{"id":29253,"date":"2023-04-02T10:36:27","date_gmt":"2023-04-02T08:36:27","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=29253"},"modified":"2023-04-02T10:36:27","modified_gmt":"2023-04-02T08:36:27","slug":"design-flaw-in-wifi-protocol-allows-attackers-to-intercept-network-traffic","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2023\/04\/02\/design-flaw-in-wifi-protocol-allows-attackers-to-intercept-network-traffic\/","title":{"rendered":"Design flaw in WiFi protocol allows attackers to intercept network traffic"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2023\/04\/02\/design-schwche-im-wifi-protokoll-ermglicht-angreifern-das-abfangen-des-netzwerkverkehrs\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Another small addendum from the end of March 2023. Security researchers have discovered a serious design weakness in the IEEE 802.11 WiFi protocol standard. This weakness could allow attackers to eavesdrop on WLAN access points and transmit network frames in plain text. This could, for example, inject malicious JavaScript commands into the network packets. It is an academic finding, and there is no evidence yet that this flaw is being exploited.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg07.met.vgwort.de\/na\/e94db86b1db14e7b8b37dda1a9ab47e0\" alt=\"\" width=\"1\" height=\"1\" \/>Security researchers found that n queues buffered WiFi frames are not sufficiently protected against attackers. These could eavesdrop on the data transmission by means of client spoofing and manipulate it via frame redirection. The colleagues from Bleeping Computer picked up on this in<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/wifi-protocol-flaw-allows-attackers-to-hijack-network-traffic\/\" target=\"_blank\" rel=\"noopener\"> this article<\/a> (see the following <a href=\"https:\/\/twitter.com\/BleepinComputer\/status\/1640792297120968704\" target=\"_blank\" rel=\"noopener\">tweet<\/a>).<\/p>\n<p><a href=\"https:\/\/twitter.com\/BleepinComputer\/status\/1640792297120968704\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"WiFi protocol flaw\" src=\"https:\/\/i.imgur.com\/fcNu0DM.png\" alt=\"WiFi protocol flaw\" \/><\/a><\/p>\n<p>The technical details are described in the PDF document <a href=\"https:\/\/papers.mathyvanhoef.com\/usenix2023-wifi.pdf\" target=\"_blank\" rel=\"noopener\">Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues<\/a> by security researchers Domien Schepers and Aanjhan Ranganathan (both Northeastern University) and Mathy Vanhoef (imec-DistriNet, KU Leuven).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Another small addendum from the end of March 2023. Security researchers have discovered a serious design weakness in the IEEE 802.11 WiFi protocol standard. This weakness could allow attackers to eavesdrop on WLAN access points and transmit network frames in &hellip; <a href=\"https:\/\/borncity.com\/win\/2023\/04\/02\/design-flaw-in-wifi-protocol-allows-attackers-to-intercept-network-traffic\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-29253","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/29253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=29253"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/29253\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=29253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=29253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=29253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}