Hacking Wireless Networks

Table FF.9. WPA Versus WPA2

Mode

WPA

WPA2

Enterprise mode

Authentication: IEEE 802.1x EAP

Authentication: IEEE 802.1x EAP

 

Encryption: TKIP/MIC

Encryption: AES-CCMP

Personal mode

Authentication: PSK

Authentication: PSK

 

Encryption: TKIP/MIC

Encryption: AES-CCMP

Table FF.10. EAP Types

Service

EAP-MD5

LEAP

EAP-TLS

EAP-TTLS

PEAP

Server Authentication

No

Uses password hash

Public key certificate

Public key certificate

Public key certificate

Supplicant Authentication

Uses password hash

Uses password hash

Smart card or public key certificate

PAP, CHAP, or MS-CHAP

Any EAP type such as public key certificate

Dynamic Key Delivery

No

Yes

Yes

Yes

Yes

Security Concerns

Vulnerable to man-in-the-middle attack, session hijack, or identity exposure

Vulnerable to dictionary attack or identity exposure

Vulnerable to identity exposure

Vulnerable to man-in-the-middle attack

Vulnerable to man-in-the-middle attack

Virus and Worms

Категории