https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • Complete 2023 MSP 501 Rankings
    • 2023 MSP 501 50-1
    • 2023 MSP 501 100-51
    • 2023 MSP 501 150-101
    • 2023 MSP 501 200-151
    • 2023 MSP 501 250-201
    • 2023 MSP 501 300-251
    • 2023 MSP 501 350-301
    • 2023 MSP 501 400-351
    • 2023 MSP 501 450-401
    • 2023 MSP 501 501-451
    • NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Channel Futures 20: Top Tech Providers
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2023 MSP 501
    • 2023 NextGen 101
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2024 CP Expo Call for Speakers
    • Channel Futures Leadership Summit
    • MSP Summit
    • CP Conference & Expo
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • Complete 2023 MSP 501 Rankings
    • 2023 MSP 501 50-1
    • 2023 MSP 501 100-51
    • 2023 MSP 501 150-101
    • 2023 MSP 501 200-151
    • 2023 MSP 501 250-201
    • 2023 MSP 501 300-251
    • 2023 MSP 501 350-301
    • 2023 MSP 501 400-351
    • 2023 MSP 501 450-401
    • 2023 MSP 501 501-451
    • NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Channel Futures 20: Top Tech Providers
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2023 MSP 501
    • 2023 NextGen 101
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2024 CP Expo Call for Speakers
    • Channel Futures Leadership Summit
    • MSP Summit
    • CP Conference & Expo
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

Malicious hacker at computer with code

FragAttacks Wi-Fi Vulnerabilities Pose Widespread Threat to Individuals, Businesses

  • Written by Edward Gately
  • May 13, 2021
Potential damage could include denial of service, information leakage and to some extent exfiltration.

FragAttacks, a new set of Wi-Fi vulnerabilities, can be exploited to steal user information or attack devices. And every Wi-Fi is affected by by at least one vulnerability.

That’s according to Malwarebytes Labs, which issued a report on the Wi-Fi vulnerabilities. They are mostly in how Wi-Fi and connected devices handle data packets; specifically, how they handle fragments and frames of data packets.

FragAttacks is short for fragmentation and aggregation attacks. Mathy Vanhoef, a Belgian researcher, discovered the vulnerabilities dating back to 1997. He launched a website providing details.

“Three of the discovered vulnerabilities are design flaws in the Wi-Fi standard and therefore affect most devices,” he writes. “On top of this, several other vulnerabilities were discovered that are caused by widespread programming mistakes in Wi-Fi products. Experiments indicate that every Wi-Fi product is affected by at least one vulnerability and that most products are affected by several vulnerabilities.”

All Types of Wi-Fi Affected

Keatron Evans is principal security researcher at Infosec. He’s been responding to emails from individuals panicking over the Wi-Fi vulnerabilities.

Infosec's Keatron Evans

Infosec’s Keatron Evans

“FragAttacks vulnerabilities range from somewhat benign, to what most of us would consider medium-to-severe-level vulnerabilities,” he said. “They affect all types of Wi-Fi because the vulnerabilities exist in the protocols that we use to communicate over Wi-Fi and not any individual device or software. Anyone who uses Wi-Fi devices can be impacted by FragAttacks.”

There should be moderate concern for organizations that use Wi-Fi in the office, and concern about employees using Wi-Fi at home, Evans said.

“Concerns include information leakage with potential for exfiltrating some packets and frames from even protected networks,” he said. “But it’s a long way from opening up devices and networks to something as devastating as remote code execution. It’s possible, but so difficult that we may not see [an] effort in trying to build it out to that level of exploitability.”

Potential damage could include denial of service, information leaks, and to some extent, exfiltration, Evans said.

“Keep in mind, though, most of these vulnerabilities are also known risks of just using wireless in general,” he said.

Definite Danger

There is definitely some danger to businesses and individuals, Evans said.

“Individuals may be more at risk than businesses because individuals are less likely to be using enterprise-level security and controls, and are more likely to be using clear text communications on their wireless networks at home,” he said. “They are also more likely to run unpatched or out-of-date operating systems and software.”

Businesses and individuals need to stay vigilant on all security 101 best practices, Evans said. These include:

  • Keep software and systems patched and up to date. Even if you don’t think you need the updates, apply them anyway. This advice has different implications following the recent SolarWinds incident. But you should still install updates, just with more caution.
  • Only use Wi-Fi internally where it makes business sense. And minimize how often employees use public uncontrolled Wi-Fi such as coffee shops, hotels, airports, etc. These public hotspots are actually the perfect playgrounds to exploit these vulnerabilities.
  • Educate yourself and the workforce on computing securely and using secure Wi-Fi at home.
Tags: MSPs VARs/SIs Mobility & Wireless Best Practices Cloud MSSP Insider Security

Most Recent


  • 2023 Kaseya DattoCon logo
    Kaseya Intros AI Bots, Credit for Unused Appliances, Passive Recurring Revenue
    Kaseya CEO Fred Voccola kicks off DattoCon with partner updates, new products and a litter of AI bots
  • Boomi GPT debuts
    Boomi GPT First Offering in Company's New AI Suite
    Boomi announced its AI suite this past summer.
  • women leaders in tech
    Women Leaders in Tech Are Challenged to Find Balance
    Can women really have it all? And if so, how do they do it? Gilli Aliotti has the answers.
  • Schneider Electric among Canalys sustainability champions
    Canalys Names HP, Lenovo, Schneider Electric as Sustainability Champions
    The leadership matrix also lists contenders, scalers and foundation vendors.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Malicious hacker group
    Big Hack Takes Financial Toll On SolarWinds MSP Spinoff N-Able
  • College classroom
    Community College Ransomware Attack Wreaks Havoc
  • White House
    White House to Private Sector SMEs: Get Serious About Cybersecurity
  • zero trust security
    Leveraging Partner Expertise to Build a Zero-Trust Strategy

Upcoming Events

View all

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Channel Partners Conference & Expo

March 11, 2024 - March 14, 2024

Channel Futures Leadership Summit 2024

September 17, 2024 - September 19, 2024

Galleries

View all

Channel People on the Move: HP, 8×8, Five9, Nitel, RapidScale, More

October 3, 2023

7 Trends Impacting Ingram Micro Partners: Marriage of AI, Data Looms Large

October 2, 2023

Nutanix Partner Program Sees More Changes, Vendor Touts ‘Channel-Led’

October 2, 2023

Industry Perspectives

View all

Partners Balance Multicloud Opportunity, Complexity

September 25, 2023

Why Conversational AI Matters for Your Customers and How It Can Boost Your Revenue

September 15, 2023

The 5 Ds that Lead to Unplanned Business Sales

September 13, 2023

Webinars

View all

MSP 501: Leadership in Cybersecurity

October 19, 2023

DE&I: Find the Balance that Works for You

September 7, 2023

Above and Beyond with the NextGen 101ers

August 30, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 129: ZLH Enterprises

Coffee with Craig and James Episode 128: Channel Partner Strategies Intelligence Service

August 25, 2023

Coffee with Craig and James Episode 127: Expereo, Movie Night Returns

August 18, 2023

Coffee with Craig and James Episode 126: ARG

July 28, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X