On Wed, 6 Jul 2011 08:18:34 +0100, "Desireless"
<usenet@soundstate.co.uk> wrote:
>Could anyone tell me if exists a router that is
>invulnerable to the wifi deauth attack please? Just a basic
>ADSL home user here in the UK. Thanks for any info.
>--Will.
<http://www.aircrack-ng.org/doku.php?id=deauthentication>
Sorta. Deauth is not really an "attack" in that it does not directly
lead to unauthorized wireless access or DoS (denial of service). It's
a means of forcing the AP and client to re-associate, thus generating
a larger number of "interesting" packets suitable for use in
recovering the pass phrase. Note that for deauth to be useful, both
the client and AP traffic must be captured and filtered by airedump.
If they get lucky and grab both sides of a re-association, it can
usually be replayed (using aireplay) to gain access.
For defense, it makes no sense for a non-connected client to initiate
a disconnect. The MAC address of a connected client and AP have to be
spoofed. That can be detected. The AP would need to maintain a table
of connected client states, and reject multiple disconnect packets.
The attacker could still initiate a single disconnect, but all
subsequent deauth packets from that MAC address would be ignored. This
doesn't really solve the problem, but does reduce the number of
reconnections, thus limiting the usefulness of this attack in
collecting "interesting" packets suitable for replay. I don't think
anyone has done that since it's not really 100% effective.
Cisco has a wireless intrusion detection system, which is overkill for
the home user. It doesn't prevent attacks, but does detect most of
them:
<http://www.cisco.com/en/US/docs/wireless/mse/3350/7.0/wIPS/configuration/guide/msecg_appA_wIPS.html#wp1156098>
<http://www.cisco.com/en/US/docs/wireless/mse/3350/7.0/wIPS/configuration/guide/msecg_appA_wIPS.html#wp1143533>
This is a bit old, but the references at the bottom are still useful:
<http://www.sans.org/security-resources/security_plus/replay_attack_sp08.php>
--
Jeff Liebermann
jeffl@cruzio.com
150 Felker St #D
http://www.LearnByDestroying.com
Santa Cruz CA 95060
http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558