WPA3-PersonalºÍ̸ Dragonblood·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-04-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9494 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


WPA3-PersonalºÍ̸


·ì϶¸ÅÊö


ÔÚ4ÔÂ10ÈÕ°ä·¢µÄһƪÂÛÎÄÖÐ £¬°²È«×êÑÐÈËÔ±·¢ÏÖWPA3-PersonalºÍ̸´æÔÚзì϶Dragonblood £¬ÕâЩ·ì϶¿ÉÔÊÐíDZÔÚ¹¥»÷ÕßÆÆ½âWi-FiÃÜÂë²¢ÇÔÈ¡¼ÓÃÜÁ÷Á¿ ¡£


WPA3 ʹÓà WiFi DPP ¶ø·Ç¹²ÏíÃÜÂ뽫É豸µÇ¼Çµ½ÍøÂç £¬¸ÃºÍ̸ÔÊÐíÓû§É¨ÃèQRÂë»ò NFC ÏóÕ÷½«É豸µÇ¼µ½ÎÞÏßÍøÂç ¡£Áí±í £¬·ÖÆçÓÚ WPA2 £¬ËùÓÐÍøÂçÁ÷Á¿³ÇÊÐÔÚÏνӵ½Ê¹Óà WPA3 WiFi Security µÄÍøÂçºó±»¼ÓÃÜ ¡£


WPA3Ó×ÎÒ°æºÍ̸ͨ¹ý SAE È¡´úÁË WPA2Ó×ÎÒ°æÖеÄÔ¤¹²ÏíÃÜÔ¿ (PSK) £¬ÒÔÌṩԽ·¢×³ÊµµÄ»ùÓÚÃÜÂëµÄÈÏÖ¤ ¡£

¹ÌÈ» WPA3Ó×ÎÒ°æÖ¼ÔÚÈ¡´ú°²È«ÐԽϲîµÄÒÑ´æÔÚ14ÄêÖ®¾ÃµÄ WPA2 £¬µ«ËüµÄ SAE ÎÕÊÖ£¨»ò±»³ÆÎªDragonfly£©ËƺõÊÜ´óÁ¿µ×²ãÉè¼ÆÈ±µãµÄÓ°Ïì £¬µ¼ÖÂÓû§Ò×ÊÜÃÜÂëͶ¶¾¹¥»÷ ¡£


ÓÉÓÚ¡°DragonflyÎÕÊÖ¡±ÓÉ WiFi ÍøÂçʹÓà £¬ÒªÇó¾ß±¸½Ó¼û½ÚÔìµÄÓû§ÃûºÍÃÜÂë £¬Ëü»¹±» EAP-pwd ºÍ̸ËùÓà £¬Òò¶ø EAP-pwd Ò²¿ÉÄÜÊÜÕâЩ·ì϶ӰÏì ¡£


ÔÚÂÛÎÄÖÐ×êÑÐÈËÔ±¾ßÌå½éÉÜÁËWPA3µÄÁ½ÖÖÉè¼ÆÈ±µã£ºÒ»ÖÖÊǽµ¼¶¹¥»÷ £¬Ò»ÖÖÊDzàÐÅ·й¶ ¡£Ê×ÏÈWPA3Ìṩ¹ý¶ÉģʽÒÔÖ§³Ö¾ÉÉ豸 £¬µ«¹¥»÷ÕßÄܹ»ÀÄÓÃÕâЩÉèÖÃÀ´ÆÈʹWPA3É豸ʹÓò»°²È«µÄWPA2µÄ4´ÎÎÕÊÖ £¬²¢ÇÒÕâÖÖ½µ¼¶¹¥»÷Ö»±ØÒªÖªÂ·WPA3ÍøÂçµÄSSID ¡£Æä´Î×êÑÐÈËÔ±½éÉÜÁËÁ½ÖÖ²àÐÅ·¹¥»÷-»ùÓÚ»º´æºÍ»ùÓÚʱÐò £¬¿ÉÓÃÓÚ»ñÈ¡Wi-FiÃÜÂëºÍÇÔÈ¡¼ÓÃÜ´«ÊäµÄÃô¸ÐÐÅÏ¢ ¡£


·ì϶ÑéÖ¤


×êÑÐÈËÔ±ÔÚGitHubÉϰ䲼PoC²âÊÔ¹¤¾ß ¡£
Dragonslayer£ºÊµÏÖÕë¶Ô EAP-pwd ºÍ̸µÄ¹¥»÷£ºhttps://github.com/vanhoefm/dragonslayer ¡£
Dragondrain£º¸Ã¹¤¾ß¿É±»ÓÃÓÚ²âÊÔ½Ó¼ûµãÊÜ WPA3 SAE ÎÕÊֻؾø·þÎñ¹¥»÷Ó°ÏìµÄˮƽ£ºhttps://github.com/vanhoefm/dragondrain ¡£
Dragontime£ºËüÊÇÒ»ÖÖ³¢ÊÔ¹¤¾ß £¬ÓÃÓÚÕë¶Ô SAE ÎÕÊÖ·¢Æð°´Ê±¹¥»÷ £¬Ç°ÌáÊÇʹÓÃÁË MODP ×é22¡¢23»ò24 ¡£±ØÒª°ÑÎȵÄÊÇ £¬ÎÞÊýWPA3ʵÏÖĬÈϲ¢Î´ÆôÓÃÕâЩ×飺https://github.com/vanhoefm/dragontime ¡£

Dragonforce£ºËüÊÇÒ»¿î³¢ÊÔ¹¤¾ß £¬ÓÃÓÚ´Ó°´Ê±¹¥»÷»ò»ùÓÚ»º´æµÄ¹¥»÷Öи´Ô­ÐÅÏ¢ £¬²¢Ö´ÐÐÃÜÂëͶ¶¾¹¥»÷ ¡£ËüÀàËÆÓÚ×ֵ乥»÷£ºhttps://github.com/vanhoefm/dragonforce ¡£


½¨¸´½¨Òé


Wi-FiͬÃËÈ·ÈϳÆÔÚÓ빩¸øÉ̺Ï×÷½¨²¹ÏÖÓеÄWPA3ÈÏÖ¤É豸£ºhttps://www.wi-fi.org/security-update-april-2019


²Î¿¼Á´½Ó


http://papers.mathyvanhoef.com/dragonblood.pdf
https://wpa3.mathyvanhoef.com/
https://thehackernews.com/2019/04/wpa3-hack-wifi-password.html