{"id":36788,"date":"2019-10-31T22:13:49","date_gmt":"2019-10-31T19:13:49","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\/"},"modified":"2019-10-31T22:13:49","modified_gmt":"2019-10-31T19:13:49","slug":"novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","title":{"rendered":"Neue Schwachstellen in der WPA3-Technologie f\u00fcr drahtlose Netzwerke und in EAP-pwd","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Mathy Vanhoef und Eyal Ronen (<noindex><a rel=\"nofollow\" href=\"https:\/\/eyalro.net\/\">Eyal Ronen<\/a><\/noindex>) <noindex><a rel=\"nofollow\" href=\"https:\/\/wpa3.mathyvanhoef.com\/#new\">entdeckten<\/a><\/noindex> eine neue Angriffsmethode (CVE-2019-13377) auf drahtlose Netzwerke, die WPA3-Schutztechnologie verwenden, die es erm\u00f6glicht, Informationen \u00fcber die Merkmale eines Passworts zu erhalten, die verwendet werden k\u00f6nnen, um es im Offline-Modus zu knacken. Das Problem tritt in der aktuellen Version von <noindex><a rel=\"nofollow\" href=\"https:\/\/w1.fi\/security\/\">Hostapd<\/a><\/noindex>.<\/p>\n<p>In Erinnerung, dass im April von denselben Autoren <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50493\">wurden<\/a><\/noindex> sechs Schwachstellen in WPA3 entdeckt wurden, gegen die die Wi-Fi Alliance, die Standards f\u00fcr drahtlose Netzwerke entwickelt, \u00c4nderungen in den Empfehlungen f\u00fcr die Sicherstellung sicherer Implementierungen von WPA3 vorgenommen hat, in denen bestimmt wurde, dass sichere elliptische Kurven verwendet werden m\u00fcssen <noindex><a rel=\"nofollow\" href=\"http:\/\/bada55.cr.yp.to\/brainpool.html\">Brainpool<\/a><\/noindex>, anstelle der zuvor zul\u00e4ssigen elliptischen Kurven P-521 und P-256. <\/p>\n<p>Dennoch hat die Analyse gezeigt, dass die Verwendung von Brainpool zu einer neuen Klasse von Seitenkanallecks im in WPA3 verwendeten Verbindungsvereinbarungsalgorithmus f\u00fchrt, <noindex><a rel=\"nofollow\" href=\"https:\/\/sarwiki.informatik.hu-berlin.de\/WPA3_Dragonfly_Handshake\">Dragonfly<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=48854\">die<\/a><\/noindex> Schutz vor Offline-Passwortangriffen bietet. Das entdeckte Problem verdeutlicht, dass die Erstellung von Dragonfly- und WPA3-Implementierungen ohne Datenlecks \u00fcber Seitenkan\u00e4le eine \u00e4u\u00dferst komplexe Aufgabe ist und zeigt die Unzul\u00e4nglichkeit des Modells zur Entwicklung von Standards hinter geschlossenen T\u00fcren ohne \u00f6ffentliche Diskussion der vorgeschlagenen Methoden und Audits durch die Gemeinschaft.<\/p>\n<p>Bei der Verwendung der elliptischen Kurve Brainpool zur Kodierung des Passworts durch den Dragonfly-Algorithmus werden mehrere vorl\u00e4ufige Iterationen mit dem Passwort durchgef\u00fchrt, die mit der schnellen Berechnung eines kurzen Hashs verkn\u00fcpft sind, bevor die elliptische Kurve angewendet wird. Bis der kurze Hash gefunden wird, h\u00e4ngen die durchgef\u00fchrten Operationen direkt vom Passwort und der MAC-Adresse des Clients ab. Die Ausf\u00fchrungszeit (die mit der Anzahl der Iterationen korreliert) und die Verz\u00f6gerungen zwischen den Operationen w\u00e4hrend der Durchf\u00fchrung der vorl\u00e4ufigen Iterationen k\u00f6nnen gemessen und verwendet werden, um Passwortmerkmale zu bestimmen, die offline verwendet werden k\u00f6nnen, um die Korrektheit der Auswahl von Passwortteilen w\u00e4hrend des Crackens zu verfeinern. F\u00fcr einen Angriff ist der Zugriff auf das System des Benutzers erforderlich, der sich mit dem drahtlosen Netzwerk verbindet. <\/p>\n<p>Zus\u00e4tzlich haben die Forscher eine zweite Schwachstelle (CVE-2019-13456) entdeckt, die mit dem Informationsleck in der Implementierung des Protokolls <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Extensible_Authentication_Protocol#EAP_Password_(EAP-PWD)\">EAP-pwd<\/a><\/noindex>, der den Dragonfly-Algorithmus verwendet. Das Problem ist spezifisch f\u00fcr den RADIUS-Server FreeRADIUS und erm\u00f6glicht aufgrund einer Informationsleckage \u00fcber externe Kan\u00e4le, \u00e4hnlich wie die erste Schwachstelle, eine signifikante Vereinfachung der Passwort\u00fcberpr\u00fcfung.  <\/p>\n<p>In Kombination mit einer verbesserten Methode zur Unterdr\u00fcckung von Rauschen w\u00e4hrend der Latenzmessung, um die Anzahl der Iterationen zu bestimmen, sind 75 Messungen f\u00fcr eine MAC-Adresse ausreichend. Bei der Verwendung von GPU werden die Ressourcenaufwendungen f\u00fcr die \u00dcberpr\u00fcfung eines W\u00f6rterbuchpassworts auf 1 $ gesch\u00e4tzt. Sicherheitsverbesserungsmethoden f\u00fcr Protokolle, die die identifizierten Probleme blockieren, wurden bereits in die Entw\u00fcrfe zuk\u00fcnftiger Wi-Fi-Standards aufgenommen (<noindex><a rel=\"nofollow\" href=\"https:\/\/mentor.ieee.org\/802.11\/dcn\/19\/11-19-1173-08-000m-pwe-in-constant-time.docx\">WPA 3.1<\/a><\/noindex>) und <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/draft-harkins-eap-pwd-prime-00\">EAP-pwd<\/a><\/noindex>). Leider ist es nicht m\u00f6glich, die Lecks \u00fcber externe Kan\u00e4le in den aktuellen Versionen der Protokolle ohne Verletzung der R\u00fcckw\u00e4rtskompatibilit\u00e4t zu beheben.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51216\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef) \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen) \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438 (CVE-2019-13377) \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044e \u0437\u0430\u0449\u0438\u0442\u044b WPA3, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0445\u0430\u0440\u0430\u043a\u0442\u0435\u0440\u0438\u0441\u0442\u0438\u043a\u0430\u0445 \u043f\u0430\u0440\u043e\u043b\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0435\u0433\u043e \u043f\u043e\u0434\u0431\u043e\u0440\u0430 \u0432 offline-\u0440\u0435\u0436\u0438\u043c\u0435. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 Hostapd. \u041d\u0430\u043f\u043e\u043c\u043d\u0438\u043c, \u0447\u0442\u043e \u0432 \u0430\u043f\u0440\u0435\u043b\u0435 \u0442\u0435\u043c\u0438 \u0436\u0435 \u0430\u0432\u0442\u043e\u0440\u0430\u043c\u0438 \u0431\u044b\u043b\u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0448\u0435\u0441\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 WPA3, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-36788","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef) \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen) \u0432\u044b\u044f\u0432\u0438\u043b\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3 \u0438 \u0432 EAP-pwd | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef) \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen) \u0432\u044b\u044f\u0432\u0438\u043b\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:13:49+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:13:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Neue Schwachstellen in der WLAN-Sicherheitstechnologie WPA3 und in EAP-pwd | ProHoster","description":"wurde von Mathy Vanhoef und Eyal Ronen entdeckt.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3 \u0438 \u0432 EAP-pwd | ProHoster","og:description":"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef) \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen) \u0432\u044b\u044f\u0432\u0438\u043b\u0438.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:13:49+00:00","article:modified_time":"2019-10-31T19:13:49+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36788","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 04:50:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:38:25","updated":"2026-01-22 04:50:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/36788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=36788"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/36788\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=36788"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=36788"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=36788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}