All the latest UK technology news, reviews and analysis

Cisco thwarts EAP dictionary attacks

by Arif Mohamed

13 Apr 2004

Be the first to comment

  • Tweet this

Cisco has released a security authentication protocol to protect 802.1X Extensible Authentication Protocol (EAP) networks from dictionary attacks.

A dictionary attack uses variations of passwords to break into systems.

Cisco admitted that its password-based authentication EAP algorithm, known as Leap, is vulnerable to dictionary attacks, as are other systems.

The source code for the dictionary attack tool, known as 'Asleap', was released on 6 April, which could allow hackers to launch an offline dictionary attack on password-based authentications which leverage Microsoft MS-Chap, such as Cisco Leap.

Cisco has released the EAP-Flexible Authentication via Secure Tunneling (EAP-FAST) security protocol, which is designed to be used with Cisco Leap systems that use the MS-Chap authentication protocol.

In a statement Cisco said that it had "developed EAP-FAST for users who wish to deploy an 802.1X EAP type that does not require digital certificates and is not vulnerable to dictionary attacks".

Cisco's Security Notice can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Java or C++, Senior Developer, London

Java or C++, Senior Developer, London My client is...

ASP .net MVC Developer, C#, Betting, London

ASP .net MVC Developer, C#, Betting, London My client...

Software developer, Web developer, London

Software developer, Web developer, London My client...

Java developer, Online gaming, Agile, London

Java developer, Online gaming, Agile, London My client...

To send to more than one email address, simply separate each address with a comma.