RecentInternetNews

Vulnerabilities in the network: WPS on the router

Wi-Fi Protected Setup (WPS) is a technology that, while facilitating the connection between devices and the router, can open a large security breach in our router

The vulnerabilities of both the software and the hardware are flaws that are and will always be in each element with a chip, especially if it is connected to the Internet. That is why it can be said that one of the most vulnerable elements of the network is the router and, currently, they are essential in every home, in every company or public space in any country.

User routers are, in a certain way, the most vulnerable of all, since they are transferred by the company that is hired and are not usually the best in the market and in many cases they are not updated properly. In this article we are going to address one of the most common vulnerabilities in home routers: the WPS function of routers.

What is WPS?

Wi-Fi Protected Setup

Surely you have seen a small button on the routers with its logo or you have also seen it in the Wi-Fi configuration of your operating system. WPS, or Wi-Fi Protected Setup, is a set of security mechanisms that aims to solve a problem currently present in the day to day, enter the router password to connect to it. With WPS, simply by pressing a button or entering a PIN, we are able to connect a device that is in the authentication phase directly without entering the password. Simple, but vulnerable.

How Does It Work?

We are going to explain a little how it works, without going into too much detail. These are the different agents or roles present in this system:

  • 'Roll up' It is the device that you want to connect to the network and that does not have its wireless configuration.
  • 'To register' It is the one that provides the configuration of wireless access to the 'enrollee', that is, the router.
  • El 'Access Point' o 'AP' it is the one that offers a free wireless connection to 'enroll' to communicate to 'enroll' and 'record'. In this way, the two can exchange messages to perform the authentication process. In these cases the 'access point' is usually the same router.

WPS process

We can distinguish three types of authentication through WPS:

  • Push Button Connect o 'PBC': In this case, the user has to press both on the 'roll up' and on the 'register' button, which may be physical or virtual. For example, a mobile tries to connect to a router, and on the mobile you press the WPS option (virtual 'enroll' button) and on the router the WPS button (physical 'register' button)
  • PIN: In this case, the user has to enter an 8-digit PIN, and two types can be distinguished:
    • Internal: In this case, the 'enroll' provides a PIN and it has to be entered in the 'register', that is, the PIN is entered in the router's web interface.
    • External: In this case, the 'register' has a PIN and must be entered in the 'enroll'. This PIN is usually written on the back of the 'register', that is, behind the router.

WPS button

How the system can be compromised

As we can deduce, the PBC and internal PIN methods are the most difficult to violate, since you have to have physical access to the 'register' to press the button, whether physical or virtual, or enter the PIN. But in the case of the external PIN, you just have to enter the PIN that the 'register' has. Supposedly, we have to consult this PIN in the 'register', but there is also another way to guess the PIN, with the simple method of trial and error; that is, doing a brute force attack on the router trying different possible PIN possibilities.

The problem is, how long can it take to break the system? In a normal case, a maximum of 4 hours. This method has a second vulnerability, PIN authentication is divided into two phases. As we have said before, the WPS PIN has 8 digits, although it is really 7 digits of PIN and the last digit is a checksum, a number that is the result of an operation with the other 7 digits. The time that elapses between sending a possible PIN to the router and the response is usually 1,3 seconds.

In the first phase of authentication, the veracity of the first 4 digits is checked, and in the second phase the last 3 digits plus the checksum. If the PIN is verified in a single phase, the 7 digits and the checksum at the same time, there would be 10 ^ 8 possible PIN numbers, that is, 100.000.000 possible numbers; But, when authenticating in two phases, the check is reduced to 10 ^ 4 + 10 ^ 4 possibilities; that is, only 20.000 possible PIN numbers. In a normal case of brute force attack it can take less than 4 hours, although it usually takes half or less.

How to deactivate this function in our router

Knowing how easy it is to violate the security of our network, the best thing we can do to prevent them from accessing our network is to disable this function in our router. We have to have a device connected to it and access its gateway; ie to the router and disable this function. To do this, we will follow the following steps:

  1. In Windows, we do the Windows + R key combination and in the window that appears we enter 'cmd'. In the case of macOS or GNU / Linux systems we must enter the terminal.
  2. We write 'ipconfig' in the case of Windows or 'ifconfig', in the case of macOS and GNU / Linux and press' enter '. Among all the data that we are offered, we must observe a section that is usually called' Default gateway 'or' Gateway ', an IP address like' 192.168.0.1 'appears.
  3. We enter that IP address in the browser and enter the router's configuration page. It will ask us for a username and password that can be searched on the Internet, since some are usually used by default. Search in Google the model of your router together with the company to find out what the access credentials are.
  4. Finally, we look for the WPS option among the router menus and deactivate it.

Conclusion

WPS, even being present in current routers and being activated in most of them, is one of the biggest security holes in our routers, and should be deactivated as soon as it is started. In addition, it is always advisable to activate more security measures, such as hiding the SSID of our Wi-Fi connection, activating a MAC filter to only allow certain devices specified by us to connect to our router, changing the password and the SSID that it brings. by default, etc. We have to take into account that the router is the entry point of all the Internet in our house, and it must be the most secure element of our network.

Show more

Robert Sole

Director of Contents and Writing of this same website, technician in renewable energy generation systems and low voltage electrical technician. I work in front of a PC, in my free time I am in front of a PC and when I leave the house I am glued to the screen of my smartphone. Every morning when I wake up I walk across the Stargate to make some coffee and start watching YouTube videos. I once saw a dragon ... or was it a Dragonite?

Related publications

Leave your comment

Your email address will not be published. Required fields are marked with *

Button back to top
CLOSE

Ad blocker detected

This site is funded through the use of advertising. We always make sure that the advertising is not too intrusive for the reader and we prioritize the reader's experience on the website. However, if you block the ads, part of our funding will be reduced.