Menu

Database

GF Mode WIDS Rogue AP Evasion

WVE ID: WVE-2008-0005

Type: Vulnerability

Status: Candidate

Classification:
Other

Description:
An optional technology in the 802.11n specification known as Greenfield Mode allows rogue AP devices to evade wireless intrusion detection systems based on pre-802.11n technology.

Discussion:
The IEEE 802.11n specification promises to significantly improve the bandwidth of wireless LAN connections over that of existing 802.11a/b/g deployments. One of the mechanisms used to achieve higher data rates is the use of a new high-throughput (HT) physical layer mechanism known as greenfield (GF) mode. While operating in GF mode, APs and stations leverage a new frame preamble that precludes backward-compatibility with clients that are not HT capable. Non-HT devices cannot decode GF mode traffic, interpreting the presence of GF transmitters as spectral noise.

With the inability to decode GF mode traffic, an attacker can position a malicious rogue AP on a victim network using the GF mode preamble. This would allow an attacker to evade wireless intrusion detection systems (WIDS) based on non-HT devices. This includes all WIDS devices based on 802.11a/b/g wireless cards.

Detection and classification of rogue AP's using GF mode requires a HT capable WIDS system based on 802.11n sensors.

Credits

References
URL: http://www.networkworld.com/columnists/2006/111306-wireless-security.html
URL: http://www.willhackforsushi.com/presentations/rsa2008-wright.pdf

Released: 2006-11-13

Submitter
Joshua Wright (jwright@arubanetworks.com) : Aruba Networks

Submitted: Wed Apr 09 16:41:28 -0700 2008

Candidate Date: Wed Apr 09 19:14:28 -0700 2008


Recent Entries

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

Sidejacking
WVE-2008-0003 4/2/2008

ZiPhone
WVE-2008-0002 4/2/2008

RADIUS Key Delivery Exposure
WVE-2008-0001 3/21/2008

BackTrack
WVE-2007-0020 11/19/2007

Airoscript
WVE-2007-0019 11/19/2007

airoway.sh
WVE-2007-0018 11/19/2007

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...