republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » New method found to crack WPA - but not WPA2
Uniqs:
5415
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
NebuAd named in Class Action Lawsuit »
« Romanian NASA hacker gets suspended sentence  

TKJunkMail
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast


1 edit

New method found to crack WPA - but not WPA2

»www.pcworld.com/article/153396/
Tews and his co-researcher Martin Beck found a way to break the Temporal Key Integrity Protocol (TKIP) key, used by WPA, in a relatively short amount of time: 12 to 15 minutes, according to Dragos Ruiu, the PacSec conference's organizer.

They have not, however, managed to crack the encryption keys used to secure data that goes from the PC to the router in this particular attack.

The work of Tews and Beck does not involve a dictionary attack, however.

To pull off their trick, the researchers first discovered a way to trick a WPA router into sending them large amounts of data. This makes cracking the key easier, but this technique is also combined with a "mathematical breakthrough," that lets them crack WPA much more quickly than any previous attempt, Ruiu said.

Tews is planning to publish the cryptographic work in an academic journal in the coming months, Ruiu said. Some of the code used in the attack was quietly added to Beck's Aircrack-ng Wi-Fi encryption hacking tool two weeks ago, he added.

A new wireless standard known as WPA2 is considered safe from the attack developed by Tews and Beck, but many WPA2 routers also support WPA.

Ruiu expects a lot more WPA research to follow this work. "Its just the starting point," he said. "Erik and Martin have just opened the box on a whole new hacker playground."
Summary:
This can crack and then monitor Router-->PC traffic but NOT PC-->Router

More reason to switch to (WPA2 and AES) instead of (WPA & TKIP).
--
My BLOG .. .. Internet News .. .. My Web Page
Ask yourself one question: 'Do I feel lucky?' Well, do ya punk?

Steve
I'm a PC, so shut up
Consultant
join:2001-03-10
Yorba Linda, CA

Re: New method found to crack WPA - but not WPA2

I always thought TKIP was a hack, but it was the best they could do with the limited CPU power available on older WEP devices.

I thought that all WPA devices supported AES, so therefor would not need TKIP, but I guess there's a broad range of compatibility issues out there. So AES it is.

Steve
--
Stephen J. Friedl | Unix Wizard | Microsoft Security MVP | Tustin, California USA | my web site

F430

@cox.net

Re: New method found to crack WPA - but not WPA2

quote:
I thought that all WPA devices supported AES
AES is optional in WPA and required in WPA2. So there are a number of compliant WPA devices which do not support AES.
KodiacZiller

join:2008-09-04
73368

Re: New method found to crack WPA - but not WPA2

said by F430 :

quote:
I thought that all WPA devices supported AES
AES is optional in WPA and required in WPA2. So there are a number of compliant WPA devices which do not support AES.
You sure WPA2 "requires" AES? From the DD-WRT Wiki:

However, some devices allow WPA (not WPA2) with AES (and WPA2 with TKIP).

Kayrac
Premium
join:2001-09-29
Rochester, NH

Re: New method found to crack WPA - but not WPA2

WPA2 is AES, or AES+TKIP
jbibe
Premium,MVM
join:2001-02-22


1 edit
said by KodiacZiller See Profile :

You sure WPA2 "requires" AES? From the DD-WRT Wiki:

However, some devices allow WPA (not WPA2) with AES (and WPA2 with TKIP).
CCMP (i.e., AES) is required. See Section 8.3.1 of 802.11i.

Edit: You can find the requirements in 802.11i-2004.pdf or 802.11-2007.pdf.

caedmon

@cox.net

quote:
You sure WPA2 "requires" AES?
Yes, as others above have already stated. Support for AES is required and support for TKIP is optional in WPA2. I am not aware of any vendor implementing TKIP in WPA2 but I haven't look for it either.
quote:
However, some devices allow WPA (not WPA2) with AES (and WPA2 with TKIP).
Exactly - they allow the optional encryption method in addition to the required method. In other words some devices support the optional AES-CCMP encryption method with WPA (I have one which does not and one which does).

Just so everyone knows, if a devices is using TKIP with WPA2 it is just as vulnerable as a device using TKIP with WPA.

redxii
too big to fail
Premium,Mod
join:2001-02-26
Texas
I have two wireless cards using WPA w/ AES (one doesn't support WPA2), router has AES only enabled, so I'm not affected by this?
jbibe
Premium,MVM
join:2001-02-22

Re: New method found to crack WPA - but not WPA2

You are not affected.
Forums » Up and Running » Security » SecurityNebuAd named in Class Action Lawsuit »
« Romanian NASA hacker gets suspended sentence  


Tuesday, 01-Dec 10:17:42 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [62] Baltimore To Ban Lazy Cable Installs
· [53] Broadband Killed The Game Console
· [37] Rural Carriers Quickly Embracing Fiber
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [30] Charter Exits Chapter 11
· [22] Midcontinent Socked With Easement Lawsuit
· [14] Rogers Unveils The ISP Dream Model
· [9] Vivendi Agrees, Comcast/NBC Deal Soon
· [8] ACTA: Global Three Strikes
· [4] Monday Evening Links
Most people now reading
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· Windows 7 boot manager editing questions [Microsoft Help]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· buying a one way ticket [General Questions]
· [Rant] called out sick! [Rants, Raves, and Praise]
· Prevx says MS Nov 10 patches causing BSOD problems [Security]
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]
· [News] Windows 8 Release 2012? [Microsoft Help]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· Wind getting a little more aggressive [TekSavvy]