EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingHard
A penetration tester is attempting to compromise a WPA2-Personal network. They have captured the 4-way handshake and are now performing an offline dictionary attack. The target network uses a passphrase of 'SecurePassword123' and the SSID is 'MyCompanyWiFi'. What is the critical mathematical operation that occurs repeatedly during the dictionary attack to generate the Pairwise Master Key (PMK) for each guessed passphrase?
- AAES Encryption
- BPBKDF2 Hashing
- CRC4 Key Scheduling
- DSHA-256 Hashing
Show answer & explanationAnswer & explanation
Correct answer: B. PBKDF2 Hashing
PBKDF2 (Password-Based Key Derivation Function 2) is used in WPA/WPA2-Personal to derive the Pairwise Master Key (PMK) from the passphrase and the SSID. This computationally intensive hashing function is the core of offline dictionary attacks, as it must be performed for every guessed passphrase.
Why the other options are wrong
- A. AES is an encryption algorithm used for data confidentiality, not for deriving keys from passphrases.
- C. RC4 is a stream cipher used in WEP, not in WPA2, and is not a key derivation function for passphrases.
- D. SHA-256 is a general-purpose hashing algorithm, but PBKDF2 specifically incorporates SHA-1 or SHA-2 (like SHA-256) with iterations for key derivation, making it more resistant to brute-force than raw SHA-256.
PBKDF2 in WPA/WPA2
PBKDF2 (Password-Based Key Derivation Function 2) is a key stretching algorithm used in WPA/WPA2-Personal to derive the Pairwise Master Key (PMK) from the human-readable passphrase (PSK) and the SSID. Its iterative nature makes offline brute-force attacks computationally expensive.
- Takes passphrase, salt (SSID), iteration count, and key length as input.
- Generates the 256-bit PMK.
- Core component of WPA/WPA2-Personal security, and its weakness to dictionary attacks.
Memory trick: PBKDF2 hashes the Passphrase and SSID to create the PMK.