ALL PASS, NO FAIL!

CEH v13 Module 16: Hacking Wireless Networks

This module covers wireless network attacks including WEP/WPA/WPA2 cracking, evil twin attacks, rogue access points, deauthentication attacks, Bluetooth exploits, and Wi-Fi Protected Setup (WPS) attacks. Understanding wireless protocols is essential for both attacking and securing wireless infrastructure.

The CEHStudy app carries 13 flashcards for Module 16 across 2 sections — know the standard ladder cold: WEP is broken, WPA2 falls to handshake capture plus an offline dictionary attack, WPS PINs fall to Reaver in hours, and only WPA3 (SAE, plus protected management frames) removes both classic capture vectors.

Key Topics Covered

Important Terms & Concepts

WEP (Wired Equivalent Privacy): Oldest and weakest Wi-Fi security. Uses RC4 with static IVs. Crackable in minutes using Aircrack-ng. Completely broken — never use.
WPA/WPA2-PSK: Pre-Shared Key authentication using TKIP (WPA) or AES (WPA2). Vulnerable to handshake capture + dictionary/brute-force attacks. WPA2 is the minimum acceptable standard.
Evil Twin: Rogue AP broadcasting the same SSID as a legitimate network. Used for MITM attacks, credential harvesting, and traffic interception. Often deployed with deauth to force client association.
Rogue AP: Unauthorized access point connected to a secured network. Can be an employee's home WiFi or a malicious device. Creates a backdoor into the internal network.
Deauthentication Attack: Sends deauth frames to disconnect clients from an AP. Forces reconnection so attacker can capture the WPA handshake for offline cracking. Tools: aircrack-ng, mdk3.
WPS (Wi-Fi Protected Setup): Convenience feature with PIN-based authentication. Vulnerable to brute force — Reaver can recover WPS PIN in hours, then crack the PSK. Disable WPS on all APs.

How to Study This Module

Frequently Asked Questions

Which Wi-Fi security is easiest to crack?
WEP is the easiest (minutes). WPA2-WPS is next if WPS is enabled (hours). WPA2 without WPS requires capturing the handshake then offline dictionary/brute-force attack.

What is an evil twin attack?
Creating a rogue access point with the same SSID as a legitimate network. Victims connect automatically, and the attacker performs MITM to capture traffic and credentials.

Related Modules

What is Wireless Network Hacking in Ethical Hacking?

Wireless Network Hacking covers attacks against Wi-Fi (802.11) networks — the encryption protocols (WEP, WPA, WPA2, WPA3), management frame security, and convenience features like WPS that create attack vectors. Unlike wired attacks, wireless attacks work remotely within radio range — more accessible and more dangerous. Goals range from cracking the Wi-Fi password to full man-in-the-middle interception (evil twin + deauth). Module 16 topics account for approximately 8% of CEH v13 exam questions.

Key Concepts in Hacking Wireless Networks

Common Exam Mistakes in Module 16

Confusing PMKID capture with the full 4-way handshake: the PMKID is available from the initial EAPOL exchange — capturable without forcing reassociation, then cracked offline with hashcat. The classic flow (deauth a client, capture the 4-way handshake, crack with a wordlist) is a different, slower path. Both attack WPA2-Personal and both end at the pre-shared key.
Counting MAC filtering and hidden SSIDs as real controls: MAC addresses are trivially spoofed and a hidden SSID is still visible to any scanner — the exam's defensible stack: WPA2-AES (or WPA3) with a long random PSK, WPS disabled, current firmware, 802.1X/RADIUS where available, segmented guest Wi-Fi, and rogue-AP hunting with WIDS/WIPS.
Forgetting why deauthentication works: 802.11 management frames are unencrypted and unauthenticated — any device in radio range can forge a deauth with the victim's MAC. That one fact powers handshake capture, wireless DoS, and evil-twin setup. WPA3's PMF (Protected Management Frames, 802.11w) signs management frames, so the attack dies on WPA3 with PMF enabled.

Tools Used in Wireless Network Hacking

Tools the CEH v13 exam references for wireless hacking:

Worked Example: From Deauth to Cracked PSK, One Network at a Time

airmon-ng start wlan0 puts the adapter in monitor mode — every frame in range, regardless of BSSID. airodump-ng identifies the target (SSID, BSSID, channel, WPA2-PSK) and aireplay-ng --deauth floods the legitimate AP: management frames are unauthenticated, so clients drop instantly and reassociate, emitting a fresh 4-way handshake into the capture. Offline, aircrack-ng -w wordlist.txt handshake.cap tests candidates at hardware speed; a strong random PSK survives — which is why hardening leads with key entropy and killing WPS.

The twist: with WPS enabled, the faster path is Reaver against the PIN — the per-digit checksum collapses the search to roughly 11,000 offline combinations, and the recovered PIN yields the PSK without touching the handshake. On WPA3 the chain breaks twice: SAE resists offline dictionary attacks, and PMF makes the deauth frame itself unforgeable — a stem specifying WPA3 with PMF enabled removes both fuel and trigger.

How to Study Wireless Network Hacking for the CEH v13 Exam

To study Module 16 for the CEH v13 exam:

  1. Build a protocol comparison table: Protocol (WEP/WPA/WPA2/WPA3) | Encryption (RC4/TKIP/AES/SAE) | Authentication Method | Known Vulnerabilities | Attack Time (at typical password strength). Exam stems match vulnerabilities to protocol versions — e.g., "Which protocol is vulnerable to the PTW attack?" (Answer: WPA-TKIP, not WPA2-AES)
  2. Hands-on: set up a virtual Wi-Fi environment (VirtualBox + a USB Wi-Fi adapter that supports monitor mode). With the Aircrack-ng suite: enter monitor mode, capture an 802.11 channel, identify the target SSID, deauthenticate, capture the WPA handshake, and crack with a small wordlist. Document each step's output — this mirrors exam questions on the attack flow
  3. Memorize the deauth → reassociate → handshake → crack pipeline: (1) identify the target BSSID, (2) monitor mode on the same channel, (3) send 20-50 deauth frames, (4) capture new association + 4-way handshake, (5) offline dictionary attack. The chain works because 802.11 management frames are unencrypted in WPA2
  4. Review related modules: Module 8 (Sniffing & Traffic Analysis) for packet analysis of captured 802.11 frames, and Module 9 (Social Engineering) for evil twin + phishing combos — the rogue AP can serve a fake login page harvesting credentials beyond the Wi-Fi password

Frequently Asked Questions About Wireless Network Hacking

What is a deauthentication attack and why is it important on wireless networks?

A deauthentication attack sends forged 802.11 management frames (deauth/disassoc) to a client or access point, causing immediate disconnection. In WPA2, management frames are not encrypted or authenticated — any device within radio range can forge them using the victim's MAC. Why it matters: (1) it forces reassociation, triggering a new 4-way handshake the attacker can capture for offline cracking; (2) it disrupts service (denial of service); (3) it clears the air for evil twin attacks — the rogue AP with stronger signal wins. Defense: WPA3's PMF (Protected Management Frames, 802.11w) requires cryptographic authentication of all management frames, making forgery impossible without the pairwise key. Practically: repeated disconnections on corporate Wi-Fi? Check for deauth attacks via airmon-ng monitoring or the AP's rogue client detection.

How does an evil twin attack work step by step?

(1) Reconnaissance — Kismet or airodump-ng identifies the target SSID, BSSID (MAC), channel, and security protocol; note the legitimate AP's signal strength; (2) Prepare the rogue AP — second adapter or USB dongle with the same SSID, matching encryption (usually WPA2-PSK), optionally a spoofed BSSID if clients select by MAC. hostapd + wpa_supplicant on Linux, or turnkey tools like Wifite; (3) Deploy with higher signal strength than the legitimate AP (antenna gain or proximity); (4) Deauth all connected clients on the legitimate AP (aireplay-ng --deauth or mdk3), forcing reassociation; (5) Clients scan and automatically join the strongest-signal SSID — the rogue; (6) MITM execution — the rogue controls all traffic: captive portal with fake login pages, SSL stripping on HTTP, JavaScript injection into HTTPS via certificate spoofing, or relaying to a transparent proxy. The key vulnerability: most clients select networks by SSID (not BSSID) — two APs with the same SSID are indistinguishable by name.

Related CEH v13 Modules

Related Glossary Terms