Menu

Database

NULL SSID Probe Response DoS

WVE ID: WVE-2006-0064

Type: Vulnerability

Status: Candidate

Classification:
Denial of Service
Input Manipulation

Description:
Many varieties of legacy wireless LAN IEEE 802.11b cards are vulnerable to a persistent DoS attack condition when processing malformed probe response frames. This flaw in the firmware of wireless cards allows an attacker to mount a more effective DoS attack against vulnerable stations, often requiring a reboot for the target station to recover.

Discussion:
Legacy IEEE 802.11b wireless LAN cards based on the Choice MAC (Intersil and legacy Lucent/Agere/Orinoco cards including Apple Airport cards) are vulnerable to a flaw in the processing of malformed probe response frames. When vulnerable cards receive a probe response frame with the SSID information element set to the broadcast value, the cards become inoperable until they have been power-cycled.

Credits
Author: Joshua Wright (jwright@arubanetworks.com) : Aruba Networks
Author: Seng Ooh Too : None
Author: Mike Kershaw (mkershaw@arubanetworks.com) : Aruba Networks

References
URL: http://802.11ninja.net/papers/firmware_attack.pdf

Released: 2006-09-29

Submitter
Joshua Wright (jwright@arubanetworks.com) : Aruba Networks

Submitted: Fri Sep 29 08:08:09 -0700 2006

Candidate Date: Fri Sep 29 08:09:10 -0700 2006


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...