IKE Aggressive Mode Shared Secret Hash Leakage Weakness
BID:7423
Info
IKE Aggressive Mode Shared Secret Hash Leakage Weakness
| Bugtraq ID: | 7423 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 1999 12:00AM |
| Updated: | Oct 02 1999 12:00AM |
| Credit: | Attack first published by John Pliam <[email protected]>. |
| Vulnerable: |
IETF RFC 2409: The Internet Key Exchange (IKE) |
| Not Vulnerable: | |
Discussion
IKE Aggressive Mode Shared Secret Hash Leakage Weakness
When a VPN is configured to use a pre-shared master secret and a client attempts to negotiate keys in aggressive mode, a hash of the secret is transmitted across the network in clear-text. This may result in the hash being leaked to eavesdroppers or malicious clients. An offline brute-force attack on this hash may then be performed to obtain the clear-text secret.
When a VPN is configured to use a pre-shared master secret and a client attempts to negotiate keys in aggressive mode, a hash of the secret is transmitted across the network in clear-text. This may result in the hash being leaked to eavesdroppers or malicious clients. An offline brute-force attack on this hash may then be performed to obtain the clear-text secret.
Exploit / POC
IKE Aggressive Mode Shared Secret Hash Leakage Weakness
A utility for performing brute-force attacks on IKE secret hashes is available:
A utility for performing brute-force attacks on IKE secret hashes is available:
Solution / Fix
IKE Aggressive Mode Shared Secret Hash Leakage Weakness
Solution:
This weakness is built into the protocol. Consequently, all complete implementations of the protocol are vulnerable. It is not likely that fixes will be made available.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This weakness is built into the protocol. Consequently, all complete implementations of the protocol are vulnerable. It is not likely that fixes will be made available.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IKE Aggressive Mode Shared Secret Hash Leakage Weakness
References:
References:
- Authentication Vulnerabilities in IKE and Xauth with Weak Pre-Shared Secrets (John Pliam
) - Bugtraq ID 5920: Check Point VPN-1 IKE Aggressive Mode Forcing Vulnerability (SecurityFocus)
- IKE Aggressive Mode (Check Point Software)
- PSK Cracking Using IKE Aggressive Mode (Michael Thumann
, Enno Rey ) - RFC 2409: The Internet Key Exchange (IKE) (IETF)
- Cracking preshared keys (Michael Thumann
)