Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

November 22nd, 2012, 16:03 GMT · By

BLOG

Experts Find Way to Crack Default WPA2 Passwords of Belkin Routers

SHARE:

Adjust text size:


Experts find security hole in some Belkin routers Enlarge picture - Experts find security hole in some Belkin routers
Security researchers Jakob Lell and Jörg Schneider claim that the default WPA2 passwords used by many Belkin routers can be easily guessed by an attacker who knows the device’s WAN MAC address.

A number of Belkin wireless routers are shipped with a default WPA2 password to protect network connections. The apparently random passwords are printed on a label that’s on the bottom of the router.

Although this approach should be, in theory, more secure, because the password is likely stronger than what many users would set themselves, it turns out that the random passphrases aren’t so random.

The researchers have determined that the password is based on the device’s WAN MAC address, and since this information is not so difficult to obtain, a remote attacker could easily hack into a targeted network – given that the default configuration is used.

The default password is made of 8 characters which can be determined by replacing each hex-digit of the WAN MAC address with another value from a static substitution table.

Several device models are affected, including Belkin N450 Model F9K1105V2 and Belkin Surf N150 Model F7D1301v1.

The experts claim to have contacted Belkin back in January, but since they haven’t received any response, they’ve made their findings public. In the meantime, they advise users to change their default passphrases to something stronger and, implicitly, more secure.

TELL US WHAT YOU THINK:

5,317 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Skype Gives Security Firm Details of Alleged PayPal Hacker Without Warrant

VUPEN Researchers Find Windows 8 Zero-Day, All Exploit Mitigations Bypassed (Updated)

Skype 0-Day Vulnerability Allowed Hackers to Change the Password of Any Account – Video

Experts Investigate Malware Used in Gozi-Prinimalka Campaign Against US Banks

Experts Identify Cyber Espionage Campaign Against Palestinian and Israeli Targets

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM