{"id":107780,"date":"2023-04-08T12:48:10","date_gmt":"2023-04-08T10:48:12","guid":{"rendered":"https:\/\/prohoster.info\/?p=107780"},"modified":"2023-04-10T11:12:07","modified_gmt":"2023-04-10T09:12:07","slug":"uyazvimost-v-besprovodnyh-tochkah-dostupa-pozvolyayushhaya-organizovat-perehvat-trafika","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-besprovodnyh-tochkah-dostupa-pozvolyayushhaya-organizovat-perehvat-trafika","title":{"rendered":"Vulnerability in wireless access points allowing traffic interception","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A group of researchers from Tsinghua University (China) and George Mason University (USA) revealed information about a vulnerability (CVE-2022-25667) in wireless access points that allows for traffic interception (MITM) in wireless networks protected by WPA, WPA2, and WPA3 protocols. By manipulating ICMP packets with the 'redirect' flag, an attacker can redirect the victim's traffic within the wireless network through their system, which can be used to intercept and replace unencrypted sessions (for example, requests to sites without HTTPS).     <\/p>\n<p>The vulnerability is caused by insufficient filtering of spoofed ICMP messages with a forged source address in Network Processing Units (NPU) that provide low-level packet processing in the wireless network. Among other things, the NPU redirected unverified spoofed ICMP packets with the 'redirect' flag, which can be used to modify routing table entries on the victim's device. The attack involves sending an ICMP packet on behalf of the access point with the 'redirect' flag, specifying forged data in the packet header. Due to the vulnerability, the message is redirected by the access point and processed by the victim's network stack, which believes the message was sent by the access point.         <center><img decoding=\"async\" alt=\"Vulnerability in wireless access points allowing traffic interception\" src=\"\/wp-content\/uploads\/2023\/04\/3e2e36d2e28151c63bab9813799af592.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>Additionally, researchers have proposed a method for bypassing ICMP packet checks with the 'redirect' flag on the end user's side and altering their routing table. To circumvent filtering, the attacker first identifies an active UDP port on the victim's side. Being on the same wireless network, the attacker can intercept traffic but cannot decrypt it since they do not know the session key used when the victim connects to the access point. However, by sending verification packets to the victim, the attacker can, based on the analysis of the incoming ICMP responses with the 'Destination Unreachable' flag, determine the active UDP port. Next, the attacker constructs an ICMP message with the 'redirect' flag and a forged UDP header indicating the discovered open UDP port. Processing this message leads to distortions in the routing table on the victim's system, redirecting traffic for interception in clear text at the link layer.          <center><img decoding=\"async\" alt=\"Vulnerability in wireless access points allowing traffic interception\" src=\"\/wp-content\/uploads\/2023\/04\/439dc3af6dbd40e2b750d38814c93a5b.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>        <\/p>\n<p>The presence of the problem has been confirmed in access points using chips from HiSilicon and Qualcomm. An examination of 55 different models of access points from 10 well-known manufacturers (Cisco, NetGear, Xiaomi, Mercury, 360, Huawei, TP-Link, H3C, Tenda, Ruijie) showed that they are all vulnerable and do not block spoofed ICMP packets. Furthermore, an analysis of 122 existing wireless networks revealed the possibility of an attack in 109 networks (89%).       <center><img decoding=\"async\" alt=\"Vulnerability in wireless access points allowing traffic interception\" src=\"\/wp-content\/uploads\/2023\/04\/be0ab562c719ae31a027dfd17d545edf.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>          <\/p>\n<p>To exploit the vulnerabilities, an attacker must have legitimate access to the Wi-Fi network, meaning they must know the credentials for the wireless network (the vulnerabilities allow bypassing the traffic separation mechanisms in the WPA* protocols). Unlike traditional MITM attacks on wireless networks, by using ICMP packet spoofing techniques, the attacker can avoid deploying their own fake access point for traffic interception and instead use legitimate access points serving the network to redirect specially crafted ICMP packets to the victim.          <center>  <video controls=\"\" style=\"width: 700px; height: 550px; max-width:100%\"  width=\"700\" height=\"550\"><source src=\"https:\/\/wifi-interception.github.io\/resources\/wifi-eng-noppt-mask-LAN.mp4\" type=\"video\/mp4\"><\/video><br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58935\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0426\u0438\u043d\u0445\u0443\u0430 (\u041a\u0438\u0442\u0430\u0439) \u0438 \u0414\u0436\u043e\u0440\u0434\u0436\u0430 \u041c\u0435\u0439\u0441\u043e\u043d\u0430 (\u0421\u0428\u0410) \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2022-25667) \u0432 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0442\u043e\u0447\u043a\u0430\u0445 \u0434\u043e\u0441\u0442\u0443\u043f\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 (MITM) \u0432 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u044f\u0445, \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u044b\u0445 \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432 WPA, WPA2 \u0438 WPA3. \u0427\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u044e ICMP-\u043f\u0430\u043a\u0435\u0442\u0430\u043c\u0438 \u0441 \u0444\u043b\u0430\u0433\u043e\u043c &#171;redirect&#187; \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0436\u0435\u0440\u0442\u0432\u044b \u0432\u043d\u0443\u0442\u0440\u0438 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0447\u0435\u0440\u0435\u0437 \u0441\u0432\u043e\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u0443, \u0447\u0442\u043e \u043c\u043e\u0436\u0435\u0442 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":107781,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-107780","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0426\u0438\u043d\u0445\u0443\u0430 (\u041a\u0438\u0442\u0430\u0439) \u0438 \u0414\u0436\u043e\u0440\u0434\u0436\u0430 \u041c\u0435\u0439\u0441\u043e\u043d\u0430 (\u0421\u0428\u0410) \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2022-25667) \u0432 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0442\u043e\u0447\u043a\u0430\u0445 \u0434\u043e\u0441\u0442\u0443\u043f\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 (MITM) \u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-besprovodnyh-tochkah-dostupa-pozvolyayushhaya-organizovat-perehvat-trafika\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0442\u043e\u0447\u043a\u0430\u0445 \u0434\u043e\u0441\u0442\u0443\u043f\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0426\u0438\u043d\u0445\u0443\u0430 (\u041a\u0438\u0442\u0430\u0439) \u0438 \u0414\u0436\u043e\u0440\u0434\u0436\u0430 \u041c\u0435\u0439\u0441\u043e\u043d\u0430 (\u0421\u0428\u0410) \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2022-25667) \u0432 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0442\u043e\u0447\u043a\u0430\u0445 \u0434\u043e\u0441\u0442\u0443\u043f\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 (MITM) \u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-besprovodnyh-tochkah-dostupa-pozvolyayushhaya-organizovat-perehvat-trafika\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-04-08T10:48:12+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-04-10T09:12:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerability in wireless access points allowing traffic interception | ProHoster","description":"A group of researchers from Tsinghua University (China) and George Mason University (USA) has disclosed information about a vulnerability (CVE-2022-25667) in wireless access points that enables traffic interception (MITM).","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-besprovodnyh-tochkah-dostupa-pozvolyayushhaya-organizovat-perehvat-trafika","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0442\u043e\u0447\u043a\u0430\u0445 \u0434\u043e\u0441\u0442\u0443\u043f\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 | ProHoster","og:description":"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u043e\u0432 \u0426\u0438\u043d\u0445\u0443\u0430 (\u041a\u0438\u0442\u0430\u0439) \u0438 \u0414\u0436\u043e\u0440\u0434\u0436\u0430 \u041c\u0435\u0439\u0441\u043e\u043d\u0430 (\u0421\u0428\u0410) \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2022-25667) \u0432 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0442\u043e\u0447\u043a\u0430\u0445 \u0434\u043e\u0441\u0442\u0443\u043f\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 (MITM) \u0432.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-besprovodnyh-tochkah-dostupa-pozvolyayushhaya-organizovat-perehvat-trafika","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-04-08T10:48:12+00:00","article:modified_time":"2023-04-10T09:12:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/107780","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=107780"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/107780\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/107781"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=107780"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=107780"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=107780"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}