Cisco: change your security protocols, please!

Cisco is urging customers to switch use of security protocols after a new software tool exploited a serious flaw in its WLAN products.

The company confirmed the vulnerability in its Lightweight Extensible Authentication Protocol (LEAP), which allows hackers to launch dictionary attacks for guessing passwords for wireless LAN access.

The company is recommending customers use a new security protocol, Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (EAP-FAST), which it said reduces the threat of attack.

A dictionary attack compares a huge catalogue of words with the target computer until it finds a matching password. The LEAP protocol reduces the number of possible matches, which makes the attack faster

Cisco's advice comes after software expert Joshua Wright developed a tool for launching the attack against LEAP.

Wright waited to release the tool until Cisco was able to fix the problem.

More in News

Twitter begins rollout of two-factor authentication to limit account takeovers

Following a series of high-profile Twitter account hijacks, the microblogging service finally has delivered two-factor authentication.

Commission offers suggestions for stemming online spy threat from China

The 100-page report mostly addresses alleged Chinese cyber espionage operations, and suggests it's time for U.S. government agencies and corporations to consider more proactive approaches, possibly including hack-backs.

Researchers link "Sunshop" group to recent espionage attacks

The IE exploit was most recently used in watering hole attacks directed at the U.S. Department of Labor website.