Code Monkey home page Code Monkey logo

krackattacks's Introduction

This is the repository of the website at krackattacks.com

Feel free to submit pull requests to fix spellings mistakes or suggest new Q&A entries.

krackattacks's People

Contributors

corralpeltzer avatar dubby85 avatar jamiebuilds avatar jasondavies avatar kristate avatar mpitt avatar nulldev avatar stuntguy3000 avatar valentijnscholten avatar vanderdecken avatar vanhoefm avatar voxadam avatar womaniak avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

krackattacks's Issues

Authorization by cert

Hi all.
What are you thinking about authorization by certificate? (WPA2-Ent + cert sign-on)
Are this solve this issue or not?

Applicability / Mitigation Matrix Request

First, thank you for your contributions to information security.

Many organizations are trying to understand how to fully mitigate this vulnerability. It is very clear that there is an inherent issue with the 4-way handshake as defined in the standard. However, it is unclear how this can be effectively mitigated. Obviously, patching ALL supplicants and authenticators will address the issue. But, it would be very helpful to understand where organizations can focus their efforts for best risk reduction.

From the paper, it appears that the wireless controllers can effectively prevent the client from using old replay counter. But, it is not clear (for those of us less familiar with the nuances of this technology) to understand exactly what is vulnerable and where the issue can be mitigated.

I think something like the below table would provide an incredible value to organizations (IT/Security Teams), helping us understand the risk and prioritize efforts. The table is meant to answer the question: "Which CVEs require me to patch just my authenticators to protect my network? Which ones require both?"

Some example values are filled in for each CVE to show what I was thinking.

CVE Vulnerable Component Patch Needed
CVE-2017-13077 Both Supplicant
CVE-2017-13078 Supplicant Either
CVE-2017-13079 Authenticator Both
CVE-2017-13080
CVE-2017-13081
CVE-2017-13082
CVE-2017-13084
CVE-2017-13086
CVE-2017-13087
CVE-2017-13088

unable to use hostapd

[09:07:03] Failed to get MAC address of wlan0. Specify an existing interface in hostapd.conf at the line "interface=NAME".
Traceback (most recent call last):
File "./krack-test-client.py", line 615, in
attack = KRAckAttackClient()
File "./krack-test-client.py", line 349, in init
self.apmac = scapy.arch.get_if_hwaddr(interface)
File "/usr/lib/python2.7/dist-packages/scapy/arch/init.py", line 51, in get_if_hwaddr
addrfamily, mac = get_if_raw_hwaddr(iff)
File "/usr/lib/python2.7/dist-packages/scapy/arch/linux.py", line 95, in get_if_raw_hwaddr
return struct.unpack("16xh6s8x",get_if(iff,SIOCGIFHWADDR))
File "/usr/lib/python2.7/dist-packages/scapy/arch/common.py", line 19, in get_if
ifreq = ioctl(sck, cmd, struct.pack("16s16x", iff))
IOError: [Errno 19] No such device

This is the error that i am getting when i change the interface name in hostapd.conf. Can u suggest me a solution for this error??

Wifi

According to the video, attacking device must also be logged first on the wifi network, and the target also.
Re-routing packets is very old trick
https://lirias.kuleuven.be/bitstream/123456789/547640/1/usenix2016-wifi.pdf

Also from 2016 -- Nonce-Disrespecting Adversaries: Practical
Forgery Attacks on GCM in TLS
https://eprint.iacr.org/2016/475.pdf

Check against Chrome Canary MITM detection
https://www.bleepingcomputer.com/news/security/google-chrome-will-soon-warn-you-of-software-that-performs-mitm-attacks/

Decryption of WEP and WAP
https://github.com/ICSec/pyDot11

Only very few devices are vulnerable.

fail krack attack

i have this problem with script:
connect exception hostapd_ctrl/wlan0 9877
please a need help for solve this.

How does this works?

Hi. I want to know how does KrackAttacks works.
I can download it and use it or is just a code?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.