Posts

Showing posts with the label Wireless Security

RF Interference Troubleshooting: When the Problem Is Not the Network

Wireless problems divide into two categories that look identical from the client and have completely different fixes. Congestion is too much Wi-Fi traffic sharing a channel. Interference is energy in the band that is not Wi-Fi at all. Changing channels fixes one and can make the other worse. Telling them apart A Wi-Fi scanner — software on a laptop or phone — shows networks, their channels and their signal strengths. It sees only Wi-Fi, because it uses a Wi-Fi radio, and a channel that looks empty to it may be saturated by something else entirely. A spectrum analyser shows raw energy across the band regardless of what produced it. That is the distinction: it is the only tool that reveals non-Wi-Fi interference, and it is why a site with mysterious problems and a clean scanner reading needs one. The symptoms that point at interference rather than congestion: retransmission rates high while the number of visible networks is low, problems confined to one area or one ti...

Bluetooth Pairing Attacks: PIN Brute Force and Why Legacy Pairing Fails

Bluetooth pairing establishes a shared secret between two devices so later connections can be authenticated and encrypted. The strength of everything that follows depends on how that first exchange is protected — and in legacy pairing, it is protected by a PIN that is frequently four digits and frequently 0000. Why legacy pairing is breakable In the legacy model, both devices derive an initialization key from the PIN, their addresses, and a random value, then use it to exchange and confirm a link key. An attacker who captures that exchange has everything needed to test PIN guesses offline. Offline is the crucial word. There is no device to rate-limit the attempts and no lockout to trip, so the attacker simply derives the expected values for each candidate PIN and compares. A four-digit PIN is ten thousand possibilities, which is not a meaningful search space — it falls in under a second on ordinary hardware. Fixed PINs make it worse. Headsets, speakers, car kits, medica...

Wardriving and Wireless Network Databases: What Your SSID Discloses

Wardriving is collecting wireless network observations while moving — network name, hardware identifier, encryption type and location. Aggregated into public databases over two decades, the result is a searchable map of hundreds of millions of wireless networks worldwide, including almost certainly yours. What gets collected, and why it is passive Access points broadcast beacon frames continuously so clients can find them. Those beacons contain the network name, the radio's hardware identifier, the supported rates and the security configuration — all in the clear, by necessity, before any association occurs. A device listening while its location is recorded builds a database entry per network. Nothing is connected to and nothing is attacked, which makes this passive reconnaissance : the collector never transmits to the target. That classification matters on the exam, and it also means there is no way to detect that it happened. Hiding the network name does not remove yo...

KRACK: The Key Reinstallation Attack and What It Changed

KRACK was notable not because of the damage it caused — relatively little, in the end — but because of what it was: a flaw in the WPA2 protocol itself rather than in any implementation. The standard had been formally proven secure, and the proof did not cover the behaviour that broke. The four-way handshake After a client associates and the pre-shared key or enterprise authentication establishes a master key, WPA2 runs a four-message exchange to derive the session keys used to encrypt traffic. The client confirms installation of the session key when it receives the third message. Because Wi-Fi is unreliable, the standard requires the client to accept a retransmission of that message and respond again — an access point that did not receive the acknowledgement will resend it. That retransmission requirement is the flaw. What replaying message three does When a client receives message three, it installs the session key and resets the associated counters — th...

Wi-Fi 6, 6E and 7: Bands, Channel Width and High-Density Design

Wireless generations are marketed on peak throughput, and peak throughput is the least useful number for anyone designing a network. What changed in recent generations is how well the medium handles many clients at once , which is the problem real deployments have. The bands 2.4 GHz penetrates walls well and is hopelessly congested, with only three non-overlapping channels and interference from microwaves, cordless devices and Bluetooth. Treat it as legacy support for devices that cannot do better. 5 GHz has many more channels and shorter range, which is an advantage indoors because smaller cells mean less co-channel interference. Parts of the band require dynamic frequency selection, where the access point must vacate a channel if it detects radar — which occasionally causes an unexplained brief outage near airports and weather installations. 6 GHz , available to Wi-Fi 6E and Wi-Fi 7, is the significant addition. A large block of new spectrum, and — the part that mat...

Wireless Intrusion Detection: Finding Rogue APs and Deauth Attacks

Wireless intrusion detection monitors the radio environment for threats that no wired sensor can see. Most enterprise wireless platforms include it, most organizations leave it unconfigured, and the detections it offers are among the cheapest available — the sensors are the access points you already own. What it detects Rogue access points. An unauthorized access point connected to your wired network — usually a consumer device someone plugged in for convenience. It bypasses every control on the wired side and advertises a way in from the car park. Detection combines a radio observation with a check of whether the device is actually on your network, because an access point belonging to the business next door is a neighbour rather than a rogue, and systems that cannot tell the difference generate alerts nobody reads. Evil twins. An access point advertising your network name from a radio identifier that is not yours. This is the one worth alerting on immediately, because...

Evil Twin Attacks on WPA2-Enterprise: Why Certificate Validation Matters

WPA2-Enterprise is meant to be the strong option: every user authenticates individually against a RADIUS server, credentials can be revoked per person, and there is no shared passphrase to leak. It delivers that only if clients verify who they are authenticating to. When they do not, an attacker with a laptop collects credentials from anyone who walks past. The assumption that breaks In tunnelled EAP methods such as PEAP and EAP-TTLS, the RADIUS server presents a certificate, the client builds a TLS tunnel to it, and the username and password are sent inside that tunnel. The tunnel protects the credentials from anyone watching the air. It protects them from the network, not from the endpoint of the tunnel. If the client does not verify whose certificate it is, it will happily build a tunnel to an attacker's server and send the credentials straight into it. The encryption works perfectly; it is encrypting the handoff to the wrong recipient. This is the same class of failure as...

WPA and TKIP: Why the Wi-Fi Stopgap Was Retired

WPA with TKIP was designed as a bridge. WEP had been broken conclusively, replacement hardware was years away, and the industry needed something that would run on the radio chips already deployed. TKIP met that constraint and only that constraint, which is why it was obsolete almost as soon as it shipped and why selecting it today is a finding rather than a configuration choice. What WEP got wrong WEP used RC4 with a 24-bit initialization vector prepended to a static shared key. Three failures compounded. The IV space was small enough that values repeated on a busy network within hours, and repeated IVs with the same key expose the keystream. The key never changed, so every captured packet contributed to the same analysis. And the integrity check was a CRC, which an attacker can recompute after modifying a packet — detection of accidents, not of tampering. The result was a protocol recoverable in minutes with passive capture. Note the general lesson the exam likes: a CRC is er...

Guest and BYOD Wireless: Isolation, Onboarding and Per-User Keys

Guest and personal-device wireless is where network design meets the fact that you do not control the endpoint. The question is not how to secure those devices — you cannot — but how to give them the access they need while ensuring a compromised one reaches nothing that matters. Guest networks A guest network should provide internet access and nothing else. Getting that right means three things. Segmentation. Guest traffic goes into its own VLAN with no route to internal networks, enforced by access control lists rather than by the absence of a route — routes appear. Give it its own DHCP scope and DNS, and do not let guest clients resolve internal names. Client isolation. Guests should not reach each other either. Without it, one infected laptop scans and attacks every other device on the guest network, which in a hotel or conference setting is a substantial population. Wireless client isolation is a single setting on most controllers and is frequently left off....

Wireless Site Surveys: Predictive, Passive and Active Surveys Compared

A wireless site survey determines where access points should go and confirms that the result works. Skipping it is why so many wireless networks show full signal bars and perform badly — coverage is easy to achieve and is not the same thing as a network that works, which is the single most useful idea in this topic. The three survey types Predictive surveys are done in software from floor plans. You model the building, assign attenuation values to walls and materials, and the tool proposes access point placement and predicts coverage. It is fast, requires no site visit, and it is only as accurate as the model — a concrete wall entered as drywall produces a confident and wrong answer. Use it for initial design, then verify on site. Passive surveys walk the site with a device listening to what is already broadcasting, recording signal strength, noise, and channel usage at each point without associating to anything. This is how you measure existing coverage, find dead spo...

802.1X Port-Based Authentication: Supplicant, Authenticator, and RADIUS

802.1X authenticates a device before it is allowed to pass traffic on a switch port or wireless network. Until authentication succeeds the port carries nothing but the authentication exchange itself, which means an unauthorized device plugged into a conference room jack reaches nothing at all. It is the foundation of network access control and a reliable exam topic. The three roles The supplicant is software on the connecting device that presents credentials. Every modern operating system includes one. The authenticator is the switch or wireless access point controlling the port. It does not decide anything; it relays the conversation and enforces the verdict by opening or keeping the port closed. The authentication server is a RADIUS server holding the policy and the credential store, usually backed by a directory. It makes the decision and returns it, optionally with attributes telling the authenticator which VLAN to assign or which access list to apply. The separation matt...

Public Wi-Fi and Captive Portals: Real Risks and Sensible Advice

Public Wi-Fi advice has not kept up with what changed. Ten years ago an open network meant your traffic was readable; today almost everything is encrypted end to end, and the standard warnings describe a threat that has largely moved elsewhere. Knowing what is still true matters, because advice people recognize as outdated gets ignored entirely. What is no longer the main problem On an open network, frames are unencrypted at the radio layer, so anyone nearby can capture them. That used to mean reading traffic. Now it mostly does not. The overwhelming majority of connections use TLS, so a captured frame contains ciphertext. What remains visible is metadata: which hostnames were requested, via DNS unless encrypted and via the server name in the TLS handshake, along with volumes and timing — which is real and is a different exposure from reading content, as discussed under packet capture . Enhanced Open — the opportunistic encryption in WPA3 — encrypts an open networ...