Menu

Database

RADIUS Key Delivery Exposure

WVE ID: WVE-2008-0001

Type: Vulnerability

Status: Candidate

Classification:
Authentication Management
Cryptographic

Description:
Distributed RADIUS deployments threaten the secure delivery of key content such as the 802.11i Pairwise Master Key due to the weak security applied to protect RADIUS frames.

Discussion:
Distributed NAS clients such as a fat AP model leverage RADIUS servers for key material delivery when deployed with protocols such as IEEE 802.1X. In these deployments, the security mechanisms used in RADIUS which include a pre-shared key and the Microsoft Point-to-Point Encryption protocol (MPPE) are weak, where if an attacker is able to capture the delivery of RADIUS-protected key material, they can perform an offline brute-force attack against the RADIUS PSK. Once the RADIUS PSK is known, the attacker can capture and decrypt RADIUS traffic, revealing 802.11i keys including the Pairwise Master Key (PMK). Once an attacker has captured the PMK, they can passively decrypt all 802.11i-protected data.

Credits
Author: Merwyn Andrade : Aruba Networks
Author: Randy Chou : Aruba Networks
Author: Joshua Wright (jwright@hasborg.com) : SANS Institute

References
URL: http://802.11ninja.net/~jwright/802/radius_vuln_00.txt
URL: http://www.eweek.com/c/a/Mobile-and-Wireless/WLANs-Exposed-by-Hack/

Released: 2004-07-28

Submitter
: None

Submitted: Fri Mar 21 05:57:16 -0700 2008

Candidate Date: Fri Mar 21 06:12:14 -0700 2008


Recent Entries

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

Sidejacking
WVE-2008-0003 4/2/2008

ZiPhone
WVE-2008-0002 4/2/2008

RADIUS Key Delivery Exposure
WVE-2008-0001 3/21/2008

BackTrack
WVE-2007-0020 11/19/2007

Airoscript
WVE-2007-0019 11/19/2007

airoway.sh
WVE-2007-0018 11/19/2007

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...