EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingHard
A wireless network is configured with WPA2-Enterprise using EAP-TLS. A penetration tester attempts to perform a Man-in-the-Middle (MitM) attack by setting up a rogue access point (Evil Twin) that mimics the legitimate network. The tester configures the rogue AP to request a username and password from connecting clients. However, legitimate clients, configured to use EAP-TLS, refuse to connect to the rogue AP and display a certificate warning. What specific security feature of EAP-TLS is preventing the success of this MitM attack?
- AMutual authentication based on client and server certificates
- BDynamic Frequency Selection (DFS) for channel management
- CPre-Shared Key (PSK) requirement for connection
- DUse of Protected Management Frames (PMF)
Show answer & explanationAnswer & explanation
Correct answer: A. Mutual authentication based on client and server certificates
EAP-TLS requires both the client and the server (RADIUS/authenticator) to present and validate digital certificates. When the rogue AP tries to impersonate the legitimate network, it cannot present a valid server certificate trusted by the client, leading to the client refusing connection and displaying a warning. This mutual certificate-based authentication prevents the MitM attack.
Why the other options are wrong
- B. DFS is a mechanism for avoiding radar interference in the 5 GHz band and is unrelated to authentication security against MitM attacks.
- C. PSK is used in WPA2-Personal, not WPA2-Enterprise with EAP-TLS, which uses certificates.
- D. PMF (802.11w) protects management frames from spoofing but doesn't directly prevent a client from attempting to connect to a rogue AP if it trusts the server's identity.
EAP-TLS Mutual Authentication
EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) uses digital certificates for mutual authentication, where both the client and the authentication server verify each other's identity.
- Requires a Public Key Infrastructure (PKI).
- Provides strong protection against Man-in-the-Middle attacks.
- Client trusts the server's certificate, and the server trusts the client's certificate.
Memory trick: EAP-TLS: Both sides show their certificates, no fakes allowed.