Slashdot Mirror


WEP And PPTP Password Crackers Released

Jacco de Leeuw writes "SecurityFocus published an article by Michael Ossmann that discusses the new generation of WEP cracking tools for 802.11 wireless networks. These are much faster as they perform passive statistical analysis. In many cases, a WEP key can be determined in minutes or even seconds. For those who have switched to PPTP for securing their wireless nets: Joshua Wright released a new version of his Cisco LEAP cracker called Asleap which can now also recover weak PPTP passwords. Both LEAP and PPTP employ MS-CHAPv2 authentication." Update: 12/22 00:14 GMT by T : Michael Ossmann wrote to point out his last name has two Ns, rather than one.

6 of 244 comments (clear)

  1. Feasibility of dictionary attacks no protocol flaw by Anonymous Coward · · Score: 3, Interesting

    Every communication which uses passwords for authentication is susceptible to dictionary attacks. That is not a protocol weakness. If you use a random and long enough password, you'll be fine. Public key based authentication has other risks, like insufficiently secured storage of the key.

  2. End-to-End Security by Renegade+Lisp · · Score: 3, Interesting
    This just underlines that encryption at the wireless link level may not be the right way to go. Even if the algorithm wasn't so weak -- it strikes me as odd that a whole network should be protected by just a single key, which needs to be present on every individual machine of this network. How easily is this compromised!

    It's far better not to rely on wireless link encryption and encrypt your application-level protocols instead. SSL for web browsing, PGP or S/MIME for e-mail, ssh for login. Far better algorithms, far better key management.

  3. Easier for travelers by ad454 · · Score: 5, Interesting

    Great, I will be leaving for a business trip soon, and now I can freely *access* those commercial WEP enabled Wi/Fi access points in many airports without risking my credit card.

    Seriously though, Wi/Fi has to be treated like an unsecure public network, and anyone wants to restrict access they should use a more secure protocol like IPSec in host-to-host mode. Do not count on Wi/Fi manufactures to protect you, for some reason they just simply refuse to provide secure products.

  4. Security is an illusion ... by Gopal.V · · Score: 4, Interesting
    To be truthful, nothing is secure ... It can only be "Secure Enough". If the cost of breaking something is more than the benifit - that is security in one sense.

    Any encryption can be broken - given enough resources ... The trick is to make it so difficult that nobody finds out unless they are prepared to invest more than what you did (time, computing power, money, technology).

    Interestingly in India, according to Department of Telecom website - security means something different :).
    23. Individuals/Groups/Organisations are permitted to use encryption upto 40 bit key length in the RSA algorithms or its equivalent in other algorithms without having to obtain permission from the Telecom Authority. However, if encryption equipments higher than this limit are to be deployed, individuals/groups/organisations shall do so with the prior written permission of the Telecom Authority and deposit the decryption key, split into two parts, with the Telecom Authority.
    We have to keep our private keys in ESCROW to use >40 bit encryption ... Talk about stupid laws (of course which no-one enforces or obeys).
  5. Re:Feasibility of dictionary attacks no protocol f by wirelessbuzzers · · Score: 5, Interesting

    Every communication which uses passwords for authentication is susceptible to dictionary attacks. That is not a protocol weakness. If you use a random and long enough password, you'll be fine. Public key based authentication has other risks, like insufficiently secured storage of the key.

    First, you will note that the attack on WEP (but not on PPTP) is not a dictionary attack and works with a computer-generated random 64- or 128-bit key. This is a protocol weakness.

    Second, a good protocol does protect passwords. Either it establishes an encrypted session with the server, like SSH or SSL does, or it uses a secure password protocol like SRP. SRP in particular has the following properties:

    1) The protocol is entirely public, and open-source implementations are available.
    2) An eavesdropper on the wire does not get a dictionary attack on the password; without breaking the crypto behind the protocol, which nobody has been able to do yet, he gets no information. Of course, he can still do an online attack, but the server should prevent that.
    3) Someone impersonating the server also does not get a dictionary attack on the password, even though the client does not need to memorize a key hash.
    4) Someone who compromises the server database does get a dictionary attack on the password (this is inevitable), but they don't get the password for free. Furthermore, the password is salted, so they have some work to do.

    --
    I hereby place the above post in the public domain.
  6. Re:Now who can we blame for downloading GB of stuf by bhima · · Score: 3, Interesting
    I was speaking to an American friend, who lives in Atlanta, recently. He was complaining about this very thing. He owns & manages a variety of types of property which he leases out to people who run bars, restaurants, small businesses, warehouses, and even churches. Occasionally, he has tenants 'disappear' and when he goes down to inspect the property he finds evidence of drug related activities (i.e. rows of HPS lighting, hydroponic setups, and my favorite: money counters). So generally to keep it of his back he reports it and has the police come in and take it all in as evidence. Recently, during one of these events the investigating officer arrested him using a little known local law (either Fulton or DeKalb county) which required the owner of the property to report any illegal activities taking place on their properties. The law is so grey that they make no attempt to deal with whether or not the property owner is knowledgeable or a participant. In effect they demand that all property owners become investigators / informants.

    Welcome to post 911 America

    --
    Nothing in the world is more dangerous than sincere ignorance and conscientious stupidity.