vanhoefm / krackattacks-scripts

Other
3.33k stars 768 forks source link

Which CVEs are being tested #80

Closed vanhoefm closed 3 years ago

vanhoefm commented 3 years ago

Hi @vanhoefm There's 10 CVE's for krack attacks. Are this testing scripts cover all of them except for CVE-2017-13088(WNM)?

Originally posted by @mdalag in https://github.com/vanhoefm/krackattacks-scripts/issues/61#issuecomment-770014894

vanhoefm commented 3 years ago

There's 10 CVE's for krack attacks. Are this testing scripts cover all of them except for CVE-2017-13088(WNM)?

Several of those CVEs are more theoretical or were quite uncommon at the time and there are currently no tests for them. The README mentions which CVEs can be tested using this script.

mdalag commented 3 years ago

So the tests checking only CVE-2017-13080, CVE-2017-13077, CVE-2017-13078?

vanhoefm commented 3 years ago

Yes.

Also note the reverse situation: the tests --replay-broadcast, --group --gtkinit, and --gtkinit test for vulnerabilities that don't have a separate CVEs but are/were common in practice.

mdalag commented 3 years ago

Understood, thanks