Wi-Fi Protected Setup At Risk - Intrusion Possible Says Researcher

A security researcher has reported the pitfalls in the design and implementation of Wi-Fi Protected Setup (WPS) technology. The default configuration facilitates users to connect to the system without any issue. #-Link-Snipped-# said, WPS is susceptible to brute-force attacks due to the inefficient design specification. This flaw merely allows any stranger with good computing power to brute-force the WPS Pin as it allows the intruder to know when the first half of the 8-digit pin is correct.

#-Link-Snipped-#

The lack of proper security policy (also known as Lock Out policy) after a few failed attempts to guess the pin code of WPS enables the intruder to make such brute-force intrusion successful. The#-Link-Snipped-# confirms that when the PIN authentication fails, the access point sends an acknowledgement as an EAP-NACK message back to the user. These acknowledgement messages are sent in such a way that the attackers become quite comfortable in determining if the first half of the pin is correct. Moreover the last digit of the pin may be revealed to the user as it is a checksum for the PIN Code. This flaw enormously reduces the number of attempts to be made by the attacker in stealing the PIN.

This seems to be a warning to the essential users of the wireless access points. The attacker within the wireless range of that access point may intrude to retrieve the password of the system, alter system configurations or activate the Denial of Service condition. It is a recommendation by the US-CERT to disable the WPS and help eradicate such big threats.

Source:#-Link-Snipped-# | Image Credit:#-Link-Snipped-#

Replies

You are reading an archived discussion.

Related Posts

Samsung Electronics Co. Ltd, welcomes the year 2012, by adding an another smartphone to the Galaxy family named Galaxy Ace Plus, which was an enhanced version of Galaxy Ace released...
This 30-second video is going to mesmerize you! The teaser video of HP ultrabook named “Spectre” was first posted by The Verge. Reportedly the video was sent to their mail...
Toyota has finally decided to open its mind to speculating general public as to what it has to offer at the upcoming Detroit Auto Show. The car company has not...
Just few days away from CES 2012, reports have sprung up about the launch of Windows 8 based tablets from two PC manufacturing giants, Acer and Lenovo. Though we could...
Milagrow Business and Knowledge Solutions, a company situated in Gurgaon has developed the world's first tablet specially customized for women. This TabTop PC has a pretty reasonable size, and can...