Wi-Fi Vulnerability Leads to FragAttacks Attacks
Belgian security researcher Mathy Vanhoef found 12 critical security flaws, which attackers exploited to perform a fragmentation and aggregation attack known as FragAttacks.
Among the errors raised, there are errors that stem from wifi standards dating back to 1997, the rest are common programming errors. Tests show that every wifi product today is affected by at least one vulnerability.
FragAttacks are said to be particularly dangerous because they can allow attackers to gather information about the owner of a Wi-Fi enabled device and run malicious code to compromise the device even with security protocols enabled. WEP or WPA. However, attackers are required to be within range of the device because the FragAttacks attack mechanism cannot be performed remotely.
This is not the first time Vanhoef has found vulnerabilities in wifi devices, he has previously discovered 2 vulnerabilities KRACK and Dragonblood. These two vulnerabilities were reported to the wifi Alliance, which then worked with wifi providers to update these bugs.
Microsoft released updates to patch 3 out of 12 security flaws in March 2021. Several major technology companies such as Cisco Systems, HPE/Aruba Networks, Juniper Networks or Sierra Wireless have published security updates and advice on FragAttacks.
To protect you from FragAttacks, the Wifi Alliance recommends that users of Wi-Fi enabled devices install the latest recommended updates from device manufacturers. Doing this enables suspicious traffic to be detected or improves compliance with recommended security implementations.
You should read it
- What is 51% attack? How does 51% attack work?
- What is a Replay Attack?
- What is Volumetric DDoS Attack?
- What is SS7 attack? What can hackers use it for?
- Analysis of an attack (Part 3)
- What is BlueSmack attack?
- Warning the emergence of ransomware DDoS attack, the scale can be up to 800Gbps
- What is Teardrop attack?
May be interested
- Detected critical zero-day vulnerability on Adobe Readeradobe has just released the may security update to patch security holes in 12 of their products. among them is a serious zero-day vulnerability in adobe reader that is being actively exploited by hackers.
- All Wifi Devices Can Be Attacked by FragAttacks Vulnerabilitiesnew york university security researcher mathy vanhoef discovered fragattacks - a collection of wifi security vulnerabilities. fragattacks is affecting all wifi devices such as computers, smartphones and smart devices since 1997.
- Kaspersky discovered many fraudulent websites that took advantage of the Covid-19 vaccinescammers are constantly looking for methods to steal user data. they actively spread spam and fraudulent sites related to the covid-19 pandemic to profit from outstanding news.
- Warning: Panda Stealer malware is stealing your cryptocurrencya new malware called panda stealer is spreading across the web. panda stealer can steal cryptocurrencies, including dash, bytecoin, litecoin, and ethereum.
- The XcodeGhost malware spread to millions of iPhonesthe information revealed around the legal confrontation between epic games and apple surprised many iphone users.
- Belgium suffered an unprecedented DDoS attackbelgium, a country in the european union (eu), has suffered an unprecedented distributed denial of service (ddos) campaign.