ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื—ื“ืฉื•ืช ื‘ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ืื‘ื˜ื—ืช ืจืฉืช ืืœื—ื•ื˜ื™ืช WPA3 ื•-EAP-pwd

ืžืช'ื™ ื•ืื ื”ื•ืฃ ื•ืื™ื™ืœ ืจื•ื ืŸืื™ื™ืœ ืจื•ื ืŸ) ื’ื™ืœื” ืฉื™ื˜ืช ื”ืชืงืคื” ื—ื“ืฉื” (CVE-2019-13377) ื‘ืจืฉืชื•ืช ืืœื—ื•ื˜ื™ื•ืช ื‘ืืžืฆืขื•ืช ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ืื‘ื˜ื—ื” WPA3, ื”ืžืืคืฉืจืช ืงื‘ืœืช ืžื™ื“ืข ืขืœ ืžืืคื™ื™ื ื™ ืกื™ืกืžื” ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ื›ื“ื™ ืœื ื—ืฉ ื–ืืช ื‘ืžืฆื‘ ืœื ืžืงื•ื•ืŸ. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื‘ื’ืจืกื” ื”ื ื•ื›ื—ื™ืช Hostapd.

ื”ื‘ื” ื ื–ื›ื™ืจ ื›ื™ ื‘ืืคืจื™ืœ ื”ื™ื• ืื•ืชื ืžื—ื‘ืจื™ื ืžื–ื•ื”ื” ืฉืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-WPA3, ืฉื‘ืืžืฆืขื•ืชืŸ ืขืจื›ื” ื”-Wi-Fi Alliance, ื”ืžืคืชื—ืช ืชืงื ื™ื ืœืจืฉืชื•ืช ืืœื—ื•ื˜ื™ื•ืช, ืฉื™ื ื•ื™ื™ื ื‘ื”ืžืœืฆื•ืช ืœื”ื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ื ืžืื•ื‘ื˜ื—ื™ื ืฉืœ WPA3, ืฉื“ืจืฉื• ืฉื™ืžื•ืฉ ื‘ืขืงื•ืžื•ืช ืืœื™ืคื˜ื™ื•ืช ืžืื•ื‘ื˜ื—ื•ืช. ื‘ืจื™ื™ื ืคื•ืœ, ื‘ืžืงื•ื ื”ืขืงื•ืžื•ืช ื”ืืœื™ืคื˜ื™ื•ืช ื”ืชืงืคื•ืช ื‘ืขื‘ืจ P-521 ื•-P-256.

ืขื ื–ืืช, ื”ื ื™ืชื•ื— ื”ืจืื” ื›ื™ ื”ืฉื™ืžื•ืฉ ื‘-Brainpool ืžื•ื‘ื™ืœ ืœืกื•ื’ ื—ื“ืฉ ืฉืœ ื“ืœื™ืคื•ืช ืขืจื•ืฅ ืฆื“ื“ื™ ื‘ืืœื’ื•ืจื™ืชื ื”ืžืฉื ื•ืžืชืŸ ืขืœ ื”ื—ื™ื‘ื•ืจ ื”ืžืฉืžืฉ ื‘-WPA3 ืฉืคื™ืจ, ืžืชืŸ ื”ื’ื ื” ืžืคื ื™ ื ื™ื—ื•ืฉ ืกื™ืกืžื” ื‘ืžืฆื‘ ืœื ืžืงื•ื•ืŸ. ื”ื‘ืขื™ื” ืฉื–ื•ื”ืชื” ืžื•ื›ื™ื—ื” ืฉื™ืฆื™ืจืช ื™ื™ืฉื•ืžื™ื ืฉืœ Dragonfly ื•-WPA3 ืœืœื ื“ืœื™ืคื•ืช ื ืชื•ื ื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ื”ื™ื ืงืฉื” ื‘ื™ื•ืชืจ, ื•ืžืจืื” ื’ื ืืช ื”ื›ื™ืฉืœื•ืŸ ืฉืœ ื”ืžื•ื“ืœ ืฉืœ ืคื™ืชื•ื— ืชืงื ื™ื ื‘ื“ืœืชื™ื™ื ืกื’ื•ืจื•ืช ืœืœื ื“ื™ื•ืŸ ืฆื™ื‘ื•ืจื™ ื‘ืฉื™ื˜ื•ืช ื”ืžื•ืฆืขื•ืช ื•ื‘ื™ืงื•ืจืช ืขืœ ื™ื“ื™ ื”ืงื”ื™ืœื”.

ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืขืงื•ืžื” ื”ืืœื™ืคื˜ื™ืช ืฉืœ Brainpool, Dragonfly ืžืงื•ื“ื“ ืกื™ืกืžื” ืขืœ ื™ื“ื™ ื‘ื™ืฆื•ืข ืžืกืคืจ ืื™ื˜ืจืฆื™ื•ืช ืžืงื“ื™ืžื•ืช ืฉืœ ื”ืกื™ืกืžื” ื›ื“ื™ ืœื—ืฉื‘ ื‘ืžื”ื™ืจื•ืช hash ืงืฆืจ ืœืคื ื™ ื”ื—ืœืช ื”ืขืงื•ืžื” ื”ืืœื™ืคื˜ื™ืช. ืขื“ ืฉื ืžืฆื hash ืงืฆืจ, ื”ืคืขื•ืœื•ืช ื”ืžื‘ื•ืฆืขื•ืช ืชืœื•ื™ื•ืช ื™ืฉื™ืจื•ืช ื‘ืกื™ืกืžืช ื”ืœืงื•ื— ื•ื‘ื›ืชื•ื‘ืช ื”-MAC ืฉืœ ื”ืœืงื•ื—. ื–ืžืŸ ื‘ื™ืฆื•ืข (ื‘ืงื•ืจืœืฆื™ื” ืœืžืกืคืจ ื”ืื™ื˜ืจืฆื™ื•ืช) ื•ืขื™ื›ื•ื‘ื™ื ื‘ื™ืŸ ืคืขื•ืœื•ืช ื‘ืžื”ืœืš ื”ืื™ื˜ืจืฆื™ื•ืช ื”ืžืงื“ื™ืžื•ืช ื ื™ืชืŸ ืœืžื“ื•ื“ ื•ืœื”ืฉืชืžืฉ ื‘ื”ื ื›ื“ื™ ืœืงื‘ื•ืข ืžืืคื™ื™ื ื™ ืกื™ืกืžื” ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ื‘ืžืฆื‘ ืœื ืžืงื•ื•ืŸ ื›ื“ื™ ืœืฉืคืจ ืืช ื‘ื—ื™ืจืช ื—ืœืงื™ ื”ืกื™ืกืžื” ื‘ืชื”ืœื™ืš ื ื™ื—ื•ืฉ ื”ืกื™ืกืžื”. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ืขืœ ื”ืžืฉืชืžืฉ ื”ืžืชื—ื‘ืจ ืœืจืฉืช ื”ืืœื—ื•ื˜ื™ืช ืœื”ื™ื•ืช ื‘ืขืœ ื’ื™ืฉื” ืœืžืขืจื›ืช.

ื‘ื ื•ืกืฃ, ื”ื—ื•ืงืจื™ื ื–ื™ื”ื• ืคื’ื™ืขื•ืช ืฉื ื™ื™ื” (CVE-2019-13456) ื”ืงืฉื•ืจื” ืœื“ืœื™ืคืช ืžื™ื“ืข ื‘ื™ื™ืฉื•ื ื”ืคืจื•ื˜ื•ืงื•ืœ EAP-pwd, ื‘ืืžืฆืขื•ืช ืืœื’ื•ืจื™ืชื Dragonfly. ื”ื‘ืขื™ื” ื”ื™ื ืกืคืฆื™ืคื™ืช ืœืฉืจืช FreeRADIUS RADIUS ื•ื‘ื”ืชื‘ืกืก ืขืœ ื“ืœื™ืคืช ืžื™ื“ืข ื“ืจืš ืขืจื•ืฆื™ ืฆื“ ืฉืœื™ืฉื™, ื‘ื“ื™ื•ืง ื›ืžื• ื”ืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื”, ื”ื™ื ื™ื›ื•ืœื” ืœืคืฉื˜ ืžืฉืžืขื•ืชื™ืช ืืช ื ื™ื—ื•ืฉ ื”ืกื™ืกืžื”.

ื‘ืฉื™ืœื•ื‘ ืขื ืฉื™ื˜ื” ืžืฉื•ืคืจืช ืœืกื™ื ื•ืŸ ืจืขืฉื™ื ื‘ืชื”ืœื™ืš ืžื“ื™ื“ืช ื”ื”ืฉื”ื™ื”, ืžืกืคื™ืงื•ืช 75 ืžื“ื™ื“ื•ืช ืœื›ืœ ื›ืชื•ื‘ืช MAC ื›ื“ื™ ืœืงื‘ื•ืข ืืช ืžืกืคืจ ื”ืื™ื˜ืจืฆื™ื•ืช. ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-GPU, ืขืœื•ืช ื”ืžืฉืื‘ ืขื‘ื•ืจ ื ื™ื—ื•ืฉ ืกื™ืกืžืช ืžื™ืœื•ืŸ ืื—ืช ื ืืžื“ืช ื‘-$1. ืฉื™ื˜ื•ืช ืœืฉื™ืคื•ืจ ืื‘ื˜ื—ืช ื”ืคืจื•ื˜ื•ืงื•ืœ ืœื—ืกื™ืžืช ื‘ืขื™ื•ืช ืฉื–ื•ื”ื• ื›ื‘ืจ ื›ืœื•ืœื•ืช ื‘ื’ืจืกืื•ืช ื˜ื™ื•ื˜ื•ืช ืฉืœ ืชืงื ื™ Wi-Fi ืขืชื™ื“ื™ื™ื (WPA3.1) ื• EAP-pwd. ืœืžืจื‘ื” ื”ืฆืขืจ, ืœื ื ื™ืชืŸ ื™ื”ื™ื” ืœื—ืกืœ ื“ืœื™ืคื•ืช ื“ืจืš ืขืจื•ืฆื™ ืฆื“ ืฉืœื™ืฉื™ ืžื‘ืœื™ ืœืฉื‘ื•ืจ ืืช ื”ืชืื™ืžื•ืช ืœืื—ื•ืจ ื‘ื’ืจืกืื•ืช ื”ืคืจื•ื˜ื•ืงื•ืœ ื”ื ื•ื›ื—ื™ื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”