<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=KBeboso</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=KBeboso"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/KBeboso"/>
	<updated>2026-09-10T16:20:28Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Evil_Twin_Attack_using_Captive_Portal&amp;diff=9740</id>
		<title>WiFi Pineapple Mark VII: Evil Twin Attack using Captive Portal</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Evil_Twin_Attack_using_Captive_Portal&amp;diff=9740"/>
		<updated>2022-01-31T15:27:34Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
EvilPortal is a captive portal tool for the Wi-Fi Pineapple. It allows users to easily setup landing pages that are automatically displayed to clients who connect. In this guide, we will be using the Pineapple Mark VII to set up the Evil Portal module. This module is used for capturing victim devices, by using a rouge access point and fake login page:&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site.&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[Wi-Fi Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* This project requires you to install Evil Portal captive portal module created by frozenjava. To install on the Pineapple, go to Modules → Manage Modules → Get Modules from Hak5 Community Repositories → Evil Portal 3.2.&lt;br /&gt;
&lt;br /&gt;
* Evil Portals &amp;lt;ref&amp;gt;https://github.com/kleo/evilportals&amp;lt;/ref&amp;gt; is a collection of portals that can be loaded into the Evil Portal module. It can be used for phishing attacks against Wi-Fi clients to obtain credentials or infect the victims with malware using the Hak5 Wi-Fi Pineapple Mark VII.&lt;br /&gt;
&lt;br /&gt;
== Features ==&lt;br /&gt;
&lt;br /&gt;
* Targeted Portals&lt;br /&gt;
* Static Portals&lt;br /&gt;
* Creating/Editing/Activating/Deleting Portals&lt;br /&gt;
* White listings clients by ip address&lt;br /&gt;
* Dynamically adding and revoking authorized clients&lt;br /&gt;
* Live Preview of your portal through the module interface&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1  (Download Module) ===&lt;br /&gt;
&lt;br /&gt;
* First, we will open a browser. In the URL box, we will type 172.16.42.1:1471 to access the login interface for the Pineapple:&lt;br /&gt;
* After Login, we will be brought to the dashboard interface page. Select the Modules tab from the menu on the left side of the screen.&lt;br /&gt;
* Then click on Manage Modules.&lt;br /&gt;
* Next, click on Get Modules at the top of the screen. The following screenshot displays the screen you should be seeing in this step:&lt;br /&gt;
* Select the Evil Portal module.&lt;br /&gt;
* After you click on Evil Portal under the Modules tab (left side of screen), you will see the interface page for the module. (The following screenshot displays the interface page for the Evil Portal module):&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Create &amp;amp; Activate Portal)===&lt;br /&gt;
&lt;br /&gt;
* Download Evil Portals and upload it on to the Pineapple Mark VII Device via SFTP &amp;lt;code&amp;gt;sftp://root@172.16.42.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Now choose a given template, and we will start the portal by clicking Activate, located to the right of Portal Name. After you have clicked Activate, you will click Start in the Controls tab located toward the top left of the screen (the screenshot from Step 3 also displays where the start button is located).&lt;br /&gt;
&lt;br /&gt;
* Next, we will click on the Live Preview tab, located towards the bottom of the screen. We see the default Evil Portal page, which is the page our simulated victim will log in to when connecting through our rouge access point. Furthermore, the Evil Portal page can be customized to anything you want. For this lab, we will use the default page. We advise caution when cloning other landing pages to use as the Evil Portal page. The following screenshot displays what the Evil Portal default page looks like:&lt;br /&gt;
&lt;br /&gt;
* The final step is to see what a simulated victim looks like when they connect to the Evil Portal page. The victim device connects to the rogue access point the Pineapple is broadcasting. Once the victim connects, they will be presented with the Evil Portal default page, simulating a Wi-Fi landing page. The victim will click Authorize by entering E-Mail and Password and then will show up under the Authorized Clients tab, displaying the victim&#039;s IP. At this point, other modules can be used to launch a MITM attack by using modules like SSLsplit. In the Portal  next to the template, you can retrieve email and password by opening the log file. &lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Evil_Twin_Attack_using_Captive_Portal&amp;diff=9559</id>
		<title>WiFi Pineapple Mark VII: Evil Twin Attack using Captive Portal</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Evil_Twin_Attack_using_Captive_Portal&amp;diff=9559"/>
		<updated>2022-01-23T22:46:07Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
EvilPortal is a captive portal tool for the Wi-Fi Pineapple. It allows users to easily setup landing pages that are automatically displayed to clients who connect. In this guide, we will be using the Pineapple Mark VII to set up the Evil Portal module. This module is used for capturing victim devices, by using a rouge access point and fake login page:&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site.&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[Wi-Fi Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* This project requires you to install Evil Portal captive portal module created by frozenjava. To install on the Pineapple, go to Modules → Manage Modules → Get Modules from Hak5 Community Repositories → Evil Portal 3.2.&lt;br /&gt;
&lt;br /&gt;
* Evil Portals &amp;lt;ref&amp;gt;https://github.com/kleo/evilportals&amp;lt;/ref&amp;gt; is a collection of portals that can be loaded into the Evil Portal module. It can be used for phishing attacks against Wi-Fi clients to obtain credentials or infect the victims with malware using the Hak5 Wi-Fi Pineapple Mark VII.&lt;br /&gt;
&lt;br /&gt;
== Features ==&lt;br /&gt;
&lt;br /&gt;
* Targeted Portals&lt;br /&gt;
* Static Portals&lt;br /&gt;
* Creating/Editing/Activating/Deleting Portals&lt;br /&gt;
* White listings clients by ip address&lt;br /&gt;
* Dynamically adding and revoking authorized clients&lt;br /&gt;
* Live Preview of your portal through the module interface&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1  (Download Module) ===&lt;br /&gt;
&lt;br /&gt;
* First, we will open a browser. In the URL box, we will type 172.16.42.1:1471 to access the login interface for the Pineapple:&lt;br /&gt;
* After Login, we will be brought to the dashboard interface page. Select the Modules tab from the menu on the left side of the screen.&lt;br /&gt;
* Then click on Manage Modules.&lt;br /&gt;
* Next, click on Get Modules at the top of the screen. The following screenshot displays the screen you should be seeing in this step:&lt;br /&gt;
* Select the Evil Portal module.&lt;br /&gt;
* After you click on Evil Portal under the Modules tab (left side of screen), you will see the interface page for the module. (The following screenshot displays the interface page for the Evil Portal module):&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Create &amp;amp; Activate Portal)===&lt;br /&gt;
&lt;br /&gt;
* Download Evil Portals and upload it on to the Pineapple Mark VII Device via SFTP &amp;lt;code&amp;gt;sftp://root@172.16.42.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Now choose a given template, and we will start the portal by clicking Activate, located to the right of Portal Name. After you have clicked Activate, you will click Start in the Controls tab located toward the top left of the screen (the screenshot from Step 3 also displays where the start button is located).&lt;br /&gt;
&lt;br /&gt;
* Next, we will click on the Live Preview tab, located towards the bottom of the screen. We see the default Evil Portal page, which is the page our simulated victim will log in to when connecting through our rouge access point. Furthermore, the Evil Portal page can be customized to anything you want. For this lab, we will use the default page. We advise caution when cloning other landing pages to use as the Evil Portal page. The following screenshot displays what the Evil Portal default page looks like:&lt;br /&gt;
&lt;br /&gt;
* The final step is to see what a simulated victim looks like when they connect to the Evil Portal page. The victim device connects to the rogue access point the Pineapple is broadcasting. Once the victim connects, they will be presented with the Evil Portal default page, simulating a Wi-Fi landing page. The victim will click Authorize by entering E-Mail and Password and then will show up under the Authorized Clients tab, displaying the victim&#039;s IP. At this point, other modules can be used to launch a MITM attack by using modules like SSLsplit. In the Portal  next to the template, you can retrieve email and password by opening the log file. &lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9558</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9558"/>
		<updated>2022-01-23T22:27:10Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Dictionary Attack) ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Brut Force Attack) ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9557</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9557"/>
		<updated>2022-01-23T22:26:32Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9556</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9556"/>
		<updated>2022-01-23T22:23:28Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9555</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9555"/>
		<updated>2022-01-23T21:59:18Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
In this method we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default wifi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research you figured out that the default wifi password is an 8 digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now the cracking process may take a while depending on your processor speed but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFI_Pineapple_Mark_VII:_Initial_Setup&amp;diff=9554</id>
		<title>WiFI Pineapple Mark VII: Initial Setup</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFI_Pineapple_Mark_VII:_Initial_Setup&amp;diff=9554"/>
		<updated>2022-01-23T21:56:01Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: KBeboso moved page WiFI Pineapple Mark VII: Initial Setup to Wi-Fi Pineapple Mark VII: Initial Setup&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[Wi-Fi Pineapple Mark VII: Initial Setup]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wi-Fi_Pineapple_Mark_VII:_Initial_Setup&amp;diff=9553</id>
		<title>Wi-Fi Pineapple Mark VII: Initial Setup</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wi-Fi_Pineapple_Mark_VII:_Initial_Setup&amp;diff=9553"/>
		<updated>2022-01-23T21:56:01Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: KBeboso moved page WiFI Pineapple Mark VII: Initial Setup to Wi-Fi Pineapple Mark VII: Initial Setup&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Hak5 WiFi Pineapple is a highly advanced WiFi auditing and MITM platform. The original &amp;quot;RougeAP&amp;quot; device - the WiFi Pineapple provides an end-to-end workflow to bring WiFi clients from their trusted network to your rouge network.&lt;br /&gt;
&lt;br /&gt;
The Wi-Fi Pineapple is a wireless auditing platform from Hak5 that allows network security administrators to conduct penetration tests. Pen tests are a type of ethical hacking in which white hat hackers seek out security vulnerabilities that a black hat attacker could exploit. The labels white hat and black hat are derived from old-time Western movies in which the good guys wore white hats and the bad guys wore black hats.&lt;br /&gt;
&lt;br /&gt;
The Wi-Fi Pineapple can also be used as a rogue access point (AP) to conduct man in the middle (MitM) attacks. A MiTM attack is one in which the attacker secretly intercepts and relays messages between two parties that believe they are communicating directly with each other. The inexpensive price and friendly user interface (UI) enable attackers with little technical knowledge to eavesdrop on computing devices using public Wi-Fi networks in order to collect sensitive personal information, including passwords.&lt;br /&gt;
&lt;br /&gt;
When a Pineapple is used for pen testing, it is referred to as a honeypot. When a Pineapple is used as a rogue AP to conduct MitM security exploits, it is referred to as an evil twin or pineapple sandwich.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
[[WiFI Pineapple Mark VII: Cracking Wifi Password]]&lt;br /&gt;
&lt;br /&gt;
[[WiFI Pineapple Mark VII: Man in The Middle]]&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:mark7.png]]&lt;br /&gt;
&lt;br /&gt;
== Setup Basics ==&lt;br /&gt;
&lt;br /&gt;
To begin setting up the WiFi Pineapple Mark VII, you will first need to assemble the unit by attaching the included antennas. The antennas screw onto the RP-SMA ports around the device. Then, decide if you will be setting up the device by WiFi, by USB Ethernet, or by USB Flash Disk.&lt;br /&gt;
&lt;br /&gt;
=== Setup by WiFI ===&lt;br /&gt;
&lt;br /&gt;
1. Power the WiFi Pineapple Mark VII using the included cable and a 2-Amp USB power source. The light will begin blinking blue. When the light shows solid blue, the device is ready to setup.&lt;br /&gt;
&lt;br /&gt;
2. Using a computer or smartphone, connect to the WiFi Pineapple&#039;s open wireless network, named &amp;quot;Pineapple_XXXX&amp;quot; (where XXXX are the last 4 characters of the device&#039;s MAC address).&lt;br /&gt;
&lt;br /&gt;
3. Once connected to the wireless network, open a web browser to http://172.16.42.1:1471 and follow the on-screen instructions. The setup wizard will prompt you to connect the WiFi Pineapple to a wireless network, from which it will download and install the latest version of the WiFi Pineapple software. This process typically takes about 10 minutes—during which time it is important to keep the device plugged in and powered on.&lt;br /&gt;
&lt;br /&gt;
=== Setup by USB Ethernet ===&lt;br /&gt;
&lt;br /&gt;
The WiFi Pineapple Mark VII contains a built-in USB Ethernet adapter from the USB-C port. With this port, you can access the WiFi Pineapple LAN without needing a Cat6 Ethernet cable and RJ45 port.&lt;br /&gt;
&lt;br /&gt;
1. Connect the WiFi Pineapple Mark VII to a computer using the included USB cable. For Windows and Linux computers, the ASIX AX88772C USB Ethernet adapter drivers should install automatically. Mac OS Catalina and above may not install the driver automatically. If necessary, install the driver from the ASIX driver download page for the AX88772C.&lt;br /&gt;
&lt;br /&gt;
2.Once the WiFi Pineapple is connected to the computer, it will enumerate as a USB Ethernet adapter and that interface should receive an IP address from the WiFi Pineapple via DHCP in the 172.16.42.0/24 range.&lt;br /&gt;
&lt;br /&gt;
3.Open a web browser to http://172.16.42.1:1471 and follow the on-screen instructions. The setup wizard will prompt you to connect the WiFi Pineapple to a wireless network, from which it will download and install the latest version of the WiFi Pineapple software. This process typically takes about 10 minutes—during which time it is important to keep the device plugged in and powered on.&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360004116253-WiFi-Pineapple-Mark-VII&lt;br /&gt;
* https://elvis.science/?w=WiFi_Pineapple_Mark_VII&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFI_Pineapple_Mark_VII:_Man_in_The_Middle&amp;diff=9552</id>
		<title>WiFI Pineapple Mark VII: Man in The Middle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFI_Pineapple_Mark_VII:_Man_in_The_Middle&amp;diff=9552"/>
		<updated>2022-01-23T21:43:09Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: KBeboso moved page WiFI Pineapple Mark VII: Man in The Middle to WiFI Pineapple Mark VII: Evil Twin Attack using Captive Portal&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[WiFI Pineapple Mark VII: Evil Twin Attack using Captive Portal]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Evil_Twin_Attack_using_Captive_Portal&amp;diff=9551</id>
		<title>WiFi Pineapple Mark VII: Evil Twin Attack using Captive Portal</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Evil_Twin_Attack_using_Captive_Portal&amp;diff=9551"/>
		<updated>2022-01-23T21:43:09Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: KBeboso moved page WiFI Pineapple Mark VII: Man in The Middle to WiFI Pineapple Mark VII: Evil Twin Attack using Captive Portal&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Description what this documentation is about.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Packages: git emacs&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Device to be used with this documentation]]&lt;br /&gt;
[[Maybe another device to be used with this documentation]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFI_Pineapple_Mark_VII:_Cracking_Wi-Fi_Password&amp;diff=9550</id>
		<title>WiFI Pineapple Mark VII: Cracking Wi-Fi Password</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFI_Pineapple_Mark_VII:_Cracking_Wi-Fi_Password&amp;diff=9550"/>
		<updated>2022-01-23T21:41:13Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: KBeboso moved page WiFI Pineapple Mark VII: Cracking Wi-Fi Password to WiFI Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut force attack&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[WiFI Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut force attack]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9549</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9549"/>
		<updated>2022-01-23T21:41:13Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: KBeboso moved page WiFI Pineapple Mark VII: Cracking Wi-Fi Password to WiFI Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut force attack&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
== Mandatory ==&lt;br /&gt;
=== GNU/Linux ===&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
== Optional ==&lt;br /&gt;
=== Hashcat ===&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
In this method we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default wifi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research you figured out that the default wifi password is an 8 digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now the cracking process may take a while depending on your processor speed but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFI_Pineapple_Mark_VII:_Cracking_Wifi_Password&amp;diff=9548</id>
		<title>WiFI Pineapple Mark VII: Cracking Wifi Password</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFI_Pineapple_Mark_VII:_Cracking_Wifi_Password&amp;diff=9548"/>
		<updated>2022-01-23T18:47:17Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: KBeboso moved page WiFI Pineapple Mark VII: Cracking Wifi Password to WiFI Pineapple Mark VII: Cracking Wi-Fi Password&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[WiFI Pineapple Mark VII: Cracking Wi-Fi Password]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9547</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9547"/>
		<updated>2022-01-23T18:47:17Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: KBeboso moved page WiFI Pineapple Mark VII: Cracking Wifi Password to WiFI Pineapple Mark VII: Cracking Wi-Fi Password&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
== Mandatory ==&lt;br /&gt;
=== GNU/Linux ===&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
== Optional ==&lt;br /&gt;
=== Hashcat ===&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
In this method we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default wifi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research you figured out that the default wifi password is an 8 digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now the cracking process may take a while depending on your processor speed but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9546</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9546"/>
		<updated>2022-01-23T18:44:32Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
== Mandatory ==&lt;br /&gt;
=== GNU/Linux ===&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
== Optional ==&lt;br /&gt;
=== Hashcat ===&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
In this method we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default wifi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research you figured out that the default wifi password is an 8 digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now the cracking process may take a while depending on your processor speed but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9545</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9545"/>
		<updated>2022-01-23T18:38:37Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
== Mandatory ==&lt;br /&gt;
=== GNU/Linux ===&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
== Optional ==&lt;br /&gt;
=== Hashcat ===&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9544</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9544"/>
		<updated>2022-01-23T17:56:52Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
== Mandatory ==&lt;br /&gt;
=== GNU/Linux ===&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
== Optional ==&lt;br /&gt;
=== Hashcat ===&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
[[File:Deauth.png|500px]]&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Deauth.png&amp;diff=9543</id>
		<title>File:Deauth.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Deauth.png&amp;diff=9543"/>
		<updated>2022-01-23T17:51:40Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9542</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9542"/>
		<updated>2022-01-23T17:51:23Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
== Mandatory ==&lt;br /&gt;
=== GNU/Linux ===&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
== Optional ==&lt;br /&gt;
=== Hashcat ===&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&#039;&#039;Italic text&#039;&#039;[[File:Example.jpg]]&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9541</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=9541"/>
		<updated>2022-01-23T17:44:35Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
== Mandatory ==&lt;br /&gt;
=== GNU/Linux ===&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
== Optional ==&lt;br /&gt;
=== Hashcat ===&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8123</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8123"/>
		<updated>2021-12-05T23:34:07Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* The CBC/CFB-Gadget-Attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL &amp;lt;ref&amp;gt;https://www.efail.de/&amp;lt;/ref&amp;gt; attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
In this dokumentation will will concentrate on the three official CVE numbers for the CBC/CFB gadget attacks:&lt;br /&gt;
&lt;br /&gt;
* CVE-2017-17688: OpenPGP CFB gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17688&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2017-17689: S/MIME CBC gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17689&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2019-14664: Direct Exfiltration &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14664&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There are more vulnerabilities that target the OpenPGP protocol&#039;s specifications. Some OpenPGP implementations may be broken as a result of this public certificate poisoning. CVE-2019-13050 is another name for this vulnerability: PGP Keyservers are being targeted for certificate spamming attacks.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil1.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil2.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil3.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.&amp;lt;ref&amp;gt;https://www.usenix.org/conference/usenixsecurity18/presentation/poddebniak&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME&amp;lt;ref&amp;gt;https://efail.de/media/img/smime-attack.png&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
to prevent E-Fail attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
== Courses ==&lt;br /&gt;
Ausgewählte Kapitel der IT-Security ILV&lt;br /&gt;
== References ==&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8122</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8122"/>
		<updated>2021-12-05T23:33:49Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Mitigations */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL &amp;lt;ref&amp;gt;https://www.efail.de/&amp;lt;/ref&amp;gt; attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
In this dokumentation will will concentrate on the three official CVE numbers for the CBC/CFB gadget attacks:&lt;br /&gt;
&lt;br /&gt;
* CVE-2017-17688: OpenPGP CFB gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17688&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2017-17689: S/MIME CBC gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17689&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2019-14664: Direct Exfiltration &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14664&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There are more vulnerabilities that target the OpenPGP protocol&#039;s specifications. Some OpenPGP implementations may be broken as a result of this public certificate poisoning. CVE-2019-13050 is another name for this vulnerability: PGP Keyservers are being targeted for certificate spamming attacks.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil1.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil2.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil3.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.&amp;lt;ref&amp;gt;https://www.usenix.org/conference/usenixsecurity18/presentation/poddebniak&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME&amp;lt;ref&amp;gt;https://efail.de/media/img/smime-attack.png&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
to prevent E-Fail attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
== Courses ==&lt;br /&gt;
Ausgewählte Kapitel der IT-Security ILV&lt;br /&gt;
== References ==&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8121</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8121"/>
		<updated>2021-12-05T23:32:02Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL &amp;lt;ref&amp;gt;https://www.efail.de/&amp;lt;/ref&amp;gt; attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
In this dokumentation will will concentrate on the three official CVE numbers for the CBC/CFB gadget attacks:&lt;br /&gt;
&lt;br /&gt;
* CVE-2017-17688: OpenPGP CFB gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17688&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2017-17689: S/MIME CBC gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17689&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2019-14664: Direct Exfiltration &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14664&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There are more vulnerabilities that target the OpenPGP protocol&#039;s specifications. Some OpenPGP implementations may be broken as a result of this public certificate poisoning. CVE-2019-13050 is another name for this vulnerability: PGP Keyservers are being targeted for certificate spamming attacks.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil1.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil2.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil3.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.&amp;lt;ref&amp;gt;https://www.usenix.org/conference/usenixsecurity18/presentation/poddebniak&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME&amp;lt;ref&amp;gt;https://efail.de/media/img/smime-attack.png&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
== Courses ==&lt;br /&gt;
Ausgewählte Kapitel der IT-Security ILV&lt;br /&gt;
== References ==&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8120</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8120"/>
		<updated>2021-12-05T23:29:54Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL &amp;lt;ref&amp;gt;https://www.efail.de/&amp;lt;/ref&amp;gt; attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
In this dokumentation will will concentrate on the three official CVE numbers for the CBC/CFB gadget attacks:&lt;br /&gt;
&lt;br /&gt;
* CVE-2017-17688: OpenPGP CFB gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17688&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2017-17689: S/MIME CBC gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17689&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2019-14664: Direct Exfiltration &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14664&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There are more vulnerabilities that target the OpenPGP protocol&#039;s specifications. Some OpenPGP implementations may be broken as a result of this public certificate poisoning. CVE-2019-13050 is another name for this vulnerability: PGP Keyservers are being targeted for certificate spamming attacks.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil1.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil2.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text&amp;lt;ref&amp;gt;https://efail.de/media/img/exfil3.png&amp;lt;/ref&amp;gt;]] &lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
== Courses ==&lt;br /&gt;
Ausgewählte Kapitel der IT-Security ILV&lt;br /&gt;
== References ==&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8119</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8119"/>
		<updated>2021-12-05T23:27:39Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* References */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL &amp;lt;ref&amp;gt;https://www.efail.de/&amp;lt;/ref&amp;gt; attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
In this dokumentation will will concentrate on the three official CVE numbers for the CBC/CFB gadget attacks:&lt;br /&gt;
&lt;br /&gt;
* CVE-2017-17688: OpenPGP CFB gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17688&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2017-17689: S/MIME CBC gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17689&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2019-14664: Direct Exfiltration &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14664&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There are more vulnerabilities that target the OpenPGP protocol&#039;s specifications. Some OpenPGP implementations may be broken as a result of this public certificate poisoning. CVE-2019-13050 is another name for this vulnerability: PGP Keyservers are being targeted for certificate spamming attacks.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text]]&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
== Courses ==&lt;br /&gt;
Ausgewählte Kapitel der IT-Security ILV&lt;br /&gt;
== References ==&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8118</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8118"/>
		<updated>2021-12-05T23:27:06Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Summary */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL &amp;lt;ref&amp;gt;https://www.efail.de/&amp;lt;/ref&amp;gt; attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
In this dokumentation will will concentrate on the three official CVE numbers for the CBC/CFB gadget attacks:&lt;br /&gt;
&lt;br /&gt;
* CVE-2017-17688: OpenPGP CFB gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17688&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2017-17689: S/MIME CBC gadget attacks &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17689&amp;lt;/ref&amp;gt;&lt;br /&gt;
* CVE-2019-14664: Direct Exfiltration &amp;lt;ref&amp;gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14664&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There are more vulnerabilities that target the OpenPGP protocol&#039;s specifications. Some OpenPGP implementations may be broken as a result of this public certificate poisoning. CVE-2019-13050 is another name for this vulnerability: PGP Keyservers are being targeted for certificate spamming attacks.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text]]&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
== Courses ==&lt;br /&gt;
Ausgewählte Kapitel der IT-Security ILV&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8117</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8117"/>
		<updated>2021-12-05T23:17:48Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
In this dokumentation will will concentrate on the three official CVE numbers for the CBC/CFB gadget attacks:&lt;br /&gt;
&lt;br /&gt;
* CVE-2017-17688: OpenPGP CFB gadget attacks&lt;br /&gt;
* CVE-2017-17689: S/MIME CBC gadget attacks&lt;br /&gt;
* CVE-2019-14664: Direct Exfiltration&lt;br /&gt;
&lt;br /&gt;
There are more vulnerabilities that target the OpenPGP protocol&#039;s specifications. Some OpenPGP implementations may be broken as a result of this public certificate poisoning. CVE-2019-13050 is another name for this vulnerability: PGP Keyservers are being targeted for certificate spamming attacks.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text]]&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
== Courses ==&lt;br /&gt;
Ausgewählte Kapitel der IT-Security ILV&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8116</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8116"/>
		<updated>2021-12-05T23:11:31Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Summary */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
In this dokumentation will will concentrate on the three official CVE numbers for the CBC/CFB gadget attacks:&lt;br /&gt;
&lt;br /&gt;
* CVE-2017-17688: OpenPGP CFB gadget attacks&lt;br /&gt;
* CVE-2017-17689: S/MIME CBC gadget attacks&lt;br /&gt;
* CVE-2019-14664: Direct Exfiltration&lt;br /&gt;
&lt;br /&gt;
There are more vulnerabilities that target the OpenPGP protocol&#039;s specifications. Some OpenPGP implementations may be broken as a result of this public certificate poisoning. CVE-2019-13050 is another name for this vulnerability: PGP Keyservers are being targeted for certificate spamming attacks.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text]]&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8115</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8115"/>
		<updated>2021-12-05T23:11:24Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Summary */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
In this dokumentation will will concentrate on the three official CVE numbers for the CBC/CFB gadget attacks:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* CVE-2017-17688: OpenPGP CFB gadget attacks&lt;br /&gt;
* CVE-2017-17689: S/MIME CBC gadget attacks&lt;br /&gt;
* CVE-2019-14664: Direct Exfiltration&lt;br /&gt;
&lt;br /&gt;
There are more vulnerabilities that target the OpenPGP protocol&#039;s specifications. Some OpenPGP implementations may be broken as a result of this public certificate poisoning. CVE-2019-13050 is another name for this vulnerability: PGP Keyservers are being targeted for certificate spamming attacks.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text]]&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8114</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8114"/>
		<updated>2021-12-05T23:09:31Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Direct Exfiltration Channels in Email Clients */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text]]&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8113</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8113"/>
		<updated>2021-12-05T23:07:44Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Direct Exfiltration Channels in Email Clients */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|decrypted cipher text]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8112</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8112"/>
		<updated>2021-12-05T23:06:49Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* The CBC/CFB-Gadget-Attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8111</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8111"/>
		<updated>2021-12-05T23:06:29Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Conclusion */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8110</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8110"/>
		<updated>2021-12-05T23:05:41Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Long-Term */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
12&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8109</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8109"/>
		<updated>2021-12-05T23:05:34Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Mid-Term */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
12&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8108</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8108"/>
		<updated>2021-12-05T23:05:20Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Long-Term */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
12&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8107</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8107"/>
		<updated>2021-12-05T23:01:49Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Direct Exfiltration Channels in Email Clients */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
11&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
12&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8106</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8106"/>
		<updated>2021-12-05T23:01:32Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Direct Exfiltration Channels in Email Clients */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail[[Uni21b] ]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail[[Uni21c] ]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
11&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
12&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8105</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8105"/>
		<updated>2021-12-05T23:01:13Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Direct Exfiltration Channels in Email Clients */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail[[Uni21b] ]]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail[[Uni21c] ]]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
11&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
12&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8104</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8104"/>
		<updated>2021-12-05T23:00:08Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: /* Conclusion */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
11&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
Encryption with PGP and S/MIME is not nearly as reliable as thought. Due to&lt;br /&gt;
insufficient standards, outdated technology and faulty programs, attackers could gain&lt;br /&gt;
possession of encrypted e-mails sent.&lt;br /&gt;
Neither S/MIME nor OpenPGP can sufficiently ensure the security of encrypted&lt;br /&gt;
messages sent. An attacker who intercepts and manipulates encrypted emails can&lt;br /&gt;
acquire access to at least some of the plaintext of the communication.&lt;br /&gt;
In reality, this flaw, known as ”efail,” affects all email encryption applications, rang-&lt;br /&gt;
ing from Outlook and Windows Mail to Thunderbird and Apple Mail. The situation&lt;br /&gt;
is particularly dramatic for S/MIME: it is mainly used in corporate environments, and&lt;br /&gt;
researchers finally announced that the standard is irretrievably broken. However, even&lt;br /&gt;
the basic PGP has serious problems that can be used to carry out quite targeted at-&lt;br /&gt;
tacks. However, there is hope that updates from OpenPGP extension vendors (like&lt;br /&gt;
Enigmail [MKP+17]) can alleviate this situation, at least in the medium term.&lt;br /&gt;
This article delves into the technical details of the vulnerabilities, which may be&lt;br /&gt;
seen through electronic bug assaults. The best way to protect oneself in the current&lt;br /&gt;
environment is to avoid sending very incendiary messages via email. Preventative steps&lt;br /&gt;
such as deactivating HTML display and refreshing external elements such as photos&lt;br /&gt;
can greatly reduce the severity of the problem. Messenger communications can be&lt;br /&gt;
encrypted end-to-end as a simple option. Unlike OpenPGP and S/MIME, it uses&lt;br /&gt;
cutting-edge encryption and is unaffected by current email-related difficulties. It may&lt;br /&gt;
also be used to securely transmit files. Signal’s effectiveness in managing sensitive data&lt;br /&gt;
communicated over the Internet has been demonstrated several times in practice.&lt;br /&gt;
12&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8103</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8103"/>
		<updated>2021-12-05T22:59:17Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png|200px|thumb|middle|CBC gadgets in S/MIME]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
11&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8102</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8102"/>
		<updated>2021-12-05T22:58:20Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:smime-attack.png]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
11&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8101</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8101"/>
		<updated>2021-12-05T22:57:05Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:clients.png|200px|thumb|right|Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.]]&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:Example.jpg]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
11&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Clients.png&amp;diff=8100</id>
		<title>File:Clients.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Clients.png&amp;diff=8100"/>
		<updated>2021-12-05T22:56:07Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8099</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8099"/>
		<updated>2021-12-05T22:55:31Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|middle|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
Figure 3.5: Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.&lt;br /&gt;
[PDM+18]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:Example.jpg]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
11&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8098</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8098"/>
		<updated>2021-12-05T22:55:16Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|middle|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|left|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
Figure 3.5: Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.&lt;br /&gt;
[PDM+18]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:Example.jpg]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
11&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8097</id>
		<title>E-Fail</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=E-Fail&amp;diff=8097"/>
		<updated>2021-12-05T22:54:45Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The E-FAIL attack takes use of flaws in the OpenPGP and S/MIME protocols to&lt;br /&gt;
reveal the plaintext of encrypted emails. In short, EFAIL abuses the active content in&lt;br /&gt;
HTML emails, such as externally loaded images or styles, and leaks plaintext via the&lt;br /&gt;
requested URL. To create these exfiltration channels, the attacker must first access encrypted&lt;br /&gt;
emails by, for example, eavesdropping on network traffic, destroying email accounts,&lt;br /&gt;
email servers, backup systems or client computers. These emails may even have been&lt;br /&gt;
collected many years ago. The attacker modifies the encrypted email in some way and&lt;br /&gt;
sends the modified encrypted email to the victim. The victim’s email client decrypts&lt;br /&gt;
the email and loads all external content to reveal the plaintext to the attacker.&lt;br /&gt;
&lt;br /&gt;
== Direct Exfiltration Channels in Email Clients ==&lt;br /&gt;
Direct Exfiltration attacks exploit vulnerabilities in Apple Mail, iOS Mail, and Mozilla&lt;br /&gt;
Thunderbird to directly leak the plaintext of encrypted emails. These vulnerabilities&lt;br /&gt;
can be fixed in the corresponding email client. The attacker creates a new multipart&lt;br /&gt;
email with three paragraphs of text, as shown below 3.3 . The first is a piece of HTML&lt;br /&gt;
text that is essentially an HTML image tag. Note that the src attribute of this image&lt;br /&gt;
tag is opened with quotes, not closed. The second body contains PGP or S/MIME&lt;br /&gt;
ciphertext. The third is also an HTML body part that disables the src attribute of the&lt;br /&gt;
first body part&lt;br /&gt;
[[File:exfil1.png|200px|thumb|left|Example of an E-Mail]]&lt;br /&gt;
[[File:exfil2.png|200px|thumb|left|Example of an E-Mail]]&lt;br /&gt;
&lt;br /&gt;
This email is then sent to the victim by the assailant. The client of the victim&lt;br /&gt;
decrypts the second encrypted body part and inserts the three body parts into the&lt;br /&gt;
HTML email as illustrated below. 3.4. Note that the src attribute of the image tag in&lt;br /&gt;
line 1 is disabled in line 4, so the URL includes all four lines.&lt;br /&gt;
&lt;br /&gt;
[[File:exfil3.png|200px|thumb|left|HTML-Email]]&lt;br /&gt;
&lt;br /&gt;
Then, the email client URL encodes all non-printable characters (e.g. ”20” is a&lt;br /&gt;
space) and requests the image from that URL. Because the plaintext of the encrypted&lt;br /&gt;
email is contained in the URL route, the victim’s email client delivers the plaintext to&lt;br /&gt;
the attacker. Direct exfiltration EFAIL attacks are applicable to PGP and S/MIME&lt;br /&gt;
encrypted emails.&lt;br /&gt;
&lt;br /&gt;
Figure 3.5: Vulnerable email programs to the knowledge of the security researchers&lt;br /&gt;
who discovered the Efail vulnerability.&lt;br /&gt;
[PDM+18]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The CBC/CFB-Gadget-Attack ==&lt;br /&gt;
&lt;br /&gt;
First, we’ll go through the new CBC/CFB gadget attacks, which take use of flaws&lt;br /&gt;
in the OpenPGP and S/MIME specifications to steal plaintext.The concept of CBC&lt;br /&gt;
gadget in S/MIME is depicted in the diagram below. An attacker can precisely edit&lt;br /&gt;
plaintext blocks if they know the plaintext due to the characteristics of the CBC&lt;br /&gt;
mode of operation. As seen in 3.1 (a), S/MIME-encrypted emails frequently begin&lt;br /&gt;
with ”Content type: multipart/signed,” indicating that the attacker has at least one&lt;br /&gt;
complete plaintext block. It can then create a canonical plaintext block with zeros as&lt;br /&gt;
its content, as seen in 3.1 (b). The block pair X and C 0a is referred to as a CBC&lt;br /&gt;
device. It then appends CBC gadgets to the encrypted plaintext to insert an image&lt;br /&gt;
tag in step 3.1 (c). When the user opens the attacker email, this creates a single piece&lt;br /&gt;
of encrypted text that exfiltrates its own plaintext. OpenPGP employs the CFB mode&lt;br /&gt;
of operation, which has cryptographic features that are extremely similar to CBC and&lt;br /&gt;
allows the same attack to be carried out with CFB gadgets.&lt;br /&gt;
The distinction is that any standard-conforming client will be vulnerable, and each&lt;br /&gt;
vendor will be free to devise their own mitigations, which may or may not prevent the&lt;br /&gt;
attacks. As a result, it will be important to update the specification in the long run&lt;br /&gt;
in order to uncover and record changes that address the underlying primary causes of&lt;br /&gt;
the vulnerabilities.&lt;br /&gt;
[[File:Example.jpg]]&lt;br /&gt;
&lt;br /&gt;
Despite the fact that the CBC/CFB gadget attacks on PGP and S/MIME are&lt;br /&gt;
theoretically similar, the conditions for a successful attack differ significantly. Attacking&lt;br /&gt;
S/MIME is simple, because by sending a single designed S/MIME email to the target,&lt;br /&gt;
an attacker can break several (in our experiments, up to 500) S/MIME encrypted&lt;br /&gt;
emails. Modern OpenPGP implementations, unlike S/MIME, include a Modification&lt;br /&gt;
Detection Code (MDC) that may identify modified plaintexts and so prevent the CFB&lt;br /&gt;
gadget attack. However, we discovered that several clients only displayed the updated&lt;br /&gt;
plaintext after issuing a warning to the user for invalid MDCs.&lt;br /&gt;
&lt;br /&gt;
Despite the MDC, the CFB gadget attack was possible. PGP also compresses the&lt;br /&gt;
plaintext before encrypting it, making guessing known plaintext bytes more difficult.&lt;br /&gt;
Based on our current findings, the CFB device attack against PGP has a success rate&lt;br /&gt;
of about one out of every three attempts. Plaintext compression, we believe, is more of&lt;br /&gt;
a technical snag than a fundamental restriction of the EFAIL attacks, and that further&lt;br /&gt;
research will make the attacks more efficient.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Mitigations==&lt;br /&gt;
To continue using email encryption securely, users must implement the following points&lt;br /&gt;
To prevent EFAIL attacks. This section is divided in to three terms to visualize the&lt;br /&gt;
urgency of each implementation.&lt;br /&gt;
&lt;br /&gt;
=== Short-Term ===&lt;br /&gt;
Active content in the email client must be disabled. This includes HTML code execu-&lt;br /&gt;
tion and the reloading of external material, which is frequently authorized for aesthetic&lt;br /&gt;
reasons. E-mail servers and e-mail clients must be secured against unauthorized access&lt;br /&gt;
attempts.Moreover, in the case of OpenPGP, you can decrypt the e-mails in an external&lt;br /&gt;
program instead of in the mail client, so that an attack comes to nothing.&lt;br /&gt;
Short term: No decryption in email client. Decrypting S/MIME or PGP emails in a&lt;br /&gt;
separate program outside of your email client is the easiest strategy to avoid EFAIL&lt;br /&gt;
attacks. Decrypt incoming encrypted emails by copy and pasting the ciphertext into&lt;br /&gt;
a different program that handles the decryption for you after deleting your S/MIME&lt;br /&gt;
and PGP private keys from your email client. In this manner, email clients are unable&lt;br /&gt;
to initiate exfiltration channels. This is currently the safest option with the downside&lt;br /&gt;
that the process gets more involved.&lt;br /&gt;
Short term: Disable HTML rendering. The EFAIL attacks target active content, which&lt;br /&gt;
is often in the form of HTML pictures, styles, and other elements. The most common&lt;br /&gt;
approach of fighting EFAIL is to disable the rendering of incoming HTML emails in&lt;br /&gt;
your email client. It’s worth noting that email clients have other possible backchannels&lt;br /&gt;
that aren’t linked to HTML, but they’re more difficult to attack.&lt;br /&gt;
=== Mid-Term ===&lt;br /&gt;
Mid term: Update E-Mail client. Vendors of the email clients will publish patches that&lt;br /&gt;
either fix the E-Fail vulnerabilities or make them much harder to exploit.&lt;br /&gt;
=== Long-Term ===&lt;br /&gt;
Long term: Update OpenPGP and S/MIME standards. The EFAIL attacks exploit&lt;br /&gt;
flaws and undefined behavior in the MIME, S/MIME, and OpenPGP standards.As a&lt;br /&gt;
result, standards must be changed, which will take time. Update: Our advice to dep-&lt;br /&gt;
recate the SE packet type and not show updated ciphertexts is reflected in the current&lt;br /&gt;
draft of OpenPGP RFC4880.[CalAD]&lt;br /&gt;
The CFB gadget attacks can also be prevented by updates, the programs just have to&lt;br /&gt;
evaluate the MDC correctly (which GnuPG does by now, an error in the MDC check&lt;br /&gt;
now leads to termination) and reject the outdated SE packets so that the attacks are&lt;br /&gt;
no longer possible.&lt;br /&gt;
The CBC gadget attacks cannot be properly prevented until an updated S/MIME&lt;br /&gt;
standard is released. Until that time comes, individual developers will have to develop&lt;br /&gt;
their own solutions&lt;br /&gt;
11&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
CalAD] J. Callas. Rfc4880, Nov 200AD. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc4880. 11&lt;br /&gt;
[Cor19] MITRE Corporation, 2019. URL: https://cve.mitre.org/cgi-bin/&lt;br /&gt;
cvename.cgi?name=CVE-2019-13050. 7&lt;br /&gt;
[Gar96] Simson Garfinkel. PGP: Pretty good privacy. O’Reilly, Internat. Thomson-&lt;br /&gt;
Verl, 1996. 5&lt;br /&gt;
[MKP+17] Juan Ram ́on Ponce Mauri ́es, Kat Krol, Simon Parkin, Ruba Abu-Salma,&lt;br /&gt;
and M. Angela Sasse. Dead on arrival: Recovering from fatal flaws in&lt;br /&gt;
email encryption tools. In The LASER Workshop: Learning from Author-&lt;br /&gt;
itative Security Experiment Results (LASER 2017), pages 49–57. USENIX&lt;br /&gt;
Association, October 2017. URL: https://www.usenix.org/conference/&lt;br /&gt;
laser2017/presentation/mauries. 12&lt;br /&gt;
[OAS21] OASIS. How email really works, 2021. [Online; accessed December&lt;br /&gt;
05, 2021]. URL: https://www.oasis-open.org/khelp/kmlm/user_help/&lt;br /&gt;
html/images/howemailworks.png. 4&lt;br /&gt;
[PDM+18] Damian Poddebniak, Christian Dresen, Jens Mueller, Fabian Ising, Sebas-&lt;br /&gt;
tian Schinzel, Simon Friedberger, Juraj Somorovsky, and Joerg Schwenk.&lt;br /&gt;
Efail: Breaking S/MIME and OpenPGP email encryption using exfil-&lt;br /&gt;
tration channels. In 27th USENIX Security Symposium (USENIX Secu-&lt;br /&gt;
rity 18), pages 549–566, Baltimore, MD, August 2018. USENIX Associ-&lt;br /&gt;
ation. URL: https://www.usenix.org/conference/usenixsecurity18/&lt;br /&gt;
presentation/poddebniak. 9&lt;br /&gt;
[Pos] J Postel. Simple mail transfer protocol. URL: https://tools.ietf.org/&lt;br /&gt;
html/rfc821/. 3&lt;br /&gt;
[Pur21] PurpleSec. 2021 ransomware statistics, Aug 2021. URL: https://&lt;br /&gt;
purplesec.us/resources/cyber-security-statistics/ransomware/.&lt;br /&gt;
6&lt;br /&gt;
[Ram99] B. Ramsdell. Rfc2633, Jun 1999. URL: https://datatracker.ietf.org/&lt;br /&gt;
doc/html/rfc2633. 4&lt;br /&gt;
[Rhe13] Man Rhee. Electronic Mail Security: PGP, S/MIME, pages 353–385.&lt;br /&gt;
Wikey, 03 2013. doi:10.1002/9781118512920.ch10. 1&lt;br /&gt;
14&lt;br /&gt;
Bibliography&lt;br /&gt;
[Spi16] Dag Spicer. Raymond tomlinson: Email pioneer, part 1. IEEE Annals of&lt;br /&gt;
the History of Computing, 38:72–79, 04 2016. doi:10.1109/MAHC.2016.25.&lt;br /&gt;
1&lt;br /&gt;
[TR10] S Turner and B Ramsdell. Rfc5751, Jan 2010. URL: https://&lt;br /&gt;
datatracker.ietf.org/doc/html/rfc5751. 4&lt;br /&gt;
[Uni21a] University of Applied Sciences M ̈unster. Cbc gadgets in s/mime, 2021.&lt;br /&gt;
[Online; accessed December 05, 2021]. URL: https://efail.de/media/&lt;br /&gt;
img/smime-attack.png. 8&lt;br /&gt;
[Uni21b] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil1.png. 8&lt;br /&gt;
[Uni21c] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil2.png. 9&lt;br /&gt;
[Uni21d] University of Applied Sciences M ̈unster. Direct exfiltration, 2021. [On-&lt;br /&gt;
line; accessed December 05, 2021]. URL: https://efail.de/media/img/&lt;br /&gt;
exfil3.png. 9&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Exfil3.png&amp;diff=8096</id>
		<title>File:Exfil3.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Exfil3.png&amp;diff=8096"/>
		<updated>2021-12-05T22:50:33Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Exfil2.png&amp;diff=8095</id>
		<title>File:Exfil2.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Exfil2.png&amp;diff=8095"/>
		<updated>2021-12-05T22:50:16Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Exfil1.png&amp;diff=8094</id>
		<title>File:Exfil1.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Exfil1.png&amp;diff=8094"/>
		<updated>2021-12-05T22:49:29Z</updated>

		<summary type="html">&lt;p&gt;KBeboso: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>KBeboso</name></author>
	</entry>
</feed>