Your Ad Here

Gulp: Security Researcher Discovers WPA2 Vulnerability [Wireless]

It\’s time to be nostalgic for the days after you could assume WPA2 as the strongest, most impregnable wireless security standard. Security firm AirTight Networks has discovered a method of compromising WPA2 encryption using about ten lines of code.

Utilizing what\’s called a \” man within the middle\” exploit, whereby a certified member of an encrypted network can intercept private data to and from a router and inject their own malicious packets, researcher Sohail Ahmad has developed a straightforward way to \” drop traffic, drop a [denial-of-service] attack, or snoop.\”

The AES encryption upon which WPA2 is predicated hasn\’t been compromised-rather, the attack exploits element of the WPA2 standard that mandates the shared use of one key on the element of every user connected to the network. Which means that your WPA2 network isn\’t prone to attacks from the surface, but rather (and more creepily) from those already trusted to affix the network.

Ahmed says the attack may be pulled off using only open source software and an average network card available to any consumer-exactly how can be demoed at the approaching DEF CON 18 hacker fest. The simplest news? \” There\’s nothing within the standard to upgrade to as a way to patch or fix the outlet,\” in step with another AirTight researcher.

The only strategy to prevent an attack of this form, consistent with AirTight, is by continuously \” monitoring traffic over the air.\” Oh, and how convenient! AirTight Networks in order that happens to sell wireless security consulting services. What would a decent metaphor for this be? A barber throwing gum to your hair? Though needless to say, better for this to be discovered by wireless security experts-conflicts of interest aside-than by someone with more nefarious intent. [AirTight Networks via Network World via PC Mag]

Source

  • Twitter
  • Facebook
  • email
  • PDF
  • Digg
  • del.icio.us
  • Google Bookmarks
  • RSS

This post is tagged: , , , , , ,

Leave a Reply





  • Samsung demos new 32nm quad-core Exynos prior to MWCSamsung demos new 32nm quad-core Exynos prior to MWC

    If you were lucky enough to be on the International Solid-State Circuits Conference, then you definitely might need caught a glimpse of Samsung's latest sliver of mobile silicon. The as yet unnamed Exynos parts will are available in dual- and quad-core configurations running at as much as 1.5GHz. Perhaps crucial change though, is the switch from a 45nm manufacturing process to… »
  • LG’s upcoming MWC lineup runs into some Italians, gets documented on videoLG’s upcoming MWC lineup runs into some Italians, gets documented on video

    You might need already seen LG's upcoming Optimus Vu in video form , but what concerning the remainder of the company's Mobile World Congress debutants ? Enter Italian site Telefonino, who's managed to wrangle hands-ons with that phablet and two of its co-stars, the Optimus 3D Max and the delectable Tegra-3 powered Optimus 4X HD . Catch the latter running LG's customized… »

Categories

Subscribe

Enter your email address: