
Automated vulnerability tester for Wi-Fi clients and access points, detecting FragAttacks fragmentation/aggregation flaws through frame injection, mixed-mode testing, and packet capture analysis.
This repository contains the FragAttacks tool. It can test Wi-Fi clients and access points for fragmentation and aggregation attacks. These vulnerabilities affect all protected Wi-Fi networks. For more information about these vulnerabilities see fragattacks.com.
The following additional resources are available:
See the change log for a detailed overview of updates to the tool made since 11 August 2020. This change log also contains information on which version of hostap the FragAttacks tool is based on.
Note that the attacks are identical against WPA2 and WPA3 because their CCMP and GCMP encryption ciphers are identical. Older WPA networks by default use TKIP for encryption, and the applicability of the attacks against TKIP are discussed in the paper and on the website. To illustrate that Wi-Fi has been vulnerable since its creation, the paper and website also briefly discusses the applicability of the attacks against WEP.
Only specific wireless network cards are supported. This is because some network cards may overwrite the sequence or fragment number of injected frames, or may reorder frames of different priority, and this interferes with the test tool (i.e. the tool might say a device is secure although it's not). I have confirmed that the following network cards work properly:
| Network Card | USB | 5GHz | mixed mode | injection mode |
|---|---|---|---|---|
| Technoethical N150 HGA | Yes | No | patched driver/firmware | patched driver/firmware |
| TP-Link TL-WN722N v1.x | Yes | No | patched driver/firmware | patched driver/firmware |
| Alfa AWUS036NHA | Yes | No | patched driver/firmware | patched driver/firmware |
| Intel Wireless-AC 8265 | No | Yes | patched driver | yes |
| Intel Wireless-AC 3160 | No | Yes | patched driver | yes |
| Alfa AWUS036ACM | Yes | Yes | patched driver | yes |
| Netgear WN111v2 | Yes | No | patched driver | yes |
| Alfa AWUS036ACH | Yes | Yes | no | yes |
The last two columns signify:
Mixed mode: whether the network card can be used in the recommended mixed mode.
Injection mode: whether the network card can be used as a second interface to inject frames in injection mode.
Yes indicates the card works out-of-the-box in the given mode. Patched driver/firmware means that the card is compatible when used with patched drivers and/or firmware. No means this mode is not supported by the network card. I recommend using the test tool in mixed mode.
Note that USB devices can be used inside a virtual machine, and the modified drivers and/or firmware can be installed in this virtual machine. However, I found that the usage of virtual machines can make network cards less reliable, and I instead recommend the usage of a live USB image if you cannot install the modified drivers/firmware natively.
My experience with the above network cards can be found here. Summarized:
The AWUS036ACM in mixed mode appears reliable with our latest drivers and is the one I recommend. A cheaper but almost identical device is one with a MT7612U chipset. See more info here.
I previously recommended the Technoethical N150 HGA in mixed mode. This dongle is identical to the TP-Link TL-WN722N v1.x and requires the usage of patched drivers and firmware. This is one of the most well-tested dongles, but it's hard to get. That's why I now recommend the AWUS036ACM instead.
The Intel 3160 and 8265 are supported and extensively tested. Sometimes their firmware crashed but a reboot makes the network card usable again. The Intel AX200 is not compatible with the test tool.
The WN111v2 seems to work well, although I did not test it extensively.
The driver for the AWUS036ACH is not part of the Linux kernel and requires the installation of a separate driver. On Kali you can install this driver through the package manager. This card was not extensivly tested.
If you are unable to find one of the above network cards, you can search for alternative network cards that have a high chance of also working. When using a network card that is not explicitly supported I strongly recommend to first run the injection tests before using it, and using the tool against a known-vulnerable implementation to confirm the tool works properly.
The test tool was tested on Ubuntu 20.04 using kernel 5.8. If you use another Linux distribution, please note that only kernel versions below or equal to 5.12 are supported.
When using Ubuntu 20.04 you will first have to install kernel 5.8 as follows. Note that your existing kernel will keep being installed and will also keep being used by default:
sudo apt install linux-image-5.8.0-63-generic linux-headers-5.8.0-63-generic linux-hwe-5.8-headers-5.8.0-63 \
linux-modules-5.8.0-63-generic linux-modules-extra-5.8.0-63-generic
Now reboot Ubuntu, hold the shift key while booting, select "Advanced options for Ubuntu", and then start kernel 5.8 by picking "Ubuntu, with Linux 5.8.0-63-generic". You can edit your GRUB config so Ubuntu will use this kernel version by default. Continue the next instructions under this now-running kernel.
Install the required dependencies:
sudo apt-get update
sudo apt-get install libnl-3-dev libnl-genl-3-dev libnl-route-3-dev libssl-dev \
libdbus-1-dev git pkg-config build-essential macchanger net-tools python3-venv \
aircrack-ng rfkill firmware-ath9k-htc
# Note: on Kali linux use the package firmware-atheros instead of firmware-ath9k-htc
Now clone this repository, build the tools, and configure a virtual python3 environment:
git clone https://github.com/vanhoefm/fragattacks.git fragattacks
cd fragattacks/research
./build.sh
./pysetup.sh
The above instructions only have to be executed once. After pulling in new code using git you do
have to execute ./build.sh and ./pysetup.sh again.