ÖÐÎÄ
Ðû²¼Ê±¼ä£º2017-10-23
ʲôÊÇKRACKÎó²î(Key Reinstallation Attacks)£¿£¿£¿£¿£¿£¿£¿
KRACK Îó²î£¬£¬£¬£¬£¬£¬£¬£¬¼´ÃÜÔ¿ÖØ×°¹¥»÷Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÊÇ2017Äê10ÔÂ16ÈÕÓɱÈÀûʱÑо¿Ö°Ô±Mathy Vanhoef£¨ÂíµÙ·ÍòºÕ¸¥£©Ðû²¼µÄWPA/WPA2ÐÒéÇå¾²ÎÊÌâ¡£¡£¡£¡£¡£¡£¸ÃÎó²îͨ¹ýWPA/WPA2ÐÒéÔÚʵÏÖÉϵÄȱÏÝ£¬£¬£¬£¬£¬£¬£¬£¬´¥·¢ÃÜÔ¿µÄ֨װÖ㬣¬£¬£¬£¬£¬£¬£¬¿ÉÄÜʹÖÐÐÄÈ˹¥ »÷Õß»ñµÃ½âÃÜÎÞÏßÊý¾Ý°üµÄÄÜÁ¦¡£¡£¡£¡£¡£¡£
ͨÓÃÎó²îÅûÂ¶ÍøÕ¾£¨CVE£©¼Í¼ÁË10¼¸¸öKRACKÎó²î¿ÉÄÜÒý·¢µÄÎÊÌ⣨CVE-2017-13077 ~ 13082£¬£¬£¬£¬£¬£¬£¬£¬CVE-2017-13084 ~ 13088£©£¬£¬£¬£¬£¬£¬£¬£¬ÏÖʵÉÏÕâÊ®¼¸¸öÎó²î¾ùÖ¸Ïòͳһ¸öÎÊÌâ--ÃÜÔ¿ÖØ×°¡£¡£¡£¡£¡£¡£
ÕâÀàÇ徲ȱÏݱ£´æÓÚ Wi-Fi ±ê×¼×Ô¼º£¬£¬£¬£¬£¬£¬£¬£¬¶ø·ÇÌØ¶¨Ä³Ð©²úÆ·»òÕßʵÏּƻ®ÖС£¡£¡£¡£¡£¡£ÊµÖÊÉÏ£¬£¬£¬£¬£¬£¬£¬£¬ÎªÁ˰ü¹ÜÇå¾²£¬£¬£¬£¬£¬£¬£¬£¬Ò»¸öÃÜÔ¿Ö»Ó¦¸Ã×°ÖúÍʹÓÃÒ»´Î£¬£¬£¬£¬£¬£¬£¬£¬¶øWPA2ȴûÓаü¹ÜÕâÒ»µã¡£¡£¡£¡£¡£¡£
ÂÛÎÄ¡¶Key Reinstallation Attacks:Forcing Nonce Reuse in WPA2¡·ÄÚµÄPOC(Proof of Concept)£¬£¬£¬£¬£¬£¬£¬£¬¶ÔÒ»²¿ Android ÊÖ»úÖ´ÐÐÁËÒ»´Î KRACK¡£¡£¡£¡£¡£¡£ÔÚ±¾´ÎÑÝʾÖУ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÓÐÄÜÁ¦¶ÔÊܺ¦Õß´«ÊäµÄËùÓÐÊý¾Ý¾ÙÐнâÃÜ¡£¡£¡£¡£¡£¡£¹ØÓÚ¹¥»÷·½¶øÑÔ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒ»¹¥»÷·½·¨ºÜÊÇÒ×ÓÚʵÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚAndroid ÒÔ¼° Linux »áÔÚ¹¥»÷ÕßµÄÖ¸µ¼Ï£¨ÖØÐ£©×°ÖÃÒ»ÌõÈ«Áã¼ÓÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£
ÂÛÎÄÒ²Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ¹¥»÷ÆäËû×°±¸Ê±£¨ÎÞÈ«Áã¼ÓÃÜÃÜÔ¿Îó²îµÄ×°±¸£©£¬£¬£¬£¬£¬£¬£¬£¬ËäÈ»½âÃÜËùÓÐÊý¾Ý°üÄѶȼ«´ó£¬£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÈÔÈ»ÓÐÄÜÁ¦½âÃÜÏ൱һ²¿·ÖÊý¾Ý°ü¡£¡£¡£¡£¡£¡£ÏÖʵÉÏ£¬£¬£¬£¬£¬£¬£¬£¬ÂÛÎÄ×÷ÕßÈϿɣ¬£¬£¬£¬£¬£¬£¬£¬Ëû×Ô¼º»¹Ã»ÓÐÕⲿ·Ö¹¥»÷µÄPOC¡£¡£¡£¡£¡£¡£
KRACKÎó²îµÄ¹¥»÷¹¤¾ßºÍ¹¥»÷·½·¨
¸ÃÎó²îÖ÷ÒªÊÇÕë¶Ô WiFi ½ÓÈëµÄ¿Í»§¶Ë£¨ÊÖ»ú¡¢Ìõ¼Ç±¾¡¢padµÈ×°±¸£©£¬£¬£¬£¬£¬£¬£¬£¬ÓÕ·¢¿Í»§¶Ë¾ÙÐÐÃÜÔ¿ÖØ×°£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø´øÀ´¿ÉÄܱ»½âÃܵÄÒþ»¼£¬£¬£¬£¬£¬£¬£¬£¬±»¹¥»÷µÄÖ÷ÒªÌõ¼þÊǹ¥»÷ÕßÔÚÎïÀíλÖÃÉϺÜÊÇ¿£¿£¿£¿£¿£¿£¿¿½üÄ¿µÄ Wi-Fi ÍøÂ磬£¬£¬£¬£¬£¬£¬£¬²Å¿ÉÄܾÙÐÐ֨װÃÜÔ¿ÓÕµ¼¡£¡£¡£¡£¡£¡£
¿ÉÄܵĹ¥»÷·½·¨°üÀ¨£º

Wi-Fi ʹÓÃÕßÓ¦¸ÃÔõÑù¿´´ý¸ÃÎó²î
Îó²î¶ÔAP×°±¸µÄÓ°Ïì
¶Ôstake¹ÙÍøAPÓ°Ïì½ÏС£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐAPÔËÐÐÔÚÒÔϽÏÉÙʹÓõÄÁ½ÖÖ³¡¾°Ï£¬£¬£¬£¬£¬£¬£¬£¬Ä¿½ñµÄÈí¼þ°æ±¾²Å»áÊÜ´ËÎó²îÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬Ïà¹ØµÄ½â¾ö¼Æ»®ÈçÏ£º
>>>ÓÑÇéÌáÐÑ<<<
ÔÚ¸ÃÎó²îϸ½ÚÆØ¹âÖ®ºó£¬£¬£¬£¬£¬£¬£¬£¬Linux¡¢Î¢Èí¡¢Æ»¹ûÏà¼Ì¶¼Ðû²¼Á˲¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÇ¿ÁÒ½¨Òé¸÷ÈËʵʱµÄ¸üÐÂ×Ô¼ºµÄϵͳ°æ±¾»òÕß×°Öò¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬×èÖ¹ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬£¬£¬Ö÷Á÷Öն˵IJ¹¶¡Ï£ÍûÈçÏ£º
¹ØÓÚ´Ë£¬£¬£¬£¬£¬£¬£¬£¬¸÷ÈËÓÐÆäËûÒÉÎÊ£¬£¬£¬£¬£¬£¬£¬£¬»¶ÓÖµçstake¹ÙÍøÍøÂç7*24Сʱ·þÎñÈÈÏß¡£¡£¡£¡£¡£¡£
