3 ms·
> If Radius is being used, there's no way to successfully impersonate the AP and have the victim accidentally try to join it because the AP won't be able to au
by GenericsMotors 9y ago
> If Radius is being used, there's no way to successfully impersonate the AP and have the victim accidentally try to join it because the AP won't be able to authenticate the WPA2-Enterprise credentials?
From what I understand the credentials won't matter. Anyone else more knowledgeable please correct me if I'm wrong, but the attack goes something like this:
1. Capture trafic that includes the 4-way handshake
2. replay message #3 of the handshake
3. client's encryption key is set to zero (in the case of wpa_supplicant), and nonce/IV are reused going forward
4. you are now in control of the encryption key being used (again, only wpa_supplicant) so you can go ahead and MITM the victim's DNS queries, capture cookies, etc...
The Details section of the researcher's site explains it pretty well:
https://www.krackattacks.com/#details https://www.krackattacks.com/#details
Lastly, the most urgent task for mitigating this is to patch client devices as quickly as possible.
Android's fractured vendor-specific distributions and lack of long-term support for the low-mid level models is going to make this a difficult/impossible task...
- PakG1 9y agoThanks, it's right there in the text, clear as day. :) Note that our attacks do not recover the password of the Wi-Fi network. They also do not recover (any parts of) the fresh encryption key that is negotiated during the 4-way handshake.