windows 7 users system administration rights so that they can't turn it back on.

Still another is to install mobile device management and/or security agent software on the laptop that enforces centralised policies such as disabling soft APs and ad-hoc Wi-Fi modes. Such software is available from a quickly growing number of companies in the mobile device management space. And AirTight, in addition to offering WIPS, also has such a client agent it calls SpectraGuard SAFE, which the company says can be used on any Wi-Fi, Bluetooth, 3G, infrared or WiMAX network.



Comments

Force Factor said: When we try to use the new magnifier with high-contrast which I dont use as I dont need 133 dpi is fine for me it goes back to the old screen magnifier which if I read correctly is a feature rather than a bug Doesnt makes much sense to me maybe the new magnifier should work even if aero is not the default themed no I mean if you have the hardware capability why not use themAs a part-blind legally blind user I thank your team for the high-dpi custom settings although it woul




Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Optimise Performance For Global eCommerce

Global is all the rage: eBusiness teams are feverishly building new international initiatives in...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Techworld UK - Technology - Business

Part 2 of your journey to virtualisation

You can still access part 2 of our virtualisation journey - explore how you can improve your servers, storage and networks by developing your infrastructure.

Watch now...
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *