Pocket PC Thoughts - Daily News, Views, Rants and Raves

Check out the hottest Windows Mobile devices at our Expansys store!





Go Back   Thoughts Media Forums > POCKET PC THOUGHTS > Pocket PC Articles

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-17-2005, 10:00 PM
Contributing Editor
Janak Parekh's Avatar
Join Date: Aug 2006
Posts: 14,942
Default Security Flaw in x50 WiFi WEP Key Store

http://www.airscanner.com/blog/blog...ogid=0501151031

"Airscanner discovered a serious flaw in the way the Windows Mobile Odyssey client manages the WEP key information. The Odyssey client included with the Dell X50 stores the WEP keys as plaintext in the registry. The following illustrates: Byte 5 - 9 list my entered WEP keys for each entry."

In other words, if someone gets their physical hands on your x50, it's possible to extract the WEP key without too much hassle. It isn't great that a unit stores WEP keys in plaintext, but on the other hand, WEP isn't that secure anyway. If you're using WEP to secure critical business interests, you should have already developed a migration path to WPA. And for personal use, I wouldn't worry too much about it, since this only becomes an issue if you lose your PDA.
 
Reply With Quote
  #2 (permalink)  
Old 01-17-2005, 10:36 PM
Ponderer
Join Date: Dec 2004
Posts: 77

What about the Odyssey on the X30?

Why do we need it anyway? It seems I can do everything I do with Odyssey with the native Dell client (WLAN util on the X30).

Amnon
 
Reply With Quote
  #3 (permalink)  
Old 01-17-2005, 11:01 PM
Pupil
Join Date: Dec 2004
Posts: 33

Quote:
Originally Posted by amnon
t seems I can do everything I do with Odyssey with the native Dell client (WLAN util on the X30).
Which is probably what most other Axim users do, and thus are not affected by the leak. I also found this information.
 
Reply With Quote
  #4 (permalink)  
Old 01-18-2005, 02:22 AM
Oracle
ctitanic's Avatar
Join Date: Mar 2005
Posts: 1,001

May be Iīm wrong but i believe that itīs a bug in the OS and not just of Dellīs PPC. Can any one with WEP check these keys

[HKEY_LOCAL_MACHINE\Comm\<NICCARDNAME>\Parms]
HTCWEPDefaultKey4
HTCWEPDefaultKey3
HTCWEPDefaultKey2
HTCWEPDefaultKey1
__________________
Ctitanic
http://www.tweaks2k2.com
 
Reply With Quote
  #5 (permalink)  
Old 01-18-2005, 02:34 AM
Intellectual
Join Date: Apr 2004
Posts: 167

You'll be at the mercy of the hardware vendor. For instance, most OEM implementations of the Pegasus do, in fact, encrypt the key in the registry. However, someone with time could probably just copy the key anyway.

Odyssey gets used for LEAP, and, for me, non-standard SSIDs. For instance, my SSID contains punctuation of sorts, something that the built-in Windows setup won't allow you to use.

WEP is secure enough for most, as I recall last hearing, to crack WEP, you needed to sniff 10MB worth of data. Still not perfect, but good enough for most. I hear WPA is emerging as the 'one to use' but I don't know much about it.

*Phil
 
Reply With Quote
  #6 (permalink)  
Old 01-18-2005, 02:49 AM
Contributing Editor
Ed Hansberry's Avatar
Join Date: Aug 2006
Posts: 7,898

Quote:
Originally Posted by ctitanic
[HKEY_LOCAL_MACHINE\Comm\<NICCARDNAME>\Parms]
HTCWEPDefaultKey4
HTCWEPDefaultKey3
HTCWEPDefaultKey2
HTCWEPDefaultKey1
Those keys do not exist on my WEP protected iMATE PDA2K.
 
Reply With Quote
  #7 (permalink)  
Old 01-18-2005, 03:04 AM
Pontificator
Join Date: Jul 2003
Posts: 1,051
Send a message via AIM to ricksfiona

No problem. Allowing someone to hold my PDA would be the equivalent of allowing them to grab my girlfriend's ass. :evil:
__________________
Rick Gomez - Owner/Consultant
fiona Systems Integration
www.fionasystems.com
 
Reply With Quote
  #8 (permalink)  
Old 01-18-2005, 03:11 AM
Oracle
ctitanic's Avatar
Join Date: Mar 2005
Posts: 1,001

Quote:
Originally Posted by Ed Hansberry
Quote:
Originally Posted by ctitanic
[HKEY_LOCAL_MACHINE\Comm\<NICCARDNAME>\Parms]
HTCWEPDefaultKey4
HTCWEPDefaultKey3
HTCWEPDefaultKey2
HTCWEPDefaultKey1
Those keys do not exist on my WEP protected iMATE PDA2K.
Well, I'm sure I have seen that problem before but i can recall in what machine and now that i think about it, those keys are created by the OEM that made the WiFi card.
__________________
Ctitanic
http://www.tweaks2k2.com
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +1. The time now is 04:24 AM.



Search Engine Friendly URLs by vBSEO 3.2.0 RC7