Dragonblood: the first vulnerabilities in Wi-Fi WPA3 have been identified.

In October 2017, it was unexpectedly revealed that the Wi-Fi Protected Access II (WPA2) protocol for encrypting Wi-Fi traffic had a serious vulnerability that allowed for the discovery of user passwords and the subsequent eavesdropping on the victim's data exchange. The vulnerability was named KRACK (short for Key Reinstallation Attack) and was identified by researchers Mathy Vanhoef and Eyal Ronen. Following the discovery, the KRACK vulnerability was addressed with patched firmware for devices, and the WPA3 protocol, which succeeded WPA2 last year, was expected to eliminate security issues in Wi-Fi networks altogether. 

Dragonblood: the first vulnerabilities in Wi-Fi WPA3 have been identified.

Unfortunately, the same researchers found equally dangerous vulnerabilities in the WPA3 protocol. Therefore, we once again have to wait and hope for new firmware for wireless access points and devices; otherwise, we will have to live with the knowledge of vulnerabilities in home and public Wi-Fi networks. The vulnerabilities found in WPA3 are collectively referred to as Dragonblood.

The roots of the problem, as before, lie in the functioning of the connection establishment mechanism, or, as they are called in the standard, 'handshakes'. This mechanism in the WPA3 standard is called Dragonfly. Until the Dragonblood discovery, it was considered well protected. The Dragonblood set contained five types of vulnerabilities: denial of service, two vulnerabilities related to network downgrade, and two side-channel attack vulnerabilities.


Dragonblood: the first vulnerabilities in Wi-Fi WPA3 have been identified.

Denial of service does not lead to data leakage, but it can be a frustrating experience for a user who repeatedly cannot connect to an access point. The other vulnerabilities allow an attacker to recover passwords for connecting a user to the access point and track any critical information of the user.

Downgrade attacks allow for a forced transition to an older version of the WPA2 protocol or to weaker encryption algorithm options in WPA3, after which known hacking methods can be used. Side-channel attacks exploit the features of WPA3 algorithms and their implementation, ultimately allowing the use of previously known password cracking methods. More details here. A toolkit for discovering Dragonblood vulnerabilities can be found at this link.

Dragonblood: the first vulnerabilities in Wi-Fi WPA3 have been identified.

The Wi-Fi Alliance, responsible for developing Wi-Fi standards, has been informed about the discovered vulnerabilities. It is reported that equipment manufacturers are preparing modified firmware to close the security gaps identified. No replacements or returns of equipment will be necessary.




Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster