Tuesday, June 29, 2010

Researchers Can Force Mixed-Mode Cisco Routers to Spit Up WEP

Researchers Can Force Mixed-Mode Cisco Routers to Spit Up WEP

WEP continues to rear its ugly head: Researchers from Core Security Technologies have found a way to force Cisco Aironet 1200 Series access points to use WEP for broadcast communications if a mixed-mode WEP/WPA security model is set.

I'm not surprised. Devices in mixed mode behave in peculiar ways, and being able to force a WEP broadcast means that the entire network is susceptible to that weak method.

The only good WEP is dead WEP. Companies that have been weaning themselves off WEP need to do an audit, figure out if they have any mixed-mode networks operating, and why in god's name any piece of gear on the network has a need for WEP a this point.

WEP should be dead, but legacy gear that would be expensive to operate provides holes in retail and corporate networks. Companies should have taken the pain to upgrade, rather than face multi-million-dollar risks.



The Twilight Saga : Eclipse soundtrack revealedClass-Action Suit against Google Has Gaping Hole