Skip Links

Network World

Brandon Carroll

Are you Vulnerable?

Recently described vulnerabilities in Cisco Wireless Networks..

By brandon on Wed, 10/07/09 - 12:31am.
Newsletter Signup

Is your network Vulnerable? If you are running 4.x and 5.x WLC software you may be. Ask yourself, "Did I follow Cisco Best Practices?" If you didn't you may be sorry. A recent issue with OTAP has been widely discussed in online forums, blogs, and such. You may be familiar, but, If you don't understand OTAP (Over the Air Provisioning) visit the following site to get you up to speed:

http://www.cisco.com/en/US/products/ps6366/products_tech_note09186a008093d74a.shtml

And if you are familiar with how OTAP works but not with the vulnerability, check out the following URL:

http://tools.cisco.com/security/center/viewAlert.x?alertId=18919

George Stefanick at http://www.my80211.com claimes that there may be more to it than Cisco is mentioning.  His post with Video detailes it here:

http://www.my80211.com/security-labs/2009/9/5/there-is-more-to-the-recent-cisco-wireless-otap-issue-that-i.html

But aside from that, could your network be even MORE vulnerable?  Hard to imagine right? But check out Georges latest post where he discusses how default SNMP strings could further add to the issue, leaving your network open to some major issues.  

http://www.my80211.com/home/2009/10/6/cisco-wlc-rogue-wcs-attack-all-your-base-are-belong-to-us.html

Nice find George!  Great way to dig deep, find an issue, and teach people what they should do to correct the issue.  It shows that you care about the technology and what can happen if you just take shortcuts (like leaving SNMP strings with default values) to get things up an running in a hurry.

George Stefanick is a  Senior Wireless Engineer at Texas Medical Center, working on a large wireless network for a major heathcare system.  Guys like this are invaluable.

Million Dollar Mistake

0

It would be a million dollar mistake to let that guy go....

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • You can use BBCode tags in the text.
  • Lines and paragraphs break automatically.
  • Allowed HTML tags: <p> <strong> <i> <br /> <br> <ul> <ol> <li> <dl> <dt> <dd> <blockquote>

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Welcome, visitor. Register Log in
About Cisco Unwired

Brandon Carroll, CCIE # 23837, is a certified Cisco Systems Instructor working for Ascolta Training, based out of the Bellevue, Wa. Training Center. He is published by Cisco Press/Pearson Education in the area of network security and wireless.

His most recent book is CCNA Wireless Official Exam Certification Guide and we have 15 copies to give away. Go here for entry details and go here for a sneak peek of a chapter.

This blog is part of the Cisco Subnet blogging community.

Blog Roll
Ascolta's Cisco Study Blog
http://www.ascoltablogs.com/