CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A tester is attempting to capture a WPA2 four-way handshake, but the target client has been idle for over an hour with no new authentication traffic. Which technique should the tester use to force a new handshake capture?
- AKarma attack
- BARP spoofing
- CWPS PIN brute force
- DDeauthentication attack
Show answer & explanationAnswer & explanation
Correct answer: D. Deauthentication attack
A deauthentication attack sends spoofed deauth frames to force the client to disconnect and reauthenticate, generating a new four-way handshake that can be captured with tools like airodump-ng. ARP spoofing manipulates local network traffic, a Karma attack lures clients to a rogue AP by responding to probe requests, and WPS brute force targets the WPS PIN, not the handshake.
Why the other options are wrong
- A. Karma attacks impersonate networks to attract clients, not force reconnection to the current AP.
- B. ARP spoofing manipulates traffic routing, it does not force reauthentication.
- C. WPS brute force attacks the WPS PIN mechanism, unrelated to handshake capture.
WPA2 Handshake Capture
An attacker captures the WPA2 four-way handshake between client and AP, often forcing reauthentication via a deauthentication attack to speed up capture.
- Deauth frames force client disconnect/reconnect
- Handshake captured with airodump-ng
- Cracked offline with hashcat mode 22000 or aircrack-ng
Memory trick: 'Deauth to force the handshake to happen again'