Ausnahme gefangen: SSL certificate problem: certificate is not yet valid 📌 Attackers Could Exploit Flaw in WiFi Protocol to Hijack TCP Connections

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Attackers Could Exploit Flaw in WiFi Protocol to Hijack TCP Connections


💡 Newskategorie: Hacking
🔗 Quelle: blackhatethicalhacking.com

Attackers Could Exploit Flaw in WiFi Protocol to Hijack TCP Connections

Premium Content

Patreon
Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes

Vulnerability in the IEEE 802.11 WiFi protocol standard

Cybersecurity researchers have found a significant vulnerability in the IEEE 802.11 WiFi protocol standard, which can be exploited by hackers to trick access points into leaking network frames in plaintext form. WiFi frames are data containers that contain information such as the source and destination MAC address, control, and management data. The researchers discovered that queued or buffered frames are not adequately protected from attackers, who can manipulate data transmission, client spoofing, frame redirection, and capturing.

See Also: So you want to be a hacker?
Offensive Security, Bug Bounty Courses

Power-saving flaw

The IEEE 802.11 standard includes power-save mechanisms that allow WiFi devices to conserve power by buffering or queuing frames destined for sleeping devices. However, the standard does not provide explicit guidance on managing the security of these queued frames and does not set limitations on how long the frames can stay in this state. An attacker can spoof the MAC address of a device on the network and send power-saving frames to access points, forcing them to start queuing frames destined for the target.

Attack diagram

Attack diagram (papers.mathyvanhoef.com)

The researchers warn that these attacks could be used to inject malicious content, such as JavaScript, into TCP packets.

Devices tested by the analysts

Tested devices found vulnerable (papers.mathyvanhoef.com)

 

The flaw impacts devices and operating systems across various models, including Cisco, Asus, D-Link, and Aruba. While no instances of malicious use have been reported, experts warn that attackers could exploit the vulnerability to inject malicious content, such as JavaScript, into TCP packets, which could be used to exploit vulnerabilities in a victim’s browser

Cisco acknowledges vulnerability

Cisco has acknowledged the vulnerability and recommends mitigation measures, including implementing policy enforcement mechanisms and transport layer security.

Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com

Source: bleepingcomputer.com

Source Link

Merch

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.

The post Attackers Could Exploit Flaw in WiFi Protocol to Hijack TCP Connections first appeared on Black Hat Ethical Hacking. ...



📌 Attackers Could Exploit Flaw in WiFi Protocol to Hijack TCP Connections


📈 81.98 Punkte

📌 WiFi protocol flaw allows attackers to hijack network traffic


📈 47.32 Punkte

📌 Off-Path TCP Exploit Allows Attackers to Steal Data via Unencrypted Connections


📈 37.77 Punkte

📌 New WiFi Flaw Let Attackers Hijack Network Traffic


📈 37.76 Punkte

📌 Critical Linux Vulnerability Let Hackers Hijack VPN-Tunneled TCP Connections


📈 35.64 Punkte

📌 Microsoft Teams flaw could let attackers hijack accounts


📈 35.41 Punkte

📌 Apple Touch ID Flaw Could Have Let Attackers Hijack iCloud Accounts


📈 35.41 Punkte

📌 New Linux Vulnerability Lets Attackers Hijack VPN Connections


📈 34.66 Punkte

📌 New vulnerability lets attackers sniff or hijack VPN connections


📈 34.66 Punkte

📌 New Linux Vulnerability Lets Attackers Hijack VPN Connections


📈 34.66 Punkte

📌 Attackers using Linux Vulnerability to Hijack VPN Connections


📈 34.66 Punkte

📌 New Linux Vulnerability Lets Attackers Hijack VPN Connections


📈 34.66 Punkte

📌 New Vulnerability Lets Attackers Hijack VPN Connections on Most UNIX Systems


📈 34.66 Punkte

📌 New Linux Bug Lets Attackers Hijack Encrypted VPN Connections


📈 34.66 Punkte

📌 New Linux Bug Lets Attackers Hijack Encrypted VPN Connections


📈 34.66 Punkte

📌 New Linux Vulnerability Lets Attackers Hijack VPN Connections


📈 34.66 Punkte

📌 New BLUFFS attack lets attackers hijack Bluetooth connections


📈 34.66 Punkte

📌 New Linux Bug Lets Attackers Hijack Encrypted VPN Connections


📈 34.66 Punkte

📌 Attackers exploit flaw in GDPR-themed WordPress plugin to hijack websites


📈 33.9 Punkte

📌 RealVNC up to 4.0 TCP Connection 100 TCP Connections denial of service


📈 33.87 Punkte

📌 One-Click Exploit Could Have Let Attackers Hijack Any Atlassian Account


📈 33.04 Punkte

📌 New Terrapin Flaw Could Let Attackers Downgrade SSH Protocol Security


📈 32.72 Punkte

📌 A Bug With Firefox for Android Let Attackers Hijack without user Interaction on the Same WiFi Network


📈 30.5 Punkte

📌 Linux TCP Flaw allows Hackers to Hijack Internet Traffic and Inject Malware Remotely


📈 30 Punkte

📌 Linux TCP Flaw allows Hackers to Hijack Internet Traffic and Inject Malware Remotely


📈 30 Punkte

📌 Researchers Break IPsec VPN Connections with 20-Year-Old Protocol Flaw


📈 29.71 Punkte

📌 New Bluetooth KNOB Flaw Lets Attackers Manipulate Connections


📈 29.66 Punkte

📌 Virus Bulletin 2018: macOS Flaw Allows Attackers to Hijack Installed Apps


📈 29.02 Punkte

📌 SUPRA Smart TV Flaw Lets Attackers Hijack Screens With Any Video


📈 29.02 Punkte

📌 SUPRA Smart TV Flaw Lets Attackers Hijack Screens With Any Video


📈 29.02 Punkte

📌 New Android Flaw Affecting Over 1 Billion Phones Let Attackers Hijack Apps


📈 29.02 Punkte

📌 Critical Android flaw lets attackers hijack almost any app, steal data


📈 29.02 Punkte

📌 New Android Flaw Affecting Over 1 Billion Phones Let Attackers Hijack Apps


📈 29.02 Punkte

📌 Mozilla fixes flaw that let attackers hijack Firefox for Android via Wi‑Fi


📈 29.02 Punkte

📌 Synology NAS System Flaw Let Attackers Remotely Hijack the Admin Account


📈 29.02 Punkte











matomo