New vulnerabilities in the WPA3 wireless network protection technology and EAP-pwd

Mathy Vanhoef and Eyal RonenEyal Ronen) identified a new attack method (CVE-2019-13377) on wireless networks using WPA3 protection technology, allowing for the extraction of password characteristics that can be used for offline password cracking. The issue is present in the current version of Hostapd.

Recall that in April, the same authors had three vulnerabilities have been identified identified six vulnerabilities in WPA3, which led the Wi-Fi Alliance, responsible for developing standards for wireless networks, to update its recommendations for secure implementations of WPA3, mandating the use of secure elliptic curves Brainpool, instead of the previously permissible elliptic curves P-521 and P-256.

However, analysis revealed that the use of Brainpool results in a new class of side-channel leaks in the Dragonfly connection agreement algorithm used in WPA3. Dragonfly, providing protection against offline password cracking. The identified issue demonstrates that creating implementations of Dragonfly and WPA3 free from side-channel data leaks is an extremely challenging task, as well as highlighting the shortcomings of developing standards behind closed doors without public discussions of proposed methods and community audits.

When using the Brainpool elliptic curve to encode the password with the Dragonfly algorithm, several preliminary iterations concerning fast computation of a short hash are performed before the elliptic curve is applied. Before finding the short hash, the operations performed directly depend on the password and the client's MAC address. The execution time (which correlates with the number of iterations) and the delays between operations during the preliminary iterations can be measured and used to determine characteristics of the password that can be utilized offline to refine the correctness of chosen password segments during the cracking process. To carry out the attack, access to the user's system connecting to the wireless network is required.

Additionally, researchers identified a second vulnerability (CVE-2019-13456) related to information leakage in the implementation of the EAP-pwd protocol., using the Dragonfly algorithm. The issue is specific to the FreeRADIUS server, and based on leaks from third-party sources, as well as the first vulnerability, it significantly simplifies password cracking.

Combined with an improved noise filtering method during delay measurements, only 75 readings are required for one MAC address to determine the number of iterations. When using a GPU, resource costs for cracking a single dictionary password are estimated at $1. Security enhancements to protocols that can block the identified issues have already been incorporated into draft versions of future Wi-Fi standards (WPA 3.1) and EAP-pwd protocol.). Unfortunately, it will not be possible to eliminate leaks through third-party channels in the current protocol versions without breaking backward compatibility.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster