Wireless Penetration testing actively examines the process of Information security Measures which is Placed in WiFi Networks and also analyses the Weakness, technical flows, and Critical wireless Vulnerabilities.
The most important countermeasures we should focus on are Threat Assessment, Data theft Detection, security control auditing, Risk prevention and Detection, information system Management, and Upgrade infrastructure and a Detailed report should be prepared.What is Wireless Penetration Testing?
Wireless Penetration Testing is aimed to test wireless infrastructure to find vulnerabilities in the network. Testing involves both manual testing techniques and automated scans to simulate a real-world attack and identify risks.Why is wireless penetration testing important?
Usage of Wi-Fi access dramatically increased nowadays, and the quality of Wi-Fi security is in question. By using Wi-Fi access thousands of transaction processing every minute.
If the network is vulnerable it allows hackers to launch various attacks and intercept the data.
Common Wireless Network Vulnerabilities
- Deployment of Vulnerable WEP Protocol
- Man-in-the-Middle Attacks
- Default SSIDs and Passwords
- Misconfigured Firewalls
- WPA2 Krack Vulnerability
- NetSpectre – Remote Spectre Exploit
- Warshipping
- Packet Sniffing
- Warshipping
Wireless Penetration Testing Checklist
- Framework for Wireless Penetration Testing
- Wireless Pentesting with WEP Encrypted WLAN
- Wireless Penetration Testing with WPA/WPA2 Encrypted WLAN
- LEAP Encrypted WLAN
- Wireless Penetration Testing with Unencrypted WLAN
Let’s take a detailed look at the Wireless Penetration Testing Checklist and the steps to be followed.
Framework for Wireless Penetration Testing
- Discover the Devices connected with Wireless Networks.
- Document all the findings if Wireless Device is Found.
- If a wireless Device is found using Wifi Networks, then perform common wifi Attacks and check the devices using WEP Encryption.
- If you found WLAN using WEP Encryption then Perform WEP Encryption Pentesting.
- Check whether WLAN Using WPA/WPA2 Encryption. If yes then perform WPA/WPA2 pen-testing.
- Check Whether WLAN using LEAP Encryption. If yes then perform LEAP Pentesting.
- No other Encryption Method was used which I mentioned above, Then Check whether WLAN using unencrypted.
- If WLAN is unencrypted then perform common wifi network attacks, check the vulnerability which is placed in the unencrypted method and generate a report.
- Before generating a Report make sure no damage has been caused to the pentesting assets.
Wireless Pentesting with WEP Encrypted WLAN
- Check the SSID and analyze whether SSID is Visible or Hidden.
- Check for networks using WEP encryption.
- If you find the SSID as visible mode then try to sniff the traffic and check the packet capturing status.
- If the packet has been successfully captured and injected then it’s time to break the WEP key by using a WiFi cracking tool such as Aircrack-ng, or WEPcrack.
- If packets are not reliably captured then sniff the traffic again and capture the Packet.
- If you find SSID is the Hidden mode, then do Deauthentication for the target client by using some deauthentication tools such as Commview and Airplay-ng.
- Once successfully Authenticated with the client and Discovered the SSID is, then again follow the Above Procedure which is already used for discovering SSID in earlier steps.
- Check if the Authentication method used is OPN (Open Authentication) or SKA (Shared Key Authentication). If SKA is used, then bypassing mechanism needs to be performed.
- Check if the STA (stations/clients) are connected to AP (Access Point) or not. This information is necessary to perform the attack accordingly.
If clients are connected to the AP, an Interactive packet replay or ARP replay attack needs to be performed to gather IV packets which can be then used to crack the WEP key.
If there’s no client connected to the AP, Fragmentation Attack or Korex Chop Chop attack needs to be performed to generate the keystream which will be further used to reply to ARP packets.
10. Once the WEP key is cracked, try to connect to the network using WPA-supplicant and check if the AP is allotting any IP address or not.”EAPOL handshake“.
Wireless Penetration Testing with WPA/WPA2 Encrypted WLAN
- Start and Deauthenticate with WPA/WPA2 Protected WLAN client by using WLAN tools Such as Hotspotter, Airsnarf, Karma, etc.
- If the Client is Deaauthenticated, then sniff the traffic and check the status of captured EAPOL Handshake.
- If the client is not Deauthenticate then do it again.
- Check whether the EAPOL handshake is captured or Not.
- Once you captured the EAPOL handshake, then perform a PSK Dictionary attack using coWPAtty, Aircrack-ng to gain confidential information.
- Add Time-memory trade-off method (Rainbow tables) also known as WPA-PSK Precomputation attack for cracking WPA/2 passphrase. Genpmk can be used to generate pre-computed hashes.
- If it’s Failed then Deauthenticate again and try to capture again and redo the above steps.
LEAP Encrypted WLAN
- Check and Confirm whether WLAN is protected by LEAP Encryption or not.
- De-authenticate the LEAP Protected Client using tools such as karma, hotspotter, etc.
- If the client is De authenticated then break the LEAP Encryption using a tool such as asleapto steal the confidential information
- If the process dropped then de-authenticate again
Wireless Penetration Testing with Unencrypted WLAN
- Check whether SSID is Visible or not
- Sniff for IP range if SSID is visible then check the status of MAC Filtering.
- If MAC filtering is enabled then spoof the MAC Address by using tools such as SMAC
- Try to connect to AP using IP within the discovered range.
- If SSID is hidden then discover the SSID using Aircrack-ng and follow the procedure of visible SSID which I Declared above.
Wireless Penetration Testing
Checkout our previous posts on InfoSec “Cheat Sheet”
InfoSec books | InfoSec tools | InfoSec services