<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace Site Server v5.11.81 (http://www.squarespace.com/) on Sun, 27 May 2012 09:07:43 GMT--><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><title>News</title><link>http://www.tacnetsol.com/news/</link><description></description><lastBuildDate>Wed, 25 Apr 2012 02:47:04 +0000</lastBuildDate><copyright></copyright><language>en-US</language><generator>Squarespace Site Server v5.11.81 (http://www.squarespace.com/)</generator><item><title>HTC 2012 Awards</title><dc:creator>Tactical Network Solutions</dc:creator><pubDate>Wed, 25 Apr 2012 02:40:32 +0000</pubDate><link>http://www.tacnetsol.com/news/2012/4/25/htc-2012-awards.html</link><guid isPermaLink="false">1186374:13852672:15984620</guid><description><![CDATA[<p>Howard Tech Council announced that Tactical Network Solutions won 2012 New/Emerging Company of the Year!</p><p>http://www.hceda.org/newsDetail.aspx?id=282</p>]]></description><wfw:commentRss>http://www.tacnetsol.com/news/rss-comments-entry-15984620.xml</wfw:commentRss></item><item><title>Reaver Pro on HakShop</title><category>Reaver</category><category>hak5</category><category>hakshop</category><category>products</category><category>reaver</category><dc:creator>Tactical Network Solutions</dc:creator><pubDate>Tue, 17 Apr 2012 17:47:57 +0000</pubDate><link>http://www.tacnetsol.com/news/2012/4/17/reaver-pro-on-hakshop.html</link><guid isPermaLink="false">1186374:13852672:15884038</guid><description><![CDATA[<p><a href="http://tacnetsol.com/products">Reaver Pro</a> is now on sale at the <a href="http://hakshop.myshopify.com/products/reaver-pro">HakShop</a> for $99!
<br></p><span class="full-image-block ssNonEditable"><span><img src="http://www.tacnetsol.com/storage/reaverpro_combo.jpg?__SQUARESPACE_CACHEVERSION=1334684993979" alt=""/></span></span>]]></description><wfw:commentRss>http://www.tacnetsol.com/news/rss-comments-entry-15884038.xml</wfw:commentRss></item><item><title>Reaver Breakout Session at CCDC</title><category>Breakout Talk</category><category>CCDC</category><category>Press Release</category><category>reaver</category><dc:creator>Tactical Network Solutions</dc:creator><pubDate>Wed, 14 Mar 2012 19:27:36 +0000</pubDate><link>http://www.tacnetsol.com/news/2012/3/14/reaver-breakout-session-at-ccdc.html</link><guid isPermaLink="false">1186374:13852672:15432867</guid><description><![CDATA[<p>Terry Dunlap of Tactical Network Solutions will be giving two one hour talks in breakout sessions at the High School Cybersecurity Fair and Expo (CCDC) and the Johns Hopkins APL this Saturday. If you're interested in hearing about the latest vulnerability in WPS and how to exploit it successfully, please join us for this event! Details to follow.</p>
<p><strong>Title:</strong></p>
<p>Reaver: Wireless (In)Security Once Again</p>
<p><strong>What: </strong></p>
<p><strong></strong>2012 High School Cybersecurity Fair and Expo<br /><a href="http://www.midatlanticccdc.org/CCDC/" target="_blank">http://www.midatlanticccdc.org/CCDC/</a><br /><br /><strong>When:</strong></p>
<p><strong></strong> Saturday, March 17, 2012&nbsp;&nbsp; 10:00 AM-4:00 PM<br /><br /><strong>Where:</strong></p>
<p>John Hopkins Applied Physics Lab,<br />Kossiakoff Conference and Education Center<br />11100 Johns Hopkins Road<br />Laurel Maryland 20723</p>
<p><strong>Speaker:&nbsp;</strong></p>
<p><strong></strong>Terry Dunlap, Tactical Network Solutions</p>
<p><strong>Abstract:</strong></p>
<p><span>Just when you thought wireless networks were secure with WPA/WPA2&nbsp;</span><span>encryption, along comes WiFi Protected Setup (WPS) to&nbsp;</span><span>make security even easier. Or does it? Due to a flaw in the WPS&nbsp;</span><span>protocol, it is possible once again to access encrypted wireless&nbsp;</span><span>networks with ease! Unfortunately, there is no simple fix to this&nbsp;</span><span>rather large, world-wide security flaw. This talk will explain WPS,&nbsp;</span><span>how it works, why it's broken, and demonstrate how easy it is to gain&nbsp;</span><span>access using the free, open-source tool called Reaver.</span></p>]]></description><wfw:commentRss>http://www.tacnetsol.com/news/rss-comments-entry-15432867.xml</wfw:commentRss></item><item><title>bFLT-Utils Tool Release</title><dc:creator>Craig Heffner</dc:creator><pubDate>Wed, 14 Mar 2012 00:36:59 +0000</pubDate><link>http://www.tacnetsol.com/news/2012/3/13/bflt-utils-tool-release.html</link><guid isPermaLink="false">1186374:13852672:15422734</guid><description><![CDATA[<p>We've just <a href="http://bflt-utils.googlecode.com">released</a> a set of tools for analyzing bFLT (binary flat) files.</p>
<p>bFLT is a lightweight alternative to ELF which is primarily used in embedded systems running <a href="http://www.uclinux.org/">uClinux</a>. Bflt-utils includes:</p>
<ul>
<li>Bfltldr &nbsp; &nbsp; &nbsp;- A bFLT loader for IDA Pro</li>
<li>Readbflt &nbsp;- Like readelf, but for bFLT files</li>
<li>Flthdr &nbsp; &nbsp; &nbsp;- A tool for manipulating bFLT files (from the <a href="https://docs.blackfin.uclinux.org/doku.php?id=toolchain:elf2flt">elf2flt</a> project)&nbsp;</li>
</ul>
<p>&nbsp;</p>
<p>The bFLT IDA loader is arguably the most useful of the three. IDA unfortunately does not have a built-in bFLTloader, and although some simple bFLT loaders can be found floating around the Web, they neglect to patch the bFLT relocation and global offset tables. This means that precious string and data references aren't resolved properly in the resulting disassembly:</p>
<p><span class="full-image-block ssNonEditable"><span><img src="http://www.tacnetsol.com/storage/relocations_not_fixed.png?__SQUARESPACE_CACHEVERSION=1331686443578" alt="" /></span></span></p>
<p>&nbsp;</p>
<p>Bfltldr <em>does</em> process the relocation and global offset tables, resulting in a much easier to read disassembly:</p>
<p><span class="full-image-block ssNonEditable"><span><img src="http://www.tacnetsol.com/storage/relocations_fixed.png?__SQUARESPACE_CACHEVERSION=1331686471826" alt="" /></span></span></p>
<p>&nbsp;</p>
<p>The readbflt tool is also quite useful, as it not only lists all of the entries in the relocation and global offset tables, but also what data those entries point to:</p>
<p><span class="full-image-block ssNonEditable"><span><img src="http://www.tacnetsol.com/storage/readbflt.png?__SQUARESPACE_CACHEVERSION=1331686667426" alt="" /></span></span></p>
<p>&nbsp;</p>
<p>Finally, flthdr is useful for manipulating bFLT binaries. Most notably, it allows you to extract compressed bFLT files:</p>
<p><span class="full-image-block ssNonEditable"><span><img src="http://www.tacnetsol.com/storage/flthdr.png?__SQUARESPACE_CACHEVERSION=1331686941954" alt="" /></span></span></p>
<p>&nbsp;</p>
<p>Bflt-utils can be <a href="http://bflt-utils.googlecode.com">downloaded</a> from its Google Code project page.</p>
<p>&nbsp;</p>]]></description><wfw:commentRss>http://www.tacnetsol.com/news/rss-comments-entry-15422734.xml</wfw:commentRss></item><item><title>Reaver on Hak5</title><category>Reaver</category><category>hak5</category><category>reaver</category><category>wpa</category><category>wps</category><dc:creator>Tactical Network Solutions</dc:creator><pubDate>Thu, 09 Feb 2012 01:27:46 +0000</pubDate><link>http://www.tacnetsol.com/news/2012/2/8/reaver-on-hak5.html</link><guid isPermaLink="false">1186374:13852672:14941873</guid><description><![CDATA[<p><strong>UPDATE</strong>: Reaver Pro now available on the <a href="http://hakshop.myshopify.com/products/reaver-pro">HakShop</a>!
<br></p>
<iframe src="http://revision3.com/html5player-v11787?external=true&width=555&height=312" width="555" height="312" frameborder="0" allowFullScreen mozAllowFullscreen webkitAllowFullScreen></iframe>
<br><br>
<a href="http://devttys0.com">Craig Heffner</a>, Senior Researcher at TNS, talks about the WPS brute force and <a href="http://tacnetsol.com/products">Reaver</a> on <a href="http://revision3.com/hak5/shmoo2012">Hak5</a>.]]></description><wfw:commentRss>http://www.tacnetsol.com/news/rss-comments-entry-14941873.xml</wfw:commentRss></item><item><title>Reaver Pro Demo Video</title><dc:creator>Tactical Network Solutions</dc:creator><pubDate>Fri, 06 Jan 2012 20:04:09 +0000</pubDate><link>http://www.tacnetsol.com/news/2012/1/6/reaver-pro-demo-video.html</link><guid isPermaLink="false">1186374:13852672:14471408</guid><description><![CDATA[<p><strong>UPDATE</strong>: Reaver Pro now available on the <a href="http://hakshop.myshopify.com/products/reaver-pro">HakShop</a>!
<br></p>
<p><iframe src="http://player.vimeo.com/video/34667806?title=0&amp;byline=0&amp;portrait=0" width="525" height="295" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe><p><a href="http://vimeo.com/34667806">TNS Reaver Pro Demo</a> from <a href="http://vimeo.com/tacnetsol">Tactical Network Solutions</a> on <a href="http://vimeo.com">Vimeo</a>.</p></p>]]></description><wfw:commentRss>http://www.tacnetsol.com/news/rss-comments-entry-14471408.xml</wfw:commentRss></item><item><title>Reaver Pro is Coming</title><category>Products</category><category>reaver</category><category>wpa</category><category>wps</category><dc:creator>Tactical Network Solutions</dc:creator><pubDate>Thu, 05 Jan 2012 20:27:07 +0000</pubDate><link>http://www.tacnetsol.com/news/2012/1/5/reaver-pro-is-coming.html</link><guid isPermaLink="false">1186374:13852672:14453419</guid><description><![CDATA[<p><strong>UPDATE</strong>: Reaver Pro now available on the HakShop!</p>
<p><a href="http://hakshop.myshopify.com/products/reaver-pro">http://hakshop.myshopify.com/products/reaver-pro</a></p>
<p><br /><span class="full-image-block ssNonEditable"><span><img style="width: 600px;" src="http://www.tacnetsol.com/storage/post-images/ReaverAd.jpg?__SQUARESPACE_CACHEVERSION=1325795330688" alt="" /></span></span></p>]]></description><wfw:commentRss>http://www.tacnetsol.com/news/rss-comments-entry-14453419.xml</wfw:commentRss></item><item><title>Reaver Now Goes to 11</title><category>Reaver</category><category>open source</category><category>reaver</category><category>wpa</category><category>wps</category><dc:creator>Tactical Network Solutions</dc:creator><pubDate>Mon, 02 Jan 2012 19:41:25 +0000</pubDate><link>http://www.tacnetsol.com/news/2012/1/2/reaver-now-goes-to-11.html</link><guid isPermaLink="false">1186374:13852672:14411975</guid><description><![CDATA[<p><strong>UPDATE</strong>: Reaver Pro now available on the <a href="http://hakshop.myshopify.com/products/reaver-pro">HakShop</a>! </p>

<p>The decision has been made to open source the Reaver command line tool.  The commercial version will contain all the features the open source command-line tool has along with a web based client, support, and service options.</p>

<p>This means that the open source version of Reaver will have much requested features, such as identification of WPS enabled networks and pause/resume functionality.</p>

<p>This also means that Reaver will have the ability to specify specific options for a given model inside a database. In other words, if it is known that certain options are required or helpful when attacking XYZ router, you can put them in the database and they will be automatically applied whenever you target that model router. How often the FOSS database will be updated remains to be seen, obviously those paying for the support plan will take priority.</p>

<p>The latest Reaver <a href="http://code.google.com/p/reaver-wps/downloads/list">release</a> (1.3) now also implements the short DH key optimizations described in the original vulnerability release paper, which reduces computation time on the target AP and increases the attack speed.</p>
]]></description><wfw:commentRss>http://www.tacnetsol.com/news/rss-comments-entry-14411975.xml</wfw:commentRss></item><item><title>Official Reaver Screencast</title><dc:creator>Tactical Network Solutions</dc:creator><pubDate>Fri, 30 Dec 2011 19:53:35 +0000</pubDate><link>http://www.tacnetsol.com/news/2011/12/30/official-reaver-screencast.html</link><guid isPermaLink="false">1186374:13852672:14384213</guid><description><![CDATA[<iframe src="http://player.vimeo.com/video/34378644?title=0&amp;byline=0&amp;portrait=0" width="525" height="295" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe><p><a href="http://vimeo.com/34378644">Cracking WPS with Reaver</a> from <a href="http://vimeo.com/user9824463">Zach</a> on <a href="http://vimeo.com">Vimeo</a>.</p>]]></description><wfw:commentRss>http://www.tacnetsol.com/news/rss-comments-entry-14384213.xml</wfw:commentRss></item><item><title>Cracking WiFi Protected Setup with Reaver</title><dc:creator>Craig Heffner</dc:creator><pubDate>Wed, 28 Dec 2011 17:51:16 +0000</pubDate><link>http://www.tacnetsol.com/news/2011/12/28/cracking-wifi-protected-setup-with-reaver.html</link><guid isPermaLink="false">1186374:13852672:14358496</guid><description><![CDATA[<p><strong>UPDATE</strong>: Reaver Pro now available on the <a href="http://hakshop.myshopify.com/products/reaver-pro">HakShop</a>!&nbsp;</p>
<p>Yesterday, Stefan over at <a href="http://sviehb.wordpress.com/">.braindump</a> released a <a href="http://sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf">white paper</a> detailing vulnerabilities in the WiFi Protected Setup (WPS) protocol that allows attackers to recover WPA/WPA2 passphrases in a matter of hours.</p>
<p>This is a capability that we at TNS have been testing, perfecting and using for nearly a year. But now that this vulnerability has been discussed publicly we have decided to announce and release Reaver, our WPS attack tool, to the open source community. Reaver is capable of breaking WPS pins and recovering the plain text WPA/WPA2 passphrase of the target access point in approximately 4-10 hours (attack time varies based on the access point).</p>
<p>While we have released Reaver as an <a href="http://www.tacnetsol.com/products/">open source project</a>, we also offer a commercial version with additional features and functionality as well as a support plan.&nbsp;Since nearly all access points manufactured in the past few years have WPS support enabled by default, attacking WPS provides several advantages over attacking WPA directly:</p>
<p>&nbsp;</p>
<ol>
<li>Cracking the WPS pin is, obviously, much faster.</li>
<li>Once you have the WPS pin you can instantly recover the WPA passphrase, even if the owner changes the passphrase.</li>
<li>Access points with multiple radios (2.4/5GHz) can be configured with multiple WPA keys. Since the radios use the same WPS pin, knowledge of the pin allows an attacker to recover all WPA keys.</li>
</ol>
<p>&nbsp;</p>
<p>Of course the disadvantage is that WPS can be disabled. However, in our experience even security experts with otherwise secure configurations neglect to disable WPS; further, some access points don't provide an option to disable WPS, or don't actually disable WPS when the owner tells it to.</p>
<p>To learn more about Reaver, visit our <a href="http://www.tacnetsol.com/products/">product page</a>, or the open source project&nbsp;on Googlecode.</p>]]></description><wfw:commentRss>http://www.tacnetsol.com/news/rss-comments-entry-14358496.xml</wfw:commentRss></item></channel></rss>
