An enterprise network administrator notices that wireless clients in a branch office are repeatedly disconnected from the secure corporate Wi-Fi network. Subsequent packet analysis reveals a stream of spoofed 802.11 management frames instructing host devices to sever their existing wireless associations, followed immediately by hosts connecting to an unauthorized access point operating on a higher-power channel while broadcasting the identical corporate Service Set Identifier (SSID). Which network attack vector is being executed?
- A deauthentication attack combined with an Evil Twin access pointCevap
- BAn ARP poisoning attack redirecting Layer 2 traffic via gratuitous ARP frames
- CA DNS cache poisoning attack altering hostname resolution record entries
- DAn SSH man-in-the-middle attack executing session hijacking over port 23
Cevap
A deauthentication attack combined with an Evil Twin access point
The scenario describes a wireless deauthentication attack paired with an Evil Twin. An attacker transmits spoofed 802.11 management frames (deauthentication/disassociation) to break legitimate client connections, causing devices to automatically search for and associate with the strongest available signal broadcasting the expected SSID—which is provided by the attacker's rogue Evil Twin access point.
Adım Adım Çözüm
Anahtar Kavram
Wireless Attacks: Deauthentication and Evil Twin Vectors
Tahmini Süre:1m 15s