{"id":31424,"date":"2019-10-31T21:41:11","date_gmt":"2019-10-31T18:41:11","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\/"},"modified":"2019-10-31T21:41:11","modified_gmt":"2019-10-31T18:41:11","slug":"uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","title":{"rendered":"Vulnerabilit\u00e0 nella tecnologia di protezione delle reti wireless WPA3 e in EAP-pwd.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef), \u0430\u0432\u0442\u043e\u0440 \u0430\u0442\u0430\u043a\u0438 KRACK \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438 \u0441 WPA2, \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen), \u0441\u043e\u0430\u0432\u0442\u043e\u0440 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 TLS, \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0448\u0435\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (CVE-2019-9494 &#8212; CVE-2019-9499) \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0431\u0435\u0437 \u0437\u043d\u0430\u043d\u0438\u044f \u043f\u0430\u0440\u043e\u043b\u044f. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c Dragonblood \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043c\u0435\u0442\u043e\u0434  \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 Dragonfly, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0439 \u0437\u0430\u0449\u0438\u0442\u0443 \u043e\u0442 \u043f\u043e\u0434\u0431\u043e\u0440\u0430 \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u0432 offline-\u0440\u0435\u0436\u0438\u043c\u0435. \u041a\u0440\u043e\u043c\u0435 WPA3 \u043c\u0435\u0442\u043e\u0434 Dragonfly \u0442\u0430\u043a\u0436\u0435 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u043e\u0442 \u0441\u043b\u043e\u0432\u0430\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0434\u0431\u043e\u0440\u0430 \u0432 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0435 EAP-pwd, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432 Android, RADIUS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430\u0445 \u0438 \u0432 hostapd\/wpa_supplicant.<\/p>\n<p>Lo studio ha rivelato due principali tipi di problemi architetturali in WPA3. Entrambi i tipi di problemi possono essere usati per ricreare la password di accesso. Il primo tipo consente un attacco di downgrading a metodi crittografici non sicuri: meccanismi di compatibilit\u00e0 con WPA2 (modalit\u00e0 transitoria che consente l'uso sia di WPA2 che di WPA3) permettono all'attaccante di costringere il cliente a eseguire il processo di negoziazione delle connessioni WPA2 a quattro fasi, consentendo di effettuare attacchi classici basati sulla forza bruta, applicabili a WPA2. Inoltre, \u00e8 stata identificata la possibilit\u00e0 di un attacco di downgrading direttamente sul metodo di negoziazione delle connessioni Dragonfly, che consente di tornare a tipi di curve elliptiche meno sicuri.<\/p>\n<p>Il secondo tipo di problemi porta a perdite di informazioni sulle caratteristiche della password attraverso canali esterni ed \u00e8 basato su imperfezioni nel metodo di codifica delle password in Dragonfly, che consentono, attraverso dati indiretti come la variazione dei ritardi durante l'esecuzione delle operazioni, di ricostruire la password originale. L'algoritmo utilizzato in Dragonfly per la trasformazione dell'hash in una curva ellittica (hash-to-curve) si \u00e8 rivelato vulnerabile ad attacchi che monitorano la fuoriuscita di informazioni dalla cache del processore (cache attack), mentre l'algoritmo per la trasformazione dell'hash in gruppo (hash-to-group) \u00e8 suscettibile ad attacchi che misurano il tempo di esecuzione delle operazioni (timing attack).<\/p>\n<p> Per effettuare attacchi attraverso l'analisi della cache, l'attaccante deve avere la possibilit\u00e0 di eseguire codice non privilegiato sul sistema dell'utente connesso alla rete wireless. Entrambi i metodi consentono di ottenere le informazioni necessarie per affinare la correttezza della selezione dei caratteri della password durante il processo di attacco. L'efficacia dell'attacco \u00e8 piuttosto elevata e permette di decifrare una password di 8 caratteri, che include lettere minuscole, intercettando solo 40 sessioni di handshake e spendendo risorse equivalenti al noleggio di capacit\u00e0 Amazon EC2 per 125 dollari. <\/p>\n<p>Sulla base delle vulnerabilit\u00e0 identificate, sono stati proposti diversi scenari di attacco:<\/p>\n<ul>\n<li class=\"l\"> Attacco di downgrade su WPA2 con possibilit\u00e0 di attacco lessicale. In scenari in cui il client e il punto di accesso supportano sia WPA3 che WPA2, un attaccante pu\u00f2 installare un proprio punto di accesso fasullo con lo stesso nome della rete, che supporta solo WPA2. In questa situazione, il client utilizzer\u00e0 il metodo di negoziazione tipico di WPA2, nel processo del quale verr\u00e0 determinata l'inadeguatezza di tale downgrade, ma ci\u00f2 avverr\u00e0 in una fase in cui i messaggi di negoziazione del canale sono gi\u00e0 stati inviati e tutte le informazioni necessarie per l'attacco lessicale sono gi\u00e0 trapelate. Un metodo simile \u00e8 applicabile anche per il downgrade a versioni problematiche delle curve ellittiche in SAE.\n<p>\u041a\u0440\u043e\u043c\u0435 \u0442\u043e\u0433\u043e, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e, \u0447\u0442\u043e \u0434\u0435\u043c\u043e\u043d iwd, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Intel \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0430\u043b\u044c\u0442\u0435\u0440\u043d\u0430\u0442\u0438\u0432\u044b wpa_supplicant, \u0438 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u0439 \u0441\u0442\u0435\u043a Samsung Galaxy S10 \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b downgrade-\u0430\u0442\u0430\u043a\u0435 \u0434\u0430\u0436\u0435 \u0432 \u0441\u0435\u0442\u044f\u0445, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u044e\u0449\u0438\u0445 \u0442\u043e\u043b\u044c\u043a\u043e WPA3 &#8212; \u0435\u0441\u043b\u0438 \u0434\u0430\u043d\u043d\u044b\u0435 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430 \u0434\u043e \u044d\u0442\u043e\u0433\u043e \u0441\u043e\u0435\u0434\u0438\u043d\u044f\u043b\u0438\u0441\u044c \u0441 WPA3-\u0441\u0435\u0442\u044c\u044e, \u043e\u043d\u0438 \u043f\u043e\u043f\u044b\u0442\u0430\u044e\u0442\u0441\u044f \u0441\u043e\u0435\u0434\u0438\u043d\u0438\u0442\u044c\u0441\u044f \u0441 \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u043d\u043e\u0439 \u0441\u0435\u0442\u044c\u044e WPA2 \u0441 \u0442\u0435\u043c \u0436\u0435 \u0438\u043c\u0435\u043d\u0435\u043c.<\/p>\n<li class=\"l\"> Attacco tramite canali laterali con estrazione di informazioni dalla cache della CPU. L'algoritmo di codifica delle password in Dragonfly contiene ramificazioni condizionali e un attaccante, avendo la possibilit\u00e0 di eseguire codice nel sistema dell'utente della rete wireless, pu\u00f2, analizzando il comportamento della cache, determinare quale blocco della condizione if-then-else sia stato scelto. Le informazioni ottenute possono essere utilizzate per effettuare un attacco a forza bruta progressivo, impiegando metodi simili a quelli utilizzati negli attacchi lessicali offline per le password WPA2. Per la protezione, si consiglia di passare a operazioni con tempi di esecuzione costanti, indipendenti dalla natura dei dati trattati;\n<li class=\"l\"> Attacco tramite canali laterali con valutazione del tempo di esecuzione delle operazioni. Nel codice di Dragonfly, durante la codifica delle password, vengono utilizzati diversi gruppi moltiplicativi (MODP) e un numero variabile di iterazioni, il cui conteggio dipende dalla password utilizzata e dall'indirizzo MAC del punto di accesso o del client. Un attaccante remoto pu\u00f2 determinare quante iterazioni sono state eseguite durante la codifica della password e utilizzarle come indicatore nel tentativo di attacco a forza bruta progressivo.\n<li class=\"l\"> Denial of Service. An attacker can disrupt certain functionalities of an access point by exhausting available resources through sending a large number of connection agreement requests. To bypass the flood protection included in WPA3, it is sufficient to send requests with fictitious, non-repeating MAC addresses.\n<li class=\"l\">  Fallback to less secure cryptographic groups used in the connection negotiation process in WPA3. For example, if a client supports elliptic curves P-521 and P-256 and uses P-521 as the preferred option, an attacker, regardless of support for P-521 on the access point side, can force the client to use P-256. The attack is carried out by filtering out certain messages during the connection negotiation and sending fake messages indicating the lack of support for certain types of elliptic curves.<br \/>\nTo verify devices for vulnerabilities, several scripts with examples of attacks have been prepared:<\/p>\n<\/ul>\n<p>Dragonslayer \u2014 implementation of attacks on EAP-pwd;<\/p>\n<ul>\n<li class=\"l\"> Dragonslayer &#8212; \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u0430\u0442\u0430\u043a \u043d\u0430 EAP-pwd;\n<li class=\"l\"> Dragondrain  &#8212; \u0443\u0442\u0438\u043b\u0438\u0442\u0430 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043f\u043e\u0434\u0432\u0435\u0436\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0442\u043e\u0447\u0435\u043a \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043c\u0435\u0442\u043e\u0434\u0430 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 SAE (Simultaneous Authentication of Equals), \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438;\n<li class=\"l\"> Dragontime &#8212; \u0441\u043a\u0440\u0438\u043f\u0442 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043f\u043e \u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0438\u043c \u043a\u0430\u043d\u0430\u043b\u0430\u043c \u043f\u0440\u043e\u0442\u0438\u0432 SAE, \u0443\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u0439 \u0440\u0430\u0437\u043d\u0438\u0446\u0443 \u0432\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439 \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u0433\u0440\u0443\u043f\u043f MODP 22, 23 \u0438 24;\n<li class=\"l\"> Dragonforce &#8212; \u0443\u0442\u0438\u043b\u0438\u0442\u0430 \u0434\u043b\u044f \u0432\u043e\u0441\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 (\u043f\u043e\u0434\u0431\u043e\u0440 \u043f\u0430\u0440\u043e\u043b\u044f) \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u0439 \u043e \u0440\u0430\u0437\u043d\u043e\u043c \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439 \u0438\u043b\u0438 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u043e\u0441\u0435\u0434\u0430\u043d\u0438\u044f \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043a\u044d\u0448\u0435.\n<\/ul>\n<p>L'Associazione Wi-Fi Alliance, che sviluppa standard per le reti wireless, ha annunciato che il problema riguarda un numero limitato di implementazioni iniziali di WPA3-Personal e pu\u00f2 essere risolto tramite aggiornamenti di firmware e software. Finora non sono stati riscontrati casi di sfruttamento delle vulnerabilit\u00e0 a fini malevoli. Per migliorare la sicurezza, Wi-Fi Alliance ha aggiunto ulteriori test al programma di certificazione dei dispositivi wireless per verificare la correttezza delle implementazioni e ha contattato i produttori di dispositivi per coordinare insieme la risoluzione dei problemi riscontrati. Le patch per la risoluzione dei problemi sono gi\u00e0 state rilasciate per hostap\/wpa_supplicant. Gli aggiornamenti dei pacchetti sono disponibili per Ubuntu. I problemi rimangono ancora non risolti in Debian, RHEL, SUSE\/openSUSE, Arch, Fedora e FreeBSD.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50493\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef), \u0430\u0432\u0442\u043e\u0440 \u0430\u0442\u0430\u043a\u0438 KRACK \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438 \u0441 WPA2, \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen), \u0441\u043e\u0430\u0432\u0442\u043e\u0440 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 TLS, \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0448\u0435\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (CVE-2019-9494 &#8212; CVE-2019-9499) \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0431\u0435\u0437 \u0437\u043d\u0430\u043d\u0438\u044f \u043f\u0430\u0440\u043e\u043b\u044f. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c Dragonblood [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-31424","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef), \u0430\u0432\u0442\u043e\u0440 \u0430\u0442\u0430\u043a\u0438 KRACK \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438 \u0441 WPA2, \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen), \u0441\u043e\u0430\u0432\u0442\u043e\u0440 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 TLS, \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0448\u0435\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (CVE-2019-9494 - CVE-2019-9499) \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0431\u0435\u0437 \u0437\u043d\u0430\u043d\u0438\u044f \u043f\u0430\u0440\u043e\u043b\u044f. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c Dragonblood\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3 \u0438 \u0432 EAP-pwd | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef), \u0430\u0432\u0442\u043e\u0440 \u0430\u0442\u0430\u043a\u0438 KRACK \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438 \u0441 WPA2, \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen), \u0441\u043e\u0430\u0432\u0442\u043e\u0440 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 TLS, \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0448\u0435\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (CVE-2019-9494 - CVE-2019-9499) \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0431\u0435\u0437 \u0437\u043d\u0430\u043d\u0438\u044f \u043f\u0430\u0440\u043e\u043b\u044f. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c Dragonblood\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:41:11+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:41:11+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 nella tecnologia di protezione delle reti wireless WPA3 e in EAP-pwd | ProHoster","description":"Mathy Vanhoef, autore dell'attacco KRACK alle reti wireless con WPA2, ed Eyal Ronen, coautore di alcuni attacchi a TLS, hanno rivelato informazioni su sei vulnerabilit\u00e0 (CVE-2019-9494 - CVE-2019-9499) nella tecnologia di protezione delle reti wireless WPA3, che consentono di ricreare la password di connessione e accedere alla rete wireless senza conoscere la password. Le vulnerabilit\u00e0 sono state raccolte sotto il nome in codice Dragonblood.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3 \u0438 \u0432 EAP-pwd | ProHoster","og:description":"\u041c\u044d\u0442\u0438 \u0412\u0430\u043d\u0445\u043e\u0444\u043e\u043c (Mathy Vanhoef), \u0430\u0432\u0442\u043e\u0440 \u0430\u0442\u0430\u043a\u0438 KRACK \u043d\u0430 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0435 \u0441\u0435\u0442\u0438 \u0441 WPA2, \u0438 \u042d\u044f\u043b\u044c \u0420\u043e\u043d\u0435\u043d (Eyal Ronen), \u0441\u043e\u0430\u0432\u0442\u043e\u0440 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 TLS, \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0448\u0435\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 (CVE-2019-9494 - CVE-2019-9499) \u0432 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 WPA3, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0431\u0435\u0437 \u0437\u043d\u0430\u043d\u0438\u044f \u043f\u0430\u0440\u043e\u043b\u044f. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c Dragonblood","og:url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/uyazvimosti-v-tehnologii-zashhity-besprovodnyh-setej-wpa3-i-v-eap-pwd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:41:11+00:00","article:modified_time":"2019-10-31T18:41:11+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31424","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 06:08:14","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:17:25","updated":"2026-01-21 06:08:14","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/31424","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=31424"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/31424\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=31424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=31424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=31424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}