Menu

Database

WEP IV collision reveals plaintext

WVE ID: WVE-2006-0035

Type: Vulnerability

Status: Candidate

Classification:
Cryptographic
Design Flaw

Description:
WEP networks are vulnerable to collisions in the selection of the initialization vector, which violates the integrity of the underlying RC4 cipher. With knowledge of two encrypted packets and the associated plaintext of one encrypted packet, an attacker can determine the plaintext contents of the second packet.

Discussion:
WEP networks suffer from a design flaw in the selection of the WEP initialization vector (IV) value. The IV is transmitted plaintext in each WEP encrypted packet, and should never be re-used.

Since the number of WEP IV's is finite however (the IV is a 24-bit number), IV collisions are prevalent in WEP implementations where multiple stations share the same shared secret, or for busy stations that do not change the shared secret before the IV space is exhausted.

When two encrypted frames are transmitted with the same IV, the integrity of the underlying RC4 cipher is compromised. If an attacker has knowledge of the plaintext contents of one frame in an an IV collision, it is possible to determine the plaintext contents of the 2nd frame by XOR'ing the encrypted and unencrypted contents together. This allows an attacker to decrypt traffic on a WEP network without knowledge of the WEP key.

Credits
Author: Jesse Walker : Intel Corporation

References
URL: http://grouper.ieee.org/groups/802/11/Documents/DocumentHolder/0-362.zip
URL: http://802.11ninja.net/code/ivcoltest.pl

Released: 2000-10-27

Submitter
Joshua Wright (jwright@arubanetworks.com) : Aruba Networks

Submitted: Mon May 01 12:34:28 -0700 2006

Candidate Date: Mon May 01 12:55:11 -0700 2006


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...