<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WPA2 finds itself in a &#8220;hole&#8221;! Vulnerable to insider attacks!</title>
	<atom:link href="http://blog.airtightnetworks.com/wpa2-finds-itself-in-a-hole-vulnerable-to-insider-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.airtightnetworks.com/wpa2-finds-itself-in-a-hole-vulnerable-to-insider-attacks/</link>
	<description></description>
	<lastBuildDate>Thu, 05 Jan 2012 23:48:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<item>
		<title>By: Kaustubh Phanse</title>
		<link>http://blog.airtightnetworks.com/wpa2-finds-itself-in-a-hole-vulnerable-to-insider-attacks/comment-page-1/#comment-6133</link>
		<dc:creator>Kaustubh Phanse</dc:creator>
		<pubDate>Mon, 16 Aug 2010 05:49:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.airtightnetworks.com/?p=1382#comment-6133</guid>
		<description>Hi Douglas,

You are absolutely right! 

Wi-Fi client isolation alone is not of much use because it can be bypassed if the attacker poisons the cache of the victim with the attacker&#039;s Ethernet NIC MAC address.

As you have rightly suggested, if the Wi-Fi APs are put on a separate VLAN then the victim&#039;s data cannot reach the attacker&#039;s machine (which will be on a VLAN different from the AP). In that case, the ARP poisoning attack will end up as a denial of service and man in the middle will not be successful.</description>
		<content:encoded><![CDATA[<p>Hi Douglas,</p>
<p>You are absolutely right! </p>
<p>Wi-Fi client isolation alone is not of much use because it can be bypassed if the attacker poisons the cache of the victim with the attacker&#8217;s Ethernet NIC MAC address.</p>
<p>As you have rightly suggested, if the Wi-Fi APs are put on a separate VLAN then the victim&#8217;s data cannot reach the attacker&#8217;s machine (which will be on a VLAN different from the AP). In that case, the ARP poisoning attack will end up as a denial of service and man in the middle will not be successful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Douglas Smith</title>
		<link>http://blog.airtightnetworks.com/wpa2-finds-itself-in-a-hole-vulnerable-to-insider-attacks/comment-page-1/#comment-5967</link>
		<dc:creator>Douglas Smith</dc:creator>
		<pubDate>Thu, 05 Aug 2010 14:33:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.airtightnetworks.com/?p=1382#comment-5967</guid>
		<description>Client Isolation plus IP subnetting: MITM-&gt;DOS

Client isolation (PSPF) cannot prevent the attack if the attacker adds an ethernet node to redirect traffic to.

If the hackers ethernet NIC is on a different IP subnet, then the ARP poisoning redirect will not result in packets being forwarded to the hackers ethernet NIC as it will be on an unreachable ethernet segment.  The attack will become a denial-of-service rather than man-in-the-middle.

Do you agree that the combination of client isolation and IP subnetting could be used to partially address the Hole196 ARP poisoning attack?</description>
		<content:encoded><![CDATA[<p>Client Isolation plus IP subnetting: MITM-&gt;DOS</p>
<p>Client isolation (PSPF) cannot prevent the attack if the attacker adds an ethernet node to redirect traffic to.</p>
<p>If the hackers ethernet NIC is on a different IP subnet, then the ARP poisoning redirect will not result in packets being forwarded to the hackers ethernet NIC as it will be on an unreachable ethernet segment.  The attack will become a denial-of-service rather than man-in-the-middle.</p>
<p>Do you agree that the combination of client isolation and IP subnetting could be used to partially address the Hole196 ARP poisoning attack?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WPA2 Hole196 Vulnerability &#124; Pablumfication</title>
		<link>http://blog.airtightnetworks.com/wpa2-finds-itself-in-a-hole-vulnerable-to-insider-attacks/comment-page-1/#comment-5758</link>
		<dc:creator>WPA2 Hole196 Vulnerability &#124; Pablumfication</dc:creator>
		<pubDate>Sun, 25 Jul 2010 18:47:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.airtightnetworks.com/?p=1382#comment-5758</guid>
		<description>[...] WEP &amp; TKIP WPA2 Hole196 Vulnerability WPA2 finds itself in a “hole”! Vulnerable to insider attacks! Black Hat ® Technical Security Conference: USA 2010 // Black Hat Arsenal WPA2 Exposed with [...]</description>
		<content:encoded><![CDATA[<p>[...] WEP &amp; TKIP WPA2 Hole196 Vulnerability WPA2 finds itself in a “hole”! Vulnerable to insider attacks! Black Hat ® Technical Security Conference: USA 2010 // Black Hat Arsenal WPA2 Exposed with [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: [ATNB] WPA2 - You don't even need to crack it. - Overclock.net - Overclocking.net</title>
		<link>http://blog.airtightnetworks.com/wpa2-finds-itself-in-a-hole-vulnerable-to-insider-attacks/comment-page-1/#comment-5711</link>
		<dc:creator>[ATNB] WPA2 - You don't even need to crack it. - Overclock.net - Overclocking.net</dc:creator>
		<pubDate>Fri, 23 Jul 2010 10:31:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.airtightnetworks.com/?p=1382#comment-5711</guid>
		<description>[...] announced its plan to phase out WEP and TKIP, promoting WPA2 as the go-to security standard.    Source  Basically an exploit was found (known as Hole 196) and exploiting this vulnerability, you can [...]</description>
		<content:encoded><![CDATA[<p>[...] announced its plan to phase out WEP and TKIP, promoting WPA2 as the go-to security standard.    Source  Basically an exploit was found (known as Hole 196) and exploiting this vulnerability, you can [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention WPA2 finds itself in a “hole”! Vulnerable to insider attacks! -- Topsy.com</title>
		<link>http://blog.airtightnetworks.com/wpa2-finds-itself-in-a-hole-vulnerable-to-insider-attacks/comment-page-1/#comment-5707</link>
		<dc:creator>Tweets that mention WPA2 finds itself in a “hole”! Vulnerable to insider attacks! -- Topsy.com</dc:creator>
		<pubDate>Fri, 23 Jul 2010 06:45:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.airtightnetworks.com/?p=1382#comment-5707</guid>
		<description>[...] This post was mentioned on Twitter by AirTight Networks, Rocky Gregory and CWNP, MD SOHAIL AHMAD. MD SOHAIL AHMAD said: WPA2 finds itself in a “hole”! Vulnerable to insider attacks! http://bit.ly/bHdqmS [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by AirTight Networks, Rocky Gregory and CWNP, MD SOHAIL AHMAD. MD SOHAIL AHMAD said: WPA2 finds itself in a “hole”! Vulnerable to insider attacks! <a href="http://bit.ly/bHdqmS" rel="nofollow">http://bit.ly/bHdqmS</a> [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

