by Mario Morejon wrote:
Two researchers from the Technical University of Darmstadt, Germany, have discovered a method of bypassing the Wi-Fi Protected Access (WPA) encryption used by many wireless routers.
The exploit takes advantage of a weakness on networks that use WPA with TKIP (Temporal Key Integrity Protocol, a security algorithm based on key switching that is used to strengthen the WPA encryption) by circumventing the algorithm that encrypts the Wi-Fi data packets. Researchers Erik Tews and Martin Beck, who are members of the ethical hacking group known as Aircrack-ng, have not only discovered how to bypass WPA, they've also created a tool to do so. They plan to release the tool at the PacSec conference next week in Tokyo, Japan, Aircrack-ng member Rick Farina confirmed to PC Magazine on Friday.
With the exploit tool in hand, hackers will be able break into networks that have WPA with TKIP encryption. TKIP is a predecessor of AES and was developed to overcome the flaw with WEP [Wired Equivalent Private] security. WPA is essentially WEP with a couple of fixes. The TKIP algorithm rotates keys between clients and access points after enough packets pass between them. By default, most routers on the market change the keys every couple of hours. The exploit takes advantage of this data flowing to and from access points and masquerades its packets by inserting its own and passing them to clients. The packet insertion bypasses the countermeasures used by routers can catch the malicious activity. From a computer's point of view, the data packets appear to belong to a legitimate access point. According to Farina, just seven packets are needed to gain access to a computer.
Researchers found it even easier to gain access to wireless networks that are using QoS [Quality of Service]. Networks that mix data and voice packets often rely on QoS to prioritize the voice data. However, data packets with QoS are rearranged in sequential order so that they travel faster and are received efficiently. The protection algorithm used by TKIP was relaxed to allow for QoS.
As the exploit tool gains access to a computer, hackers can easily inject new packets and install and execute tools such as Metasploit that can give them permanent access. Metasploit is a large toolkit for testing exploits and it uses well known exploits in its arsenal. Rick said, "With 2 or 3 packets you can fit most tools in the Metasploit toolkit," Farina said.
Because the exploit is specific, users simply need to change the WPA encryption to work with AES or change it to the much more hardened WPA2. If your router doesn't support WPA2, the best course of action is to shorten the timing of the TKIP in the routers, so that keys are refreshed every two minutes or less. The fast refresh makes it harder but not impossible for hackers to gain access. The best course of action, however, is to buy a new router that supports WPA2.
Tool to Crack Wi-Fi's WPA Will Appear Next Week
Moderator: Moderators
- sirwilliam
- Resident Poop Expert
- Posts: 7226
- Joined: Mon Aug 01, 2005 1:27 pm
- Location: The Wild Serengeti Suburbs
Tool to Crack Wi-Fi's WPA Will Appear Next Week
As some of you might have already heard: ARTICLE LINKY
2004 SG Model A PearlBlackObsidian (RIP)
2008 SG Model D BlueRallyWorld
"When I get sad, I stop being sad and be awesome instead. True story." -Barney Stinson
"Nothing shuts my pie-hole but pie." -Shawn Spencer
2008 SG Model D BlueRallyWorld
"When I get sad, I stop being sad and be awesome instead. True story." -Barney Stinson
"Nothing shuts my pie-hole but pie." -Shawn Spencer
-
- Moderator
- Posts: 6314
- Joined: Wed Oct 19, 2005 1:15 am
- Location: Alexandria
Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week
does this work if your router is set to wpa with tkip AND mac filtering AND a small, specific dhcp scope AND no broadcasting of ssid?
-Ben


-
- DCAWD Groupie
- Posts: 1316
- Joined: Sun Oct 01, 2006 3:48 pm
- Location: Arlington, VA
- Contact:
Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week
a little birdie told me that a certain office in clarendon has a handheld that can crack that in less than five minutes. i might have even seen it done. i might even have one kicking around the office.chicken n waffles wrote:does this work if your router is set to wpa with tkip AND mac filtering AND a small, specific dhcp scope AND no broadcasting of ssid?
rocket scientist
- Cereb Daithi
- DCAWD Groupie
- Posts: 3747
- Joined: Wed Apr 26, 2006 11:07 pm
- Location: Pittsburgh, PA
- Contact:
Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week

internets. we be hacking ur tubes box.
- Mr Kleen
- DCAWD Founding Member
- Posts: 15034
- Joined: Mon Apr 18, 2005 6:46 pm
- Location: Wiesbaden.DE
Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week
securing a personal wireless network is the same game as securing your car when it's parked on a public street: you can't make it completely secure, you can only make sure the other person is an easier target. 

- Libra Monkee
- Moderator
- Posts: 6478
- Joined: Wed Mar 29, 2006 11:04 pm
- Location: The Ether
- Contact:
Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week
*Penn Gillette impression* Wi Fi security is... Bullshit! */Penn Gillette impression*

Libra Monkee- "Helping DCAWD meet its Equal Opportunity requirement since 2006."
- complacent
- DCAWD Founding Member
- Posts: 11651
- Joined: Sun Aug 29, 2004 8:00 pm
- Location: near the rockies. very.
- Contact:
Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week
This particular hack does not apply to WPA2 networks that are encrypted using AES.
colin
a tank, a yammie, a spaceship
i <3 teh 00ntz
a tank, a yammie, a spaceship
i <3 teh 00ntz
- Sabre
- DCAWD Founding Member
- Posts: 21432
- Joined: Wed Aug 11, 2004 8:00 pm
- Location: Springfield, VA
- Contact:
Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week
You're right, this one does notcomplacent wrote:This particular hack does not apply to WPA2 networks that are encrypted using AES.

I still do not trust wireless in any way shape or form, but necessity requires me to run it at home. As Gabe said, make sure you're not the easy target.
Sabre (Julian)

92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.

92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.