|
@singe | |||||
|
Here's a detailed write-up of the EAP bug that affected all Apple devices (except watchOS), CVE-2019-6203. It includes a deep dive into MSCHAPv2 sensepost.com/blog/2019/unde… there's some code at github.com/sensepost/unde… too
|
||||||
|
||||||
|
Dominic White
@singe
|
18. tra |
|
This might also be useful for WiFi generalists studying for their CWNP or CWNE cc @robrobstation
|
||
|
|
||
|
Dominic White
@singe
|
21. tra |
|
github.com/sensepost/wpa_… from @_cablethief looks exciting. Sycophant can not only get you on the network but let you keep the victim device connected to your rogue AP.
|
||
|
|
||
|
Glenn Wilkinson 🇿🇼
@glennzw
|
19. tra |
|
|
||
|
Dominic White
@singe
|
19. tra |
|
For macOS and tvOS too twitter.com/singe/status/1… ;)
|
||
|
|
||
|
Adam Toscher
@W00Tock
|
18. tra |
|
I wonder if this is why the EAP-GTC downgrade works too ? Apple/Android need to address this issue. Once again something @brad_anton had buit into his code but didn't report?
|
||
|
|
||
|
Dominic White
@singe
|
18. tra |
|
I'll get around to that next :)
|
||
|
|
||
|
Brad Antoniewicz
@brad_anton
|
18. tra |
|
great write up and thanks for the shouts!
|
||
|
|
||
|
Dominic White
@singe
|
18. tra |
|
You’re welcome ;)
|
||
|
|
||
|
Mathy Vanhoef
@vanhoefm
|
16. svi |
|
Nice work! We wanted to study issues like this as well, but haven't found the time. Are you planning any follow-up work? :)
|
||
|
|
||