Menu

Database

EAPoL-LogOff DoS

WVE ID: WVE-2005-0050

Type: Vulnerability

Status: Candidate

Classification:
Denial of Service
Design Flaw

Description:
802.11 networks utilizing 802.1x for authentication can be vulnerable to DoS attacks that involve sending spoofed EAPoL-LogOff messages.

Discussion:
The Extensible Authentication Protocol (EAP) is an extension to PPP which provides a general frame work to allow a connection to be authenticated. It itself does not specify the authentication mechanism. The IEEE created the 802.1x standard in order to allow EAP to be used on IEEE 802 networks.

When a station wishes to leave a WLAN it will send an EAP-LogOff message to the AP to end its authenticated session. Therefore it's possible for an attacker to spoof the MAC address of an authenticated station and send an EAP-LogOff message to the AP. This will cause the AP to believe that the legitimate station has ended its session. The legitimate station will not be aware that its session has been ended until it attempts to transmit data. At this point it will attempt to re-authenticate.

Credits

References
URL: http://standards.ieee.org/getieee802/download/802.11i-2004.pdf
URL: http://standards.ieee.org/getieee802/download/802.1X-2004.pdf

Released: 2000-01-01

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Wed Nov 30 14:22:44 -0800 2005

Candidate Date: Wed Nov 30 14:24:05 -0800 2005


Recent Entries

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

Sidejacking
WVE-2008-0003 4/2/2008

ZiPhone
WVE-2008-0002 4/2/2008

RADIUS Key Delivery Exposure
WVE-2008-0001 3/21/2008

BackTrack
WVE-2007-0020 11/19/2007

Airoscript
WVE-2007-0019 11/19/2007

airoway.sh
WVE-2007-0018 11/19/2007

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...