EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingEasy
A penetration tester is evaluating the security of a corporate wireless network. They have successfully captured a WPA2-Personal 4-way handshake using a tool like Airodump-ng. The target network's SSID is 'CorpNet' and its PSK is known to be a dictionary word followed by a year. Which of the following attack methods would be MOST efficient for attempting to recover the PSK in this scenario?
- ARainbow table attack with precomputed hashes
- BEvil Twin attack to trick users into revealing the PSK
- CBrute-force attack with a custom character set
- DDictionary attack using a targeted wordlist
Show answer & explanationAnswer & explanation
Correct answer: D. Dictionary attack using a targeted wordlist
Since the PSK is known to follow a predictable pattern (dictionary word + year), a dictionary attack using a targeted wordlist combining common dictionary words and years would be the most efficient method to recover the PSK from the captured handshake.
Why the other options are wrong
- A. Rainbow tables are not effective against WPA/WPA2 PSKs because the SSID is part of the hash calculation, making precomputed tables impractical without knowing the SSID beforehand.
- B. An Evil Twin attack aims to capture credentials directly or force a connection, not directly crack a captured WPA2 handshake.
- C. A brute-force attack is computationally intensive and inefficient when the PSK structure is somewhat known.
WPA2-Personal PSK Cracking
Recovering the Pre-Shared Key (PSK) for a WPA2-Personal network, typically after capturing a 4-way handshake, often involves offline dictionary or brute-force attacks.
- Requires capturing the 4-way handshake between a client and AP.
- Attacks are performed offline against the captured handshake.
- PSK strength directly impacts the feasibility of cracking.
Memory trick: Handshake captured, now dictionary words unlock the key.