Menu

Database

Auto Immune Attack

WVE ID: WVE-2008-0011

Type: Vulnerability

Status: Candidate

Classification:
Input Manipulation

Description:
A condition can be triggered on certain access points to transmit de-authentication and disassociation frames to all clients.

Discussion:
By sending management frames with forged fields, vulnerable access points will return deauthenticate or disassociate frames to all clients. Triggers that can cause this condition include the use of broadcast or multicast MAC address in the source address field.

Credits
Author: Amit Vartak (amit.vartak@airtightnetworks.com) : Airtight Networks
Author: J V R Murthy (Murthy.jvr@airtightnetworks.com) : Airtight Networks
Author: Md Sohail Ahmad (md.ahmad@airtightnetworks.com) : Airtight Networks

References
URL: http://www.defcon.org/images/defcon-16/dc16-presentations/defcon-16-ahmad.pdf
URL: http://www.airtightnetworks.com/home/resources/knowledge-center/wlan-self-dos.html
URL: http://www.airtightnetworks.com/home/resources/knowledge-center/wlan-self-dos.html

Released: 2008-08-01

Submitter
Nicholas DePetrillo (ndepetrillo@arubanetworks.com) : Aruba Networks

Submitted: Wed Sep 17 13:07:21 -0700 2008

Candidate Date: Wed Sep 17 13:13:27 -0700 2008


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...