CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester is evaluating a wireless network. They observe that the network uses WPA2-PSK encryption and has Wi-Fi Protected Setup (WPS) enabled. The tester wants to exploit a known vulnerability in WPS to gain access to the network without needing to capture a full WPA2 handshake. Which tool and attack method would be most effective for this scenario?

  1. AKismet to identify hidden SSIDs and then deauthenticate clients.
  2. BHashcat with a rule-based attack on a PMKID.
  3. CAircrack-ng with a dictionary attack against a captured WPA2 handshake.
  4. DReaver to brute-force the WPS PIN.
Show answer & explanation

Correct answer: D. Reaver to brute-force the WPS PIN.

WPS has a known design flaw that allows for the brute-forcing of its PIN in two halves, significantly reducing the keyspace. Reaver is a tool specifically designed to exploit this vulnerability, making it the most effective choice for gaining access to a WPA2-PSK network with WPS enabled without needing to capture a full handshake.

Why the other options are wrong

  • A. Kismet is for discovery, and deauthentication attacks don't directly lead to network access in this context.
  • B. A PMKID attack still involves cryptographic cracking and is not directly related to the WPS PIN vulnerability.
  • C. This requires a captured WPA2 handshake, which the question states the tester wants to avoid.

WPS PIN Brute-Force (Reaver)

An attack exploiting a design flaw in Wi-Fi Protected Setup (WPS) that allows for the brute-forcing of the 8-digit PIN in two halves, significantly reducing the time required to recover the WPA2-PSK passphrase.

  • Exploits a weak authentication mechanism in WPS.
  • Typically uses the tool Reaver or similar.
  • Can recover the WPA2-PSK passphrase within hours, even with strong passwords.
  • Many modern routers disable WPS or implement lockouts to mitigate this.

Memory trick: WPS PIN: Reaver rips through the weak links.

More Attacks and Exploits questions