<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Geek Report &#187; Security</title>
	<atom:link href="http://geekreport.com/category/news/security-news/feed" rel="self" type="application/rss+xml" />
	<link>http://geekreport.com</link>
	<description>Technology Web Blog, News, Reviews, Videos and How to Guides</description>
	<lastBuildDate>Sun, 17 Apr 2011 14:08:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft Suggests Avoiding IE For Now</title>
		<link>http://geekreport.com/509/microsoft-says-avoid-ie</link>
		<comments>http://geekreport.com/509/microsoft-says-avoid-ie#comments</comments>
		<pubDate>Wed, 17 Dec 2008 18:09:17 +0000</pubDate>
		<dc:creator>Anti-Trend</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[pwned]]></category>
		<category><![CDATA[zero day]]></category>

		<guid isPermaLink="false">http://geekreport.com/?p=509</guid>
		<description><![CDATA[Guardian.co.uk is reporting on Microsoft&#8217;s humiliating decision to recommend that its customers forgo the use of Microsoft&#8217;s own Internet Explorer product. They are instead suggesting that Windows users make use of a more secure browser such as Firefox or Opera until they are able to patch the latest serious vulnerability in IE.



From the article:


  [...]]]></description>
			<content:encoded><![CDATA[<p>Guardian.co.uk is reporting on Microsoft&#8217;s humiliating decision to recommend that its customers forgo the use of Microsoft&#8217;s own Internet Explorer product. They are instead suggesting that Windows users make use of a more secure browser such as Firefox or Opera until they are able to patch the latest serious vulnerability in IE.</p>

<p><img src="http://cache.geekreport.com/assets/files/2008/12/ie_crosshairs.png" alt="" title="ie_crosshairs" width="100" height="100" class="alignleft size-full wp-image-508" /></p>

<p>From the article:</p>

<blockquote>
  <p>The flaw in IE allows criminals to gain control of computers that have visited a website infected with malicious code designed to exploit it. While restricting web surfing to trusted sites should reduce the risk of infection, the malicious code can be injected into any website. Users do not have to click or download anything to become infected, merely visiting an infected website is sufficient.</p>
</blockquote>

<p><a href="http://www.guardian.co.uk/technology/2008/dec/16/internet" title="Guardian.co.uk">Read More</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geekreport.com/509/microsoft-says-avoid-ie/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>AVG virus definition update cripples Windows PC&#8217;s</title>
		<link>http://geekreport.com/478/avg-virus-definition-update-cripples-windows-pcs</link>
		<comments>http://geekreport.com/478/avg-virus-definition-update-cripples-windows-pcs#comments</comments>
		<pubDate>Tue, 11 Nov 2008 12:44:08 +0000</pubDate>
		<dc:creator>RHochstenbach</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[pc]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[windows xp]]></category>

		<guid isPermaLink="false">http://geekreport.com/?p=478</guid>
		<description><![CDATA[A recent update in the virus definitions of AVG causes a critical file, user32.dll, to be detected as a virus. As a result, the affected computers running Windows XP keep rebooting right before the log-on screen appears.



AVG recommends affected users to boot into Safe Mode, restore the user32.dll file from the Windows CD, or from [...]]]></description>
			<content:encoded><![CDATA[<p>A recent update in the virus definitions of AVG causes a critical file, user32.dll, to be detected as a virus. As a result, the affected computers running Windows XP keep rebooting right before the log-on screen appears.</p>

<p><img src="http://cache.geekreport.com/assets/files/2008/11/avg-logo-275x250.jpg" alt="" title="AVG Logo" width="275" height="250" class="alignnone size-medium wp-image-482" /></p>

<p>AVG recommends affected users to boot into Safe Mode, restore the user32.dll file from the Windows CD, or from a website and temporarily remove AVG until an update addresses the issue.</p>

<p><a href="http://freeforum.avg.com/read.php?7,155461,backpage=,sv=">Read More</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geekreport.com/478/avg-virus-definition-update-cripples-windows-pcs/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WPA2 Personal Cracked, Russian Company Claims</title>
		<link>http://geekreport.com/403/wpa2-personal-cracked-russian-company-claims</link>
		<comments>http://geekreport.com/403/wpa2-personal-cracked-russian-company-claims#comments</comments>
		<pubDate>Mon, 13 Oct 2008 01:13:27 +0000</pubDate>
		<dc:creator>Anti-Trend</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Laptop]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AES]]></category>
		<category><![CDATA[Brute]]></category>
		<category><![CDATA[bruteforce]]></category>
		<category><![CDATA[CPU]]></category>
		<category><![CDATA[Cracked]]></category>
		<category><![CDATA[Elcomsoft]]></category>
		<category><![CDATA[Force]]></category>
		<category><![CDATA[FUD]]></category>
		<category><![CDATA[gpu]]></category>
		<category><![CDATA[NVIDIA]]></category>
		<category><![CDATA[Practical]]></category>
		<category><![CDATA[Researchers]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[Russian]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TKIP]]></category>
		<category><![CDATA[WPA]]></category>
		<category><![CDATA[WPA2]]></category>

		<guid isPermaLink="false">http://geekreport.com/?p=403</guid>
		<description><![CDATA[The Russian based security firm ElcomSoft is claiming to be able to crack WPA2 Personal wireless authentication security in a matter of weeks rather than years. According to their press release, they&#8217;ve employed purpose-written software which is powered with a backend of clustered, commodity-grade NVIDIA GPUs.



This all sounds rather alarming at face value. But how [...]]]></description>
			<content:encoded><![CDATA[<p>The Russian based security firm <em>ElcomSoft</em> is claiming to be able to crack WPA2 Personal wireless authentication security in a matter of weeks rather than years. According to <a href="http://www.prweb.com/releases/wi-fi/cracking/prweb1405954.htm" title="ElcomSoft Breaks Wi-Fi Encryption Faster with GPU Acceleration">their press release</a>, they&#8217;ve employed purpose-written software which is powered with a backend of clustered, commodity-grade NVIDIA GPUs.</p>

<p><img src="http://cache.geekreport.com/assets/files/2008/10/wifi_laptop.png" alt="" title="wifi_laptop" width="480" height="350" class="alignnone size-full wp-image-404" /></p>

<p>This all sounds rather alarming at face value. But how effective would their methods be in real-life application? Read on for my dissection of this development.</p>

<p><span id="more-403"></span></p>

<h3>WPA2 Finally Cracked?</h3>

<p>Technically, ElcomSoft isn&#8217;t claiming to have cracked WPA2 <em>per se</em>, but rather to have drastically accelerated the processes of cracking the password. This is done using good old brute force methodology, i.e. guessing the password very rapidly. In the press release, ElcomSoft claims to achieve up to 100x the brute force capabilities of classic CPU-based attacks by employing GPUs instead:</p>

<blockquote>
  <p>Moscow, Russia (PRWEB) October 9, 2008 &#8212; ElcomSoft Co. Ltd. accelerates the recovery of WPA and WPA2 encryption used in the Wi-Fi protocol by employing the new-generation NVIDIA video cards. ElcomSoft patent-pending GPU acceleration technology implemented in Elcomsoft Distributed Password Recovery allows using laptop, desktop or server computers equipped with supported NVIDIA video cards to break Wi-Fi encryption up to 100 times faster than by using CPU only.</p>
</blockquote>

<p>High-end GPUs have already proven their effectiveness in mathematically complex <a href="http://folding.stanford.edu/English/FAQ-ATI" title="Folding @ Home on Commodity GPUs">physics</a> <a href="http://www.nvidia.com/object/nvidia_physx.html" title="NVIDIA PhysX">simulations</a>, so it should come as no great surprise that this technology might be leveraged in brute force password cracking operations. Still, based on the information one can glean from their somewhat vague press release, there are some serious questions the security community should be asking.</p>

<h3>Who is the target of such an attack?</h3>

<p>One would assume that the most desirable target of such an approach would be banks, corporations and other institutions where data security is of significance. However, the PSK security model of WPA/2 Personal is not very practical for larger or security-conscious organizations, since that means effectively handing out one password for all users. As such, I would expect WPA2 Enterprise to have a greater foothold in such circles, since authentication is centralized and handled on a per-user basis. Incidentally, WPA2 Enterprise is not vulnerable to this particular brute-force methodology at all.</p>

<h3>What About Proximity?</h3>

<p>How close must this GPU cluster be to the target in order to be effective? Must they be within range of the victim wireless network, or can a proxy system (e.g. a laptop) be within range, while the cluster hums in a remote data center somewhere? In the former case, an attacker must still have said laptop within range of the wireless network for at least a few weeks while the brute force works its magic. In the latter, I&#8217;m imagining a van with a noisy diesel generator, parked in the back alley behind a corporation for 2 weeks&#8230; and that probably wouldn&#8217;t be logistically feasible in most cases. Otherwise it would be down to attacking from a neighboring building, which leaves the attacker somewhat vulnerable to local law enforcement should the attack be detected.</p>

<h3>Was The Victim Hardware Taken Into Account?</h3>

<p>Since we&#8217;ve already established that the most likely spot to find networks using WPA/WPA2 Personal is in small or home offices and not more desirable targets, what kind of hardware are we likely to see in such a case? Consumer grade hardware which is typical of SOHO application typically has between 4-64mb of onboard memory and a 100-300MHz central processor. How many simultaneous connections would such hardware handle before becoming unreachable by the attacker? My guess would be less than 1000&#8230; probably far less on most hardware (250? 100? 50?). Still, for the sake of argument, let&#8217;s assume the prospective victim&#8217;s access point can handle 5,000 simultaneous WPA2 attempts, and is secured with a meager 8-character password that utilizes only lowercase characters and a few digits. In such a scenario, it would take approximately <em><strong>19 years</strong></em> at a sustained rate of 5,000 attempts per second.</p>

<h3>Summary:</h3>

<p>This WPA2 crack doesn&#8217;t seem to be feasible in the overwhelming majority of situations. An attacker is supposed to:</p>

<ul>
<li>posses multi-thousand-dollar software (granted, this can potentially be pirated),</li>
<li>a networked cluster with plenty of relatively high-end NVIDIA video cards,</li>
<li>be able to physically position themselves in such a way as to actually perpetrate the attack.</li>
</ul>

<p>Additionally, the victim network must:</p>

<ul>
<li>posses facilities which lend themselves to a rather conspicuous multi-week brute force episode</li>
<li>have extremely high-end wireless hardware capable of handling <em>much</em> higher than average connections per second,</li>
<li>forgo WPA2 Enterprise for the less scalable WPA2 Personal,</li>
<li>utilize a ridiculously weak PSK with far under the 63-character max password limit,</li>
<li>neglect to log failed WPA2 authentication attempts or use any wireless IDS tools of any kind,</li>
<li>have something worth attacking inside the target WPA2 network (e.g. not a bare-bones DMZ that&#8217;s separated from the internal network by firewalls).</li>
</ul>

<h3>Conclusion:</h3>

<p>While I would expect the GPU-based brute force technology may hold some merit for non-wireless password cracking, the suggested WPA2 application seems an attention grab at best and snake oil at worst. Now, I&#8217;m perfectly willing to admit that ElcomSoft might possibly have some very substantial improvements over the standard brute force methodology they&#8217;ve mentioned in their press release. If that is so, hopefully they will release a more detailed whitepaper on how their technology works; some real-world figures that are readily reproducible would be nice too. But unless this comes to pass, I think we can conclude that this press release is clearly more sales pitch than zero day.</p>
]]></content:encoded>
			<wfw:commentRss>http://geekreport.com/403/wpa2-personal-cracked-russian-company-claims/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

