A wireless intrusion prevention system (WIPS) generates a high-severity alert for a mobile workstation located on an enterprise campus. The event log records that an unauthorized device is transmitting targeted unicast 802.11 Probe Response frames matching multiple distinct entries from the workstation's Preferred Network List (PNL). Immediately following the probe responses, the unauthorized device initiates an EAP-TTLS handshake and requests legacy authentication credentials. Which of the following attack mechanisms is most accurately represented by these indicators?
- A Karma attack utilizing passive probe request harvesting to spoof trusted SSIDs and intercept enterprise authentication credentials.Cevap
- BAn Initialization Vector (IV) reuse attack manipulating packet keystreams to derive the WPA2-Enterprise pre-shared encryption key.
- CA radio frequency (RF) jamming attack emitting high-power signals to force connected clients onto a secondary unencrypted fallback channel.
- DA wireless disassociation flood utilizing spoofed management frames to force all campus endpoints to re-authenticate with the primary RADIUS server.
Cevap
A Karma attack utilizing passive probe request harvesting to spoof trusted SSIDs and intercept enterprise authentication credentials.
The correct answer accurately identifies a Karma attack. Mobile wireless devices broadcast 802.11 Probe Requests containing SSIDs from their Preferred Network List (PNL) to locate known Wi-Fi networks. In a Karma attack, a rogue access point listens for these requests and immediately responds with unicast Probe Responses matching whichever SSID the client requested. Once the client auto-connects under the assumption that it is reaching a trusted network, the rogue AP initiates authentication exchanges (like EAP-TTLS) to harvest user credentials.
Adım Adım Çözüm
Anahtar Kavram
Karma Attack and Probe Request Harvesting Indicators