Menu

Database

Virtual Carrier-sense DoS

WVE ID: WVE-2005-0051

Type: Vulnerability

Status: Candidate

Classification:
Denial of Service
Design Flaw

Description:
802.11 devices can block access to the wireless LAN by specifying large duration values in frames they transmit.

Discussion:
The IEEE 802.11 standard allows a transmitting station or AP to reserve the wireless medium by specifying a duration value in frames that are transmitted. Stations use this field to program their NAV (Network Allocation Vector).

A device is not allowed to transmit until their NAV reaches 0. Thus an attacker can send frames back-to-back that contain a large duration value and block access to the channel.

This is best done by sending RTS, CTS, or ACK frames with the duration field set to 32767 -- the largest valid value. This allows an attack to effectively block all devices on a channel from transmitting by sending such frames at a rate of 30 per second.

NOTE: Attacks against this vulnerability, may also be known as duration field attacks, virtual carrier-sense attacks or network allocation vector (NAV) attacks.

Credits

References
URL: http://standards.ieee.org/getieee802/download/802.11-1999.pdf
URL: http://sysnet.ucsd.edu/~bellardo/pubs/usenix-sec03-80211dos-html/aio.html#SECTION00032000000000000000

Released: 2000-01-01

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Wed Nov 30 14:36:21 -0800 2005

Candidate Date: Wed Nov 30 14:37:10 -0800 2005


Recent Entries

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

Sidejacking
WVE-2008-0003 4/2/2008

ZiPhone
WVE-2008-0002 4/2/2008

RADIUS Key Delivery Exposure
WVE-2008-0001 3/21/2008

BackTrack
WVE-2007-0020 11/19/2007

Airoscript
WVE-2007-0019 11/19/2007

airoway.sh
WVE-2007-0018 11/19/2007

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...