WiFi explodes again technical flaw! Aggressor can build information of privacy of user of false webs

The WiFi bougie of the exposure on 315 evening parties collects CCTV this year the heat of user information is returned not subsidise, a few days ago, safe expert expresses external in A, discovered the major new issue of WiFi through research: Be based on a few blemish that exist on WPA/WPA2 design, when the user is using communal WiFi, aggressor can pass through this one blemish, atttack the certain in network of a certain WiFi or some a few users accurately, bring about an user to suffer fishing when the webpage that browse, cause information to divulge then or pecuniary loss.

WiFi explodes again technical flaw! Aggressor can build information of privacy of user of false website purloin

A few days ago, lab of Orion of the safety in A is advanced and guest of Hou of senior and safe expert, safe engineer blueness buts the peak announced the security of world top class message that in Canada Wengehua holds on meeting CanSecWest2019 achievement of this one research. In the speech, they express, protective WiFi safety needs joint efforts of industry all circles, answer to carry out the new standard be born that can solve this one blemish quickly.

According to Introduction Hou Ke, WPA full name is WiFi Protected Access, have WPA, WPA2 two standards, it is a kind of technology standard that protects wireless network WiFi to access safety. Current, WPA2 is to use the most extensive safe level, since was being rolled out 2004 oneself nevertheless, the drawback that already in succession researcher points out its exist can bring about WiFi insecure.

Newest research discovers A Lian's complete engineers, the listening user with OK and passive aggressor and WiFi receive the communication of the dot, bogus data is sent to perhaps hijack user and WiFi to accept the connection of the dot in suitable opportunity, the communication content with distort normal, bring about an user the visit is interactive data midway is distorted.

Say popularly, it is when the user in the home, a few places such as hotel, dining-room, bazaar, with the WiFi that shares a code, when using a few network application, browse a webpage with mobile phone or computer for instance, aggressor passes through the blemish of WPA2, can guide an user to arrive false website, distort even the content that the user is visitting a website.

Compare CCTV the WiFi bougie of exposure of 315 evening parties, it is to gather user information only, give an user the picture through other and associated information then, and this one risk that safe engineer discovers in A, once allow aggressor have one's way, its consequence is more serious. "In this kind attack falls, the quality that the user gets online not only can be affected, after visitting false website to be fished, the Zhang name code of the user also has by the risk of filch, suffer pecuniary loss then. Suffer pecuniary loss then..

Be aimed at this one risk, hou Ke suggests in the speech, the user is in public avoid to use communal WiFi as far as possible, use mobile network to get online as far as possible. He returns the appeal, protective WiFi safety needs joint efforts of industry all circles, already will roll out agreement of new standard WPA3 last year in June, should quicken those who carry out this one new standard to popularize be born, replace WPA2, protect user security.

[reporter] Xie Dan

[author] Xie Dan

[origin] group of southern medium signing up for course of study is southern + client end

未经允许不得转载:News » WiFi explodes again technical flaw! Aggressor can build information of privacy of user of false webs