EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium
An ethical hacker is performing a penetration test against an organization's wireless network. Before attempting to crack wireless passwords, they need to identify all active wireless networks (SSIDs), their MAC addresses (BSSIDs), and the channels they are operating on within range. Which of the following tools is specifically designed for this type of wireless network reconnaissance?
- AMetasploit
- BAircrack-ng suite
- CNmap
- DWireshark
Show answer & explanationAnswer & explanation
Correct answer: B. Aircrack-ng suite
The Aircrack-ng suite, particularly tools like `airodump-ng`, is specifically designed for wireless network reconnaissance. It can put a wireless adapter into monitor mode to capture 802.11 frames, allowing the identification of SSIDs, BSSIDs, channels, and associated clients, which is crucial for wireless enumeration.
Why the other options are wrong
- A. Metasploit is an exploitation framework, not a dedicated tool for wireless network reconnaissance.
- C. Nmap is primarily a wired network scanner and host discovery tool, not designed for wireless network enumeration of SSIDs and BSSIDs.
- D. Wireshark is a packet analyzer that can capture and analyze network traffic (including wireless if the adapter is in monitor mode), but it's a general-purpose analyzer, not a specialized reconnaissance tool for listing active networks like airodump-ng.
Aircrack-ng Suite (airodump-ng)
A collection of tools for assessing WiFi network security. Specifically, `airodump-ng` is used for capturing raw 802.11 frames, identifying access points, clients, and data packets, which is essential for wireless reconnaissance.
- Requires wireless adapter in monitor mode.
- Identifies SSIDs, BSSIDs, channels.
- Captures raw 802.11 traffic.
- Critical for wireless penetration testing.
Memory trick: Aircrack-ng is the 'Air Traffic Controller' for WiFi intel.