
KRACK
Sign in to saveAlso known as Key Reinstallation AttaCKs
KRACK ("Key Reinstallation Attack") is a replay attack (a type of exploitable flaw) on the Wi-Fi Protected Access protocol that secures Wi-Fi connections. It was discovered in 2016 by the Belgian researchers Mathy Vanhoef and Frank Piessens of the University of Leuven. Vanhoef's research group published details of the attack in October 2017. By repeatedly resetting the nonce transmitted in the third step of the WPA2 handshake, an attacker can gradually match encrypted packets seen before and learn the full keychain used to encrypt the traffic.
Key facts
- Bug.name
- KRACK
- Bug.image
- 180px
- Bug.caption
- KRACK attack logo
- Bug.CVE
- , , , , , , , , ,
- Bug.discoverer
- Mathy Vanhoef and Frank Piessens
- Bug.affected hardware
- All devices that use Wi-Fi Protected Access (WPA)
- Bug.affected software
- All operating systems that use WPA
via Wikipedia infobox
~6 min read
Article
7 sectionsContents
- Details
- Patches
- Workarounds
- Continued vulnerability
- See also
- References
- External links
KRACK ("Key Reinstallation Attack") is a replay attack (a type of exploitable flaw) on the Wi-Fi Protected Access protocol that secures Wi-Fi connections. It was discovered in 2016 by the Belgian researchers Mathy Vanhoef and Frank Piessens of the University of Leuven. Vanhoef's research group published details of the attack in October 2017. By repeatedly resetting the nonce transmitted in the third step of the WPA2 handshake, an attacker can gradually match encrypted packets seen before and learn the full keychain used to encrypt the traffic.
The weakness is exhibited in the Wi-Fi standard itself, and not due to errors in the implementation of a sound standard by individual products or implementations. Therefore, any correct implementation of WPA2 is likely to be vulnerable. The vulnerability affects all major software platforms, including Microsoft Windows, macOS, iOS, Android, Linux, OpenBSD and others.