Menu

Database

Association Request Frame DoS

WVE ID: WVE-2005-0047

Type: Vulnerability

Status: Candidate

Classification:
Denial of Service
Design Flaw

Description:
802.11 Access Points are vulnerable to DoS attacks that involve sending Association request frames to the AP from multiple spoofed station addresses.

Discussion:
802.11 networks utilize frames to manage connection and disconnection of stations from a wireless network. These are appropriately called management frames. One type of management frame, an association request is sent by stations after authenticating with the AP before the station can join the network. If the AP allows the station to join the network it will send a successful association response to the station.

However, a problem arises in that 802.11 management frames provide no authentication. Hence it is possible for an attacker to spoof a large number of stations and send out association requests for each station. Doing so can cause the APs association table to fill which can cause the AP to lock-up.

It should be noted that this will only work on APs using open authentication. This is because a station must be in the authenticated state in order for the AP to accept the associate request. Thus networks that require WEP shared key authentication are not vulnerable to this.

However, because of inherent problems in WEP keys, many networks that are designed with security in mind will use 802.1X which requires that the AP be in open authentication mode.

Credits

References
URL: http://standards.ieee.org/getieee802/download/802.11-1999.pdf
WVE: WVE-2005-0019

Released: 2000-01-01

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Wed Nov 30 12:17:59 -0800 2005

Candidate Date: Wed Nov 30 12:21:27 -0800 2005


Recent Entries

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

Sidejacking
WVE-2008-0003 4/2/2008

ZiPhone
WVE-2008-0002 4/2/2008

RADIUS Key Delivery Exposure
WVE-2008-0001 3/21/2008

BackTrack
WVE-2007-0020 11/19/2007

Airoscript
WVE-2007-0019 11/19/2007

airoway.sh
WVE-2007-0018 11/19/2007

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...