EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingEasy

A penetration tester is evaluating the security of a corporate wireless network. They have successfully captured a WPA2-Personal 4-way handshake using a tool like Airodump-ng. The target network's SSID is 'CorpNet' and its PSK is known to be a dictionary word followed by a year. Which of the following attack methods would be MOST efficient for attempting to recover the PSK in this scenario?

  1. ARainbow table attack with precomputed hashes
  2. BEvil Twin attack to trick users into revealing the PSK
  3. CBrute-force attack with a custom character set
  4. DDictionary attack using a targeted wordlist
Show answer & explanation

Correct answer: D. Dictionary attack using a targeted wordlist

Since the PSK is known to follow a predictable pattern (dictionary word + year), a dictionary attack using a targeted wordlist combining common dictionary words and years would be the most efficient method to recover the PSK from the captured handshake.

Why the other options are wrong

  • A. Rainbow tables are not effective against WPA/WPA2 PSKs because the SSID is part of the hash calculation, making precomputed tables impractical without knowing the SSID beforehand.
  • B. An Evil Twin attack aims to capture credentials directly or force a connection, not directly crack a captured WPA2 handshake.
  • C. A brute-force attack is computationally intensive and inefficient when the PSK structure is somewhat known.

WPA2-Personal PSK Cracking

Recovering the Pre-Shared Key (PSK) for a WPA2-Personal network, typically after capturing a 4-way handshake, often involves offline dictionary or brute-force attacks.

  • Requires capturing the 4-way handshake between a client and AP.
  • Attacks are performed offline against the captured handshake.
  • PSK strength directly impacts the feasibility of cracking.

Memory trick: Handshake captured, now dictionary words unlock the key.

More Wireless Network Hacking questions