EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingMedium

A cybersecurity team is investigating a reported unauthorized access to their internal wireless network. Logs show a sudden spike in deauthentication frames targeting multiple legitimate client devices, immediately followed by connections to a rogue access point. Which wireless attack technique does this sequence of events strongly suggest?

  1. AEvil Twin Attack
  2. BWPS Pixie Dust Attack
  3. CChopChop Attack
  4. DJamming Attack
Show answer & explanation

Correct answer: A. Evil Twin Attack

The sequence of deauthentication frames followed by client connections to a rogue AP is a classic indicator of an Evil Twin attack. Deauthentication is often used to force clients off the legitimate AP so they will automatically connect to the attacker's rogue AP.

Why the other options are wrong

  • B. WPS Pixie Dust is an offline brute-force attack against WPS-enabled APs, not involving deauthentication or rogue AP redirection.
  • C. ChopChop is an old WEP attack used to decrypt data by capturing packets, not for redirecting clients.
  • D. A jamming attack floods the airwaves with noise, preventing any communication, not redirecting clients to a rogue AP.

Evil Twin Attack Facilitation

An Evil Twin attack often uses deauthentication frames to disconnect legitimate clients from their access points, compelling them to search for and connect to the attacker's rogue access point, which mimics the legitimate network's SSID.

  • Deauthentication forces clients off network.
  • Clients automatically search for known SSIDs.
  • Rogue AP receives connections, enabling traffic interception.

Memory trick: Deauth + Rogue AP = Evil Twin's Deceptive Lure.

More Wireless Network Hacking questions