Table of Contents
Researcher Mathy Vanhoef from Leuven University discovered a serious security flaw on Wi-Fi Protected Access II (WPA2) network security protocol.
KRACK Attack Breaks Down the WPA2 Wi-Fi Protocol Overview
Named KRACK, short for Key Reinstallation Attack, this attack uses some key management vulnerabilities on WPA2, allowing 'eavesdropping' of traffic between the computer and Wi-Fi access point, forcing people in the Wi-Fi network to install re-encrypt key used for WPA2 traffic.
The attacker can then steal personal information and note that the hacker does not change the password but can encrypt the data without knowing the password. It means that even if you change your password, it will not prevent KRACK.
Error on Wi-Fi WPA2 security protocol helps hackers penetrate network traffic
This error is on the WPA2 protocol itself, not with any software or hardware. 'If your device has Wi-Fi support, it's probably affected too,' the researchers said. According to initial reviews, Android, Linux, Apple, Windows, OpenBSD, MediaTek, Linksys or IoT devices are all affected.
How Does KRACK WPA2 Work?
KRACK exploits WPA2's 4-step handshake protocol, which is used to set up key for encrypting traffic. In order for a hacker to succeed, the victim will need to reinstall the currently used key, obtained by modifying the handshake message to encrypt.
In addition, the attacker must also be in the above Wi-Fi network. HTTPS in some cases can protect traffic for using another encryption layer, but it is also 100% unsafe because an attacker can downgrade the connection, giving access to encrypted HTTPS traffic.
This attack allows a third party to eavesdrop on WPA2 traffic, but if Wi-Fi uses WPA-TKIP or GCMP encryption, the attacker can also inject malicious code into the victim's packet to fake traffic.
To find out more, you can read the website about this type of attack at https://www. krackattacks. com/
Below is a list of key management vulnerabilities on WPA2 protocol.
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13084 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088
See also: Microsoft silently patched the KRACK WPA2 security hole
Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.
FAQ
Why does KRACK Attack Breaks Down the WPA2 Wi-Fi Protocol matter?
Researcher Mathy Vanhoef from Leuven University discovered a serious security flaw on Wi-Fi Protected Access II (WPA2) network security protocol.
Who may be affected by this issue?
The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.
How can users reduce the risk?
Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.
Reader Comments 0
Sign in with email or Google to join the discussion.