|
Tool to Bypass WPA-TKIP to be Released Next Week - TechAmok
Tool to Bypass WPA-TKIP to be Released Next Week - [security] 06:11 AM EST - Nov,09 2008 - post a comment As I reported earlier, researchers have discovered a method that bypasses WPA encryption and will release the exploit tool next week. Fret not, for there are fixes you can use, such as switching to WPA2 or changing the WPA algorithm from TKIP to AES. Better check your Wi-Fi networks.
With the exploit tool in hand, hackers will be able break into networks that have WPA with TKIP encryption. TKIP is a predecessor of AES and was developed to overcome the flaw with WEP [Wired Equivalent Private] security. WPA is essentially WEP with a couple of fixes. The TKIP algorithm rotates keys between clients and access points after enough packets pass between them. By default, most routers on the market change the keys every couple of hours. The exploit takes advantage of this data flowing to and from access points and masquerades its packets by inserting its own and passing them to clients. The packet insertion bypasses the countermeasures used by routers can catch the malicious activity. From a computer's point of view, the data packets appear to belong to a legitimate access point. According to Farina, just seven packets are needed to gain access to a computer.
Researchers found it even easier to gain access to wireless networks that are using QoS [Quality of Service]. Networks that mix data and voice packets often rely on QoS to prioritize the voice data. However, data packets with QoS are rearranged in sequential order so that they travel faster and are received efficiently. The protection algorithm used by TKIP was relaxed to allow for QoS.
As the exploit tool gains access to a computer, hackers can easily inject new packets and install and execute tools such as Metasploit that can give them permanent access. Metasploit is a large toolkit for testing exploits and it uses well known exploits in its arsenal. Rick said, "With 2 or 3 packets you can fit most tools in the Metasploit toolkit," Farina said.
Because the exploit is specific, users simply need to change the WPA encryption to work with AES or change it to the much more hardened WPA2. If your router doesn't support WPA2, the best course of action is to shorten the timing of the TKIP in the routers, so that keys are refreshed every two minutes or less. The fast refresh makes it harder but not impossible for hackers to gain access. The best course of action, however, is to buy a new router that supports WPA2.
|
|
Add your comment (free registrationrequired)
Short overview of recent news articles |
Aug,06 2025 Corsair MAKR75 Review - Ultimate DIY Keyboard Kit Aug,06 2025 1176 Hardware vs Plugin - Is There Really a Difference? Aug,06 2025 Do this NOW: Use Disposable Windows for Maximum Security! Aug,06 2025 CPU/GPU Scaling: Ryzen 7 5800X3D (RTX 5090, 5080, RX 9070 & 9060 XT) Aug,05 2025 XRP To $1000 By 2030... Know What You Hold BUT SELL YOUR XRP HERE: ? Aug,03 2025 NURBURGRING HEAVY RAINSTORM! MANY Fails, Spins & Slippery Action! Aug,03 2025 2025 Bentley Continental GTC SPEED // REVIEW on AUTOBAHN Aug,03 2025 F1: Qualifying Highlights | 2025 Hungarian Grand Prix Aug,03 2025 TikTok Adds Community Notes Aug,03 2025 Apple Responds to US Antitrust Lawsuit Aug,03 2025 Nvidia Denies Backdoor, but I thought that's what their logo was Jul,31 2025 Threadripper 64 Core MONSTER - Holy S#!T! Jul,28 2025 HW News - Gigabyte's Motherboard Mess, Linux Gains Market Share, Jul,27 2025 Samsung Z Fold 7 Durability Test - The End is Near Jul,27 2025 Silent Night, Deadly Night - Exclusive Trailer Jul,27 2025 I Bought a Giant Video Wall on Craigslist! Jul,26 2025 My Turn: Lamborghini Revuelto // Nurburgring Jul,26 2025 F1: Qualifying Highlights | 2025 Belgian Grand Prix Jul,26 2025 F1: Sprint Qualifying Highlights | 2025 Belgian Grand Prix Jul,26 2025 I am biased against this laptop - Razer Blade 18 Jul,26 2025 PRISONER OF WAR - Official Trailer | Starring Scott Adkins | In Jul,24 2025 Battlefield 6 reveal trailer Jul,22 2025 Samsung Galaxy Z Fold 7 - Two Week Review Jul,21 2025 Killer 4K 240Hz QD-OLED for just £750: MSI MPG 272URX Jul,20 2025 LAMBORGHINI URUS *STAGE 1* // REVIEW on AUTOBAHN Jul,20 2025 THE BEST VW GOLF GTI I've Driven! Proper ClubSport Jul,19 2025 Intel Core Ultra 9 275HX vs AMD Ryzen 9 9955HX - Which CPU is Best? Jul,18 2025 LAMBORGHINI REVUELTO V12 // 370KMH REVIEW on UNLIMITED AUTOBAHN! Jul,18 2025 Mortal Kombat II - Official Trailer Jul,17 2025 Stranger Things 5 - Official Teaser Jul,14 2025 Google Is Selling Fake Products - WAN Show July 11, 2025 Jul,12 2025 Hacked by playing Call of Duty WW2 on Gamepass? Jul,12 2025 2025 VW Golf GTE // TOP SPEED REVIEW on AUTOBAHN Jul,11 2025 NEW Audi RS3 v cheapest used RS3: DRAG RACE Jul,10 2025 A critical security vulnerability in Microsoft Remote Desktop Client Jul,10 2025 Samsung Z Fold/Flip 7 Impressions: Major Upgrades! Jul,08 2025 Gmail's latest feature helps you get rid of those pesky emails from Jul,06 2025 I'm an idiot and still made top 5... here's how Jul,05 2025 The Fantastic Four: First Steps - Official 'Lift Off' Teaser Jul,04 2025 Samsung Galaxy Z Fold 7 - Hands on Look
>> News Archive <<
| |
|