{"id":36788,"date":"2019-10-31T22:13:49","date_gmt":"2019-10-31T19:13:49","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\/"},"modified":"2019-10-31T22:13:49","modified_gmt":"2019-10-31T19:13:49","slug":"novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","title":{"rendered":"Evitando el l\u00edmite de b\u00fasqueda de LinkedIn, jugando con la API","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Mathy Vanhoef y Eyal Ronen (<noindex><a rel=\"nofollow\" href=\"https:\/\/eyalro.net\/\">Eyal Ronen<\/a><\/noindex>) <noindex><a rel=\"nofollow\" href=\"https:\/\/wpa3.mathyvanhoef.com\/#new\">detectaron<\/a><\/noindex> un nuevo m\u00e9todo de ataque (CVE-2019-13377) contra redes inal\u00e1mbricas que utilizan la tecnolog\u00eda de protecci\u00f3n WPA3, que permite obtener informaci\u00f3n sobre las caracter\u00edsticas de la contrase\u00f1a, la cual puede ser utilizada para realizar intentos de adivinanza en modo offline. El problema se manifiesta en la versi\u00f3n actual de <noindex><a rel=\"nofollow\" href=\"https:\/\/w1.fi\/security\/\">Hostapd<\/a><\/noindex>.<\/p>\n<p>Recordemos que en abril los mismos autores hab\u00edan <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50493\">se han identificado<\/a><\/noindex> seis vulnerabilidades en WPA3. Para contrarrestarlas, la Wi-Fi Alliance, que desarrolla est\u00e1ndares para redes inal\u00e1mbricas, realiz\u00f3 cambios en las recomendaciones para asegurar implementaciones seguras de WPA3, en las que se prescribi\u00f3 el uso de curvas el\u00edpticas protegidas <noindex><a rel=\"nofollow\" href=\"http:\/\/bada55.cr.yp.to\/brainpool.html\">Brainpool<\/a><\/noindex>, en lugar de las curvas el\u00edpticas P-521 y P-256 que antes eran permitidas. <\/p>\n<p>Sin embargo, el an\u00e1lisis mostr\u00f3 que el uso de Brainpool da lugar a un nuevo tipo de filtraciones a trav\u00e9s de canales laterales en el algoritmo de negociaci\u00f3n de conexiones utilizado en WPA3 <noindex><a rel=\"nofollow\" href=\"https:\/\/sarwiki.informatik.hu-berlin.de\/WPA3_Dragonfly_Handshake\">Dragonfly<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=48854\">que proporciona<\/a><\/noindex> proteger contra intentos de adivinanza de contrase\u00f1as en modo offline. El problema identificado demuestra que crear implementaciones de Dragonfly y WPA3 que est\u00e9n libres de filtraciones de datos a trav\u00e9s de canales laterales es una tarea extremadamente compleja, y tambi\u00e9n pone de manifiesto la insuficiencia del modelo de desarrollo de est\u00e1ndares tras puertas cerradas, sin llevar a cabo una discusi\u00f3n p\u00fablica de los m\u00e9todos propuestos y una auditor\u00eda por parte de la comunidad.<\/p>\n<p>Al utilizar la curva el\u00edptica Brainpool al codificar la contrase\u00f1a mediante el algoritmo Dragonfly, se realizan varias iteraciones preliminares con la contrase\u00f1a, relacionadas con el c\u00e1lculo r\u00e1pido de un hash corto antes de empezar a aplicar la curva el\u00edptica. Hasta hallar el hash corto, las operaciones realizadas dependen directamente de la contrase\u00f1a y de la direcci\u00f3n MAC del cliente. El tiempo de ejecuci\u00f3n (que se correlaciona con el n\u00famero de iteraciones) y las demoras entre operaciones durante las iteraciones preliminares pueden ser medidas y utilizadas para determinar caracter\u00edsticas de la contrase\u00f1a que pueden emplearse en modo offline para afinar la selecci\u00f3n de partes de la contrase\u00f1a en el proceso de su adivinanza. Para llevar a cabo el ataque, es necesario tener acceso al sistema del usuario que se conecta a la red inal\u00e1mbrica. <\/p>\n<p>Adem\u00e1s, los investigadores identificaron una segunda vulnerabilidad (CVE-2019-13456) relacionada con la fuga de informaci\u00f3n en la implementaci\u00f3n del protocolo <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Extensible_Authentication_Protocol#EAP_Password_(EAP-PWD)\">EAP-pwd<\/a><\/noindex>, utilizando el algoritmo Dragonfly. El problema es espec\u00edfico para el servidor RADIUS FreeRADIUS y, seg\u00fan la filtraci\u00f3n de informaci\u00f3n por canales externos, al igual que la primera vulnerabilidad, facilita considerablemente la selecci\u00f3n de contrase\u00f1as.  <\/p>\n<p>En combinaci\u00f3n con un m\u00e9todo mejorado para filtrar el ruido durante la medici\u00f3n de latencias para determinar el n\u00famero de iteraciones, se requieren 75 mediciones para una direcci\u00f3n MAC. Al utilizar GPU, el costo de los recursos para descifrar una contrase\u00f1a de diccionario se estima en $1. Los m\u00e9todos para incrementar la seguridad de los protocolos, que permiten bloquear los problemas identificados, ya se han incorporado en los borradores de las futuras normas de Wi-Fi (<noindex><a rel=\"nofollow\" href=\"https:\/\/mentor.ieee.org\/802.11\/dcn\/19\/11-19-1173-08-000m-pwe-in-constant-time.docx\">WPA 3.1<\/a><\/noindex>) y <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/draft-harkins-eap-pwd-prime-00\">EAP-pwd<\/a><\/noindex>. Lamentablemente, no ser\u00e1 posible eliminar las filtraciones por canales externos en las versiones actuales de los protocolos sin comprometer la compatibilidad hacia atr\u00e1s.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51216\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef) \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen) \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438 (CVE-2019-13377) \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044e \u0437\u0430\u0449\u0438\u0442\u044b WPA3, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0445\u0430\u0440\u0430\u043a\u0442\u0435\u0440\u0438\u0441\u0442\u0438\u043a\u0430\u0445 \u043f\u0430\u0440\u043e\u043b\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0435\u0433\u043e \u043f\u043e\u0434\u0431\u043e\u0440\u0430 \u0432 offline-\u0440\u0435\u0436\u0438\u043c\u0435. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 Hostapd. \u041d\u0430\u043f\u043e\u043c\u043d\u0438\u043c, \u0447\u0442\u043e \u0432 \u0430\u043f\u0440\u0435\u043b\u0435 \u0442\u0435\u043c\u0438 \u0436\u0435 \u0430\u0432\u0442\u043e\u0440\u0430\u043c\u0438 \u0431\u044b\u043b\u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0448\u0435\u0441\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 WPA3, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-36788","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef) \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen) \u0432\u044b\u044f\u0432\u0438\u043b\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3 \u0438 \u0432 EAP-pwd | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef) \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen) \u0432\u044b\u044f\u0432\u0438\u043b\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:13:49+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:13:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Nuevas vulnerabilidades en la tecnolog\u00eda de protecci\u00f3n de redes inal\u00e1mbricas WPA3 y en EAP-pwd | ProHoster","description":"Mathy Vanhoef y Eyal Ronen identificaron.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3 \u0438 \u0432 EAP-pwd | ProHoster","og:description":"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef) \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen) \u0432\u044b\u044f\u0432\u0438\u043b\u0438.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/novye-uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:13:49+00:00","article:modified_time":"2019-10-31T19:13:49+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36788","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 04:50:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:38:25","updated":"2026-01-22 04:50:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/36788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=36788"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/36788\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=36788"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=36788"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=36788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}