EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingMedium
A penetration tester is targeting a WPA2-Enterprise network that uses 802.1X for authentication. The tester successfully captures EAPOL frames between a client and the RADIUS server. To proceed with an offline attack against the captured credentials, which specific EAP method's inner tunnel credentials must the tester attempt to extract and crack?
- AEAP-TLS
- BEAP-MD5
- CLEAP
- DPEAP (MSCHAPv2)
Show answer & explanationAnswer & explanation
Correct answer: D. PEAP (MSCHAPv2)
When PEAP is used with MSCHAPv2 as the inner authentication method, the MSCHAPv2 hashes are vulnerable to offline dictionary attacks if captured, as they can be extracted from the EAPOL frames. EAP-TLS and LEAP have different vulnerabilities or are not commonly cracked offline in this manner.
Why the other options are wrong
- A. EAP-TLS relies on client-side certificates and is generally considered very secure against offline cracking of credentials.
- B. EAP-MD5 is considered weak and vulnerable, but PEAP with MSCHAPv2 is a more common enterprise vulnerability for offline cracking.
- C. LEAP (Lightweight Extensible Authentication Protocol) is a proprietary Cisco protocol with known vulnerabilities, but PEAP/MSCHAPv2 is a more prevalent target for offline cracking of captured EAPOL frames.
PEAP (MSCHAPv2) Offline Cracking
PEAP (Protected Extensible Authentication Protocol) using MSCHAPv2 as its inner authentication method can be vulnerable to offline dictionary attacks if the MSCHAPv2 hashes are captured within EAPOL frames.
- PEAP creates an encrypted tunnel for inner EAP methods.
- MSCHAPv2 is a common inner method, but its hashes can be cracked offline.
- Tools like EAPHammer or Responder can be used to capture and crack these hashes.
Memory trick: EAPOL frames hide PEAP's MSCHAPv2, a crackable secret.