5 ms·
A man-in-the-middle attack is what can happen here. Deauth and then the device tries to reauth. At that point, the attacker can pose as the router and collect t
by cwingrav 7y ago
A man-in-the-middle attack is what can happen here. Deauth and then the device tries to reauth. At that point, the attacker can pose as the router and collect the password hash. The WiFi spec has serious problems.
- Someone1234 7y agoWiFi doesn't work the way you're claiming. You can use Deauth to be obnoxious/DoS but MITM could be accomplished without Deauth (via higher signal strength + cloned SSID) and WiFi Auth doesn't involve sending a "password hash" over the air that can be "collected." WiFi is protected via PSK (pre-shared [encryption] key), public cryptography (via CA generated key-pairs), or RADIUS. With RADIUS auth you may be able to harvest the username but the password is used as a PSK which is a shared secret between the client and RADIUS server. This is a two way check (i.e. the client confirms the RADIUS backed WiFi AP has the password too). After they both confirm each other has the password, a different encryption key is used. There's no WiFi Auth protocol that I know of that involves sending a password over the air (hashed or otherwise).
- zamadatix 7y agoAbsolutely false, the PTK is sent over the air and is constructed from a hash of the PMK, client/ap MAC, and client/AP Nonce. The attack the parent comment is describing is exactly why WPA3 was made with SAE. One need only capture 2 packets of the initial handshake to start offline cracking by comparing MICs and then you can decrypt the entire conversation since there was no perfect forward secrecy in WPA2 and older. Also what you describe with RADIUS is incorrect as well but there are too many ways to configure 802.1x and RADIUS to cover all of why in a comment. Overall it is considered safer than WPA2 though so the conclusion is sound.
- Someone1234 7y ago> Absolutely false Let's first off go back to what I was replying to: > At that point, the attacker can pose as the router and collect the password hash. By claiming my correction is "absolutely false" you're asserting that the above statement is "absolutely true." But even your technically unsound correction doesn't actually address the underlying inaccuracy of the original statement or why you seemingly believe it is "absolutely true." It is also pretty clear from your reply that you're attempting to muddy the waters by conflating the PTK with the PSK or any other "password." The PTK isn't a password. It isn't like a password, and in order to derive it you need additional information which you need to attack (which is easier than attacking the PSK itself, thus WPA3's improvements, but doesn't make the above statement technically sound or true). Your post reads like you decided to correct before having any corrections to actually make then tried to muddy the topic as much as possible in the hope that others would be fooled. Plus is "collect the password hash" really a hill worth dying on for WiFi Auth? That's obviously an unsound technical claim, that isn't how the protocol works at all (and you seemingly must know that given your knowledge). > Also what you describe with RADIUS is incorrect as well but there are too many ways to configure 802.1x and RADIUS to cover all of why in a comment. So it is "incorrect" because I simplified it rather than describing the process in intricate technical detail? And you won't point out why it was "incorrect" because it is too technically difficult..? K.
- zamadatix 7y ago> > At that point, the attacker can pose as the router and collect the password hash. > By claiming my correction is "absolutely false" you're asserting that the above statement is "absolutely true." Correct. > technically unsound correction Please explain how. > It is also pretty clear from your reply that you're attempting to muddy the waters by conflating the PTK with the PSK or any other "password." The PMK is part of the PTK hash. When using a PSK the PSK = the PMK. Not much to conflate, the PTK is a hash of the password with other variables. Exactly as I explained. > in order to derive it you need additional information which you need to attack I already explained how the rest of the information needed to derive the PTK is sent in the handshake frames. > Your post reads like... Please stick to talking about WiFi authentication. > Plus is "collect the password hash" really a hill worth dying on for WiFi Auth? Prior to WPA3, yes - as explained already. > So it is "incorrect" because I simplified it rather than describing the process in intricate technical detail? It was incorrect because the password isn't used as a PSK so cracking the PTK gets you a nonce instead of the user password. > And you won't point out why it was "incorrect" because it is too technically difficult..? Given we are still trying to agree how the 4 way handshake works and what parts get hashed in it, yes - it is. . https://www.wifi-professionals.com/2019/01/4-way-handshake https://www.wifi-professionals.com/2019/01/4-way-handshake https://security.stackexchange.com/questions/66008/how-exactly-does-4-way-handshake-cracking-work https://security.stackexchange.com/questions/66008/how-exact... https://www.aircrack-ng.org/doku.php?id=cracking_wpa https://www.aircrack-ng.org/doku.php?id=cracking_wpa
- cwingrav 7y agoI think you’re wrong on this. In the WPA handshake, you sniff the hashed password. You start this by first deauthing them off the network. See https://en.m.wikipedia.org/wiki/Wi-Fi_deauthentication_attack https://en.m.wikipedia.org/wiki/Wi-Fi_deauthentication_attac....
- oefrha 7y agoI’m not asking for an explanation of what the problem is (and your explanation is wrong), I’m asking about why WiFi spec is designed with this very specific, seemingly obvious flaw (anyone can fake deauth to DoS anyone else). I doubt this wasn’t considered during the design process, and I don’t think the rationale is “screw you”, so there’s gotta be a reason. Edit: According to other comments, it seems that “spoofed” deauth does have legit use cases (other than DoS’ing neighbor’s internet of shit devices).
- zamadatix 7y agoThe "legit" use cases people found for it were unlikely to be the reason the protocol was designed that way. Remember 802.11 came out in 1997. In 2004 WPA2 was released and allowed for protected management frames but no devices/users cared enough at the time. Now in 2019 users are more security aware and encryption is cheap so WPA3 requires it.