Vulnerabilities in WPA3 wireless security technology and EAP-pwd

Mathy Vanhoef, the author of the KRACK attack on wireless networks with WPA2, and Eyal Ronen, co-author of several attacks on TLS, have disclosed details about six vulnerabilities (CVE-2019-9494 — CVE-2019-9499) in the WPA3 wireless network protection technology. These vulnerabilities allow the recreation of the connection password and access to the wireless network without knowledge of the password. The vulnerabilities are collectively known as Dragonblood and compromise the Dragonfly connection handshake method, which provides protection against offline password guessing. In addition to WPA3, the Dragonfly method is also used to protect against dictionary attacks in the EAP-pwd protocol, used in Android, RADIUS servers, and in hostapd/wpa_supplicant.

The research identified two main types of architectural issues in WPA3. Both types of problems can ultimately be exploited to recreate the access password. The first type allows a fallback to less secure cryptographic methods (downgrade attack): compatibility features with WPA2 (transition mode allowing the use of both WPA2 and WPA3) enable an attacker to force the client to perform the WPA2 four-way handshake, thereby allowing the use of classical password guessing attacks applicable to WPA2. Additionally, a downgrade attack directly on the Dragonfly handshake method has also been discovered, allowing a fallback to less secure types of elliptic curves.

The second type of issues leads to information leakage through side channels about the characteristics of the password and is based on flaws in the password encoding method in Dragonfly. These flaws allow for the recreation of the original password from indirect data, such as changes in delays during operations. The hash-to-curve algorithm used in Dragonfly was found to be vulnerable to attacks via monitoring information leakage in the processor cache (cache attack), while the hash-to-group algorithm is vulnerable to attacks through timing measurements of operation execution (timing attack).

To carry out attacks through cache analysis, an attacker must be able to execute non-privileged code on the user's system connecting to the wireless network. Both methods provide the means to obtain information necessary for refining the correct choice of password components during the cracking process. The effectiveness of the attack is quite high and allows for the cracking of an 8-character password that includes lowercase letters by intercepting just 40 connection handshake sessions and consuming resources equivalent to renting Amazon EC2 capacity for $125.

Based on the identified vulnerabilities, several attack scenarios have been proposed:

  • Rollback attack on WPA2 with the possibility of conducting a dictionary attack. When both the client and the access point support both WPA3 and WPA2, the attacker can deploy their own rogue access point with the same network name that only supports WPA2. In this situation, the client will use the WPA2 connection negotiation method, during which it will be determined that such a rollback is not permissible, but this will occur at a stage when the channel negotiation messages have been sent, and all the necessary information for the dictionary attack has already leaked. A similar method is applicable for rolling back to problematic versions of elliptic curves in SAE.

    Furthermore, it has been found that the iwd daemon, developed by Intel as an alternative to wpa_supplicant, and the wireless stack of the Samsung Galaxy S10 are vulnerable to downgrade attacks even in networks using only WPA3 — if these devices have previously connected to a WPA3 network, they will attempt to connect to a rogue WPA2 network with the same name.

  • Side-channel attack extracting information from the processor cache. The password encoding algorithm in Dragonfly contains conditional branching, and the attacker, having the ability to execute code in the user's wireless network system, can determine which block of the if-then-else expression was chosen based on cache behavior analysis. The obtained information can be used for performing a progressive password guess using methods similar to offline dictionary attacks on WPA2 passwords. To protect against this, it is recommended to switch to constant-time operations that are independent of the nature of the processed data.
  • Side-channel attack with time complexity assessment. The Dragonfly code for password encoding uses several multiplicative groups (MODP) and a variable number of iterations, which depends on the password and the MAC address of the access point or client. A remote attacker can determine how many iterations were performed during password encoding and use this as a clue in progressive password guessing.
  • Denial of Service attack. The attacker can block certain functions of the access point due to resource exhaustion by sending a large number of channel negotiation requests. To bypass the WPA3 flood protection, it is sufficient to send requests from fake, non-repeating MAC addresses.
  • Fallback to less secure cryptographic groups used during connection negotiations in WPA3. For example, if the client supports elliptic curves P-521 and P-256, using P-521 as the preferred option, the attacker, regardless of the support on the access point's side for P-521, can force the client to use P-256. The attack is carried out by filtering some messages during the connection negotiation process and sending forged messages indicating the lack of support for certain types of elliptic curves.
    To check devices for vulnerabilities, several scripts with examples of attacks have been prepared:

Dragonslayer — implementation of attacks on EAP-pwd;

  • Dragonslayer — implementation of attacks on EAP-pwd;
  • Dragondrain — a utility for checking the susceptibility of access points to vulnerabilities in the implementation of the Simultaneous Authentication of Equals (SAE) connection agreement method, which can be used to initiate denial of service attacks;
  • Dragontime — a script for conducting side-channel attacks against SAE, taking into account the differences in the processing time of operations when using MODP groups 22, 23, and 24;
  • Dragonforce — a utility for data recovery (password cracking) based on information about the varying processing times of operations or determining data retention in cache.

The Wi-Fi Alliance, which develops standards for wireless networks, has announced that the issue affects a limited number of early implementations of WPA3-Personal and can be resolved through firmware and software updates. There are currently no documented instances of vulnerabilities being exploited for malicious purposes. To enhance security, the Wi-Fi Alliance has added additional tests to its wireless device certification program to verify the correctness of implementations and has contacted device manufacturers for coordinated resolution of identified issues. Patches addressing these problems have already been released for hostap/wpa_supplicant. Package updates are available for Ubuntu. Issues remain unresolved in Debian, RHEL, SUSE/openSUSE, Arch, Fedora, and FreeBSD.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster