EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingMedium

A penetration tester is targeting a wireless network that utilizes WPS (Wi-Fi Protected Setup) for easy device connection. The tester uses a tool to systematically guess the WPS PIN. Which specific WPS attack exploits the design flaw where the PIN verification process can be broken into two smaller, independent halves, significantly reducing the number of attempts needed for a brute-force attack?

  1. APixie Dust Attack
  2. BReaver Attack
  3. CEvil Twin Attack
  4. DChopChop Attack
Show answer & explanation

Correct answer: B. Reaver Attack

The Reaver attack (named after the tool that popularized it) exploits the design flaw in WPS where the AP reports the correctness of the first four digits of the PIN separately from the last three digits (and checksum). This allows an attacker to brute-force the PIN in two halves, drastically reducing the search space.

Why the other options are wrong

  • A. The Pixie Dust attack is an offline brute-force attack against WPS by exploiting a vulnerability in the WPS registration protocol, requiring specific AP implementations, not the two-halves PIN flaw.
  • C. An Evil Twin attack involves a rogue AP and is unrelated to WPS PIN cracking.
  • D. A ChopChop attack is an old WEP attack for decrypting packets and is irrelevant to WPS.

WPS Reaver Attack

The Reaver attack is an online brute-force attack against Wi-Fi Protected Setup (WPS) PINs. It exploits a design flaw in WPS where the Access Point (AP) confirms the correctness of the first four digits of the PIN and the last three digits (plus checksum) separately, effectively dividing an 8-digit PIN into two smaller, easier-to-brute-force sections.

  • Exploits WPS PIN validation in two halves.
  • Significantly reduces brute-force attempts.
  • Typically an online attack, can be slow but effective.

Memory trick: Reaver divides the WPS PIN, conquering it in two halves.

More Wireless Network Hacking questions