WPA3-PersonalÐÒé DragonbloodÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-04-11Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-9494£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
WPA3-PersonalÐÒé
Îó²î¸ÅÊö
ÔÚ4ÔÂ10ÈÕ½ÒÏþµÄһƪÂÛÎÄÖУ¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷WPA3-PersonalÐÒé±£´æÐÂÎó²îDragonblood£¬ÕâЩÎó²î¿ÉÔÊÐíDZÔÚ¹¥»÷ÕßÆÆ½âWi-FiÃÜÂë²¢ÇÔÈ¡¼ÓÃÜÁ÷Á¿¡£
WPA3 ʹÓà WiFi DPP ¶ø·Ç¹²ÏíÃÜÂ뽫װ±¸¹ÒºÅµ½ÍøÂ磬¸ÃÐÒéÔÊÐíÓû§É¨ÃèQRÂë»ò NFC ±ê¼Ç½«×°±¸µÇ¼µ½ÎÞÏßÍøÂç¡£ÁíÍ⣬²î±ðÓÚ WPA2£¬ËùÓÐÍøÂçÁ÷Á¿¶¼»áÔÚÅþÁ¬µ½Ê¹Óà WPA3 WiFi Security µÄÍøÂçºó±»¼ÓÃÜ¡£
ËäÈ» WPA3СÎÒ˽¼Ò°æÖ¼ÔÚÈ¡´úÇå¾²ÐԽϲîµÄÒѱ£´æ14ÄêÖ®¾ÃµÄ WPA2£¬µ«ËüµÄ SAE ÎÕÊÖ£¨»ò±»³ÆÎªDragonfly£©ËƺõÊÜ´ó×ڵײãÉè¼ÆÈ±ÏݵÄÓ°Ï죬µ¼ÖÂÓû§Ò×ÊÜÃÜÂëͶ¶¾¹¥»÷¡£
ÓÉÓÚ¡°DragonflyÎÕÊÖ¡±ÓÉ WiFi ÍøÂçʹÓã¬ÒªÇó¾ß±¸»á¼û¿ØÖƵÄÓû§ÃûºÍÃÜÂ룬Ëü»¹±» EAP-pwd ÐÒéËùÓã¬Òò´Ë EAP-pwd Ò²¿ÉÄÜÊÜÕâЩÎó²îÓ°Ïì¡£
ÔÚÂÛÎÄÖÐÑо¿Ö°Ô±ÏêϸÏÈÈÝÁËWPA3µÄÁ½ÖÖÉè¼ÆÈ±ÏÝ£ºÒ»ÖÖÊǽµ¼¶¹¥»÷£¬Ò»ÖÖÊDzàÐŵÀй¶¡£Ê×ÏÈWPA3Ìṩ¹ý¶ÉģʽÒÔÖ§³Ö¾É×°±¸£¬µ«¹¥»÷Õß¿ÉÒÔÀÄÓÃÕâЩÉèÖÃÀ´ÆÈʹWPA3×°±¸Ê¹Óò»Çå¾²µÄWPA2µÄ4´ÎÎÕÊÖ£¬²¢ÇÒÕâÖÖ½µ¼¶¹¥»÷Ö»ÐèÒªÖªµÀWPA3ÍøÂçµÄSSID¡£Æä´ÎÑо¿Ö°Ô±ÏÈÈÝÁËÁ½ÖÖ²àÐŵÀ¹¥»÷-»ùÓÚ»º´æºÍ»ùÓÚʱÐò£¬¿ÉÓÃÓÚ»ñÈ¡Wi-FiÃÜÂëºÍÇÔÈ¡¼ÓÃÜ´«ÊäµÄÃô¸ÐÐÅÏ¢¡£
Îó²îÑéÖ¤
Dragonslayer£ºÊµÏÖÕë¶Ô EAP-pwd ÐÒéµÄ¹¥»÷£ºhttps://github.com/vanhoefm/dragonslayer¡£
Dragondrain£º¸Ã¹¤¾ß¿É±»ÓÃÓÚ²âÊÔ»á¼ûµãÊÜ WPA3 SAE ÎÕÊ־ܾø·þÎñ¹¥»÷Ó°ÏìµÄˮƽ£ºhttps://github.com/vanhoefm/dragondrain¡£
Dragontime£ºËüÊÇÒ»ÖÖʵÑ鹤¾ß£¬ÓÃÓÚÕë¶Ô SAE ÎÕÊÖ·¢¶¯×¼Ê±¹¥»÷£¬Ìõ¼þÊÇʹÓÃÁË MODP ×é22¡¢23»ò24¡£ÐèÒª×¢ÖØµÄÊÇ£¬´ó¶¼WPA3ʵÏÖĬÈϲ¢Î´ÆôÓÃÕâЩ×飺https://github.com/vanhoefm/dragontime¡£
Dragonforce£ºËüÊÇÒ»¿îʵÑ鹤¾ß£¬ÓÃÓÚ´Ó׼ʱ¹¥»÷»ò»ùÓÚ»º´æµÄ¹¥»÷Öлָ´ÐÅÏ¢£¬²¢Ö´ÐÐÃÜÂëͶ¶¾¹¥»÷¡£ËüÀàËÆÓÚ×ֵ乥»÷£ºhttps://github.com/vanhoefm/dragonforce¡£
ÐÞ¸´½¨Òé
Wi-FiͬÃËÈ·ÈϳÆÕýÔÚÓ빩ӦÉÌÏàÖúÐÞ²¹ÏÖÓеÄWPA3ÈÏ֤װ±¸£ºhttps://www.wi-fi.org/security-update-april-2019
²Î¿¼Á´½Ó
https://wpa3.mathyvanhoef.com/
https://thehackernews.com/2019/04/wpa3-hack-wifi-password.html


¾©¹«Íø°²±¸11010802024551ºÅ