Results 1 to 7 of 7

Thread: WPS broken, Not good anymore - all your wifi r bel

Share             
   
   
  1. #1
    Engaged Achievements:
    VeteranCreated Album picturesThree FriendsRecommendation First Class25000 Experience PointsOverdrive
    <span style='color: #708090'><span class='glow_DAA520'>BW</span></span>'s Avatar
    Join Date
    Oct 2007
    Location
    San'do
    Posts
    5,500
    Thanks
    587
    Thanked 294 Times in 239 Posts

    Default WPS broken, Not good anymore - all your wifi r bel

    It's true.

    Yesterday came the first news:

    New WiFi Setup Flaw Allows Easy Router PIN Guessing

    "There is a newly discovered vulnerability in the WiFi Protected Setup standard that reduces the number of attempts it would take an attacker to brute-force the PIN for a wireless router's setup process. The flaw results in too much information about the PIN being returned to an attacker and makes the PIN quite weak, affecting the security of millions of WiFi routers and access points. Security researcher Stefan Viehbock

    discovered the vulnerability (PDF) and reported it to US-CERT. The problem affects a number of vendors' products, including D-Link, Netgear, Linksys and Buffalo. 'I noticed a few really bad design decisions which enable an efficient brute force attack, thus effectively breaking the security of pretty much all WPS-enabled Wi-Fi routers. As all of the of the more recent router models come with WPS enabled by default, this affects millions of devices worldwide,' Viehbock said."
    http://mobile.slashdot.org/story/11/...r-pin-guessing



    That's pretty bad.

    This morning after (today), attack tools were released.

    Attack Tool Released For WPS Setup Flaw

    "Just a day after security researcher Stefan Viehbock released details of a vulnerability in the WiFi Protected Setup (WPS) standard that enables attackers to recover the router PIN, a security firm has published an open-source tool capable of exploiting the vulnerability. The tool, known as Reaver, has the ability to find the WPS PIN on a given router and then recover the WPA passphrase for the router, as well. Tactical Network Solutions has released the tool as an open-source project on Google Code, but also is selling a more advanced commercial version."
    http://mobile.slashdot.org/story/11/...wps-setup-flaw



    heads up everybody

  2. The Following 2 Users Say Thank You to BW For This Useful Post:

    Randall (01-01-2012), Zerothree (01-02-2012)

  3. #2
    Engaged Achievements:
    VeteranCreated Album picturesThree FriendsRecommendation First Class25000 Experience PointsOverdrive
    <span style='color: #708090'><span class='glow_DAA520'>BW</span></span>'s Avatar
    Join Date
    Oct 2007
    Location
    San'do
    Posts
    5,500
    Thanks
    587
    Thanked 294 Times in 239 Posts

    Default Re: WPS broken, Not good anymore - all your wifi r

    Eight digits should produce 100,000,000 possible combinations, and testing various routers Viehböck found it took an average of around two seconds to test each combination. So brute forcing should take several years unless the router was particularly responsive.

    But the protocol used by Wi-Fi Protected Setup reports back after the first four digits have been entered, and indicates if they are right, which means they can be attacked separately. The last of the eight digits is just a checksum, so having got the first four the attacker only then has to try another 1,000 combinations (identifying the other three digits) and the entire PIN is known.

    That combination means that our attacker only has to try 11,000 different combinations to find the right PIN, reducing the attack time to a couple of hours.
    Last edited by BW; 12-30-2011 at 03:59 PM.


  4. #3
    Iz ah Trini
    Points: 22,853, Level: 66
    Level completed: 8%, Points required for next Level: 647
    Overall activity: 99.6%
    Achievements:
    Three FriendsVeteranCreated Album pictures50000 Experience PointsOverdriveTagger First Class
    Awards:
    Most Popular
    Solachica's Avatar
    Join Date
    Oct 2007
    Location
    South
    Posts
    13,250
    Points
    22,853
    Level
    66
    Thanks
    158
    Thanked 504 Times in 416 Posts

    Default Re: WPS broken, Not good anymore - all your wifi r

    So ummm BW talk non geek language for me to understand wht this is nah.

  5. The Following User Says Thank You to Solachica For This Useful Post:

    straphanger (12-30-2011)

  6. #4
    Engaged Achievements:
    VeteranCreated Album picturesThree FriendsRecommendation First Class25000 Experience PointsOverdrive
    <span style='color: #708090'><span class='glow_DAA520'>BW</span></span>'s Avatar
    Join Date
    Oct 2007
    Location
    San'do
    Posts
    5,500
    Thanks
    587
    Thanked 294 Times in 239 Posts

    Default Re: WPS broken, Not good anymore - all your wifi r

    Quote Originally Posted by Solachica View Post
    So ummm BW talk non geek language for me to understand wht this is nah.
    Many routers now ship with a feature called WiFi Protected Setup (WPS). This feature makes it easy to secure your wifi network- so others can't get access your internet connection or home network unless you specifically allow it.

    This feature is typically a 'push button' on the router that works with software on your computer to make setting up easier.

    Many new routers come with this feature on by default.

    Now here's the news:

    Yesterday security researchers discovered a flaw in that feature. This flaw allows attackers to gain access to your home network and internet connection within a matter of hours, if you are using a WPS-enabled WiFi router.

    In my mind, that means the feature is now broken. It is not good anymore.

  7. #5
    Iz ah Trini
    Points: 22,853, Level: 66
    Level completed: 8%, Points required for next Level: 647
    Overall activity: 99.6%
    Achievements:
    Three FriendsVeteranCreated Album pictures50000 Experience PointsOverdriveTagger First Class
    Awards:
    Most Popular
    Solachica's Avatar
    Join Date
    Oct 2007
    Location
    South
    Posts
    13,250
    Points
    22,853
    Level
    66
    Thanks
    158
    Thanked 504 Times in 416 Posts

    Default Re: WPS broken, Not good anymore - all your wifi r

    Oh I c

  8. #6
    Superior Member
    Points: 14,891, Level: 52
    Level completed: 99%, Points required for next Level: 9
    Overall activity: 33.0%
    Achievements:
    Veteran10000 Experience Points
    lexbarker's Avatar
    Join Date
    Oct 2007
    Posts
    3,187
    Points
    14,891
    Level
    52
    Thanks
    18
    Thanked 80 Times in 70 Posts

    Default Re: WPS broken, Not good anymore - all your wifi r

    My home is Hard Wired in many locations. I only use the WiFi when I have to use my Pad or have visitors. This wireless thing is slowly cooking people.
    If one wants to have more security, they could use the powerline network system (AC powerline in the house as the physical carrier).

  9. #7
    Superior Member
    Points: 22,846, Level: 66
    Level completed: 7%, Points required for next Level: 654
    Overall activity: 23.0%
    Achievements:
    25000 Experience PointsVeteran
    mammadon's Avatar
    Join Date
    Sep 2008
    Posts
    3,401
    Points
    22,846
    Level
    66
    Thanks
    1
    Thanked 35 Times in 31 Posts

    Default Re: WPS broken, Not good anymore - all your wifi r

    All one needs is WPA2 security, that is not so easy to crack.
    Man is the measure of all things. Happiness is finding one's own measure.




Similar Threads

  1. Barbados intends to go 100% wifi
    By Solachica in forum Technology
    Replies: 26
    Last Post: 12-24-2011, 05:41 PM
  2. See the glass as already broken
    By Amelia in forum Philosophy
    Replies: 24
    Last Post: 06-12-2010, 11:32 PM
  3. Is Anyone Faithful Anymore?
    By letric in forum Social Relations
    Replies: 7
    Last Post: 06-04-2010, 06:00 AM
  4. Blink Modem wifi
    By Solachica in forum Technology
    Replies: 5
    Last Post: 09-01-2008, 10:42 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


Available in Android Market
Follow Us on Twitter