Menu

Database

Virtual Carrier-sense DoS

WVE ID: WVE-2005-0051

Type: Vulnerability

Status: Candidate

Classification:
Denial of Service
Design Flaw

Description:
802.11 devices can block access to the wireless LAN by specifying large duration values in frames they transmit.

Discussion:
The IEEE 802.11 standard allows a transmitting station or AP to reserve the wireless medium by specifying a duration value in frames that are transmitted. Stations use this field to program their NAV (Network Allocation Vector).

A device is not allowed to transmit until their NAV reaches 0. Thus an attacker can send frames back-to-back that contain a large duration value and block access to the channel.

This is best done by sending RTS, CTS, or ACK frames with the duration field set to 32767 -- the largest valid value. This allows an attack to effectively block all devices on a channel from transmitting by sending such frames at a rate of 30 per second.

NOTE: Attacks against this vulnerability, may also be known as duration field attacks, virtual carrier-sense attacks or network allocation vector (NAV) attacks.

Credits

References
URL: http://standards.ieee.org/getieee802/download/802.11-1999.pdf
URL: http://sysnet.ucsd.edu/~bellardo/pubs/usenix-sec03-80211dos-html/aio.html#SECTION00032000000000000000

Released: 2000-01-01

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Wed Nov 30 14:36:21 -0800 2005

Candidate Date: Wed Nov 30 14:37:10 -0800 2005


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...