EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingMedium

A security consultant is performing a wireless penetration test. They observe an access point (AP) that is configured to require clients to register their MAC addresses before being granted network access. The consultant spoofs the MAC address of an authorized client and successfully connects to the network. Which of the following wireless security mechanisms was circumvented by this action?

  1. AWPA2-Enterprise authentication
  2. BMAC address filtering
  3. CWPS (Wi-Fi Protected Setup)
  4. DSSID hiding
Show answer & explanation

Correct answer: B. MAC address filtering

MAC address filtering attempts to restrict network access to devices with specific MAC addresses. By spoofing an authorized MAC address, the penetration tester directly bypassed this security mechanism, demonstrating its ineffectiveness as a primary security control.

Why the other options are wrong

  • A. WPA2-Enterprise authentication involves 802.1X and EAP methods, which are not directly bypassed by MAC spoofing alone.
  • C. WPS is a simplified connection method, often vulnerable to brute-force attacks, but not directly related to MAC address filtering bypass.
  • D. SSID hiding (disabling SSID broadcast) is a mechanism to make the network less visible, but it does not prevent connection once the SSID is known and MAC filtering is the only other control.

MAC Address Filtering Bypass

MAC address filtering, a basic wireless security measure, can be easily bypassed by an attacker who spoofs the MAC address of an authorized device.

  • Relies on the uniqueness of MAC addresses for access control.
  • MAC addresses are easily discoverable for active clients.
  • Spoofing allows an attacker to impersonate an authorized device.

Memory trick: MAC filtering's a ghost, easily spoofed by a clever host.

More Wireless Network Hacking questions