KRACK

KRACK
KRACK attack logo
CVE identifier(s)CVE-2017-13077,

CVE-2017-13078,
CVE-2017-13079,
CVE-2017-13080,
CVE-2017-13081,
CVE-2017-13082,
CVE-2017-13084,
CVE-2017-13086,
CVE-2017-13087,

CVE-2017-13088
Date discovered2016; 8 years ago (2016)
DiscovererMathy Vanhoef and Frank Piessens
Affected hardwareAll devices that use Wi-Fi Protected Access (WPA)
Affected softwareAll operating systems that use WPA

KRACK ("Key Reinstallation Attack") is a replay attack (a type of exploitable flaw) on the Wi-Fi Protected Access protocol that secures Wi-Fi connections. It was discovered in 2016[1] by the Belgian researchers Mathy Vanhoef and Frank Piessens of the University of Leuven.[2] Vanhoef's research group published details of the attack in October 2017.[3] By repeatedly resetting the nonce transmitted in the third step of the WPA2 handshake, an attacker can gradually match encrypted packets seen before and learn the full keychain used to encrypt the traffic.

The weakness is exhibited in the Wi-Fi standard itself, and not due to errors in the implementation of a sound standard by individual products or implementations. Therefore, any correct implementation of WPA2 is likely to be vulnerable.[4] The vulnerability affects all major software platforms, including Microsoft Windows, macOS, iOS, Android, Linux, OpenBSD and others.[3]

The widely used open-source implementation wpa_supplicant, utilized by Linux and Android, was especially susceptible as it can be manipulated to install an all-zeros encryption key, effectively nullifying WPA2 protection in a man-in-the-middle attack.[5][6] Version 2.7 fixed this vulnerability.[7]

The security protocol protecting many Wi-Fi devices can essentially be bypassed, potentially allowing an attacker to intercept[8] sent and received data.

Details

The attack targets the four-way handshake used to establish a nonce (a kind of "shared secret") in the WPA2 protocol. The standard for WPA2 anticipates occasional Wi-Fi disconnections, and allows reconnection using the same value for the third handshake (for quick reconnection and continuity). Because the standard does not require a different key to be used in this type of reconnection, which could be needed at any time, a replay attack is possible.

An attacker can repeatedly re-send the third handshake of another device's communication to manipulate or reset the WPA2 encryption key.[9] Each reset causes data to be encrypted using the same values, so blocks with the same content can be seen and matched, working backwards to identify parts of the keychain which were used to encrypt that block of data. Repeated resets gradually expose more of the keychain until eventually the whole key is known, and the attacker can read the target's entire traffic on that connection.

According to US-CERT:

"US-CERT has become aware of several key management vulnerabilities in the 4-way handshake of the Wi-Fi Protected Access II (WPA2) security protocol. The impact of exploiting these vulnerabilities includes decryption, packet replay, TCP connection hijacking, HTTP content injection, and others. Note that as protocol-level issues, most or all correct implementations of the standard will be affected. The CERT/CC and the reporting researcher KU Leuven, will be publicly disclosing these vulnerabilities on 16 October 2017."[10]

The paper describing the vulnerability is available online,[11] and was formally presented at the ACM Conference on Computer and Communications Security on 1 November 2017.[5] US-CERT is tracking this vulnerability, listed as VU#228519, across multiple platforms.[12] The following CVE identifiers relate to the KRACK vulnerability: CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2017-13084, CVE-2017-13086, CVE-2017-13087 and CVE-2017-13088.[5]

Some WPA2 users may counter the attack by updating Wi-Fi client and access point device software, if they have devices for which vendor patches are available.[13] However, vendors may delay in offering a patch, or not provide patches at all in the case of many older devices.[13][1]

Patches

Patches are available for different devices to protect against KRACK, starting at these versions:

System Version Patched
Android Android 5.0 and later Android 2017-11-06 security patch level[14]
ChromeOS All Stable channel 62.0.3202.74[15]
iOS iOS 11 iOS 11.1 for iPhone 7, iPad Pro 9.7 inch, and later devices;[16] iOS 11.2 for all other supported devices[17]
LineageOS 14.1 (Android 7.1) and later 14.1-20171016[18]
macOS High Sierra 10.13 macOS 10.13.1[19]
macOS Sierra 10.12 Security Update 2017-001 Sierra[19]
OS X El Capitan 10.11 Security Update 2017-004 El Capitan[19]
tvOS 11 tvOS 11.1[20]
watchOS 4 watchOS 4.1[21]
Windows 7 KB4041681 or KB4041678[22]
Windows 8.1 KB4041693 or KB4041687[22]
Windows 10 KB4042895 (initial version)
KB4041689 (version 1511)
KB4041691 (version 1607)
KB4041676 (version 1703)
Windows 10 version 1709 and later have the patch included in its release[22]
Windows Server 2008 KB4042723[22]
Windows Server 2012 KB4041690 or KB4041679[22]
Windows Server 2016 KB4041691[22]
Ubuntu Linux 14.04 LTS, 16.04 LTS, 17.04 Updates as of October 2017[23]

Workarounds

In order to mitigate risk on vulnerable clients, some WPA2-enabled Wi-Fi access points have configuration options that can disable EAPOL-Key[clarification needed] frame re-transmission during key installation. Attackers cannot cause re-transmissions with a delayed frame transmission, thereby denying them access to the network, provided TDLS is not enabled.[24] One disadvantage of this method is that, with poor connectivity, key reinstallation failure may cause failure of the Wi-Fi link.

Continued vulnerability

In October 2018, reports emerged that the KRACK vulnerability was still exploitable in spite of vendor patches, through a variety of workarounds for the techniques used by vendors to close off the original attack.[25]

See also

References

  1. ^ a b Cimpanu, Catalin (16 October 2017). "New KRACK Attack Breaks WPA2 WiFi Protocol". Bleeping Computer. Retrieved 2017-10-16.
  2. ^ Gallagher, Sean (2017-10-16). "How the KRACK attack destroys nearly all Wi-Fi security". Ars Technica. Retrieved 2017-10-16.
  3. ^ a b Hern, Alex (2017-10-16). "'All Wifi Networks' Are Vulnerable to Hacking, Security Expert Discovers". The Guardian. ISSN 0261-3077. Retrieved 2017-10-16.
  4. ^ Vanhoef, Mathy (2017). "Key Reinstallation Attacks".
  5. ^ a b c Goodin, Dan (2017-10-16). "Severe flaw in WPA2 protocol leaves Wi-Fi traffic open to eavesdropping". Ars Technica. Retrieved 2017-10-16.
  6. ^ "41 percent of Android phones are vulnerable to 'devastating' Wi-Fi attack". The Verge. Retrieved 2017-10-16.
  7. ^ https://w1.fi/cgit/hostap/plain/wpa_supplicant/ChangeLog [bare URL plain text file]
  8. ^ "What the KRACK Wi-Fi vulnerability means for you and your devices". Oct 16, 2017. Archived from the original on October 16, 2017.
  9. ^ "Wi-Fi Security Flaw: Billions of devices are affected by Eavesdropping Attacks". LookGadgets. Retrieved 2020-02-27.
  10. ^ Merriman, Chris (2017-10-16). "World WiFi at Risk from KRACK". V3. Retrieved 2017-10-16.
  11. ^ Vanhoef, Mathy; Piessens, Frank (2017). "Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2" (PDF). Retrieved 2017-10-16.
  12. ^ "Vendor Information for VU#228519". www.kb.cert.org. Archived from the original on 2017-10-16. Retrieved 2017-10-16.
  13. ^ a b Wagenseil, Paul (16 October 2017). "KRACK Attack Threatens All Wi-Fi Networks: What to Do". Tom's Guide. Retrieved 17 October 2017.
  14. ^ "Android Security Bulletin – November 2017". android.com. Retrieved 2017-11-07.
  15. ^ "Stable Channel Update for Chrome OS". chromereleases.googleblog.com. Retrieved 2017-11-07.
  16. ^ "About the security content of iOS 11.1 – Apple Support". support.apple.com. Retrieved 2017-11-01.
  17. ^ "About the security content of iOS 11.2 – Apple Support". support.apple.com. Retrieved 2017-12-07.
  18. ^ The LineageOS Project (16 October 2017). "All official 14.1 builds built after this tweet have been patched for KRACK". Twitter. Retrieved 15 December 2018.
  19. ^ a b c "About the security content of macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan – Apple Support". support.apple.com. Retrieved 2017-11-01.
  20. ^ "About the security content of tvOS 11.1". Apple Support. Retrieved 2017-11-07.
  21. ^ "About the security content of watchOS 4.1". Apple Support. Retrieved 2017-11-07.
  22. ^ a b c d e f "CVE-2017-13080 Windows Wireless WPA Group Key Reinstallation Vulnerability". microsoft.com. Retrieved 2017-11-01.
  23. ^ "Has Ubuntu been patched against the KRACK attack?". Retrieved 2019-04-17.
  24. ^ "OpenWrt Project: docs:user-guide:wifi_configuration". openwrt.org.
  25. ^ Chirgwin, Richard (5 October 2018). "Man the harpoons: The KRACK-en reawakens in updated WPA2 attack". The Register. Retrieved 2018-10-05.

Read other articles:

Kesenian tradisional suku Jawa Sintren atau Lais[1][2][3]) adalah kesenian tari tradisional masyarakat suku Jawa. Kesenian ini terkenal di pesisir utara Jawa Barat seperti Indramayu, Cirebon, Subang utara, Majalengka, dan bagian barat Jawa Tengah, antara lain di Jatibarang, Brebes, Pemalang, Tegal. Kesenian Sintren dikenal sebagai tarian dengan aroma mistis/magis yang bersumber dari cerita cinta kasih Sulasih dengan Sulandono. Toponim Kata sintrèn berasal dari dua suk...

 

 

Sahabat beralih ke halaman ini. Untuk sahabat dalam konteks sejarah Islam, lihat Sahabat Nabi. Bagian dari seri tentangCintaRed-outline heart icon Jenis-jenis cinta Afeksi Ikatan Patah hati Cinta yang penuh kasih Cinta konjugal Cinta bahaduri Pacaran Troubadour Jatuh cinta Persahabatan cross-sex romantis Zona pertemanan Keramahan Hubungan antar pribadi Intimasi Limerence Kecanduan cinta Cinta pada pandangan pertama Cinta segitiga Penyakit cinta Lovestruck Cinta obsesif Passion Cinta platonik ...

 

 

The HonorableHenry Puna Sekretaris-Jenderal Forum Kepulauan PasifikPetahanaMulai menjabat 4 Februari 2021 PendahuluMeg TaylorPenggantiPetahanaPerdana Menteri Kepulauan CookMasa jabatan30 November 2010 – 1 Oktober 2020Penguasa monarkiElizabeth IIWakilTeariki HeatherMark BrownPerwakilanFrederick Tutu GoodwinTom Marsters PendahuluJim MaruraiPenggantiMark Brown Kementerian Tambahan Menteri EnergiMasa jabatan3 Desember 2010 – 1 Oktober 2020 PendahuluWilliam (Smiley) Heath...

هاشم الأتاسي رئيس الجمهورية السورية الثاني في المنصب21 ديسمبر 1936 – 7 يوليو 1939 محمد علي العابد بهيج الخطيب رئيس الجمهورية السورية الثامن في المنصبديسمبر 1949 – 24 ديسمبر 1951 حسني الزعيم (انقلاب) فوزي السلو (انقلاب) رئيس الجمهورية السورية الحادي عشر في المنصب1 مارس 1954 – 6 سبتمبر 19...

 

 

Cet article est une ébauche concernant le droit français. Vous pouvez partager vos connaissances en l’améliorant (comment ?) selon les recommandations des projets correspondants. Article 64 de la Constitution du 4 octobre 1958 Données clés Présentation Pays France Langue(s) officielle(s) Français Type Article de la Constitution Adoption et entrée en vigueur Législature IIIe législature de la Quatrième République française Gouvernement Charles de Gaulle (3e) Promulgation 4...

 

 

Artikel ini adalah bagian dari seriPolitik dan ketatanegaraanIndonesia Pemerintahan pusat Hukum Pancasila(ideologi nasional) Undang-Undang Dasar Negara Republik Indonesia Tahun 1945 Hukum Perpajakan Ketetapan MPR Undang-undang Perppu Peraturan pemerintah Peraturan presiden Peraturan daerah Provinsi Kabupaten/kota Legislatif Majelis Permusyawaratan Rakyat Ketua: Bambang Soesatyo (Golkar) Dewan Perwakilan Rakyat Ketua: Puan Maharani (PDI-P) Dewan Perwakilan Daerah Ketua: La Nyalla Mattalitti (J...

Non-profit educational organization Academy of AchievementFormation1961TypeNon-profit organizationHeadquartersWashington, D.C., U.S.Chairman & CEOWayne R. ReynoldsVice ChairmanCatherine B. ReynoldsWebsitewww.achievement.org The American Academy of Achievement, colloquially known as the Academy of Achievement, is a nonprofit educational organization that recognizes some of the highest-achieving people in diverse fields[1] and gives them the opportunity to meet one another.[2 ...

 

 

اللغة المقدونية الاسم الذاتي (بالمقدونية: македонски јазик)‏(بالمقدونية: македонски‎)‏    الناطقون 2000000   الكتابة أبجدية مقدونية،  وألفبائية كيريلية  النسب لغات هندية أوروبية لغات هندية أوروبيةلغات بلطيقية سلافيةلغات سلافيةلغات سلافية جنوبيةالمقدونية أيز�...

 

 

LGBT rights in CuraçaoCuraçaoStatusLegalMilitaryYesDiscrimination protectionsDiscrimination based on heterosexual or homosexual orientation prohibitedFamily rightsRecognition of relationshipsSame-sex marriages performed in the Netherlands recognizedAdoptionNo Lesbian, gay, bisexual, and transgender (LGBT) people in Curaçao may face legal challenges not experienced by non-LGBT residents. Both male and female same-sex sexual activity are legal in Curaçao. Discrimination on the basis of het...

Запрос «₰» перенаправляется сюда; о денежной единице см. Пфенниг. О других символах со сходным назначением см. Символ денария. Символ пфеннига ₰ Изображение ◄ € ₭ ₮ ₯ ₰ ₱ ₲ ₳ ₴ ► Характеристики Название german penny sign Юникод U+20B0 HTML-код ₰ или &#x20...

 

 

Cet article est une ébauche concernant une localité de la communauté de Madrid. Vous pouvez partager vos connaissances en l’améliorant (comment ?) selon les recommandations des projets correspondants. Valdemoro Héraldique Église Notre-Dame de l'Assomption de Valdemoro. Administration Pays Espagne Communauté autonome Madrid Maire Mandat David Conde (PP) 2023-2027 Code postal 28340–28343 Démographie Population 81 394 hab. (2023) Densité 1 268 hab./km2 Géo...

 

 

Artikel ini sebatang kara, artinya tidak ada artikel lain yang memiliki pranala balik ke halaman ini.Bantulah menambah pranala ke artikel ini dari artikel yang berhubungan atau coba peralatan pencari pranala.Tag ini diberikan pada November 2022. Art of the Devil 2 (Long Khong)Salah satu dari lima poster film Thai.SutradaraPasith Buranajan Kongkiat Khomsiri Isara NadeeSeree PhongnithiYosapong PolsapPutipong SaisikaewArt ThamthrakulProduserCharoen IamphungpornDitulis olehKongkiat KhomsiriYosapo...

17th-century play by Thomas Middleton The Witch is a Jacobean play, a tragicomedy written by Thomas Middleton. The play was acted by the King's Men at the Blackfriars Theatre. It is thought to have been written between 1613 and 1616;[1][2] it was not printed in its own era, and existed only in manuscript until it was published by Isaac Reed in 1778. The manuscript The still-extant manuscript (since 1821, MS. Malone 12 in the collection of the Bodleian Library), a small quarto-...

 

 

Hurricane season in the Pacific Ocean 1958 Pacific hurricane seasonSeason summary mapSeasonal boundariesFirst system formedJune 6, 1958Last system dissipatedOctober 30, 1958Strongest stormNameEleven • Maximum winds85 mph (140 km/h)(1-minute sustained) • Lowest pressure960 mbar (hPa; 28.35 inHg) Seasonal statisticsTotal depressions14Total storms14Hurricanes6Major hurricanes(Cat. 3+)0Total fatalitiesUnknownTotal damageUnknownRelated articles 1958 Atlantic hurricane seaso...

 

 

12th season in existence of Liverpool F.C. Liverpool 2016–17 football seasonLiverpool2016–17 seasonLiverpool players before Manchester United away, 15 January 2017ChairmanTom WernerManagerJürgen KloppStadiumAnfieldPremier League4thFA CupFourth roundEFL CupSemi-finalsTop goalscorerLeague: Philippe CoutinhoSadio Mané(13 each)All: Philippe Coutinho (14) Home colours Away colours Third colours ← 2015–162017–18 → The 2016–17 season was Liverpool Football Club's 12...

This article possibly contains original research. Please improve it by verifying the claims made and adding inline citations. Statements consisting only of original research should be removed. (October 2015) (Learn how and when to remove this message) This article may be in need of reorganization to comply with Wikipedia's layout guidelines. Please help by editing the article to make improvements to the overall structure. (March 2024) (Learn how and when to remove this message) Shortly after...

 

 

Tramlink tram stop in London, England Lebanon RoadLebanon Road tram stop; westbound platform looking eastGeneral informationLocationAddiscombe RoadCroydonUnited KingdomOperated byTramlinkPlatforms2ConstructionAccessibleYesOther informationFare zoneLondon fare zones 3, 4, 5 and 6HistoryOpened10 May 2000; 24 years ago (2000-05-10)Passengers2009–100.537 million total boardings and alightings[1]2010–110.630 million total boardings and alightings[2] ...

 

 

SMA Negeri 3 PandeglangInformasiJenisNegeriAkreditasiAKepala SekolahEdi Supriyanto, M.PdJumlah kelas36 kelasJurusan atau peminatanIPA dan IPSRentang kelasX IPA, X IPS, XI IPA, XI IPS , XII IPA, XII IPSKurikulumKurikulum Tingkat Satuan PendidikanJumlah siswasiswa (2021/2022)Kelas X = 420 pelajar Kelas XI = 420 pelajar Kelas XII = 420 pelajarStatusNegeriAlamatLokasiJalan Perintis Kemerdekaan KM 2, Caringin, Labuan, Pandeglang, Banten, IndonesiaTel./Faks.0253 -Lain-lainLulusanOran...

GalgeninselThe Galgeninsel. Foreground: the bridge in Lindau. Antoni Remm, 1579GeographyCoordinates47°33′00″N 9°42′14″E / 47.55000°N 9.70389°E / 47.55000; 9.70389Adjacent toBay of Reutin, Obersee, BodenseeArea0.0016 km2 (0.00062 sq mi)Length0.066 km (0.041 mi)Width0.046 km (0.0286 mi)AdministrationGermany 1836 map showing the Galgeninsel still clearly as an island The Galgeninsel is a peninsula on the shore of Lake Constan...

 

 

Neighborhood in Honolulu, Hawaii, United States Neighborhood in Honolulu, Hawaii, United StatesPāloloNeighborhoodWelcome sign in PāloloPāloloLocation in Hawaii, United States & Pacific OceanShow map of HawaiiPāloloPālolo (Pacific Ocean)Show map of Pacific OceanCoordinates: 21°17′44.8″N 157°47′48.4″W / 21.295778°N 157.796778°W / 21.295778; -157.796778Country United StatesState HawaiiCounty HonoluluCity HonoluluGovernment • Mayo...