openskills.info
Course Preview

Wireless Penetration Testing

Wireless penetration testing checks whether unauthorized devices or users can cross a wireless network's security boundaries. This course focuses on Wi-Fi: radio discovery, authentication, client trust, and access to the networks behind an access point.

itOffensive security and application security

Don't Panic: Wireless Penetration Testing

Wireless penetration testing checks whether a Wi-Fi network's security boundaries hold under an authorized test. The radio is the entrance. Authentication decides who can enter. Network policy decides where they can go afterward. Combining those questions produces a confident report about the wrong thing, which is an efficient way to waste confidence.

An access point, the device connecting wireless clients to a network, advertises a network name called an SSID. Several access points can share that name. An impostor can copy it too. The name helps a client find a service; it does not establish that the service belongs to the intended operator. Think of the label as a label, and inspect the trust mechanism separately.

The first useful distinction is between encryption and identity. An ordinary open network has no Wi-Fi link encryption. OWE, a mechanism for opportunistic wireless encryption, adds encryption without authenticating the network. A captive portal puts a web gate after the wireless connection. That gate cannot travel backward in time and encrypt the radio exchange that already happened.

The second distinction is between personal and enterprise authentication. WPA2-Personal uses a shared credential. A usable saved handshake can support an offline test of candidate passwords. The password is not included as a helpful note in the capture. If the candidate list fails, the list failed. That result does not certify the entire universe of possible passwords.

WPA3-Personal changes the password-authentication mechanism to SAE, Simultaneous Authentication of Equals. It is designed to resist passive offline dictionary guessing. Transition deployments retain a WPA2 compatibility path, so the strongest advertised option does not tell you what every client selected. Inspect the connection that happened rather than the upgrade announcement.

Enterprise Wi-Fi introduces a client authentication component and commonly a RADIUS authentication service behind the access point. The client needs to trust the intended server. A trusted certificate chain and an expected server name are separate checks. Copying an SSID should not persuade a properly constrained client to accept an impostor server.

The third distinction is between security failure and observation failure. A receiving radio listens on one channel at a time. Hopping finds more networks, but it can miss a short exchange. Monitor mode exposes raw wireless frames only when the adapter and driver support it. No handshake in a capture can mean that the capture missed the handshake. Absence needs working equipment and stated coverage before it becomes evidence.

Start with the Intro for the connection model and security modes. Use the Cheatsheet when comparing an observation with the conclusion it actually supports. The Practice Reference supplies isolated-lab capture examples. The Exercise checks enterprise client settings without transmitting anything. Field Notes explains where assessment time disappears. Follow the Reference path into protocol research after those distinctions are familiar.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources