HomeinetKrack Attacks when WPA2 is not so secure

Crack Attacks when WPA2 is not so secure

Krack Attacks: Researchers have discovered a flaw in the Wi-Fi standard that can be used by attackers to monitor wireless network traffic even if WPA2 protection is used.Crack Attacks

Key Reinstallation Attacks or Krack Attacks work on all Wi-Fi networks protected by WPA2 and in some cases can be used for injections that result in data manipulation. The attack works on WPA and WPA2 security standards and against personal and corporate networks that have Wi-Fi connections.

The attack method works against the 4-way handshake of the WPA2 protocol. This handshake is performed when client devices, such as a smartphone or laptop, try to connect to the Wi-Fi network.

The handshakeverifiescredentials and negotiates an encryption key that is then used to protect traffic for as long as the connection remains active.

The main flaw discovered by the researchers affects the key and is achieved by “manipulating and replying cryptographic handshake messages”.

In other words, the attacker tricks the victim into installing a key that is already in use.

“When a client connects to a network, the 4-way handshake process is run to negotiate a new encryption key. The client will install this key after receiving the third handshake message out of 4. Once the key is installed, it will be used to encrypt regular data frames using an encryption protocol. However, because messages can be lost or dropped, the Access Point (AP) will retransmit the third message if it does not receive a proper response as an acknowledgement. As a result, the client will receive the third message multiple times. Each time it receives this message, it reinstalls the same encryption key.”

The researchers demonstrated that an attacker can force these replays by collecting and replaying the retransmissions of the third message of the 4-way handshake. In this way, the encryption protocol can be attacked, e.g., they can send the same packets, decrypt them, or forge them.

The researchers note that the data being transferred can (theoretically) be decrypted by the attacker.

Below you will find the identifiers issued for the issue published by Krack Attacks:

  • CVE-2017-13077: Reinstallation of the pairwise encryption key (PTK-TK) in the 4-way handshake.
  • CVE-2017-13078: Reinstallation of the group key (GTK) in the 4-way handshake.
  • CVE-2017-13079: Reinstallation of the integrity group key (IGTK) in the 4-way handshake.
  • CVE-2017-13080: Reinstallation of the group key (GTK) in the group key handshake.
  • CVE-2017-13081: Reinstallation of the integrity group key (IGTK) in the group key handshake.
  • CVE-2017-13082: Accepting a retransmitted Fast BSS Transition (FT) Reassociation Request and reinstalling the pairwise encryption key (PTK-TK) while processing it.
  • CVE-2017-13084: Reinstallation of the STK key in the PeerKey handshake.
  • CVE-2017-13086: reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake.
  • CVE-2017-13087: reinstallation of the group key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame.
  • CVE-2017-13088: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame.

You can download the paper here (PDF), and more information can be read on the Crack Attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS