Page 1 of 1

Tool to Crack Wi-Fi's WPA Will Appear Next Week

Posted: Tue Nov 11, 2008 9:43 am
by sirwilliam
As some of you might have already heard: ARTICLE LINKY
by Mario Morejon wrote:
Two researchers from the Technical University of Darmstadt, Germany, have discovered a method of bypassing the Wi-Fi Protected Access (WPA) encryption used by many wireless routers.

The exploit takes advantage of a weakness on networks that use WPA with TKIP (Temporal Key Integrity Protocol, a security algorithm based on key switching that is used to strengthen the WPA encryption) by circumventing the algorithm that encrypts the Wi-Fi data packets. Researchers Erik Tews and Martin Beck, who are members of the ethical hacking group known as Aircrack-ng, have not only discovered how to bypass WPA, they've also created a tool to do so. They plan to release the tool at the PacSec conference next week in Tokyo, Japan, Aircrack-ng member Rick Farina confirmed to PC Magazine on Friday.

With the exploit tool in hand, hackers will be able break into networks that have WPA with TKIP encryption. TKIP is a predecessor of AES and was developed to overcome the flaw with WEP [Wired Equivalent Private] security. WPA is essentially WEP with a couple of fixes. The TKIP algorithm rotates keys between clients and access points after enough packets pass between them. By default, most routers on the market change the keys every couple of hours. The exploit takes advantage of this data flowing to and from access points and masquerades its packets by inserting its own and passing them to clients. The packet insertion bypasses the countermeasures used by routers can catch the malicious activity. From a computer's point of view, the data packets appear to belong to a legitimate access point. According to Farina, just seven packets are needed to gain access to a computer.

Researchers found it even easier to gain access to wireless networks that are using QoS [Quality of Service]. Networks that mix data and voice packets often rely on QoS to prioritize the voice data. However, data packets with QoS are rearranged in sequential order so that they travel faster and are received efficiently. The protection algorithm used by TKIP was relaxed to allow for QoS.

As the exploit tool gains access to a computer, hackers can easily inject new packets and install and execute tools such as Metasploit that can give them permanent access. Metasploit is a large toolkit for testing exploits and it uses well known exploits in its arsenal. Rick said, "With 2 or 3 packets you can fit most tools in the Metasploit toolkit," Farina said.

Because the exploit is specific, users simply need to change the WPA encryption to work with AES or change it to the much more hardened WPA2. If your router doesn't support WPA2, the best course of action is to shorten the timing of the TKIP in the routers, so that keys are refreshed every two minutes or less. The fast refresh makes it harder but not impossible for hackers to gain access. The best course of action, however, is to buy a new router that supports WPA2.

Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week

Posted: Tue Nov 11, 2008 10:01 am
by chicken n waffles
does this work if your router is set to wpa with tkip AND mac filtering AND a small, specific dhcp scope AND no broadcasting of ssid?

Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week

Posted: Tue Nov 11, 2008 9:25 pm
by avriette
chicken n waffles wrote:does this work if your router is set to wpa with tkip AND mac filtering AND a small, specific dhcp scope AND no broadcasting of ssid?
a little birdie told me that a certain office in clarendon has a handheld that can crack that in less than five minutes. i might have even seen it done. i might even have one kicking around the office.

Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week

Posted: Wed Nov 12, 2008 5:12 am
by Cereb Daithi
:banana2:

internets. we be hacking ur tubes box.

Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week

Posted: Wed Nov 12, 2008 7:15 am
by Mr Kleen
securing a personal wireless network is the same game as securing your car when it's parked on a public street: you can't make it completely secure, you can only make sure the other person is an easier target. :ugh:

Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week

Posted: Wed Nov 12, 2008 9:16 am
by Libra Monkee
*Penn Gillette impression* Wi Fi security is... Bullshit! */Penn Gillette impression*

Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week

Posted: Wed Nov 12, 2008 9:27 am
by complacent
This particular hack does not apply to WPA2 networks that are encrypted using AES.

Re: Tool to Crack Wi-Fi's WPA Will Appear Next Week

Posted: Sat Jan 10, 2009 2:45 pm
by Sabre
complacent wrote:This particular hack does not apply to WPA2 networks that are encrypted using AES.
You're right, this one does not ;)

I still do not trust wireless in any way shape or form, but necessity requires me to run it at home. As Gabe said, make sure you're not the easy target.