RE: Bluetooth Wireless Keyboards

From: Butler, Theodore (Theodore.Butler@EssexCorp.com)
Date: Mon Sep 25 2006 - 15:35:01 EDT


Policies need enforcement and monitoring.

-----Original Message-----
From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com]
On Behalf Of Kevin white
Sent: Monday, September 25, 2006 1:02 PM
To: pen-test@securityfocus.com
Subject: Re: Bluetooth Wireless Keyboards

List,

Thanks for all the excellent advice so far. Here's some more FYI.
Our policy does prohibit the installation of any "unauthorized devices"
and state that IT is supposed to approve all devices. This is why I
think taking the policy route will alleviate the problem the quickest.

None the less, here's what I'm going to put together today with my BT
dongle to see just how far I can get with it.
http://www.usbwifi.orcon.net.nz/wifi5km.jpg

I've got a lake behind me with about a quarter mile shot across it to
the nearest residences. I've connected back to our regular wifi as a
proof of concept on keeping unsecured wireless out of our facilities.
Since BT is in the same range I'm curious to see how many BT enabled
phones and other devices I can hit across the lake. Once this antenna is
optimized then I'll check out the range on this keyboard if the install
ever happens on it.

I'll let the list know how this turns out.

-- 
Kevin
------------------------------------------------------------------------
This List Sponsored by: Cenzic
Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=7016
00000008bOW
------------------------------------------------------------------------
 
 
 
 
This electronic message and any files transmitted with it contain information which may be privileged
and/or proprietary.  The information is intended for use solely by the intended recipient(s).  If you are
not the intended recipient, be aware that any disclosure, copying, distribution or use of this
information is prohibited.  If you have received this electronic message in error, please advise the
sender by reply email or by telephone (301-939-7000) and delete the message.
------------------------------------------------------------------------
This List Sponsored by: Cenzic
Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:57:01 EDT