<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; wps</title>
	<atom:link href="http://hackaday.com/tag/wps/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 06:18:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; wps</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>A chink in the armor of WPA/WPA2 WiFi security</title>
		<link>http://hackaday.com/2011/12/29/a-chink-in-the-armor-of-wpawpa2-wifi-security/</link>
		<comments>http://hackaday.com/2011/12/29/a-chink-in-the-armor-of-wpawpa2-wifi-security/#comments</comments>
		<pubDate>Thu, 29 Dec 2011 20:01:44 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[security hacks]]></category>
		<category><![CDATA[wireless hacks]]></category>
		<category><![CDATA[access point]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[wi-fi protected setup]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wpa]]></category>
		<category><![CDATA[wpa2]]></category>
		<category><![CDATA[wps]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=64344</guid>
		<description><![CDATA[Looks like your WiFi might not be quite as secure as you thought it was. A paper recently published by [Stefan Viehböck] details a security flaw in the supposedly robust WPA/WPA2 WiFi security protocol. It&#8217;s not actually that protocol which is the culprit, but an in-built feature called Wi-Fi Protected Setup. This is an additional [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=64344&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-64346" title="wi-fi-protected-setup" src="http://hackadaycom.files.wordpress.com/2011/12/wi-fi-protected-setup.jpg" alt="" width="180" height="80" /></p>
<p>Looks like your WiFi might not be quite as secure as you thought it was. A paper recently published by [Stefan Viehböck] details <a href="http://sviehb.wordpress.com/2011/12/27/wi-fi-protected-setup-pin-brute-force-vulnerability/">a security flaw in the supposedly robust WPA/WPA2 WiFi security protocol</a>. It&#8217;s not actually that protocol which is the culprit, but an in-built feature called <a href="http://en.wikipedia.org/wiki/Wi-Fi_Protected_Setup">Wi-Fi Protected Setup</a>. This is an additional security protocol that allows you to easily setup network devices like printers without the need to give them the WPA passphrase. [Stephan's] proof-of-concept allows him to get the WPS pin in 4-10 hours using brute force. Once an attacker has that pin, they can immediately get the WPA passphrase with it. This works even if the passphrase is frequently changed.</p>
<p>Apparently, most WiFi access points not only offer WPS, but have it enabled by default. To further muck up the situation, some hardware settings dashboards offer a disable switch that doesn&#8217;t actually do anything!</p>
<p>It looks like [Stephan] wasn&#8217;t the only one working on this exploit. [Craig] wrote in to let us know he&#8217;s already released <a href="http://www.tacnetsol.com/news/2011/12/28/cracking-wifi-protected-setup-with-reaver.html">software to exploit the hole</a>.</p>
<br />Filed under: <a href='http://hackaday.com/category/security-hacks/'>security hacks</a>, <a href='http://hackaday.com/category/wireless-hacks/'>wireless hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/64344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/64344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/64344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/64344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/64344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/64344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/64344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/64344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/64344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/64344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/64344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/64344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/64344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/64344/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=64344&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2011/12/29/a-chink-in-the-armor-of-wpawpa2-wifi-security/feed/</wfw:commentRss>
		<slash:comments>57</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2011/12/wi-fi-protected-setup.jpg" medium="image">
			<media:title type="html">wi-fi-protected-setup</media:title>
		</media:content>
	</item>
		<item>
		<title>D-Link router captcha broken</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/</link>
		<comments>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/#comments</comments>
		<pubDate>Wed, 20 May 2009 00:55:45 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[security hacks]]></category>
		<category><![CDATA[wireless hacks]]></category>
		<category><![CDATA[captcha]]></category>
		<category><![CDATA[d-link]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[sourcesec]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wireless]]></category>
		<category><![CDATA[wpa]]></category>
		<category><![CDATA[wps]]></category>
		<category><![CDATA[wpspy]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=11234</guid>
		<description><![CDATA[We reported last week that D-Link was adding captchas to their routers to prevent automated login by malware. Unsurprisingly, it doesn&#8217;t work all time. The team from SourceSec grabbed the new firmware and began poking at it. They found that certain pages don&#8217;t require the authentication to be passed for access. One of these is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=11234&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-11235" title="d-link" src="http://hackadaycom.files.wordpress.com/2009/05/d-link.jpg" alt="d-link" width="450" height="243" /></p>
<p>We reported last week that D-Link was <a title="D-Link adds captcha to routers  - Hack a Day" href="http://hackaday.com/2009/05/12/d-link-adds-captcha-to-routers/">adding captchas to their routers</a> to prevent automated login by malware. Unsurprisingly, it doesn&#8217;t work all time. The team from SourceSec grabbed the new firmware and began poking at it. They found that <a title="SourceSec Security Research  » Blog Archive   » D-Link Captcha Partially Broken" href="http://www.sourcesec.com/2009/05/12/d-link-captcha-partially-broken/">certain pages don&#8217;t require the authentication</a> to be passed for access. One of these is WPS activation. <a title="Wi-Fi Protected Setup - Wikipedia, the free encyclopedia" href="http://en.wikipedia.org/wiki/Wi-Fi_Protected_Setup">WPS</a> lets you do push button WPA configuration. Once activated, any nearby client can request the WPA key using a tool like <a href="http://www.sourcesec.com/2009/05/09/wpscan-wpspy-tools/">WPSpy</a>. Only user level credentials are needed to pull this off, so changing just the admin password won&#8217;t prevent it.</p>
<p>[photo: <a title="D-Link DI-524 undressed on Flickr - Photo Sharing!" href="http://www.flickr.com/photos/schoschie/1448798334/">schoschie</a>]</p>
<br />Posted in security hacks, wireless hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/11234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/11234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/11234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/11234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/11234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/11234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/11234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/11234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/11234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/11234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/11234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/11234/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/11234/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/11234/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=11234&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/feed/</wfw:commentRss>
		<slash:comments>24</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/05/d-link.jpg" medium="image">
			<media:title type="html">d-link</media:title>
		</media:content>
	</item>
		<item>
		<title>Eye-Fi Explore review</title>
		<link>http://hackaday.com/2008/06/27/eye-fi-explore-review/</link>
		<comments>http://hackaday.com/2008/06/27/eye-fi-explore-review/#comments</comments>
		<pubDate>Fri, 27 Jun 2008 22:55:00 +0000</pubDate>
		<dc:creator>Juan Aguilar</dc:creator>
				<category><![CDATA[digital cameras hacks]]></category>
		<category><![CDATA[wireless hacks]]></category>
		<category><![CDATA[eye-fi]]></category>
		<category><![CDATA[geotagging]]></category>
		<category><![CDATA[photography]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[sdcard]]></category>
		<category><![CDATA[wi-fi]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wps]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/27/eye-fi-explore-review/</guid>
		<description><![CDATA[The WiFi uploading Eye-Fi SD card made a big splash when it was first introduced, but now Eye-Fi has a whole line of different products. The top of the line is the Eye-Fi Explore, which supports geotagging without using a GPS. Instead of GPS hardware, it uses the Skyhook Wireless Wi-Fi Postitioning System, which correlates [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2134&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<object type="application/x-shockwave-flash" width="400" height="300" data="http://www.flickr.com/apps/video/stewart.swf?v=1.161" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"> <param name="flashvars" value="photo_id=2611298593&amp;photo_secret=0&amp;flickr_show_info_box=true"></param><param name="movie" value="http://www.flickr.com/apps/video/stewart.swf?v=1.161"></param><param name="bgcolor" value="#000000"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="opaque"></param><embed type="application/x-shockwave-flash" src="http://www.flickr.com/apps/video/stewart.swf?v=1.161" bgcolor="#000000" allowfullscreen="true" flashvars="photo_id=2611298593&amp;photo_secret=0&amp;flickr_show_info_box=true" wmode="opaque" height="300" width="400"></embed></object>
<p>The WiFi uploading <a href="http://www.mahalo.com/Eye_Fi">Eye-Fi</a> SD card made a big splash when it was first introduced, but now Eye-Fi has a whole line of different products. The top of the line is the Eye-Fi Explore, which <a href="http://paulstamatiou.com/2008/06/26/review-eye-fi-explore-geotagging-sd-card">supports geotagging without using a GPS</a>. Instead of GPS hardware, it uses the Skyhook Wireless Wi-Fi Postitioning System, which correlates the position of the Eye-Fi&#8217;s access point to GPS locations, creating virtual GPS functionality. This allows photos taken with the Eye-Fi to be be geotagged. Of course, the accuracy of the system is noticeably lower than true GPS and seems to be affected by a number of external factors, but it is still accurate enough to tag the photo within the immediate vicinity of where it was taken. </p>
<p>WiFi positioning is great feature, but certainly not limited to photography. Since the Eye-Fi is at its core SD storage media, you could probably have it geotag data saved to the card, even if it wasn&#8217;t created by a digital camera..</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2134/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2134/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2134/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2134&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/06/27/eye-fi-explore-review/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">juanaguilar</media:title>
		</media:content>
	</item>
	</channel>
</rss>
