WPA2 wireless security cracked
sciencespot.co.uk
sciencespot.co.uk
The methodology appears to be as naive as a brute force attack against the Pre-Shared Key (PSK):
"At the beginning, the area was scanned-sniffed with ‘Airodump’ and then a deauthentication attack was made with ‘Aireplay’," according to the paper. "Through that, an instance of the PSK was caught. Finally, ‘Aircrack’ was attempting to reveal the secret password by using the instance of the PSK and matching it with every record of the dictionary. For these experiments we used a very big dictionary that consisted of 666,696 standard printable ASCII character records of various lengths. ‘Airodump’ and ‘Aireplay’ are commands of the ‘Aircrack’ suite, responsible for sniffing and deauthentication respectively."
Which part of this paper is new or novel?
Fortunately, this is far from the case.
" it is the de-authentication step in the wireless setup that represents a much more accessible entry point for an intruder with the appropriate hacking tools. As part of their purported security protocols routers using WPA2 must reconnect and re-authenticate devices periodically and share a new key each time. The team points out that the de-authentication step essentially leaves a backdoor unlocked albeit temporarily."
In fact, even the idea of "year of CPU time" doesn't sooth me much, because while most of your traffic might be "quickly-expiring" it's definitely not true for all of your traffic, and what's possible to do with a year of CPU time will be possible to do comparatively cheap very soon. And I guess we all remember stuff like Google collecting some wi-fi traffic anyway.
So, it sounds somewhat scary to me. We don't even have anything better than WPA2 now, do we?
That doesn't sound like something that would take a year of CPU time, but since no one seems to have actually read and analyzed the paper yet, who knows.
i wonder how quickly you could solve that problem, cracking the wpa2 key, if you had $$$ resources to scale up. could it be usable? would make for a great android app :) i'd buy it!
"At the beginning, the area was scanned-sniffed with ‘Airodump’ and then a deauthentication attack was made with ‘Aireplay’," according to the paper. "Through that, an instance of the PSK was caught. Finally, ‘Aircrack’ was attempting to reveal the secret password by using the instance of the PSK and matching it with every record of the dictionary. For these experiments we used a very big dictionary that consisted of 666,696 standard printable ASCII character records of various lengths. ‘Airodump’ and ‘Aireplay’ are commands of the ‘Aircrack’ suite, responsible for sniffing and deauthentication respectively." [1]
[1]http://www.securityweek.com/researchers-outline-how-crack-wp...
What bothers me most however is what the authors seem to recommend as additional security measures (per http://www.securityweek.com/researchers-outline-how-crack-wp...): MAC ACLs and Hidden SSIDs. I don't think I need to point out here how ridiculous these 'security' measures are, especially in light of the nature of the alleged weakness and how one would need to exploit it.
That doesn't really lend a lot of credibility to the paper's / this link's title.
Also, it looks like that without rainbow tables, the PSK cannot be cracked in a meaningful timespan? They compared the 'captured' hash (?) against a dictionary to determine their success, but again, I might be extrapolating too much from too little information.
I'm sure we'll see an analysis written up by Securosis or someone along those lines soon. I'm tempted to buy it myself, but given the synopsis, I'm a little skeptical.
"The researchers have now shown that a brute force attack on the WPA2 password is possible and that it can be exploited, although the time taken to break into a system rises with longer and longer passwords."
A brute force attack is possible on any symmetric encryption system. Difficulty is increased with the size of the keyspace. These are truisms. No offence to the authors, but this isn't really a discovery, unless they've discovered a way to reduce the key space.
"As part of their purported security protocols routers using WPA2 must reconnect and re-authenticate devices periodically and share a new key each time. The team points out that the de-authentication step essentially leaves a backdoor unlocked albeit temporarily. "
This isn't really a backdoor. If there was an actual fault that would allow you to authenticate without passing a key, that would be one thing. But you still have to pass a key by the way they describe it. To perform a brute force attack on the authentication step, you need to capture the handshake. You can wait for that to happen, or try and force one yourself. Here's an aircrack tutorial on how to do this:
http://www.aircrack-ng.org/doku.php?id=cracking_wpa&DokuWiki...
Note though, that while this gets you the packets needed to perform your attack on (as opposed to waiting for the Client/AP to periodically reauthenticate), and potentially saved you a couple of hours, you still have to break the key.
And that's what it all comes down to. Breaking a weak password is easy. Breaking a lengthy key is hard. The only vulnerability that exists as described so far is insufficiently long keys. That's a key management/user problem, not so much a technological one.
1. Set up a PSK of at least 30 random lower case letters.
2. Switch off WPS.
(I used to tell people 20 random characters using mixed case letters, digits and symbols. Using lower case letters only is easier to type on a phone.)Is a WiFi access point set up this way vulnerable to this new attack?
So many times I've been warned that "WPA2 has been cracked" but when reading, it turns out that someone has just built a system to perform brute force dictionary attacks.
anyone know if the techniques here are new? all existing techniques are prohibitive without a lot of time and cycling wifi keys fixes that as far as i'm aware.