WPA3-PersonalºÍ̸ Dragonblood·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-04-11·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-9494£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
WPA3-PersonalºÍ̸
·ì϶¸ÅÊö
ÔÚ4ÔÂ10ÈÕ°ä·¢µÄһƪÂÛÎÄÖУ¬°²È«×êÑÐÈËÔ±·¢ÏÖWPA3-PersonalºÍ̸´æÔÚзì϶Dragonblood£¬ÕâЩ·ì϶¿ÉÔÊÐíDZÔÚ¹¥»÷ÕßÆÆ½âWi-FiÃÜÂë²¢ÇÔÈ¡¼ÓÃÜÁ÷Á¿¡£
WPA3 ʹÓà WiFi DPP ¶ø·Ç¹²ÏíÃÜÂ뽫É豸µÇ¼Çµ½ÍøÂ磬¸ÃºÍ̸ÔÊÐíÓû§É¨ÃèQRÂë»ò NFC ÏóÕ÷½«É豸µÇ¼µ½ÎÞÏßÍøÂç¡£Áí±í£¬·ÖÆçÓÚ WPA2£¬ËùÓÐÍøÂçÁ÷Á¿³ÇÊÐÔÚÏνӵ½Ê¹Óà WPA3 WiFi Security µÄÍøÂçºó±»¼ÓÃÜ¡£
¹ÌÈ» WPA3Ó×ÎÒ°æÖ¼ÔÚÈ¡´ú°²È«ÐԽϲîµÄÒÑ´æÔÚ14ÄêÖ®¾ÃµÄ WPA2£¬µ«ËüµÄ SAE ÎÕÊÖ£¨»ò±»³ÆÎªDragonfly£©ËƺõÊÜ´óÁ¿µ×²ãÉè¼ÆÈ±µãµÄÓ°Ï죬µ¼ÖÂÓû§Ò×ÊÜÃÜÂëͶ¶¾¹¥»÷¡£
ÓÉÓÚ¡°DragonflyÎÕÊÖ¡±ÓÉ WiFi ÍøÂçʹÓã¬ÒªÇó¾ß±¸½Ó¼û½ÚÔìµÄÓû§ÃûºÍÃÜÂ룬Ëü»¹±» EAP-pwd ºÍ̸ËùÓã¬Òò¶ø EAP-pwd Ò²¿ÉÄÜÊÜÕâЩ·ì϶ӰÏì¡£
ÔÚÂÛÎÄÖÐ×êÑÐÈËÔ±¾ßÌå½éÉÜÁËWPA3µÄÁ½ÖÖÉè¼ÆÈ±µã£ºÒ»ÖÖÊǽµ¼¶¹¥»÷£¬Ò»ÖÖÊDzàÐÅ·й¶¡£Ê×ÏÈWPA3Ìṩ¹ý¶ÉģʽÒÔÖ§³Ö¾ÉÉ豸£¬µ«¹¥»÷ÕßÄܹ»ÀÄÓÃÕâЩÉèÖÃÀ´ÆÈʹWPA3É豸ʹÓò»°²È«µÄWPA2µÄ4´ÎÎÕÊÖ£¬²¢ÇÒÕâÖÖ½µ¼¶¹¥»÷Ö»±ØÒªÖªÂ·WPA3ÍøÂçµÄSSID¡£Æä´Î×êÑÐÈËÔ±½éÉÜÁËÁ½ÖÖ²àÐÅ·¹¥»÷-»ùÓÚ»º´æºÍ»ùÓÚʱÐò£¬¿ÉÓÃÓÚ»ñÈ¡Wi-FiÃÜÂëºÍÇÔÈ¡¼ÓÃÜ´«ÊäµÄÃô¸ÐÐÅÏ¢¡£
·ì϶ÑéÖ¤
Dragonslayer£ºÊµÏÖÕë¶Ô EAP-pwd ºÍ̸µÄ¹¥»÷£ºhttps://github.com/vanhoefm/dragonslayer¡£
Dragondrain£º¸Ã¹¤¾ß¿É±»ÓÃÓÚ²âÊÔ½Ó¼ûµãÊÜ WPA3 SAE ÎÕÊֻؾø·þÎñ¹¥»÷Ó°ÏìµÄˮƽ£ºhttps://github.com/vanhoefm/dragondrain¡£
Dragontime£ºËüÊÇÒ»ÖÖ³¢ÊÔ¹¤¾ß£¬ÓÃÓÚÕë¶Ô SAE ÎÕÊÖ·¢Æð°´Ê±¹¥»÷£¬Ç°ÌáÊÇʹÓÃÁË MODP ×é22¡¢23»ò24¡£±ØÒª°ÑÎȵÄÊÇ£¬ÎÞÊýWPA3ʵÏÖĬÈϲ¢Î´ÆôÓÃÕâЩ×飺https://github.com/vanhoefm/dragontime¡£
Dragonforce£ºËüÊÇÒ»¿î³¢ÊÔ¹¤¾ß£¬ÓÃÓÚ´Ó°´Ê±¹¥»÷»ò»ùÓÚ»º´æµÄ¹¥»÷Öи´ÔÐÅÏ¢£¬²¢Ö´ÐÐÃÜÂëͶ¶¾¹¥»÷¡£ËüÀàËÆÓÚ×ֵ乥»÷£ºhttps://github.com/vanhoefm/dragonforce¡£
½¨¸´½¨Òé
Wi-FiͬÃËÈ·ÈϳÆÔÚÓ빩¸øÉ̺Ï×÷½¨²¹ÏÖÓеÄWPA3ÈÏÖ¤É豸£ºhttps://www.wi-fi.org/security-update-april-2019
²Î¿¼Á´½Ó
https://wpa3.mathyvanhoef.com/
https://thehackernews.com/2019/04/wpa3-hack-wifi-password.html


¾©¹«Íø°²±¸11010802024551ºÅ