
FragAttacks术语是由短语Fragmentation 和Ag gregation (Fr)Attacks创造的。这些是针对WiFi设备的安全威胁。在这些攻击中,攻击者主要针对其 WiFi 网络范围内的(within the range of its WiFi network)设备并窃取受害者的敏感信息(例如密码)。这些攻击影响所有最近的WiFi安全协议,包括 WPA3 和 WPA2(including WPA3 and WPA2)。家庭路由器、物联网(IoT)、智能手机和许多其他设备都会受到此类攻击的影响。
FragAttacks 利用了WiFi中的几个漏洞。它们可以通过多种方式进行,包括:
攻击者可能会将未加密的WiFi帧注入到安全的WiFi网络中。他们可以利用WiFi(WiFi)标准中的第一个设计缺陷,即其聚合(aggregation)功能。在这种情况下,框架中的“已聚合(is aggregated)”标志未经过验证,并且可以轻松修改。因此(Hence),攻击者注入数据包并欺骗受害者将他重定向到他们的恶意服务器。
WiFi的第二个设计缺陷是其帧碎片化( frame fragmentation)特性,被称为混合密钥攻击(mixed key attack)。来自同一帧的片段使用相同的密钥加密,而接收者可以使用不同的密钥重新组合片段。攻击者可以使用它来窃取受害者的数据。
第三个设计缺陷同样与WiFi中的帧碎片功能有关,称为碎片缓存攻击(fragment cache attack)。发生的情况是,当用户与网络断开连接时,WiFi设备不会从内存中删除未重组的片段。这可以通过将恶意片段注入接入点的内存来加以利用。现在,当用户连接到WiFi网络并传输碎片帧时,这些碎片将与攻击者注入的恶意碎片重新组合。
Mathy Vanhoef 的 FragAttacks 演示:
如何保护您的WiFi免受FragAttacks 攻击(FragAttacks)?
一些标准做法可以帮助您保护您的WiFi免受FragAttacks 攻击(FragAttacks)。这些都是:
- 升级您的设备
- 安装安全更新
- 使用加密
- 使用 VPN
- 设置自定义 DNS
Mathy Vanhoef 在他的博客中说:
The biggest risk in practice is likely the ability to abuse the discovered flaws to attack devices in someone’s home network. For instance, many smart home and internet-of-things devices are rarely updated, and Wi-Fi security is the last line of defense that prevents someone from attacking these devices. Unfortunately, due to the discover vulnerabilities, this last line of defense can now be bypassed. In the demo above, this is illustrated by remotely controlling a smart power plug and by taking over an outdated Windows 7 machine.
因此,如果您使用的是旧版本的设备,则必须升级它们。例如,如果您仍在使用Windows 7/8,那么现在是升级到 Windows 10(upgrade to Windows 10)以保护您的设备免受FragAttacks和其他新的安全攻击的最佳时机。
在Windows 10的情况下,您可以通过转到“Settings > Update和Security > Windows Update选项来安装安全更新和其他更新,并检查可用的更新,然后下载并将它们安装在您的 PC 上。
在线浏览时,请确保您位于具有HTTPS(安全超文本传输协议(Hypertext Transfer Protocol Secure))证书的安全网站上。不仅如此,随时随地使用加密。例如,使用提供端到端加密的安全应用程序在设备之间传输数据。请记住,当未加密的数据通过安全网络发送时,就会发生FragAttacks 。(Remember FragAttacks)所以,加密是必须的。
考虑使用 VPN 服务(using a VPN service),因为它可以通过加密连接路由您的流量,从而为您提供针对FragAttacks的保护。(FragAttacks)
您可以通过访问 fragattacks.com 进一步了解FragAttacks。(fragattacks.com.)
What are FragAttacks? How to secure your WiFi against FragAttacks?
Just about recently, a security researсher has discovered and reported new vulnerabilities in WiFi devices known as FragAttacks. These are new types of attacks that exploit design flaws in the WiFi standard and affect most WiFi-enabled devices. He has previously discovered the KRACK attack which basically affected WPA2 protocol.

What are FragAttacks?
FragAttacks term is coined with the phrase Fragmentation and Aggregation Attacks. These are security threats that target WiFi devices. In these attacks, the attacker basically targets a device that is within the range of its WiFi network and steals the victim’s sensitive information (e.g., password). These attacks impact all recent WiFi security protocols including WPA3 and WPA2. Home routers, IoT, smartphones, and many other devices are affected by these kinds of attacks.
Design Flaws in WiFi
FragAttacks take advantage of several vulnerabilities in WiFi. They can be carried out in various ways including:
The attacker may inject an unencrypted WiFi frame into a secure WiFi network. They can use the first design flaw in the WiFi standard which is its aggregation feature. In this, the “is aggregated” flag in a frame is not validated and can easily be modified. Hence, the attacker injects the packet and tricks the victim into redirecting him to their malicious server.
The second design flaw in WiFi is its frame fragmentation feature and is known as a mixed key attack. The fragments from the same frame are encrypted with the same key, while the receiver can reassemble fragments with different keys. An attacker can use this to exfiltrate the victim’s data.
The third design flaw is again with the frame fragmentation feature in WiFi and is called fragment cache attack. What happens is that the WiFi device doesn’t eliminate non-reassembled fragments from memory when a user is disconnected from a network. This can be exploited by injecting a malicious fragment into the access point’s memory. Now, when a user connects to the WiFi network and transmits a fragmented frame, those fragments will be reassembled with the attacker’s injected malicious fragment.
FragAttacks Demo by Mathy Vanhoef:
How to secure your WiFi against FragAttacks?
Some standard practices can help you protect your WiFi from FragAttacks. These are:
- Upgrade your device
- Install Security Updates
- Use Encryption
- Use a VPN
- Set up a Custom DNS
1] Upgrade your device
Mathy Vanhoef says in his blog:
The biggest risk in practice is likely the ability to abuse the discovered flaws to attack devices in someone’s home network. For instance, many smart home and internet-of-things devices are rarely updated, and Wi-Fi security is the last line of defense that prevents someone from attacking these devices. Unfortunately, due to the discover vulnerabilities, this last line of defense can now be bypassed. In the demo above, this is illustrated by remotely controlling a smart power plug and by taking over an outdated Windows 7 machine.
So, if you are using an older version of your devices, you must upgrade them. For example, if you are still using Windows 7/8, it’s the right time to upgrade to Windows 10 to protect your device against FragAttacks and other new security attacks.
And, if you are using an old router that has no upgrades available for a long, you must consider changing your router and getting a new one. Simply replace your device if there are no firmware updates regularly.
2] Install Security Updates
Always make sure that you have installed security updates on your device. Security updates help you protect your devices against any new vulnerability and security attacks. So, keep on checking for security updates and install them as soon as they are available. Although, smartphones and other modern devices automatically download and install security updates. But, also check manually to ensure the same.
In the case of Windows 10, you can install security and other updates by going to the Settings > Update & Security > Windows Update option and check for updates available and then download and install them on your PC.
3] Use Encryption
When browsing online, ensure that you are on a secure website with an HTTPS (Hypertext Transfer Protocol Secure) certificate. Not just that, use encryption all the time and everywhere. For example, use a secure application that offers end-to-end encryption to transfer data between devices. Remember FragAttacks occur when unencrypted data is sent over a secure network. So, encryption is a must.
4] Use a VPN
Consider using a VPN service as it can provide you protection against FragAttacks by routing your traffic through an encrypted connection.
5] Set up a Custom DNS
You can also configure a custom DNS manually in your router and other devices to obstruct any attack that redirects you to a malicious server.
FragAttacks are a new collection of vulnerabilities in WiFi standard that puts multiple devices at risk. An attacker within the range of your network can carry out these types of attacks where he attempts to steal your data. However, some basic security practices can help you protect your WiFi against FragAttacks.
You can further educate yourself on FragAttacks by going to fragattacks.com.