{"id":31424,"date":"2019-10-31T21:41:11","date_gmt":"2019-10-31T18:41:11","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\/"},"modified":"2019-10-31T21:41:11","modified_gmt":"2019-10-31T18:41:11","slug":"uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","title":{"rendered":"Vulnerabilities in WPA3 wireless security technology and EAP-pwd","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Mathy Vanhoef, the author of the KRACK attack on wireless networks with WPA2, and Eyal Ronen, co-author of some attacks on TLS, have disclosed six vulnerabilities (CVE-2019-9494 \u2014 CVE-2019-9499) in the WPA3 wireless network protection technology. These vulnerabilities allow for the recreation of connection passwords and access to wireless networks without the knowledge of the password. The vulnerabilities are collectively named Dragonblood and can compromise the Dragonfly connection negotiation method, which provides protection against offline password guessing. In addition to WPA3, the Dragonfly method is also used to protect against dictionary attacks in the EAP-pwd protocol, implemented in Android, RADIUS servers, and hostapd\/wpa_supplicant.<\/p>\n<p>The research identified two main types of architectural issues in WPA3. Both types of problems can ultimately be exploited to recreate the access password. The first type allows a fallback to less secure cryptographic methods (downgrade attack): compatibility features with WPA2 (transition mode allowing the use of both WPA2 and WPA3) enable an attacker to force the client to perform the WPA2 four-way handshake, thereby allowing the use of classical password guessing attacks applicable to WPA2. Additionally, a downgrade attack directly on the Dragonfly handshake method has also been discovered, allowing a fallback to less secure types of elliptic curves.<\/p>\n<p>The second type of issues leads to information leakage through side channels about the characteristics of the password and is based on flaws in the password encoding method in Dragonfly. These flaws allow for the recreation of the original password from indirect data, such as changes in delays during operations. The hash-to-curve algorithm used in Dragonfly was found to be vulnerable to attacks via monitoring information leakage in the processor cache (cache attack), while the hash-to-group algorithm is vulnerable to attacks through timing measurements of operation execution (timing attack).<\/p>\n<p> To carry out attacks through cache analysis, an attacker must be able to execute non-privileged code on the user's system connecting to the wireless network. Both methods provide the means to obtain information necessary for refining the correct choice of password components during the cracking process. The effectiveness of the attack is quite high and allows for the cracking of an 8-character password that includes lowercase letters by intercepting just 40 connection handshake sessions and consuming resources equivalent to renting Amazon EC2 capacity for $125. <\/p>\n<p>Based on the identified vulnerabilities, several attack scenarios have been proposed:<\/p>\n<ul>\n<li class=\"l\"> Rollback attack on WPA2 with the possibility of conducting a dictionary attack. When both the client and the access point support both WPA3 and WPA2, the attacker can deploy their own rogue access point with the same network name that only supports WPA2. In this situation, the client will use the WPA2 connection negotiation method, during which it will be determined that such a rollback is not permissible, but this will occur at a stage when the channel negotiation messages have been sent, and all the necessary information for the dictionary attack has already leaked. A similar method is applicable for rolling back to problematic versions of elliptic curves in SAE.\n<p>Additionally, it has been revealed that the iwd daemon, developed by Intel as an alternative to wpa_supplicant, and the wireless stack of the Samsung Galaxy S10 are vulnerable to downgrade attacks even on networks that only use WPA3\u2014if these devices have previously connected to a WPA3 network, they will attempt to connect to a spoofed WPA2 network with the same name.<\/p>\n<li class=\"l\"> Side-channel attack extracting information from the processor cache. The password encoding algorithm in Dragonfly contains conditional branching, and the attacker, having the ability to execute code in the user's wireless network system, can determine which block of the if-then-else expression was chosen based on cache behavior analysis. The obtained information can be used for performing a progressive password guess using methods similar to offline dictionary attacks on WPA2 passwords. To protect against this, it is recommended to switch to constant-time operations that are independent of the nature of the processed data.\n<li class=\"l\"> Side-channel attack with time complexity assessment. The Dragonfly code for password encoding uses several multiplicative groups (MODP) and a variable number of iterations, which depends on the password and the MAC address of the access point or client. A remote attacker can determine how many iterations were performed during password encoding and use this as a clue in progressive password guessing.\n<li class=\"l\"> Denial of Service attack. The attacker can block certain functions of the access point due to resource exhaustion by sending a large number of channel negotiation requests. To bypass the WPA3 flood protection, it is sufficient to send requests from fake, non-repeating MAC addresses.\n<li class=\"l\">  Fallback to less secure cryptographic groups used during connection negotiations in WPA3. For example, if the client supports elliptic curves P-521 and P-256, using P-521 as the preferred option, the attacker, regardless of the support on the access point's side for P-521, can force the client to use P-256. The attack is carried out by filtering some messages during the connection negotiation process and sending forged messages indicating the lack of support for certain types of elliptic curves.<br \/>\nTo check devices for vulnerabilities, several scripts with examples of attacks have been prepared:<\/p>\n<\/ul>\n<p>Dragonslayer \u2014 implementation of attacks on EAP-pwd;<\/p>\n<ul>\n<li class=\"l\"> Dragonslayer \u2014 an implementation of attacks on EAP-pwd;\n<li class=\"l\"> Dragondrain \u2014 a utility for testing the vulnerability of access points in the implementation of the SAE (Simultaneous Authentication of Equals) connection negotiation method, which can be used to initiate denial of service;\n<li class=\"l\"> Dragontime \u2014 a script for conducting side-channel attacks against SAE, taking into account the difference in operation processing times when using MODP groups 22, 23, and 24;\n<li class=\"l\"> Dragonforce \u2014 a utility for information recovery (password cracking) based on timing differences in operation processing or identifying data residing in cache.\n<\/ul>\n<p>The Wi-Fi Alliance, which develops standards for wireless networks, has announced that the issue affects a limited number of early implementations of WPA3-Personal and can be resolved through firmware and software updates. There are currently no documented instances of vulnerabilities being exploited for malicious purposes. To enhance security, the Wi-Fi Alliance has added additional tests to its wireless device certification program to verify the correctness of implementations and has contacted device manufacturers for coordinated resolution of identified issues. Patches addressing these problems have already been released for hostap\/wpa_supplicant. Package updates are available for Ubuntu. Issues remain unresolved in Debian, RHEL, SUSE\/openSUSE, Arch, Fedora, and FreeBSD.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50493\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef), \u0430\u0432\u0442\u043e\u0440 \u0430\u0442\u0430\u043a\u0438 KRACK \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438 \u0441 WPA2, \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen), \u0441\u043e\u0430\u0432\u0442\u043e\u0440 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 TLS, \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0448\u0435\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (CVE-2019-9494 &#8212; CVE-2019-9499) \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0431\u0435\u0437 \u0437\u043d\u0430\u043d\u0438\u044f \u043f\u0430\u0440\u043e\u043b\u044f. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c Dragonblood [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-31424","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef), \u0430\u0432\u0442\u043e\u0440 \u0430\u0442\u0430\u043a\u0438 KRACK \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438 \u0441 WPA2, \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen), \u0441\u043e\u0430\u0432\u0442\u043e\u0440 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 TLS, \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0448\u0435\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (CVE-2019-9494 - CVE-2019-9499) \u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3 \u0438 \u0432 EAP-pwd | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef), \u0430\u0432\u0442\u043e\u0440 \u0430\u0442\u0430\u043a\u0438 KRACK \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438 \u0441 WPA2, \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen), \u0441\u043e\u0430\u0432\u0442\u043e\u0440 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 TLS, \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0448\u0435\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (CVE-2019-9494 - CVE-2019-9499) \u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:41:11+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:41:11+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilities in WPA3 wireless network security technology and in EAP-pwd | ProHoster","description":"Mathy Vanhoef, the author of the KRACK attack on wireless networks with WPA2, and Eyal Ronen, co-author of some attacks on TLS, have disclosed information about six vulnerabilities (CVE-2019-9494 - CVE-2019-9499) in.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3 \u0438 \u0432 EAP-pwd | ProHoster","og:description":"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef), \u0430\u0432\u0442\u043e\u0440 \u0430\u0442\u0430\u043a\u0438 KRACK \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438 \u0441 WPA2, \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen), \u0441\u043e\u0430\u0432\u0442\u043e\u0440 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 TLS, \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0448\u0435\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (CVE-2019-9494 - CVE-2019-9499) \u0432.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:41:11+00:00","article:modified_time":"2019-10-31T18:41:11+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31424","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 06:08:14","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:17:25","updated":"2026-01-21 06:08:14","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31424","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=31424"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31424\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=31424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=31424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=31424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}