EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingMedium
A security auditor is performing a penetration test against a client's wireless network. They notice that the network's APs are broadcasting multiple SSIDs, some of which are hidden. During a deauthentication attack against a connected client, the client reassociates with the network, and the auditor captures the full 4-way handshake. Which of the following tools is specifically designed to perform this type of targeted deauthentication and capture the handshake for WPA/WPA2 cracking?
- AAirmon-ng
- BNetcat
- CAireplay-ng
- DWireshark
Show answer & explanationAnswer & explanation
Correct answer: C. Aireplay-ng
Aireplay-ng is a part of the Aircrack-ng suite specifically used for injecting frames, including deauthentication frames, to force clients to disconnect and reconnect, thereby capturing the WPA/WPA2 4-way handshake.
Why the other options are wrong
- A. Airmon-ng is used to put a wireless adapter into monitor mode, which is a prerequisite, but it doesn't perform the deauthentication attack itself.
- B. Netcat is a networking utility for reading from and writing to network connections, not for wireless frame injection or deauthentication attacks.
- D. Wireshark is a powerful network protocol analyzer for capturing and inspecting packets, but it doesn't actively inject frames or deauthenticate clients.
Aireplay-ng Deauthentication
Aireplay-ng is a tool within the Aircrack-ng suite used to inject frames into a wireless network, most notably for deauthentication attacks to capture WPA/WPA2 handshakes.
- Part of the Aircrack-ng suite.
- Used to send deauthentication frames to clients.
- Forces clients to reconnect, allowing handshake capture for cracking.
Memory trick: Aireplay's ghost deauths, Airodump sniffs the handshake.