The attack chop-chop to TKIP ........El ataque chop-chop a TKIP

Late last year jumped an attack on one of those famous conferences where researchers surprised the world with their latest discoveries. The work presented was called "Gone in 900 Seconds, Some Issues with Crypto WPA" in which a crack TKIP package in less than 15 minutes. The idea is to do the work an attempt to inject packets without knowing the key and waiting for response from the access point to decrypt the result.

The target of the attack was to decrypt the response to a request through an ARP attack chop-chop to know that the key has been encrypted with that package and reuse in order to inject new packets into the network.

Although it is a step in the insecurity of Wi-Fi networks when the attack is less difficult to make and difficult to exploit. The system TKIP uses the RC4 protocol like WEP system but with two variations. The first is that the encryption keys are derived from the values snoce and anonce, then a different authentication keys. The second is that encryption of a packet is not only a key plus the initialization vector but used an extended initialization vector is the fourth most value known as TSC [TKIP Sequence Counter]. This value varies from 48 bits while the fourth varies by not reuse IV + a TSC in a channel in years.

If you get to know the key that has an encryption package, it could not be reused unless you increase the TSC. If the TSC is increased, then the encryption key of the package is invalid. To reuse the key for a packet of this attack makes use of the extensions of service quality of multimedia channels. It is necessary therefore that the access point functionality support IEEE 802.11e QoS (Quality of Service) called WMM (Wifi Multimedia) or WME (Wireless Multimedia Extensions) that are part of the certification of the Wi-Fi-Alliance for the standard IEEE 802.11e. These extensions bandwidth divided into eight channels with different priority in each of them.

Image: Wi-Fi routers in WMM



In the environment of the attack if it is discovered that the key has been encrypted with a package for a particular channel, with an IV and a specific TSC will reuse this key to send a package by another channel different. After this proof of concept could be to inject up to 7 packages valid.

To achieve this attack, the researchers performed a brute force attack on the encryption key for a package to an ARP request for a response channel. Logically, this package brings an IV and a known TSC. Where does the key access point replies with the response to the ARP request. From that moment, with that IV, the TSC, on the other channel and during the time that TKIP keys are not renegotiated 7 packets can be injected to the network assuming that the TSC of the other channels is greater than those used here. Obviously this attack opens up many possibilities for the future and is likely to be beaten back to TKIP, but it is far less definitive yet.
................................................................

A finales del año pasado saltó un ataque realizado en una de esas famosas conferencias dónde los investigadores sorprenden al mundo con sus últimos descubrimientos. El trabajo presentado se llamaba “Gone in 900 Seconds, Some Crypto Issues with WPA” en el que se crackeaba un paquete TKIP en menos de 15 minutos. La idea del trabajo consiste en realizar un intento de inyectar paquetes sin conocer la clave y esperar a obtener la respuesta del punto de acceso para descifrar el resultado.

El objetivo del ataque era conseguir descifrar la respuesta de una petición ARP mediante un ataque chop-chop y así conocer la clave con que se ha cifrado ese paquete y reutilizarla para poder inyectar nuevos paquetes en la red.

Aunque es un avance en la inseguridad de redes Wifi el ataque sigue siendo cuando menos difícil de efectuar y difícil de sacar partido. El sistema TKIP utiliza el protocolo RC4 al igual que el sistema WEP pero con dos variaciones. La primera es que las claves de cifrado son derivadas de los valores snoce y anonce, luego son distintas a las claves de autenticación. La segunda es que el cifrado de un paquete no se realiza sólo con una clave más el vector de inicialización sino que se utiliza un vector de inicialización extendido, es decir el IV más un valor conocido como TSC [TKIP Sequence Counter]. Este valor de 48 bits varía al mismo tiempo que varía el IV haciendo que no se reutilice un IV+TSC en un canal en años.

Si se consigue conocer la clave con que se ha cifrado un paquete, ésta no podría ser reutilizada a no ser que se incremente el TSC. Si el TSC se incrementa, entonces la clave de cifrado del paquete queda invalidada. Para poder reutilizar la clave de un paquete éste ataque hace uso de las extensiones de calidad de servicio de los canales multimedia. Es necesario por tanto que el punto de acceso soporte las funcionalidades del IEEE 802.11e QoS (Calidad de Servicio) llamadas WMM (Wifi Multimedia) o WME (Wireless Multimedia Extensions) y que son parte de la certificación de la Wifi-Alliance para el estándar IEEE 802.11e. Estas extensiones dividen el ancho de banda en ocho canales con distinta prioridad en cada uno de ellos.

Imagen: WMM en routers Wifi



En el entorno del ataque si se descubre la clave con que se ha cifrado un paquete para un canal concreto, con un IV y un TSC concreto se podrá reutilizar esta clave para enviar un paquete por otro canal distinto. Luego con esta prueba de concepto se podrían llegar a inyectar hasta 7 paquetes válidos.

Para la realización de este ataque, los investigadores realizaron un ataque de fuerza bruta a la clave de cifrado de un paquete para una petición de respuesta ARP por un canal concreto. Lógicamente ese paquete lleva un IV y un TSC conocidos. Cuando la clave funciona el punto de acceso contesta con la respuesta a la petición ARP. A partir de ese momento, con ese IV, ese TSC, por otro canal y durante el tiempo que las claves TKIP no se renegocien se pueden inyectar 7 paquetes a la red suponiendo que el TSC de los otros canales sea superior a los utilizados allí. Lógicamente este ataque abre muchas posibilidades de futuro y es probable que TKIP vuelva a ser golpeado, pero no es ni mucho menos definitivo todavía


Autor : Maligno , un informatico que esta del lado del mal,...mmm asi dicen :)

1 comentario:

Chema Alonso dijo...

Hola,

soy Chema Alonso, el Maligno, el autor de este artículo. Me agrada que te hagas eco de él, pero te agradecería que pusieras un link a la fuente original.

Elladodelmal: Ataque Chop chop a TKIP

Saludos Malignos!

Protected by Copyscape Original Article Checker