Owfuzz: WiFi Nightmare

Presented at Black Hat Europe 2021, Nov. 10, 2021, 11:20 a.m. (40 minutes)

WiFi, which uses unprotected air as a medium, faces unique challenges in ensuring the security and availability of communication. Throughout the development process of WiFi protocol, it is also the evolution process of WiFi security protocol. Even with the popularization of WIFI6 and WPA3, there are still many flaws in the security of WiFi protocol and its implementation.

Owfuzz is a WiFi fuzzing tool. It can perform fuzzing tests to any WiFi device, including client and AP. Over the past few months, I've used owfuzz to fuzz WiFi chips of different vendors and found many WiFi vulnerabilities, the affected vendors include Qualcomm, Intel, Espressif, Broadcom, Huawei and others. These vulnerabilities include both design and implementation flaws, some even affect multiple vendors at the same time.

WiFi vulnerabilities can cause remote zero-click attacks, and will affect a large number of users. Therefore, chip vendors need to pay more attention to the security and robustness of WiFi. This talk will cover the practice and thinking about owfuzz and the vulnerabilities discovered by owfuzz.


Presenters:

  • Hongjian Cao - Security Expert, Ant Group
    Hongjian Cao is a security researcher at Ant Security Frontage Lab. He is now focusing on IoT security, 802.11 protocol analysis and vulnerability discovery. He has found many 802.11 vulnerabilities of multiple vendors like Qualcomm, Broadcom, Intel,Espressif and more.

Links:

Similar Presentations: