ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    WPA2 Hacked

    IT Discussion
    9
    56
    4.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch
      last edited by

      The handshake has always been the weak spot of WPA and WPA2. WPA had other issues, but was only even supposed to be a stopgap until WPA2 hardware was readily available.

      You can easily negate this entire thing by using PEAP to prevent malicious actors from spoofing disconnect frames that make your devices reconnect and thus require a new 4 way handshake.

      1 Reply Last reply Reply Quote 1
      • JaredBuschJ
        JaredBusch
        last edited by

        Also, while this is a serious flaw, it requires a malicious actor on site.

        This is not anything that I am worried about at a business.

        I will of course patch as soon as non-beta patches are available, but it is not some stupid OMG FUCKING PANIC situation.

        1 Reply Last reply Reply Quote 1
        • JaredBuschJ
          JaredBusch @JaredBusch
          last edited by

          @jaredbusch said in WPA2 Hacked:

          @dashrender said in WPA2 Hacked:

          In the past, I only got new firmware when updating the Unifi Controller software itself. The Firmware update button is kinda new (though I'm sure this is where JB will tell me it's been in there for years).

          It has been there since 5.0 was reelased

          Oh additionally, your UniFi instance will download updates on a schedule even without you pressing that button or updating the version.

          DustinB3403D 1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403 @JaredBusch
            last edited by

            @jaredbusch said in WPA2 Hacked:

            @jaredbusch said in WPA2 Hacked:

            @dashrender said in WPA2 Hacked:

            In the past, I only got new firmware when updating the Unifi Controller software itself. The Firmware update button is kinda new (though I'm sure this is where JB will tell me it's been in there for years).

            It has been there since 5.0 was reelased

            Oh additionally, your UniFi instance will download updates on a schedule even without you pressing that button or updating the version.

            Isn't this only enabled by the admin and not by default? (I'll have to double check my controller)

            JaredBuschJ 1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch @DustinB3403
              last edited by

              @dustinb3403 said in WPA2 Hacked:

              @jaredbusch said in WPA2 Hacked:

              @jaredbusch said in WPA2 Hacked:

              @dashrender said in WPA2 Hacked:

              In the past, I only got new firmware when updating the Unifi Controller software itself. The Firmware update button is kinda new (though I'm sure this is where JB will tell me it's been in there for years).

              It has been there since 5.0 was reelased

              Oh additionally, your UniFi instance will download updates on a schedule even without you pressing that button or updating the version.

              Isn't this only enabled by the admin and not by default? (I'll have to double check my controller)

              There is no button for it to my knowledge, but I am almost certain I read that in the guide. My devices occasionally have firmware updates when I have not clicked the button, nor updated the controller itself.

              DashrenderD 1 Reply Last reply Reply Quote 1
              • DashrenderD
                Dashrender @JaredBusch
                last edited by

                @jaredbusch said in WPA2 Hacked:

                @dustinb3403 said in WPA2 Hacked:

                @jaredbusch said in WPA2 Hacked:

                @jaredbusch said in WPA2 Hacked:

                @dashrender said in WPA2 Hacked:

                In the past, I only got new firmware when updating the Unifi Controller software itself. The Firmware update button is kinda new (though I'm sure this is where JB will tell me it's been in there for years).

                It has been there since 5.0 was reelased

                Oh additionally, your UniFi instance will download updates on a schedule even without you pressing that button or updating the version.

                Isn't this only enabled by the admin and not by default? (I'll have to double check my controller)

                There is no button for it to my knowledge, but I am almost certain I read that in the guide. My devices occasionally have firmware updates when I have not clicked the button, nor updated the controller itself.

                Yeah, I think I've seen this once - but I wrote it off as - I updated the controller, and then got side tracked and didn't push out the firmware to the APs.

                1 Reply Last reply Reply Quote 0
                • gjacobseG
                  gjacobse
                  last edited by

                  Just updated the UniFi Controller here at home,.. now running 5.5.24 and AP version 3.8.14.6780.. have to check the above link as well....

                  JaredBuschJ 1 Reply Last reply Reply Quote 0
                  • JaredBuschJ
                    JaredBusch
                    last edited by

                    0_1508166535922_ddba928b-53a7-49b7-a39b-078bc1e7299c-image.png
                    0_1508166506976_4f93984b-dc05-4494-9c42-15a6605bbb49-image.png

                    DustinB3403D 1 Reply Last reply Reply Quote 2
                    • DustinB3403D
                      DustinB3403 @JaredBusch
                      last edited by

                      @jaredbusch said in WPA2 Hacked:

                      0_1508166535922_ddba928b-53a7-49b7-a39b-078bc1e7299c-image.png
                      0_1508166506976_4f93984b-dc05-4494-9c42-15a6605bbb49-image.png

                      Can you post direct links for that?

                      JaredBuschJ 1 Reply Last reply Reply Quote 0
                      • JaredBuschJ
                        JaredBusch
                        last edited by

                        0_1508166815779_255bfd45-c359-492f-8528-7f0dd52b8bd1-image.png

                        1 Reply Last reply Reply Quote 1
                        • JaredBuschJ
                          JaredBusch @DustinB3403
                          last edited by

                          @dustinb3403 said in WPA2 Hacked:

                          @jaredbusch said in WPA2 Hacked:

                          0_1508166535922_ddba928b-53a7-49b7-a39b-078bc1e7299c-image.png
                          0_1508166506976_4f93984b-dc05-4494-9c42-15a6605bbb49-image.png

                          Can you post direct links for that?

                          Thread in quesiton: https://community.ubnt.com/t5/UniFi-Wireless/FIRMWARE-3-9-3-7537-for-UAP-USW-has-been-released/td-p/2099370

                          I am jsut picking out the news from the noise.

                          1 Reply Last reply Reply Quote 0
                          • JaredBuschJ
                            JaredBusch @gjacobse
                            last edited by

                            @gjacobse said in WPA2 Hacked:

                            Just updated the UniFi Controller here at home,.. now running 5.5.24 and AP version 3.8.14.6780.. have to check the above link as well....

                            5.5.24 was released like two weeks ago slacker.

                            gjacobseG 1 Reply Last reply Reply Quote 0
                            • gjacobseG
                              gjacobse @JaredBusch
                              last edited by

                              @jaredbusch said in WPA2 Hacked:

                              @gjacobse said in WPA2 Hacked:

                              Just updated the UniFi Controller here at home,.. now running 5.5.24 and AP version 3.8.14.6780.. have to check the above link as well....

                              5.5.24 was released like two weeks ago slacker.

                              Your point being? It's not something I have on my daily agenda to check on. and since it's my home setup,.. and it was working fine,.. there wasn't any business critical need.

                              DustinB3403D 1 Reply Last reply Reply Quote 1
                              • DustinB3403D
                                DustinB3403 @gjacobse
                                last edited by

                                @gjacobse said in WPA2 Hacked:

                                @jaredbusch said in WPA2 Hacked:

                                @gjacobse said in WPA2 Hacked:

                                Just updated the UniFi Controller here at home,.. now running 5.5.24 and AP version 3.8.14.6780.. have to check the above link as well....

                                5.5.24 was released like two weeks ago slacker.

                                Your point being? It's not something I have on my daily agenda to check on. and since it's my home setup,.. and it was working fine,.. there wasn't any business critical need.

                                Excuses excuses

                                gjacobseG 1 Reply Last reply Reply Quote 0
                                • gjacobseG
                                  gjacobse @DustinB3403
                                  last edited by

                                  @dustinb3403 said in WPA2 Hacked:

                                  @gjacobse said in WPA2 Hacked:

                                  @jaredbusch said in WPA2 Hacked:

                                  @gjacobse said in WPA2 Hacked:

                                  Just updated the UniFi Controller here at home,.. now running 5.5.24 and AP version 3.8.14.6780.. have to check the above link as well....

                                  5.5.24 was released like two weeks ago slacker.

                                  Your point being? It's not something I have on my daily agenda to check on. and since it's my home setup,.. and it was working fine,.. there wasn't any business critical need.

                                  Excuses excuses

                                  Not any form of excuse... it's reality. Those things involving having a home and 3 children - and sports... they are a higher priority and take center focus... then what is broke...

                                  DustinB3403D 1 Reply Last reply Reply Quote 0
                                  • DustinB3403D
                                    DustinB3403 @gjacobse
                                    last edited by

                                    @gjacobse said in WPA2 Hacked:

                                    @dustinb3403 said in WPA2 Hacked:

                                    @gjacobse said in WPA2 Hacked:

                                    @jaredbusch said in WPA2 Hacked:

                                    @gjacobse said in WPA2 Hacked:

                                    Just updated the UniFi Controller here at home,.. now running 5.5.24 and AP version 3.8.14.6780.. have to check the above link as well....

                                    5.5.24 was released like two weeks ago slacker.

                                    Your point being? It's not something I have on my daily agenda to check on. and since it's my home setup,.. and it was working fine,.. there wasn't any business critical need.

                                    Excuses excuses

                                    Not any form of excuse... it's reality. Those things involving having a home and 3 children - and sports... they are a higher priority and take center focus... then what is broke...

                                    Sorry that was a joke, as I up voted your post to which I replied. . .

                                    gjacobseG 1 Reply Last reply Reply Quote 1
                                    • gjacobseG
                                      gjacobse @DustinB3403
                                      last edited by

                                      @dustinb3403 said in WPA2 Hacked:

                                      @gjacobse said in WPA2 Hacked:

                                      @dustinb3403 said in WPA2 Hacked:

                                      @gjacobse said in WPA2 Hacked:

                                      @jaredbusch said in WPA2 Hacked:

                                      @gjacobse said in WPA2 Hacked:

                                      Just updated the UniFi Controller here at home,.. now running 5.5.24 and AP version 3.8.14.6780.. have to check the above link as well....

                                      5.5.24 was released like two weeks ago slacker.

                                      Your point being? It's not something I have on my daily agenda to check on. and since it's my home setup,.. and it was working fine,.. there wasn't any business critical need.

                                      Excuses excuses

                                      Not any form of excuse... it's reality. Those things involving having a home and 3 children - and sports... they are a higher priority and take center focus... then what is broke...

                                      Sorry that was a joke, as I up voted your post to which I replied. . .

                                      The reply was for the channeled JB in that response...

                                      1 Reply Last reply Reply Quote 0
                                      • ObsolesceO
                                        Obsolesce
                                        last edited by Obsolesce

                                        If this is a client patching issue, what does patching access points do? Or are there two separate things here?

                                        Looks like MS and some others have released a patch to fix this already, and you should be fine if you are regularly patching... but Android and others still have yet to release a patch to fix this.

                                        https://www.theverge.com/2017/10/16/16481818/wi-fi-attack-response-security-patches

                                        gjacobseG 1 Reply Last reply Reply Quote 0
                                        • hobbit666H
                                          hobbit666
                                          last edited by

                                          Main Download page for the Unifi's still only showing 3.8 firmware

                                          gjacobseG 1 Reply Last reply Reply Quote 0
                                          • gjacobseG
                                            gjacobse @hobbit666
                                            last edited by

                                            @hobbit666 said in WPA2 Hacked:

                                            Main Download page for the Unifi's still only showing 3.8 firmware

                                            Seems they have updated its your post...

                                            0_1508328886915_f2573275-c14c-442f-8e70-6f41de66d430-image.png

                                            hobbit666H 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 2 / 3
                                            • First post
                                              Last post