republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » New method found to crack WPA - but not WPA2
Search Topic:
Uniqs:
5411
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
NebuAd named in Class Action Lawsuit »
« Romanian NASA hacker gets suspended sentence  
AuthorAll Replies


TKJunkMail
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast


1 edit
 New method found to crack WPA - but not WPA2

»www.pcworld.com/article/153396/
Tews and his co-researcher Martin Beck found a way to break the Temporal Key Integrity Protocol (TKIP) key, used by WPA, in a relatively short amount of time: 12 to 15 minutes, according to Dragos Ruiu, the PacSec conference's organizer.

They have not, however, managed to crack the encryption keys used to secure data that goes from the PC to the router in this particular attack.

The work of Tews and Beck does not involve a dictionary attack, however.

To pull off their trick, the researchers first discovered a way to trick a WPA router into sending them large amounts of data. This makes cracking the key easier, but this technique is also combined with a "mathematical breakthrough," that lets them crack WPA much more quickly than any previous attempt, Ruiu said.

Tews is planning to publish the cryptographic work in an academic journal in the coming months, Ruiu said. Some of the code used in the attack was quietly added to Beck's Aircrack-ng Wi-Fi encryption hacking tool two weeks ago, he added.

A new wireless standard known as WPA2 is considered safe from the attack developed by Tews and Beck, but many WPA2 routers also support WPA.

Ruiu expects a lot more WPA research to follow this work. "Its just the starting point," he said. "Erik and Martin have just opened the box on a whole new hacker playground."
Summary:
This can crack and then monitor Router-->PC traffic but NOT PC-->Router

More reason to switch to (WPA2 and AES) instead of (WPA & TKIP).
--
My BLOG .. .. Internet News .. .. My Web Page
Ask yourself one question: 'Do I feel lucky?' Well, do ya punk?


Steve
I'm a PC, so shut up
Consultant
join:2001-03-10
Yorba Linda, CA

I always thought TKIP was a hack, but it was the best they could do with the limited CPU power available on older WEP devices.

I thought that all WPA devices supported AES, so therefor would not need TKIP, but I guess there's a broad range of compatibility issues out there. So AES it is.

Steve
--
Stephen J. Friedl | Unix Wizard | Microsoft Security MVP | Tustin, California USA | my web site


F430

@cox.net
quote:
I thought that all WPA devices supported AES
AES is optional in WPA and required in WPA2. So there are a number of compliant WPA devices which do not support AES.

KodiacZiller

join:2008-09-04
73368

said by F430 :

quote:
I thought that all WPA devices supported AES
AES is optional in WPA and required in WPA2. So there are a number of compliant WPA devices which do not support AES.
You sure WPA2 "requires" AES? From the DD-WRT Wiki:

However, some devices allow WPA (not WPA2) with AES (and WPA2 with TKIP).


Kayrac
Premium
join:2001-09-29
Rochester, NH
WPA2 is AES, or AES+TKIP

jbibe
Premium,MVM
join:2001-02-22


1 edit
reply to KodiacZiller
said by KodiacZiller See Profile :

You sure WPA2 "requires" AES? From the DD-WRT Wiki:

However, some devices allow WPA (not WPA2) with AES (and WPA2 with TKIP).
CCMP (i.e., AES) is required. See Section 8.3.1 of 802.11i.

Edit: You can find the requirements in 802.11i-2004.pdf or 802.11-2007.pdf.


redxii
too big to fail
Premium,Mod
join:2001-02-26
Texas
reply to TKJunkMail
I have two wireless cards using WPA w/ AES (one doesn't support WPA2), router has AES only enabled, so I'm not affected by this?

jbibe
Premium,MVM
join:2001-02-22
You are not affected.


caedmon

@cox.net

reply to KodiacZiller
quote:
You sure WPA2 "requires" AES?
Yes, as others above have already stated. Support for AES is required and support for TKIP is optional in WPA2. I am not aware of any vendor implementing TKIP in WPA2 but I haven't look for it either.
quote:
However, some devices allow WPA (not WPA2) with AES (and WPA2 with TKIP).
Exactly - they allow the optional encryption method in addition to the required method. In other words some devices support the optional AES-CCMP encryption method with WPA (I have one which does not and one which does).

Just so everyone knows, if a devices is using TKIP with WPA2 it is just as vulnerable as a device using TKIP with WPA.
-
Forums » Up and Running » Security » SecurityNebuAd named in Class Action Lawsuit »
« Romanian NASA hacker gets suspended sentence  


Monday, 30-Nov 20:49:02 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [44] Baltimore To Ban Lazy Cable Installs
· [37] Broadband Killed The Game Console
· [30] Rural Carriers Quickly Embracing Fiber
· [28] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [23] Charter Exits Chapter 11
· [19] Midcontinent Socked With Easement Lawsuit
· [3] Monday Morning Links
· [2] Monday Evening Links
Most people now reading
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]
· Portable power for blackouts? [Home Repair & Improvement]
· [Internet] Gaming problem for "Heroes of Newerth" ( New bell Upd [Bell Canada]
· [Rant] called out sick! [Rants, Raves, and Praise]
· Windows 7 boot manager editing questions [Microsoft Help]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· Wind getting a little more aggressive [TekSavvy]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [Newsgroups] Newzleech down? [Filesharing Software]