<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>American Butifarra &#187; Wireless</title> <atom:link href="http://claude.betancourt.us/tag/wireless/feed/" rel="self" type="application/rss+xml" /><link>http://claude.betancourt.us</link> <description>Claude Betancourt&#039;s Personal Blog</description> <lastBuildDate>Fri, 16 Dec 2011 02:43:25 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>WPA Cracked, Sort Of</title><link>http://claude.betancourt.us/wpa-cracked-sort-of/</link> <comments>http://claude.betancourt.us/wpa-cracked-sort-of/#comments</comments> <pubDate>Wed, 12 Nov 2008 02:01:02 +0000</pubDate> <dc:creator>Claude</dc:creator> <category><![CDATA[Articles]]></category> <category><![CDATA[Research]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[WiFi]]></category> <category><![CDATA[Wireless]]></category><guid isPermaLink="false">http://claude.betancourt.us/?p=217</guid> <description><![CDATA[Arstechnica has a great explanation of the issue. Academic researchers have found an exploitable hole in a popular form of wireless networking encryption. The hole is in a part of 802.11i that forms the basis of WiFi Protected Access (WPA), &#8230; <a href="http://claude.betancourt.us/wpa-cracked-sort-of/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description> <content:encoded><![CDATA[<p><img class="alignright frame" src="http://media.arstechnica.com/articles/paedia/wpa-cracked.media/eriktews.png" title="Eric Tews"/><span class="drop_cap">A</span><a href="http://arstechnica.com/articles/paedia/wpa-cracked.ars/1"><strong>rstechnica</strong></a> has a great explanation of the issue.</p><blockquote><p>Academic researchers have found an exploitable hole in a popular form of wireless networking encryption. The hole is in a part of 802.11i that forms the basis of WiFi Protected Access (WPA), so it could affect routers worldwide. German graduate student Erik Tews will present a paper at next week&#8217;s PacSec in Tokyo coauthored with fellow student and aircrack-ng team member Martin Beck that reveals how remnants of WPA&#8217;s predecessor allow them to slip a knife into a crack in the encryption scheme and send bogus data to an unsuspecting WiFi client.</p><p>In an interview from Germany, where he is a PhD candidate studying encryption at the Technical University of Darmstadt, Tews explained that an existing attack on Wired Equivalent Privacy (WEP) was modified to provide a slim vector for sending arbitrary data to networks that use the Temporal Key Integrity Protocol (TKIP). (Tews&#8217; collaborator Beck is a student at the Technical University of Dresden; Tews credits Beck with the discovery, after which they jointly developed the paper that Tews will present at PacSec.)</p><p>With the Tews/Beck method, an attacker sniffs a packet, makes minor modifications to affect the checksum, and checks the results by sending the packet back to the access point. &#8220;It&#8217;s not a key recovery attack,&#8221; Tews said, &#8220;It just allows you to do the decryption of individual packets.&#8221; This approach works only with short packets, but could allow ARP (Address Resolution Protocol) poisoning and possibly DNS (Domain Name Service) spoofing or poisoning.</p><p>The paper, <a href="http://dl.aircrack-ng.org/breakingwepandwpa.pdf"><strong>Practical Attacks against WEP and WPA</strong></a>, is now available for download.</p></blockquote><p>So even though TKIP is not broken, the best way to protect your network is by switching from TKIP to AES with a relatively random password at least 20 characters long.</p> ]]></content:encoded> <wfw:commentRss>http://claude.betancourt.us/wpa-cracked-sort-of/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Served from: claude.betancourt.us @ 2012-02-07 14:51:43 by W3 Total Cache -->
