Wireless Penetration Testing
Wireless penetration testing checks whether unauthorized devices or users can cross a wireless network's security boundaries. This course focuses on Wi-Fi: radio discovery, authentication, client trust, and access to the networks behind an access point.
itOffensive security and application security | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic: Wireless Penetration Testing
Wireless penetration testing checks whether a Wi-Fi network's security boundaries hold under an authorized test. The radio is the entrance. Authentication decides who can enter. Network policy decides where they can go afterward. Combining those questions produces a confident report about the wrong thing, which is an efficient way to waste confidence.
An access point, the device connecting wireless clients to a network, advertises a network name called an SSID. Several access points can share that name. An impostor can copy it too. The name helps a client find a service; it does not establish that the service belongs to the intended operator. Think of the label as a label, and inspect the trust mechanism separately.
The first useful distinction is between encryption and identity. An ordinary open network has no Wi-Fi link encryption. OWE, a mechanism for opportunistic wireless encryption, adds encryption without authenticating the network. A captive portal puts a web gate after the wireless connection. That gate cannot travel backward in time and encrypt the radio exchange that already happened.
The second distinction is between personal and enterprise authentication. WPA2-Personal uses a shared credential. A usable saved handshake can support an offline test of candidate passwords. The password is not included as a helpful note in the capture. If the candidate list fails, the list failed. That result does not certify the entire universe of possible passwords.
WPA3-Personal changes the password-authentication mechanism to SAE, Simultaneous Authentication of Equals. It is designed to resist passive offline dictionary guessing. Transition deployments retain a WPA2 compatibility path, so the strongest advertised option does not tell you what every client selected. Inspect the connection that happened rather than the upgrade announcement.
Enterprise Wi-Fi introduces a client authentication component and commonly a RADIUS authentication service behind the access point. The client needs to trust the intended server. A trusted certificate chain and an expected server name are separate checks. Copying an SSID should not persuade a properly constrained client to accept an impostor server.
The third distinction is between security failure and observation failure. A receiving radio listens on one channel at a time. Hopping finds more networks, but it can miss a short exchange. Monitor mode exposes raw wireless frames only when the adapter and driver support it. No handshake in a capture can mean that the capture missed the handshake. Absence needs working equipment and stated coverage before it becomes evidence.
Start with the Intro for the connection model and security modes. Use the Cheatsheet when comparing an observation with the conclusion it actually supports. The Practice Reference supplies isolated-lab capture examples. The Exercise checks enterprise client settings without transmitting anything. Field Notes explains where assessment time disappears. Follow the Reference path into protocol research after those distinctions are familiar.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/115/final
Supports
- Assessment planning, wireless scanning, rules of engagement, evidence handling and reporting
- https://csrc.nist.gov/pubs/sp/800/153/final
Supports
- WLAN architecture, security lifecycle, configuration, segmentation and monitoring; 2012 publication
- https://standards.ieee.org/ieee/802.11i/3127/
Supports
- 2004 security amendment and MAC security scope
- https://www.aircrack-ng.org/doku.php?id=airmon-ng
Supports
- Adapter listing, process interference, monitor mode start/stop and optional channel
- https://www.aircrack-ng.org/doku.php?id=airodump-ng
Supports
- Raw 802.11 capture, BSSID/channel selection, write prefix, capture formats and incomplete observations
- https://www.aircrack-ng.org/doku.php?id=aircrack-ng
Supports
- WPA/WPA2-PSK dictionary audits, candidate and BSSID arguments and capture requirements
- https://wiki.wireshark.org/CaptureSetup/WLAN
Supports
- Raw 802.11 versus Ethernet-like capture and hardware, driver and operating-system limitations
- https://www.wireshark.org/docs/man-pages/tshark.html
Supports
- Offline reads, display filters, verbose decoding and original capture preservation
- https://www.wireshark.org/docs/dfref/w/wlan.html
Supports
- BSSID, beacon subtype, RSN AKM and PMF field names
- https://www.wireshark.org/docs/dfref/e/eapol.html
Supports
- EAPOL protocol filtering and decoded key-management traffic
- https://www.globenewswire.com/news-release/2018/06/26/1529297/0/en/Wi-Fi-Alliance-introduces-Wi-Fi-CERTIFIED-WPA3-security.html
Supports
- 2018 WPA3 introduction, SAE, PMF and WPA2 transition compatibility
- https://datatracker.ietf.org/doc/html/rfc8110
Supports
- 2017 OWE specification, encryption without peer authentication and passive exposure limits
- https://w1.fi/wpa_supplicant/
Supports
- Supplicant role and enterprise/personal authentication implementations
- https://w1.fi/wpa_supplicant/devel/structtls__connection__params.html
Supports
- CA trust and distinct full-name/domain-suffix server identity constraints
- https://chromium.googlesource.com/external/w1.fi/cgit/hostap/+/refs/tags/hostap_2_5/wpa_supplicant/wpa_supplicant.conf
Supports
- Stable ca_cert, domain_match and domain_suffix_match semantics used by the offline profile exercise
- https://w1.fi/hostapd/
Supports
- AP authenticator, EAP and RADIUS roles and test infrastructure placement
- https://www.kb.cert.org/vuls/id/723755
Supports
- PIN enrollment weakness and disabling vulnerable enrollment
- https://sviehb.wordpress.com/2011/12/27/wi-fi-protected-setup-pin-brute-force-vulnerability/
Supports
- December 2011 disclosure and enrollment mechanism distinct from WPA passphrase strength
- https://www.usenix.org/conference/10th-usenix-security-symposium/presentation/using-fluhrer-mantin-and-shamir-attack-break-
Supports
- 2001 demonstrated passive WEP key recovery
- https://www.krackattacks.com/
Supports
- 2017 key-reinstallation disclosure, implementation remediation and separation from password recovery
- https://wpa3.mathyvanhoef.com/
Supports
- 2019 SAE/EAP-pwd research, downgrade and side-channel risks and patch/configuration assessment
- https://www.fragattacks.com/
Supports
- May 2021 aggregation/fragmentation design and implementation flaws across Wi-Fi security modes
- https://www.kismetwireless.net/
Supports
- Passive wireless observation and landscape/awesome-link placement
- https://www.kismetwireless.net/docs/readme/datasources/wifi-linux/
Supports
- Capture compatibility, channel control and radio coverage constraints
- https://www.wireshark.org/
Supports
- Packet analysis placement, open-source licensing and free availability
- https://hashcat.net/hashcat/
Supports
- Offline credential audit tooling and free/open-source product placement
- https://www.freeradius.org/
Supports
- Enterprise authentication service and free/open-source landscape placement
- https://shop.hak5.org/products/wifi-pineapple
Supports
- Paid wireless test appliance placement; active testing requires separate authorization
- https://github.com/sindresorhus/awesome
Supports
- Discovery of security resource lists
- https://github.com/enaqx/awesome-pentest
Supports
- Wireless-tool entries for Aircrack-ng, Kismet and WiFi Pineapple
- https://www.aircrack-ng.org/documentation.html
Supports
- Suite documentation index and primary-source discovery
