Unstrung News Analysis

Look Before You LEAP

One of the highlights of the first-ever Unstrung Live conference in New York today was the demonstration -- by a real, live hacker (albeit one on the side of the angels) -- of just how easy it is to break into Cisco Systems Inc.'s (Nasdaq: CSCO) proprietary Lightweight Extensible Authentication Protocol (LEAP) wireless LAN security mechanism and gain unauthorized access to supposedly secure 802.11 networks.

Joshua Wright, an information security architect (who humorously referred to himself as a hacker several times during the presentation) from Johnson & Wales University in Providence, demonstrated -- to an audience of around 200 people -- a tool he has developed to exploit flaws in the LEAP technology.

"I call it ‘Asleep’ -- as in asleep at the wheel," Wright quipped.

This kind of hack involves the use of two applications. The first is the Kismet Linux wireless LAN network sniffer, which is similar to the popular Netstumbler tool that is available on Windows. Wright says he uses this tool to track down Cisco access points that are broadcasting in the area.

After locating his prey, it's time to bring out the big gun: the Asleep tool. This application exploits the challenge/response technique used by a Cisco system when it is trying to authenticate a client connecting to the wireless network. "Challenge/response leaks information about the network," Wright bluntly notes.

This enables a tooled-up hacker to run a so-called "dictionary attack" against the LEAP system. Wright showed two data feeds where he ran massive lists of words -- and even numbers -- against the Maginot Line of the Cisco defenses. In minutes, even seconds, the Asleep tool had found the passwords it needed to gain access to the network.

After compromising the wireless LAN, Wright says, a hacker can often leap onto other parts of a network, because a user may well have the same password to access various directories and applications.

Wright says he informed Cisco about the flaw in LEAP several months ago. In response, the firm issued a brief warning on their Website and asked for more time before he released the tool to the public. Wright now says that the tool will be generally available in a couple of months.

"They've known about this for years -- and that's what really bothers me -- [that] I had to go and point it out to them," Wright says.

— Dan Jones, Senior Editor, Unstrung

Newest Comments First       Display in Chronological Order
menexis
User Ranking
Wednesday June 10, 2009 12:53:44 PM
no ratings

I don't think this is so much about the users. If you present them with the opportunity to utilize a stronger password and encorced it they will. If you don't they wont.  

jdelaney44
User Ranking
Saturday February 14, 2004 9:26:20 PM
no ratings
I agree 120% that stronger passwords need to be enforced. But this needs to be tempered with reality. We already subject end users to a ridiculous level of complexity. It's the ultimate piss off to make it hard for someone to get to their information. Remember, these systems are not ours. They belong to the end users. Us IT types are too arrogant about the fact that we have the keys to the car when someone else has the pink slip.
WizzKid
User Ranking
Thursday October 16, 2003 4:10:59 AM
no ratings
They are no security measures against dumb selection of passwords. Exhaustive search attacks can be made enormously difficult with the use of 1024 bit (or more non-repeating/random) Nonce, and using SHA-1 instead of MD5 based Keyed MACs, but if even a small percentage of admins are DUMB enough to use dictionary words as passwords, it takes a small effort to build the list of SHA-1 hashes of all dictionary words offline, capture the LEAP (or any other auth) packets, encrypt the nonce and compare them, to beat any "well-designed" security system.

The Solution -
---------------
It should be "Mandatory" to select Mixed Case Alpha-Numeric passwords, and use of punctuation characters should always be "Recommended", otherwise strong cryptography cannot take you any further in protecting your network assets from Hackers.

--- WizzKid.



mpmartin
User Ranking
Tuesday October 7, 2003 6:59:57 PM
no ratings
The problem here isn't really that passwords are poor (which can be a problem anywhere passwords are used) but that it is easy to tell when and where passwords are sent. Discovering stored password hashes on an OS is one thing, but a secure network protocol should completely obscure the authentication process, making it impossible to even tell where the hash occurs in the data stream. If this tool can pull encrypted passwords out of the ether and attack them at leisure, this is a serious problem.
jjared
User Ranking
Sunday October 5, 2003 12:49:23 PM
no ratings
I have been told that this was done offline. Is this true? If so does that mean you can capture traffic during an authentication attempt and then use the dictionary attack offline to get the username/password and therefore bypass any password policy that would disable an account after a number of failed login attempts?
Chalke
User Ranking
Thursday October 2, 2003 2:22:25 PM
Since this was a dictionary attack, couldn't it have just been prevented with better passwords?
rwever
User Ranking
Wednesday October 1, 2003 8:17:24 PM
no ratings
I am sure we'd all like to keep an eye on this tool. Could there already exist a litle more description on the vulnerability; so far, this sounds nothing more than a weakness in the passwords themselves, which admins can reduce its risk by using (and forcing their users) strong passwords, not typically found by dictionary attacks.
I also suppose Cisco development could use the approach of revoking access to expecific (by MAC address perhaps) to possible attackers who tried more than (customizable) number of wrong passwords?
UNSTRUNG MARKET PLACE
FREE Download: Why SIP Makes Sense
Learn from XO® the advantages of SIP as an enabler of Unified Communications
Share VoIP Across Multiple Sites & SAVE
Extend VoIP across branches without local PBXs or trunks at every location
Used and Refurbished Cisco Routers
Purchase Your Routers From Network Liquidators. Savings of Up to 90% with a Lifetime Warranty!
Online Webcast: Unified Computing-Part 2
Learn the way to a more efficient & simplified data center. Register for 2/10/10
100% Online MBA's
Earn a Masters in Business Administration 100% Online. No GMAT Required!
The blogs and comments are the opinions only of the writers and do not reflect the views of Unstrung. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
Events
Cable Next-Gen Broadband Strategies: Docsis 3.0, Wireless, Fiber & Beyond
Thursday, February 25, 2010
The Cable Center, Denver
Tower Technology Summit
March 23- 25, 2010
Las Vegas Convention Center, Las Vegas
Ethernet Europe
Monday & Tuesday, April 12 & 13, 2010
London Marriott Hotel Grosvenor Square, London
OSS Virtual Event
Tuesday, April 20, 2010
Webinars
White Papers SPONSORED CONTENT
Featured
Companies
Alltel (102), Apple (453), Aruba Networks (97), AT&T (formerly Cingular) (910), Cisco (875), Clearwire (328), Google (418), Intel (696), Juniper (148), Microsoft (509), Motorola (1299), Nokia (1881), NTT DoCoMo (483), Palm (294), Qualcomm (500), Research In Motion (RIM) (344), Sprint Nextel (966), Symbol Technologies (169), T-Mobile (533), Texas Instruments (206), Verizon Wireless (808), Vodafone (1243)

Fixed/Mobile Convergence
ATM (10), Backhaul (51), Circuit Switch (13), Copper (3), Core Network (411), DWDM (6), Email/Personal Information Management (403), Ethernet (36), Finance & Banking (85), Fixed Mobile Convergence (335), Frame Relay (1), General Packet Radio Service (GPRS) (613), Global System for Mobile Communications (GSM) (1540), Handheld Computers (379), IP Multimedia Subsystem (IMS) (28), IPv6 (15), Media Gateways (19), Message Gateways (SMS, MMS) (717), Microwave (69), Mobile Data Gateways (104), Mobile Devices (790), Mobile Management (98), Mobile VPNs (61), MPLS (8), Packet Switch (109), Sales Force Apps (43), Session Border Controllers (3), Shop-Floor Apps (23), Smartphones & Handsets (2047), Sonet (8), Vertical Apps (235), Webpads (93), WiMax (33), Wireless Web Gateways (WAP, i-mode) (105)

Handhelds
Email/Personal Information Management (403), Finance & Banking (85), Fixed Mobile Convergence (335), Global Positioning System (GPS) (121), Global System for Mobile Communications (GSM) (1540), Handheld Computers (379), iDEN (74), Message Gateways (SMS, MMS) (717), Microbrowsers (66), Mobile Data Gateways (104), Mobile Databases (30), Mobile Devices (790), Mobile Java(J2ME) (104), Mobile Management (98), Mobile Operating Systems (Pocket PC, Palm, EPOC, RIM) (318), Mobile VPNs (61), Sales Force Apps (43), Security (293), Shop-Floor Apps (23), Smartphones & Handsets (2047), Univeral Mobile Telecommunications Service (UMTS) (1283), Vertical Apps (235), Webpads (93), Wireless Web Gateways (WAP, i-mode) (105)

Mobile Applications
Bluetooth (246), Email/Personal Information Management (403), Finance & Banking (85), Global Positioning System (GPS) (121), Handheld Computers (379), Message Gateways (SMS, MMS) (717), Mobile Data Gateways (104), Mobile Databases (30), Mobile Devices (790), Mobile Java(J2ME) (104), Mobile Management (98), Mobile Operating Systems (Pocket PC, Palm, EPOC, RIM) (318), Mobile VPNs (61), Sales Force Apps (43), Security (293), Service Gateways(GGSN/PDSN) (163), Shop-Floor Apps (23), Smartphones & Handsets (2047), Vertical Apps (235), Webpads (93), Wireless Applications (940), Wireless Web Gateways (WAP, i-mode) (105)

Mobile Workforce
Bluetooth (246), Email/Personal Information Management (403), Finance & Banking (85), Fixed Mobile Convergence (335), Global Positioning System (GPS) (121), Handheld Computers (379), Message Gateways (SMS, MMS) (717), Microbrowsers (66), Middleware (54), Mobile .Net (15), Mobile Databases (30), Mobile Devices (790), Mobile Java(J2ME) (104), Mobile Management (98), Mobile Operating Systems (Pocket PC, Palm, EPOC, RIM) (318), Mobile VPNs (61), Sales Force Apps (43), Security (293), Shop-Floor Apps (23), Smartphones & Handsets (2047), Vertical Apps (235), Webpads (93), Wireless Web Gateways (WAP, i-mode) (105)

Mobile/Wireless System (OS's)
Email/Personal Information Management (403), Fixed Mobile Convergence (335), Handheld Computers (379), Mobile .Net (15), Mobile Devices (790), Mobile Java(J2ME) (104), Mobile Management (98), Mobile Operating Systems (Pocket PC, Palm, EPOC, RIM) (318), Smartphones & Handsets (2047), Webpads (93)

RFID
Bluetooth (246), Global Positioning System (GPS) (121), Mobile Management (98), Radio (RF) Chips (79), Shop-Floor Apps (23), Vertical Apps (235)

Telco Wireless
802.16 (587), Access Points (722), Base Station Controller (BSC) (242), Base Transceiver Station (BTS) (281), Code Division Multiple Access (CDMA) (780), Enhanced Data GSM Environment (EDGE) (405), iDEN (74), IEEE 802.11 (a,b,g) (1190), OSS/Billing/CRM (646), Service Gateways(GGSN/PDSN) (163), Ultrawideband (UWB) (140), WLAN Bridges (71), WLAN Switches (480)

WiMax/Broadband Wireless
802.11 Chipsets (282), 802.16 (587), 802.20 (66), Antennas (63), Enhanced Data GSM Environment (EDGE) (405), Fixed WiMax (212), General Packet Radio Service (GPRS) (613), HiperLAN (11), Home Base Stations/Femtocells (392), Mobile WiMax (805), WiMax (751), Wireless Broadband (722)

Wireless VOIP
Email/Personal Information Management (403), Fixed Mobile Convergence (335), Handheld Computers (379), Smartphones & Handsets (2047)

WLANs/WiFi/802.11
802.11 Chipsets (282), 802.11 Single Chips (SOC) (39), Access Points (722), Antennas (63), Base Station Controller (BSC) (242), Base Transceiver Station (BTS) (281), Baseband Controller (49), Comms Chips & Wireless Components (1297), HiperLAN (11), IEEE 802.11 (a,b,g) (1190), Multimedia Mobile Access Communication (MMAC) (17), Power Amplifiers (75), Public Access Hotspots (986), Radio (RF) Chips (79), Security (404), Smart Antennas (61), Wireless LAN (1217), WLAN Bridges (71), WLAN cards (119), WLAN Switches (480)