The News Glory
  • World
  • India
  • Politics
  • Sports
  • Business
  • Entertainment
  • Tech
  • Lifestyle
  • Viral
No Result
View All Result
The News Glory
  • World
  • India
  • Politics
  • Sports
  • Business
  • Entertainment
  • Tech
  • Lifestyle
  • Viral
No Result
View All Result
The News Glory
No Result
View All Result

Home Tech

Discovering a vulnerability in the Wi-Fi protocol that allows hijacking of network traffic

The News GlorybyThe News Glory
29/03/2023
Discovering a vulnerability in the Wi-Fi protocol that allows hijacking of network traffic

Cybersecurity researchers have discovered a fundamental security flaw in the design of the IEEE 802.11 WiFi wireless networking protocol standard that allows attackers to trick Internet-connected devices into leaking network frames in plain text.

Wi-Fi frames are data containers consisting of a header, payload, and slave. These containers contain information such as source, destination MAC address, control, and management data.

These frames are queued and sent in a controlled manner to avoid collisions, and to increase data exchange performance by monitoring the busy and idle states of receiving points.

The researchers found that queued or cached frames are not adequately protected from threat actors, who can manipulate data transmission, impersonate the client, and forward and capture frames.

The technical paper published by the researchers stated: “The attacks have a wide impact because they affect many devices and operating systems, such as: Linux, (FreeBSD) FreeBSD, (iOS) and Android, and because they can be used to hijack protocol communications.” TCP, or Intercepting Client and Web Traffic».

IEEE 802.11 includes power-saving mechanisms that allow Wi-Fi devices to conserve power by caching or arranging frames for idle devices.

When the client station (receiver) goes into sleep mode, it sends a frame to the access point with a header containing the power-saving bit, so that all frames assigned to it are queued.

However, the standard does not provide clear guidance on the security management of these queued frames, nor does it set restrictions such as how long frames can remain in this state.

After the client station comes back online, the access point or device connected to the Internet removes the cached frames, applies encryption to them, and transmits them to the destination.

An attacker can spoof the MAC address of a device on the network and send power-saving frames to access points, forcing them to start queuing the target’s frames. Then, the attacker sends an alert frame to retrieve the frame packet.

Transmitted frames are usually encrypted using a group-oriented encryption key and shared between all devices in a Wi-Fi network, or using a double encryption key, which is unique to each device and is used to encrypt frames exchanged between two devices.

However, an attacker can change the security context of the frames by sending authentication and association frames to the access point, and then forcing it to send the frames in plain text or encrypting them with a key provided by the attacker.

This attack can be accomplished using custom tools created by the researchers called MacStealer, which can test Wi-Fi networks to bypass client isolation and intercept traffic destined for other clients in the MAC layer.

The researchers reported that they knew of network hardware models from (Lancome), (Aruba), (Cisco), (Asus), and (D-Link) affected by these attacks. The researchers warn that these attacks could be used to inject malicious content, such as JavaScript, into TCP packets.

Currently, there are no known cases of malicious use of the vulnerability discovered by the researchers.

Share on FacebookShare on Twitter
The News Glory

The News Glory

The News Glory is one of the best news providers in India, we bring you stories on world news, India News, Business, Politics, Technology, Gadgets, Finance and Entertainment. Follow us for special features.

Related Posts

World’s Youngest Billionaire Trains AI With Sensitive US Data
Tech

World’s Youngest Billionaire Trains AI With Sensitive US Data

03/06/2023
The chip sector falls 20% until March and the supply begins to exceed the demand
Tech

The chip sector falls 20% until March and the supply begins to exceed the demand

03/06/2023
Gradually, Google launches its artificial intelligence assistant, Duet AI
Tech

Gradually, Google launches its artificial intelligence assistant, Duet AI

03/06/2023

Popular

Andreescu loses, Coco Gauff wins

Andreescu loses, Coco Gauff wins

04/06/2023
End of relief operations after train disaster in India

End of relief operations after train disaster in India

04/06/2023
This is how China reacts to the arrival of US-supplied Stinger missiles in Taiwan

This is how China reacts to the arrival of US-supplied Stinger missiles in Taiwan

04/06/2023

Editors Pick

Putin is absent when the war reaches the portals of the Russians

Putin is absent when the war reaches the portals of the Russians

04/06/2023
Dayaa First Look: JD Chakraborty’s ‘Dayaa’.. Deep Thinking First Look Poster!

Dayaa First Look: JD Chakraborty’s ‘Dayaa’.. Deep Thinking First Look Poster!

03/06/2023
Screen time of children and adolescents must be controlled at home and at school

Screen time of children and adolescents must be controlled at home and at school

03/06/2023

About

The News Glory

The News Glory: Get up-to-date Latest Breaking News from Politics, Business, Technology, Entertainment, Sports & Much More Around India and World.

Categories

  • Automobile
  • Business
  • Education
  • Entertainment
  • Featured
  • Gadgets
  • Gaming
  • Health
  • India
  • Lifestyle
  • News
  • Politics
  • Sports
  • Tech
  • Viral
  • World

Recent Posts

  • Bear destroys 60 cupcakes after breaking into Connecticut bakery
  • Tragedy in India when a train hit two derailed wagons
  • Aena gets stuck in contests
  • Contact Us
  • Privacy Policy
  • Disclaimer
  • Terms and Conditions

Copyright © 2023 The News Glory - All Rights Reserved

No Result
View All Result
  • World
  • India
  • Politics
  • Sports
  • Business
  • Entertainment
  • Tech
  • Lifestyle
  • Viral

Copyright © 2023 The News Glory - All Rights Reserved

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
x
x