Encryption Invalidation Attacks: Is your Wi-Fi encryption really working?
Taketo Inoue, Kosuke Kuriyama, Yoshiaki Shiraishi, Masakatu Morii · 2023
In the 2023 Usenix Security Symposium, M. Vanhoef et al. demonstrated how to exploit power-save features and delete encryption keys to trick an access point into leaking frames in plaintext from its buffer. However, it is uncertain whether packets will be buffered due to the possibility of client devices sending wake-up frames. Therefore, the transmission of plaintext packets is unlikely. Furthermore, the captured packets in their study were mainly responses to echo requests, which may not contain sensitive information. We propose a method to buffer packets regardless of the client’s wake-up frame usage, enabling access points to send plaintext packets even when the client is accessing a web page. Our proposed method significantly enhances the efficiency of intercepting sensitive data, such as IP addresses, port numbers, and even TCP payloads, outperforming the approach proposed by M. Vanhoef et al.