CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A tester wants to harvest employee credentials during a physical/wireless assessment. The tester configures an access point broadcasting the same SSID as the corporate wireless network but with a stronger signal, and sets up a captive portal that mimics the company's login page. Which attack is being performed?
- ADeauthentication attack
- BKARMA attack
- CEvil twin attack
- DWPS PIN attack
Show answer & explanationAnswer & explanation
Correct answer: C. Evil twin attack
An evil twin attack involves creating a rogue access point that impersonates a legitimate SSID, often with a stronger signal and a fake captive portal, to trick users into connecting and submitting credentials.
Why the other options are wrong
- A. Deauthentication attacks disconnect clients but do not involve a fake captive portal.
- B. KARMA attacks respond to any probe request from clients, a related but distinct technique without necessarily mimicking one specific SSID.
- D. WPS PIN attacks brute force the WPS PIN, not SSID impersonation.
Evil Twin Attack
A rogue access point that impersonates a legitimate network's SSID, often paired with a fake captive portal, to capture credentials or traffic.
- Uses a stronger signal to lure clients away from the real AP
- Often paired with a fake login page to harvest credentials
- May be combined with deauth attacks to force reconnection
Memory trick: Twins look alike but one is evil in disguise.