Paper Published on Breaking WPA TKIP

Posted on November 11, 2008. Filed under: Penetration Testing | Tags: , , , |

Two German university researchers have discovered a combination of techniques that could allow an attacker to compromise Wi-Fi Protected Access (WPA) encryption in less than 15 minutes.  The attack does not result in the encryption key being discovered.  Rather, the technique allows attackers “to decrypt packets and inject packets with custom content.”  Martin Beck and Eric Tews present their findings at the PacSec 2008 conference in Tokyo this week.  The attack targets the WPA’s Temporal Key Integrity Protocol (TKIP).
http://www.securityfocus.com/news/11537
http://www.heise-online.co.uk/security/Security-experts-reveal-details-of-WPA-hack–/news/111922
http://dl.aircrack-ng.org/breakingwepandwpa.pdf

[(Note from Johannes Ullrich): Although the attack rather limited, it highlights the fact that WPA and TKIP were meant to serve as a transitional fix for older hardware. WPA2 is the "real fix". And from Raul Siles at Internet Storm Center: This new research opens the door to new WPA/TKIP attacks and future attack enhancements, so it is time to start applying and planning the appropriate security countermeasures to remove or mitigate this and similar future threats:
Update to WPA2/AES as soon as you can! Because the vulnerability is in TKIP, both WPA and WPA2 can be affected. The attack affects WPA2 if configured with TKIP because WPA2 allows both, AES and TKIP (while WPA only allows TKIP).


Read Full Post | Make a Comment ( 1 so far )

Recently on secauditor speaks: hmmmm…Security – Imagine That...

More Free Training – Penetration Testing

Posted on November 11, 2008. Filed under: Penetration Testing, Training | Tags: , , , , , |

4 Web Training Session – (Threat Update, WPA/2 Crack, Adaptive Security)

Posted on November 10, 2008. Filed under: Auditing, Penetration Testing, Training | Tags: , , , , , , |

Latest Vulnerability Breakdown – 11/07/08

Posted on November 7, 2008. Filed under: Auditing, Penetration Testing | Tags: , , , , , , , |

What Do They Know About YOU??

Posted on November 6, 2008. Filed under: General | Tags: , |

Latest Vulnerability Breakdown – 10/30/08

Posted on October 30, 2008. Filed under: Auditing, Penetration Testing | Tags: , , , , , , , , |

FrSIRT – Fedora Security Update Fixes Drupal Security Bypass Vulnerabilities / Exploit (Security Advisories)

Posted on October 28, 2008. Filed under: Penetration Testing | Tags: , , |

Free Training – Protecting the Evolving Network, Log Management, Using IDS/IPS for Post-Connect NAC, Reducing IT Costs, and more…

Posted on October 27, 2008. Filed under: General, Training | Tags: , , , , , , , , |

Latest Vulnerability Breakdown – 10/24/08

Posted on October 23, 2008. Filed under: Auditing, Penetration Testing | Tags: , , , , , , , |

Now the Tools – Pt.3 Hydra

Posted on October 23, 2008. Filed under: Auditing, Penetration Testing | Tags: , , , , , |

Now the Tools – Pt.2 Cisco Torch

Posted on October 21, 2008. Filed under: Auditing, Penetration Testing, Training | Tags: , , , |

    About

    “The soft and the pliable will defeat the hard and strong.” Lao Tzu

    RSS

    Subscribe Via RSS

    • Subscribe with Bloglines
    • Add your feed to Newsburst from CNET News.com
    • Subscribe in Google Reader
    • Add to My Yahoo!
    • Subscribe in NewsGator Online
    • The latest comments to all posts in RSS
    • Subscribe in Rojo

    Meta

Liked it here?
Why not try sites on the blogroll...