NTA Monitor

Latest News

New version of network scanning tool arp-scan released

15th March 2011 A new version of a respected and popular network scanning tool has been released. Read More

Tests show rise in number of vulnerabilities affecting web applications with SQL Injection and XSS most common flaws

1st March 2011 SQL injection and cross-site scripting (XSS) were the most common flaws found in web applications in 2010 according to results from tests carried out by NTA Monitor. Read More

Assess risk to manage effects of budget cuts

9th February 2011 Signs of economic recovery may be appearing in some industries, but for most organisations - particularly in the public sector - budget cuts and cost savings are here to stay for the foreseeable future. Read More

"Basic security threats not changed in 15 years"

1st February 2011 There may have been significant technological advances to the hardware and software organisations use, but according to Roy Hills, who co-founded NTA Monitor in 1996, the basic security threats have not changed in the last 15 years. Read More
Date: 3rd April 2006
Risk: Informational

Wi-fi access equipment will be installed in lampposts and road signs that will enable anyone in the City of London to access the Internet outside of offices.

Security concerns are growing about the Square Mile's wi-fi, particularly as many PCs operating on Windows XP and 2000 have the automatic searching for wi-fi connection spots facility enabled. If a computer can't set up a wireless connection, it will establish an ad hoc connection to a local address. This is assigned with an IP address, which Windows then associates with the SSID of the last wireless network it connected to. The machine will then broadcast this SSID, looking to connect with other computers in the immediate area. The danger arises if an attacker listens for computers that are broadcasting in this way, and creates a network connection of their own with that same SSID. This would allow the two machines to associate together, potentially giving the attacker access to files on the victim's PC. Although firewalls should be able to stop this happening, and those using Windows XP Service Pack 2 are not thought to be at risk, the repercussions of this feature being exploited could be disastrous. Microsoft plans to adjust the default behaviour in a future Service Pack, however, it does not plan to release the next XP Service Park until the second half of 2007.

A large number of financial organisations inhabit the Square Mile, which may mean that it is a very tempting target for attackers. The service is due to go live in a couple of months, with full access to be available within six months.

References