BetaONE will rise again!


Reply
  #1  
Old 4th Apr 07, 03:29 PM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
WEP security totally broken
Can be hacked between 50 and 95 per cent of the time

SECURITY EXPERTS say that the WEP protocol for security LANs is totally broken and should be dumped on sensitive networks.

Boffins at Darmstadt Polytechnic said that WEP uses the RC4 stream to encrypt data which is transmitted over the air, using usually a single secret key 40 or 104 bit long.

WEP has been known to be insecure since 2001 after Scott Fluhrer, Itsik Mantin, and Adi Shamir published an analysis of the RC4 stream cipher. Since then crackers have been able to recover the key to a greater or lesser degree of success.

In 2005, Andreas Klein presented another analysis of the RC4 stream cipher which proved there more correlations between the RC4 keystream. Darmstadt boffins took this idea and managed to adapt it so that it was possible to recover a 104 bit WEP key half the time using just 40,000 captured packets.

The more packets that the Darmstadt boffins could nick, the more likely it could find the key. With 85,000 packets intercepted, they could find the key 95 percent of the time.

Using 40,000 packets, which can be captured in less than a minute, computation takes about three seconds on a Pentium M 1.7 GHz.

The boffins say that the hack makes WEP as useful as a chocolate teapot in sensitive environments. Since most wireless equipment vendors provide support WPA1 and WPA2 punters should shift to that, they recommend.

More here.



The INQuirer
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft's April Security Updates NewsBot NeoWin News 0 12th Apr 05 08:30 PM
Microsoft Security Bulletin Advance Notification NewsBot NeoWin News 0 8th Apr 05 06:00 PM
No new security updates from Microsoft for March NewsBot NeoWin News 0 4th Mar 05 12:00 AM
Neowin Talks Security with Microsoft NewsBot NeoWin News 0 7th Feb 05 01:00 AM
Microsoft Commits to Security NewsBot BetaONE News 0 4th Nov 04 02:00 PM


All times are GMT +1. The time now is 12:01 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.