EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingMedium

A security auditor is performing a wireless penetration test on a corporate network. They successfully capture a WPA/WPA2 4-way handshake. To crack the passphrase offline, which specific cryptographic element from the handshake is essential for a dictionary or brute-force attack?

  1. AInitialization Vector (IV)
  2. BMessage Integrity Code (MIC)
  3. CPairwise Master Key (PMK)
  4. DPairwise Transient Key (PTK)
Show answer & explanation

Correct answer: B. Message Integrity Code (MIC)

The Message Integrity Code (MIC) in the 4-way handshake is crucial for offline cracking. An attacker can use a dictionary or brute-force attack to guess the passphrase, derive the PMK, PTK, and then calculate the MIC. If the calculated MIC matches the captured MIC, the guessed passphrase is correct.

Why the other options are wrong

  • A. IVs are used in encryption but not directly for offline cracking of the passphrase in WPA/WPA2 handshakes.
  • C. The PMK is derived from the passphrase and SSID; it is not directly captured in the handshake for cracking but is generated during the cracking process.
  • D. The PTK is derived from the PMK and nonces; it's also generated during cracking, not the primary target for offline passphrase guessing.

WPA/WPA2 4-Way Handshake MIC

The Message Integrity Code (MIC) is a cryptographic checksum included in the WPA/WPA2 4-way handshake messages. It ensures the integrity of the handshake messages and is critical for offline passphrase cracking, as a correct passphrase will yield a matching MIC.

  • Verifies integrity of handshake messages.
  • Calculated using the Pairwise Transient Key (PTK).
  • Used to confirm a guessed passphrase in offline cracking.

Memory trick: MIC is the Key to Cracking Passwords.

More Wireless Network Hacking questions