Wireless Network Security (I of III)
Securing a Wireless Network Thursday, January 22, 2009
What Kind Of Weave Does Lala Where
Chema Alonso. Microsoft MVP Windows Security
Attacking Wireless networks have long since become a sport, a diversion or a hobby. In almost all the media have written articles on how to hack wireless networks (I myself wrote an article about this same almost 2 years ago) and even in the Microsoft Security Days 2005 and the tour went Technet Security giving demonstrations of how easily you can make an attack on a wireless network.
However, it is still common wireless network attacks to succeed. Why is this happening? Justifications such as Who is going to attack me? Or if I have nothing important, I do not use my network that often reflect a lack of knowledge of risk or a problem of technical knowledge of how you can secure a wireless network. Let's do a quick review of the security technologies Wireless networks and seeing the risks of each one of them to choose a good option when protecting our network.
Wireless Technology
Any connection to make wireless LAN is considered, but we will focus on the WLAN, or Wireless Local Area Network. Wireless networks can be of two types, Ad-hoc, which would be a network between two computers same network (peer) or Infrastructure, which simulate a network connection based on a hub or hub connections. This is important because it mediates the types of attacks can be performed.
standards governing these technologies are the 802.11 and the first that reached the public were the 802.11b and 802.11g standards that allow data rates from 11 Mb / s to 108 Mb / s. From 2004, working on the 802.11n standard that will allow deployments of up to 500 Mb / s and is expected to be published later this year or early 2007. Surprisingly, as happened with the pending 802.11i (we'll talk about it a little later) is already ahead of the market and are available for purchase 802.11n devices are designed according to the information in the draft [1] standard was approved. To complete some of the "letters" that can be found in standards, there 802.11e version, designed for streaming video and audio in real time using quality of service protocols.
Okay, so far about "letters" that mark some features of the connections, but not security. Let's move on.
Defining a WLan
The first thing to define is the name of our WLAN network, and for that brief definitions to clarify:
MAC Protection To prevent unwanted clients from connecting many AP offers options to create white lists of equipment that can be connected according to the MAC address of the customer. To this are added the AP machine directions we want to allow and ready.
This is not a security measure as it is fairly robust easy to jump to an attacker. Using any network analysis tool com wlan Netstumbler we discover the SSID, channel and frequency being used and the MAC of the AP.
Once you know the MAC of the AP to know the customer authorized Macs as easy as opening a Sniffer as AiroPeek network and see what addresses are communicated to the MAC of the AP. Those are the authorized MACs. Once you have the list of authorized addresses, because the attacker is configured with a valid MAC one of the many tools that are available for spoof (impersonate) addresses and will have already skipped this protection.
Conclusion: The MAC address filtering is not a good security protection, it's easy for an attacker to bypass this protection.
Authentication and Encryption Keys
64 and 128-bit WEP
The 802.11 standard defines a system for authentication and encryption of communications Wlan called WEP (Wireless Equivalent Privacy).
WEP uses a keyword that will be used to authenticate to WEP networks closed to encrypt messages and communication.
To generate the key, in many AP calls for a sentence and then after it generated 5 different keys to ensure the best chance in the election of the same, but others simply asked to be introduced with restrictions length that is configured and ready.
for encryption of each frame plus a changing sequence of bits, called Initialization Vector (IV), so they do not always use the same key for encryption and decryption. Thus, two identical messages will not generate the same result as the encryption key changes.
As you can see in the image, in this case we have an AP that can generate 5 key from a phrase or directly set a key. When we have 5 key, we check which is what we will use it only uses 1 WEP key to everything. As you can see we have selected a choice of 64-bit WEP key, of which 5 bytes (40 bits) are the key and the remaining 24 bits are the IV. That is, in normal communication would have 2 to 24 different encryption keys.
For 128-bit WEP we will have 13 fixed bytes (104 bytes) and 24-bit shifting (IV), ie we have the same number of keys but longer.
Encryption and Decryption Process
To understand the process of authentication in WLAN networks with WEP is necessary to explain in advance the process of encryption and decryption as it is used during the authentication process for a client.
The encryption process is as follows:
Step 1: Selection of the IV (24 bits). The standard does not require a specific formula.
Step 2: Joining the WEP key and IV to generate a sequence of 64 or 128 bits. This value is Keystream called RC4.
Step 3: It happens that sequence by an RC4 algorithm to generate an encrypted value of that particular key.
Step 4: It generates a value of integrity of the message to be transmitted (ICV) to verify that the message has been decoded correctly and is added to the bottom.
Step 5: Make a XOR between the message and the message generated keystream RC4 encryption.
Step 6: Add the encrypted message the IV used for the recipient is able to decrypt the message.
The decryption process is the reverse:
Step 1: read the message received IV
Step 2: paste the WEP key IV
Step 3: RC4 generates Keystream
Step 4: XOR ago between the encrypted message and the RC4 keystream and gets the message and the ICV.
Step 5: It checks the ICV to the message received. Process
Authentication When a client connects to a WLAN must be authenticated. This authentication can be opened, ie there is no measure of demand so that you can associate with the network, or closed, which will produce a process of recognition of a valid client.
Thus, WEP authentication uses a very simple idea. If you have the WEP key encryption will be able to give me back what you send. Thus, the client calls connect and the AP 128 generates a sequence of bytes that the client sends encryption. Cilento decodes that string of 128 bytes and returns it in another frame encrypted with another IV. For mutual authentication to the process is repeated in reverse, ie the AP sending the connection request to the client and repeated sending the encrypted string of 128 bytes from client to AP.
WEP Security Is it safe to use WEP then? For the truth is no. For years it was shown that could be broken, and today break a WEP is fairly trivial, and within minutes you get out the WEP key. The attacker only has to capture enough frames encrypted with the same IV, the WEP key is in all messages, so if they get enough messages encrypted with the same IV can make a mathematical interpolation and within seconds you get out the WEP key. To get enough messages encrypted with the same IV, the attacker can simply wait or generate many messages repeated through traffic injection tool. Today, for the attackers is very easy to break the WEP because there are free tools simple enough to circumvent the process carried out to break the WEP.
But even here in Spain, where a research group on the subject of Wireless security (http://hwagm.elhacker.net/) have developed GUI tools to be more Sencillito.
Once you have generated a sufficient capture file is passed through the cracker that will return the WEP key being used.
WLanDecrypter
A concrete specification WEP networks has occurred in Spain. A TV company Internet installed in their wireless networks to customers whenever they set as a value of type SSID: WLAN_XX.
These networks use a simple WEP key has been discovered. The key is made with the first letter of the brand of router used in case (Comtrend, Zyxel, Xavi) and MAC of the router's WAN interface. Also the name of the network is WLAN_XX where XX are the last two digits of the MAC address of WAN interface. Since each router has a partnership between the manufacturer of the wireless interface and WAN interface, since they are made in series and with the same parts, if we know the wireless MAC interface also know the first 3 pairs of hexadecimal digits the WAN MAC (corresponding to manufacturer).
In short, with a simple and capture a network message within a few seconds to break the WEP key for this type of network. Until companies change their policies.
Network Addressing
For an attacker to find the network address must be used in a WLAN that has been cast is also a trivial step:
- The network DHCP server, the attacker's computer will be configured automatically and you will not do anything. If you have supplanted MAC address of a client, the attacker can not use this IP address because it is already being used by another (because the DHCP server assigns addresses based on MAC addresses), but will be to see the range of addresses that can be used and gateway.
- The network has DHCP: Client connects to a valid IP address and by capturing the network with a sniffer (Wireshark, Ethereal, AiroPeek, ...). In a catch in traffic will quickly see which IP addresses are being used. To find the gateway will only have to find a connection between an internal team with an external IP. That message, necessarily have been sent to the gateway, then the MAC destination of that message is the MAC of the gateway. Just use the ARP to find the IP associated with that MAC.
802.11i, WPA and WPA2
Having seen, everyone knew he had to do something with the Wireless Network Security. The only solution that arose with this situation was to make VPN connections from the client to be connected to a WLAN to a server on the network to get encrypted connections, that is, treat the WLAN as an insecure network like the Internet and performing encryption and authentication over the mechanisms that give us servers VPN. The IEEE 802.11
announced a new safe version would be called 802.11i WLAN security protocols change of WLANs. As the approval process was long a standard and the market needed a quick fix, a group of companies, united under the organization set up Wi-Fi Alliance WPA (Wireless Protected Access) as a practical implementation of what would become the next standard 802.11 i.
Attacking Wireless networks have long since become a sport, a diversion or a hobby. In almost all the media have written articles on how to hack wireless networks (I myself wrote an article about this same almost 2 years ago) and even in the Microsoft Security Days 2005 and the tour went Technet Security giving demonstrations of how easily you can make an attack on a wireless network.
However, it is still common wireless network attacks to succeed. Why is this happening? Justifications such as Who is going to attack me? Or if I have nothing important, I do not use my network that often reflect a lack of knowledge of risk or a problem of technical knowledge of how you can secure a wireless network. Let's do a quick review of the security technologies Wireless networks and seeing the risks of each one of them to choose a good option when protecting our network.
Wireless Technology
Any connection to make wireless LAN is considered, but we will focus on the WLAN, or Wireless Local Area Network. Wireless networks can be of two types, Ad-hoc, which would be a network between two computers same network (peer) or Infrastructure, which simulate a network connection based on a hub or hub connections. This is important because it mediates the types of attacks can be performed.
standards governing these technologies are the 802.11 and the first that reached the public were the 802.11b and 802.11g standards that allow data rates from 11 Mb / s to 108 Mb / s. From 2004, working on the 802.11n standard that will allow deployments of up to 500 Mb / s and is expected to be published later this year or early 2007. Surprisingly, as happened with the pending 802.11i (we'll talk about it a little later) is already ahead of the market and are available for purchase 802.11n devices are designed according to the information in the draft [1] standard was approved. To complete some of the "letters" that can be found in standards, there 802.11e version, designed for streaming video and audio in real time using quality of service protocols.
Okay, so far about "letters" that mark some features of the connections, but not security. Let's move on.
Defining a WLan
The first thing to define is the name of our WLAN network, and for that brief definitions to clarify:
- BSS (Basic Service Set). It refers to a set of machines belonging to the same wireless network and share a common point of access to the wireless network (AP)
- BSSID (Basic Service Set Identifier): The identifier that is used to refer to a BSS. Has the MAC address structure and generally all manufacturers use the MAC address of AP. This is important because attackers find this value to identify the clients on the network. To do this, attackers look for in network communications that machines are connecting to the AP.
- ESS (Extended Service Set). BSS is a set of forming a network, usually will be a complete WLAN.
- SSID (Service Set Identifier): The name of the WLAN, understandable to the user, which we configure: mi_wlan, escrufi or wlan1.
- ESSID (Extender Set Service Identifier): The ESS ID is transparent to the user and carries information the SSID.
MAC Protection To prevent unwanted clients from connecting many AP offers options to create white lists of equipment that can be connected according to the MAC address of the customer. To this are added the AP machine directions we want to allow and ready.
This is not a security measure as it is fairly robust easy to jump to an attacker. Using any network analysis tool com wlan Netstumbler we discover the SSID, channel and frequency being used and the MAC of the AP.
Once you know the MAC of the AP to know the customer authorized Macs as easy as opening a Sniffer as AiroPeek network and see what addresses are communicated to the MAC of the AP. Those are the authorized MACs. Once you have the list of authorized addresses, because the attacker is configured with a valid MAC one of the many tools that are available for spoof (impersonate) addresses and will have already skipped this protection.
Image: SMAC tool spoof the MAC address of your WLAN with the value 00-13-02-2E-8B-41 by the value FA-BA-DA-FE-AF-EA
Conclusion: The MAC address filtering is not a good security protection, it's easy for an attacker to bypass this protection.
Authentication and Encryption Keys
64 and 128-bit WEP
The 802.11 standard defines a system for authentication and encryption of communications Wlan called WEP (Wireless Equivalent Privacy).
WEP uses a keyword that will be used to authenticate to WEP networks closed to encrypt messages and communication.
To generate the key, in many AP calls for a sentence and then after it generated 5 different keys to ensure the best chance in the election of the same, but others simply asked to be introduced with restrictions length that is configured and ready.
for encryption of each frame plus a changing sequence of bits, called Initialization Vector (IV), so they do not always use the same key for encryption and decryption. Thus, two identical messages will not generate the same result as the encryption key changes.
As you can see in the image, in this case we have an AP that can generate 5 key from a phrase or directly set a key. When we have 5 key, we check which is what we will use it only uses 1 WEP key to everything. As you can see we have selected a choice of 64-bit WEP key, of which 5 bytes (40 bits) are the key and the remaining 24 bits are the IV. That is, in normal communication would have 2 to 24 different encryption keys.
For 128-bit WEP we will have 13 fixed bytes (104 bytes) and 24-bit shifting (IV), ie we have the same number of keys but longer.
Encryption and Decryption Process
To understand the process of authentication in WLAN networks with WEP is necessary to explain in advance the process of encryption and decryption as it is used during the authentication process for a client.
The encryption process is as follows:
Step 1: Selection of the IV (24 bits). The standard does not require a specific formula.
Step 2: Joining the WEP key and IV to generate a sequence of 64 or 128 bits. This value is Keystream called RC4.
Step 3: It happens that sequence by an RC4 algorithm to generate an encrypted value of that particular key.
Step 4: It generates a value of integrity of the message to be transmitted (ICV) to verify that the message has been decoded correctly and is added to the bottom.
Step 5: Make a XOR between the message and the message generated keystream RC4 encryption.
Step 6: Add the encrypted message the IV used for the recipient is able to decrypt the message.
The decryption process is the reverse:
Step 1: read the message received IV
Step 2: paste the WEP key IV
Step 3: RC4 generates Keystream
Step 4: XOR ago between the encrypted message and the RC4 keystream and gets the message and the ICV.
Step 5: It checks the ICV to the message received. Process
Authentication When a client connects to a WLAN must be authenticated. This authentication can be opened, ie there is no measure of demand so that you can associate with the network, or closed, which will produce a process of recognition of a valid client.
Thus, WEP authentication uses a very simple idea. If you have the WEP key encryption will be able to give me back what you send. Thus, the client calls connect and the AP 128 generates a sequence of bytes that the client sends encryption. Cilento decodes that string of 128 bytes and returns it in another frame encrypted with another IV. For mutual authentication to the process is repeated in reverse, ie the AP sending the connection request to the client and repeated sending the encrypted string of 128 bytes from client to AP.
WEP Security Is it safe to use WEP then? For the truth is no. For years it was shown that could be broken, and today break a WEP is fairly trivial, and within minutes you get out the WEP key. The attacker only has to capture enough frames encrypted with the same IV, the WEP key is in all messages, so if they get enough messages encrypted with the same IV can make a mathematical interpolation and within seconds you get out the WEP key. To get enough messages encrypted with the same IV, the attacker can simply wait or generate many messages repeated through traffic injection tool. Today, for the attackers is very easy to break the WEP because there are free tools simple enough to circumvent the process carried out to break the WEP.
But even here in Spain, where a research group on the subject of Wireless security (http://hwagm.elhacker.net/) have developed GUI tools to be more Sencillito.
Once you have generated a sufficient capture file is passed through the cracker that will return the WEP key being used.
WLanDecrypter
A concrete specification WEP networks has occurred in Spain. A TV company Internet installed in their wireless networks to customers whenever they set as a value of type SSID: WLAN_XX.
These networks use a simple WEP key has been discovered. The key is made with the first letter of the brand of router used in case (Comtrend, Zyxel, Xavi) and MAC of the router's WAN interface. Also the name of the network is WLAN_XX where XX are the last two digits of the MAC address of WAN interface. Since each router has a partnership between the manufacturer of the wireless interface and WAN interface, since they are made in series and with the same parts, if we know the wireless MAC interface also know the first 3 pairs of hexadecimal digits the WAN MAC (corresponding to manufacturer).
In short, with a simple and capture a network message within a few seconds to break the WEP key for this type of network. Until companies change their policies.
Network Addressing
For an attacker to find the network address must be used in a WLAN that has been cast is also a trivial step:
- The network DHCP server, the attacker's computer will be configured automatically and you will not do anything. If you have supplanted MAC address of a client, the attacker can not use this IP address because it is already being used by another (because the DHCP server assigns addresses based on MAC addresses), but will be to see the range of addresses that can be used and gateway.
- The network has DHCP: Client connects to a valid IP address and by capturing the network with a sniffer (Wireshark, Ethereal, AiroPeek, ...). In a catch in traffic will quickly see which IP addresses are being used. To find the gateway will only have to find a connection between an internal team with an external IP. That message, necessarily have been sent to the gateway, then the MAC destination of that message is the MAC of the gateway. Just use the ARP to find the IP associated with that MAC.
802.11i, WPA and WPA2
Having seen, everyone knew he had to do something with the Wireless Network Security. The only solution that arose with this situation was to make VPN connections from the client to be connected to a WLAN to a server on the network to get encrypted connections, that is, treat the WLAN as an insecure network like the Internet and performing encryption and authentication over the mechanisms that give us servers VPN. The IEEE 802.11
announced a new safe version would be called 802.11i WLAN security protocols change of WLANs. As the approval process was long a standard and the market needed a quick fix, a group of companies, united under the organization set up Wi-Fi Alliance WPA (Wireless Protected Access) as a practical implementation of what would become the next standard 802.11 i.
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment