Home ME Facebook ME LinkedIn ME Twitter map of ME logo

MET

CONTACT US | SUBSCRIBE | NEWSLETTER | RSS

 
Welcome, Guest |   Sign In   |   Register  
 
Print Email Page RSS Feeds

Posted Date: 1/5/2010

Don't Be Scared

By  Ben Halpert
"The security guys adequately scared everyone," was the feedback of one attendee at the 2009 Mobile Enterprise Executive Summit, held in Los Angeles this past November. While Jasyn Voshell, Enterprise Security Manager at Textron Inc., and I were hoping to leave a lasting impression, "scared" was not the goal.

Our session, entitled Securing WLAN and VoIP for the Mobile Workforce, incorporated two live demonstrations; one involved a Voice over Internet Protocol (VoIP) phone call and the other, a Wireless Local Area Network (WLAN) public hotspot environment.

For the VoIP demonstration, we used a free VoIP calling service to place a call between two computers. We used a third computer to intercept and record the conversation using a free software program downloadable from the Internet. Jasyn and I proceeded to have a conversation using our two VoIP-enabled devices. Subsequently, we played back the captured voice call for the audience to hear. When we placed the next demonstration call, each computer was loaded with a free program that automatically encrypts voice conversations. When we played the encrypted call back for the audience, all that was heard was static.

An "evil-twin" public hotspot threat environment was then created for the WLAN demonstration. The "evil-twin" is a fake network or wireless access point set up to trick wireless-enabled computing devices in the area to connect unknowingly and capture information or trick users into divulging authentication information (i.e. - username and password), personal information, and organizational sensitive information. For the WLAN demonstration we had one computer act as the "evil-twin" and another act as a typical user in a public hotspot environment.

One of the features of the free evil-twin program we used is that it forces all nearby devices with an active WiFi connection off their existing network and onto the "evil-twin" network. Several audience members were surprised to see their computers automatically reconnect to the "evil-twin" network we temporarily set up. We then disabled the freely available "evil-twin" software.

While some attendees were "...adequately scared..." others found the session contained an "intriguing demonstration to make a valuable point" and others "liked the interplay between speakers and the demos."

All of the software used in the session is freely available to anyone on the Internet. However, we do not recommend or condone using the tools except for demonstration purposes and with permission of the network owners, as appropriate.

See you at the 2010 Mobile Enterprise Executive Summit on November 3-5!

 



 

Ben Halpert CISSP, is an information security researcher and practitioner and writes monthly about security. Comments, questions and requests can be sent to him at editor@mobileenterprisemag.com; please include SECURITY in the subject line.

Rate this Content (5 Being the Best)
12345
Current rating: 0 (0 ratings)

 


Show Off the Rugged: Next Gen Devices Modernize the Field
5/15/2013 2:00:00 PM (EST)
Moderator:
Dorene Rettas, Publisher, Mobile Enterprise
Panelists:
Michael Ho, Regional Service Manager, Canon Canada Inc.
David Krebs, VP, Enterprise Mobility and Connected Devices Practice, VDC Research
Mika Majapuro, Product Marketing Manager, Honeywell
Wes Rupel, Co-Founder, President and Chief Technology Officer, Allegro Mobile Solutions
Savino Griesi, Co-Founder and Chief Executive Officer, Allegro Mobile Solutions
View On Demand

Mobilizing Your Ecosystem through BYOD and MAM
3/28/2013 2:00:00 PM (EST)

Moderator: 
Lori Castle, Editor In Chief, Mobile Enterprise

Panelists:
Chris Marsh, Principal Analyst, Yankee Group
Gabriel Weiss, Head of Interactive Marketing Technologies, Mitsubishi Electric

View On Demand

Mobile Engagement: Leveraging Cross-Channel Communications to Improve Business Operations Mobile Engagement: Leveraging Cross-Channel Communications to Improve Business Operations
5/15/2013
As enterprises recognize the need for a mobile strategy, there are many challenges to capitalizing on the opportunities. This paper explains why enterprises can and should embrace mobile engagement to help solve customer, partner and employee communication challenges.
Download Now

Mobile Application Management - Meeting the BYOD challenge with next-generation application and device management Mobile Application Management - Meeting the BYOD challenge with next-generation application and device management
5/1/2013
Discover how a well-designed Mobile Application Management (MAM) solution enables IT teams to achieve fine-grained control over mobile applications across a range of devices, over every type of network and deployment mode, without impinging on users' privacy rights or damaging end users' personal property.
Download Now


MEDIA KIT | CALENDAR OF EVENTS | EDITORIAL CALENDAR | PRIVACY STATEMENT | TERMS & CONDITIONS | ABOUT US | CONTACT US | PARTNER PAGE
All materials on this site Copyright Edgell Communications. All rights reserved.