This module covers wireless network attacks including WEP/WPA/WPA2 cracking, evil twin attacks, rogue access points, deauthentication attacks, Bluetooth exploits, and Wi-Fi Protected Setup (WPS) attacks. Understanding wireless protocols is essential for both attacking and securing wireless infrastructure.
What is Wireless Network Hacking in Ethical Hacking?
Wireless Network Hacking covers attacks against Wi-Fi (802.11) networks — the encryption protocols (WEP, WPA, WPA2, WPA3), management frame security, and convenience features like WPS that create attack vectors. Unlike wired attacks, wireless attacks work remotely within radio range — more accessible and more dangerous. Goals range from cracking the Wi-Fi password to full man-in-the-middle interception (evil twin + deauth). Module 16 topics account for approximately 8% of CEH v13 exam questions.
Key Concepts in Hacking Wireless Networks
- WEP Cracking & RC4 IV Vulnerability: WEP secures Wi-Fi with RC4 and a 24-bit initialization vector (IV) prepended to each encrypted packet. The flaw: the IV is transmitted in cleartext and reused frequently, so collecting enough IVs enables statistical analysis of the RC4 key stream. Aircrack-ng needs approximately 5-10 million IVs for a 64-bit WEP key (minutes on busy networks) or ~200,000 IVs for 128-bit keys (still feasible with deauth-assisted traffic). WEP is broken at the protocol level — password complexity doesn't save it. The specific RC4 weakness is the FMS attack (Fluhrer, Mantin, Shamir), which exploits statistical biases in the first bytes of RC4 output for certain IV patterns. WPA replaced WEP because TKIP/AES cannot be attacked this way.
- WPA2 Handshake Capture & Dictionary Attack Flow: The WPA2-PSK attack requires: (1) capturing the 4-way handshake between a client and AP — deauthentication frames force a client to reconnect, triggering a new handshake; (2) running an offline dictionary/brute-force attack against the capture with Aircrack-ng or Hashcat. The handshake proves both parties know the PSK without transmitting it — but its Message Integrity Code (MIC) can be verified offline by guessing the PSK. The attack is fully offline after capture, and success depends entirely on password strength: a 12-character random alphanumeric password is ~69^12 = 10^22 combinations — effectively uncrackable; common passwords like "password" or "welcome1" crack in seconds. WPA3's SAE (Dragonfly) handshake eliminates this by never exposing values usable for offline guessing.
- Evil Twin & Deauthentication Attack Chain: The flow: (1) recon — identify target SSID, BSSID (MAC), and security type with airmon-ng and airodump-ng; (2) monitor mode (airmon-ng start wlan0); (3) deploy a rogue AP with identical SSID and stronger signal (hostapd or a USB Wi-Fi dongle); (4) send deauthentication frames to all clients on the legitimate AP (aircrack-ng --deauth), forcing reconnection; (5) clients associate with the rogue AP (same SSID, stronger signal); (6) man-in-the-middle — capture credentials, inject content, or relay traffic. 802.11 management frames (deauth, authentication, association) are NOT encrypted in WPA2 — anyone within radio range can forge them. WPA3's PMF (Protected Management Frames) fixes this by encrypting and authenticating management frames.
- WPS PIN Brute Force & Reaver: Wi-Fi Protected Setup uses an 8-digit PIN verified in two independent halves (4 + 4 digits, each with its own checksum), reducing the attack space from 10^8 to approximately 11,111. Reaver automates this brute force, typically recovering the PIN in 2-12 hours; with the PIN the attacker can connect via WPS or derive the WPA PSK. Disable WPS on production access points — plug-and-pair convenience vastly increases attack surface. Detection: unusual reconnection patterns, a WPS LED blinking repeatedly, or Reaver's characteristic request pattern (typically 3 requests per minute per PIN attempt).
Common Exam Mistakes in Module 16
Confusing PMKID capture with the full 4-way handshake: the PMKID is available from the initial EAPOL exchange — capturable without forcing reassociation, then cracked offline with hashcat. The classic flow (deauth a client, capture the 4-way handshake, crack with a wordlist) is a different, slower path. Both attack WPA2-Personal and both end at the pre-shared key.
Counting MAC filtering and hidden SSIDs as real controls: MAC addresses are trivially spoofed and a hidden SSID is still visible to any scanner — the exam's defensible stack: WPA2-AES (or WPA3) with a long random PSK, WPS disabled, current firmware, 802.1X/RADIUS where available, segmented guest Wi-Fi, and rogue-AP hunting with WIDS/WIPS.
Forgetting why deauthentication works: 802.11 management frames are unencrypted and unauthenticated — any device in radio range can forge a deauth with the victim's MAC. That one fact powers handshake capture, wireless DoS, and evil-twin setup. WPA3's PMF (Protected Management Frames, 802.11w) signs management frames, so the attack dies on WPA3 with PMF enabled.
Tools Used in Wireless Network Hacking
Tools the CEH v13 exam references for wireless hacking:
- Aircrack-ng suite: the primary wireless toolkit — airmon-ng puts the adapter in monitor mode, airodump-ng captures traffic and handshakes, aireplay-ng generates deauthentication, and aircrack-ng cracks WEP/WPA keys offline against a wordlist
- Reaver: automated WPS PIN brute-forcer — exploits the weak per-digit checksum (~11,000 offline combinations) to recover the 8-digit PIN, then derives the PSK
- Kismet: passive wireless detector and sniffer — finds rogue APs, hidden SSIDs, and non-standard channels without transmitting a single packet
- mdk3 / mdk4: multi-function attack tool covering deauthentication, fog attacks against WPA, fake authentication frame injection, and channel hopping
- Cowpatty: precomputed-attack cracker for PMKID hashes — trades disk space (PMKID rainbow tables) for speed when a station is connected or the SSID is known
- Wireshark: packet analyzer for dissecting captured 802.11 frames — handshake structure and protocol anomalies
- Honeyd: transparent proxy used in evil twin setups to redirect client traffic so interception is invisible to the victim
Worked Example: From Deauth to Cracked PSK, One Network at a Time
airmon-ng start wlan0 puts the adapter in monitor mode — every frame in range, regardless of BSSID. airodump-ng identifies the target (SSID, BSSID, channel, WPA2-PSK) and aireplay-ng --deauth floods the legitimate AP: management frames are unauthenticated, so clients drop instantly and reassociate, emitting a fresh 4-way handshake into the capture. Offline, aircrack-ng -w wordlist.txt handshake.cap tests candidates at hardware speed; a strong random PSK survives — which is why hardening leads with key entropy and killing WPS.
The twist: with WPS enabled, the faster path is Reaver against the PIN — the per-digit checksum collapses the search to roughly 11,000 offline combinations, and the recovered PIN yields the PSK without touching the handshake. On WPA3 the chain breaks twice: SAE resists offline dictionary attacks, and PMF makes the deauth frame itself unforgeable — a stem specifying WPA3 with PMF enabled removes both fuel and trigger.
How to Study Wireless Network Hacking for the CEH v13 Exam
To study Module 16 for the CEH v13 exam:
- Build a protocol comparison table: Protocol (WEP/WPA/WPA2/WPA3) | Encryption (RC4/TKIP/AES/SAE) | Authentication Method | Known Vulnerabilities | Attack Time (at typical password strength). Exam stems match vulnerabilities to protocol versions — e.g., "Which protocol is vulnerable to the PTW attack?" (Answer: WPA-TKIP, not WPA2-AES)
- Hands-on: set up a virtual Wi-Fi environment (VirtualBox + a USB Wi-Fi adapter that supports monitor mode). With the Aircrack-ng suite: enter monitor mode, capture an 802.11 channel, identify the target SSID, deauthenticate, capture the WPA handshake, and crack with a small wordlist. Document each step's output — this mirrors exam questions on the attack flow
- Memorize the deauth → reassociate → handshake → crack pipeline: (1) identify the target BSSID, (2) monitor mode on the same channel, (3) send 20-50 deauth frames, (4) capture new association + 4-way handshake, (5) offline dictionary attack. The chain works because 802.11 management frames are unencrypted in WPA2
- Review related modules: Module 8 (Sniffing & Traffic Analysis) for packet analysis of captured 802.11 frames, and Module 9 (Social Engineering) for evil twin + phishing combos — the rogue AP can serve a fake login page harvesting credentials beyond the Wi-Fi password
Frequently Asked Questions About Wireless Network Hacking
What is a deauthentication attack and why is it important on wireless networks?
A deauthentication attack sends forged 802.11 management frames (deauth/disassoc) to a client or access point, causing immediate disconnection. In WPA2, management frames are not encrypted or authenticated — any device within radio range can forge them using the victim's MAC. Why it matters: (1) it forces reassociation, triggering a new 4-way handshake the attacker can capture for offline cracking; (2) it disrupts service (denial of service); (3) it clears the air for evil twin attacks — the rogue AP with stronger signal wins. Defense: WPA3's PMF (Protected Management Frames, 802.11w) requires cryptographic authentication of all management frames, making forgery impossible without the pairwise key. Practically: repeated disconnections on corporate Wi-Fi? Check for deauth attacks via airmon-ng monitoring or the AP's rogue client detection.
How does an evil twin attack work step by step?
(1) Reconnaissance — Kismet or airodump-ng identifies the target SSID, BSSID (MAC), channel, and security protocol; note the legitimate AP's signal strength; (2) Prepare the rogue AP — second adapter or USB dongle with the same SSID, matching encryption (usually WPA2-PSK), optionally a spoofed BSSID if clients select by MAC. hostapd + wpa_supplicant on Linux, or turnkey tools like Wifite; (3) Deploy with higher signal strength than the legitimate AP (antenna gain or proximity); (4) Deauth all connected clients on the legitimate AP (aireplay-ng --deauth or mdk3), forcing reassociation; (5) Clients scan and automatically join the strongest-signal SSID — the rogue; (6) MITM execution — the rogue controls all traffic: captive portal with fake login pages, SSL stripping on HTTP, JavaScript injection into HTTPS via certificate spoofing, or relaying to a transparent proxy. The key vulnerability: most clients select networks by SSID (not BSSID) — two APs with the same SSID are indistinguishable by name.
Related CEH v13 Modules