WarDriving & Wireless Penetration Testing

By David Maynor
Security used to be a little different than it is today. Not long ago, worms such as Blaster and the SQL Slammer were causing mass Internet disruptions and serving as a catapult to bring network security into the eyes of the average consumer. This was especially true in the case of the Slammer worm, because it actually disrupted communications between ATM machines and their respective financial intuitions. Although Slammer did bring security to the public s attention, Zotob is the worm that is (arguably) responsible for cementing security in everyone s mind, when in mid-2005 it took down a portion of CNN s operating capabilities.
This served as a wake-up call to many consumers and, by proxy, the makers of security software. As a result, operating system vendors began spending more time, effort, and money eliminating security problems in their products. Not just Microsoft, but also other vendors, such as Apple, and open source projects that produce free operating systems such as FreeBSD and Linux, are doing all they can to proactively eliminate security problems from their offerings as well as quickly respond to reported threats. This means the typical attacker will need to adapt to this changing environment and find new ways to compromise victims machines.
Attackers have two choices: they can go up or they can go down. When I say go up I mean that an attacker can start to exploit applications that run on top of the operating system. Examples of such applications include...