Linchakin

Researchers Discover Vulnerability Used for Deception and SSID Stripping

 September 15, 2021     No comments   

Deception and SSID StrippingResearchers at AirEye have discovered a vulnerability in the way in which devices connect to wireless networks that could allow an attacker to trick a user into connecting to a malicious network. The method, dubbed “SSID Stripping,” enables attackers to create an Access Point (AP) that appears to have the exact same name as a legitimate network. The flaw affects Windows, iOS and macOS, Android, and Ubuntu.

“Since the attacker creates a rogue AP with a name that looks exactly like the known legitimate network name, users are more likely to fall prey to this attack,” the researchers write. “Operating system vendors have put in place controls to prevent users from connecting to rogue APs displaying the same network name as legitimate networks. These controls mainly rely on the fact that the device is configured to use the same security measures, such as a certificate, every time it connects to a network name it already has in its memory. Thus, a device cannot connect to a rogue AP with the same network name since the rogue AP does not require the same security measures.”

The vulnerability stems from the fact that certain characters aren’t displayed in the name of the network shown on the device.

“We found out that many special characters are simply omitted from the actual display (especially those considered ‘non-printable’ characters),” the researchers explain. “For example, the NULL byte when introduced into a network name is not part of the display on Android phones. A network name of the form ‘aireye_network’ would be displayed exactly the same as ‘aireye_network.’ The same holds true for Ubuntu machines when handling a NULL byte. Other ‘non-printable’ characters have similar effects on iPhone and Mac devices. For example, the network name ‘aireye_x1cnetwork’ (with x1c representing a byte with the value 0x1C hex), is displayed exactly the same as “aireye_network.’”

“SSID Stripping bypasses these security controls since the device itself processes the network names as they actually are, not as they are displayed,” the researchers add. “Hence, the devices do not consider the rogue AP to have the same name as the legitimate network.”

New-school security awareness training can give your employees a healthy sense of suspicion so they can avoid falling for social engineering attacks.

AirEye has the full story. 

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • iPhone 14 tipped to get a huge storage boost — but we're not buying itCould the iPhone 14 really support up to 2TB of storage? We’re dubious.Apple could give the iPhone 14 a whopping 2TB of storage, double that of the maximum 1TB of onboard storage the iPhone 13 Pro and iPhone 13 Pro Max ca… Read More
  • How To Use The Raspberry Pi Sense HATByLes Pounder With the news that two Raspberry Pi 4 are heading to space housed inside custom designed “space gra...The Astro Pi project sees experiments, written by school children running on real Raspberry Pis. This might not seem very exciting until you hear wher… Read More
  • Kekeo - A Little Toolbox To Play With Microsoft Kerberos In C kekeo is a little toolbox I have started to manipulate Microsoft Kerberos in C (and for fun) ASN.1 library In kekeo, I use an external commercial li… Read More
  • How to Build A Person-Following Creepy Head for Halloween with a Raspberry PiByRyder Damen Scare your friends and neighbors with a creepy mannequin he...Halloween is coming, and what better way to celebrate the season than by using machine learning and a Raspberry Pi to accomplish something spooky! Thi… Read More
  • How to Calibrate Your Screen in Windows 11 or 10ByNathaniel Mott Default color profiles get better all the time, but calibrating your screen in Window...It would be nice if every display was calibrated exactly the same way straight from the factory, but the reality is that even though default color pro… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates