CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester is assessing the wireless network of a coffee shop. They observe an open Wi-Fi network named 'FreeCoffee_Guest' that requires users to accept terms and conditions on a web portal before gaining internet access. The tester notices that after connecting to 'FreeCoffee_Guest', their device is assigned an IP address, but all web requests are redirected to `portal.freecoffee.local`. Which of the following attacks could the tester leverage to bypass the captive portal and gain direct internet access?

  1. AEvil Twin Attack
  2. BDNS Spoofing
  3. CMAC Address Spoofing
  4. DWPS PIN Brute-Force
Show answer & explanation

Correct answer: C. MAC Address Spoofing

Captive portals often rely on the MAC address of a device to track authentication status. If a legitimate user has already authenticated, their MAC address will be whitelisted. By spoofing the MAC address of an already authenticated device, the tester can bypass the captive portal without needing to authenticate themselves.

Why the other options are wrong

  • A. An Evil Twin attack aims to trick users into connecting to a malicious AP, not bypass a legitimate captive portal.
  • B. DNS Spoofing might redirect traffic, but it wouldn't inherently bypass the MAC-based authentication of a captive portal.
  • D. WPS PIN Brute-Force is for WPA/WPA2 networks with WPS enabled, not relevant for open networks with captive portals.

Captive Portal Bypass

Techniques used to circumvent the authentication requirements of a captive portal, which typically restricts internet access until users agree to terms or provide credentials.

  • Captive portals usually track users by MAC address.
  • Spoofing an authenticated MAC address is a common bypass.
  • Other methods include DNS manipulation or exploiting portal vulnerabilities.

Memory trick: Wireless world: Evil twins, DNS tricks, MAC magic, WPS woes.

More Attacks and Exploits questions