CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A penetration tester is evaluating a wireless network. They observe that the network uses WPA2-PSK encryption and has Wi-Fi Protected Setup (WPS) enabled. The tester wants to exploit a known vulnerability in WPS to gain access to the network without needing to capture a full WPA2 handshake. Which tool and attack method would be most effective for this scenario?
- AKismet to identify hidden SSIDs and then deauthenticate clients.
- BHashcat with a rule-based attack on a PMKID.
- CAircrack-ng with a dictionary attack against a captured WPA2 handshake.
- DReaver to brute-force the WPS PIN.
Show answer & explanationAnswer & explanation
Correct answer: D. Reaver to brute-force the WPS PIN.
WPS has a known design flaw that allows for the brute-forcing of its PIN in two halves, significantly reducing the keyspace. Reaver is a tool specifically designed to exploit this vulnerability, making it the most effective choice for gaining access to a WPA2-PSK network with WPS enabled without needing to capture a full handshake.
Why the other options are wrong
- A. Kismet is for discovery, and deauthentication attacks don't directly lead to network access in this context.
- B. A PMKID attack still involves cryptographic cracking and is not directly related to the WPS PIN vulnerability.
- C. This requires a captured WPA2 handshake, which the question states the tester wants to avoid.
WPS PIN Brute-Force (Reaver)
An attack exploiting a design flaw in Wi-Fi Protected Setup (WPS) that allows for the brute-forcing of the 8-digit PIN in two halves, significantly reducing the time required to recover the WPA2-PSK passphrase.
- Exploits a weak authentication mechanism in WPS.
- Typically uses the tool Reaver or similar.
- Can recover the WPA2-PSK passphrase within hours, even with strong passwords.
- Many modern routers disable WPS or implement lockouts to mitigate this.
Memory trick: WPS PIN: Reaver rips through the weak links.