236w ago - PCWorld reports today that security researchers have developed a way to partially crack the Wi-Fi Protected Access (WPA) encryption standard used to protect data on many wireless networks.
However, the attack does not however work with the WPA2 standard states
Dragos Ruiu, the
PacSec conference's organizer who will be discussing it next week in Tokyo.
To quote: "Everybody has been saying, 'Go to WPA because WEP is broken,'" Ruiu said. "This is a break in WPA."
If WPA is significantly compromised, it would be a big blow for enterprise customers who have been increasingly adopting it, said Sri Sundaralingam, vice president of product management with wireless network security vendor AirTight Networks.
Although customers can adopt Wi-Fi technology such as WPA2 or virtual private network software that will protect them from this attack, there are still may devices that connect to the network using WPA, or even the thoroughly cracked WEP standard, he said.
Ruiu expects a lot more WPA research to follow this work. "Its just the starting point," he said. "Erik and Martin have just opened the box on a whole new hacker playground."
eg. you could modify someones DNS request to return a result that point them to another site.
It does not let you connect to the router and use the network like you could if you have the key.
Daweed30, you do not need to connect to a router to sniff packets.
here in my neighborhood there are about 2 wpa2, 20 wpa networks, 3 wep and 1 without encryption. I have the passwords of 4 of them
I think this will make it possible for me to get even more passwords xD
this method apparently is somthing else and already existing in aircrakc-ng as one of the guy is the co-developer of that tool: http://www.heise-online.co.uk/security/WPA-alleged-to-be-crackable-in-less-than-15-minutes--/news/111906
can't wait to see.