Billions of Devices Open to Wi-Fi Eavesdropping Attacks

The Kr00k bug arises from an all-zero encryption key in Wi-Fi chips that reveals communications from devices from Amazon, Apple, Google, Samsung and others. Continue reading Billions of Devices Open to Wi-Fi Eavesdropping Attacks

Key reinstallation attack how does it work without a pre-shared key?

The author of the key reinstallation attack released scripts on Github to test AP and clients.
To test the clients, you have to connect to a fake AP but you still need to know the pre-shared key. Of course you know the password, because y… Continue reading Key reinstallation attack how does it work without a pre-shared key?

With all the recent WIFI hacks, how we should configure our organizational Wifi security configs and version?

In recent few months, we see WiFi hacks (e.g. KRACK) and other vulnerabilities.

NIST is not updated and there are not official security best practices to follow.

How we can set our organizational enterprise WiFi to be secur… Continue reading With all the recent WIFI hacks, how we should configure our organizational Wifi security configs and version?

KRACK – does the ability to replay broadcast and multicast frames affect all clients in a wireless network?

I apologise if this is a silly question, I just want to make sure I understand the impact of CVE-2017-13078 and CVE-2017-13080 correctly. Is the following assumption true?

If there is just one client on a Wi-Fi network th… Continue reading KRACK – does the ability to replay broadcast and multicast frames affect all clients in a wireless network?