EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingEasy
A security analyst is conducting a wireless assessment and discovers an access point broadcasting an SSID named 'FreeWiFi' with no encryption enabled. The analyst observes numerous clients connecting to this network. Which type of attack is most readily facilitated by this configuration, allowing an attacker to intercept client communications?
- AEvil Twin Attack
- BWPA2 Krack Attack
- CDeauthentication Attack
- DWPS Brute-Force Attack
Show answer & explanationAnswer & explanation
Correct answer: A. Evil Twin Attack
An Evil Twin attack involves an attacker setting up a rogue AP with the same SSID as a legitimate network, often without encryption, to trick users into connecting and then intercepting their traffic.
Why the other options are wrong
- B. KRACK targets vulnerabilities in WPA2's 4-way handshake, not open networks.
- C. A deauthentication attack disconnects clients but doesn't inherently intercept traffic; it's often a precursor to other attacks.
- D. WPS brute-force attacks target the WPS PIN, which is irrelevant for an open network without WPS enabled or used for authentication.
Evil Twin Attack
A type of attack where a rogue wireless access point (AP) mimics a legitimate one, often using the same SSID, to trick unsuspecting users into connecting to it. Once connected, the attacker can intercept, monitor, or manipulate their network traffic.
- Uses a rogue AP with a spoofed SSID.
- Often targets open or easily guessable networks.
- Facilitates man-in-the-middle attacks.
Memory trick: Spoofed APs create Evil Twins for data interception.