Hands-On Ethical Hacking and Network Defense, Third Edition 11-1
© Cengage Learning 2017
Chapter 11
Hacking Wireless Networks
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Quick Quizzes
Hands-On Ethical Hacking and Network Defense, Third Edition 11-2
Lecture Notes
Overview
This chapter provides an overview of wireless technology. Students will learn about different
wireless networking standards. Next, they will learn the process of authentication in relation to
wireless networks. Wardriving and other wireless hacking techniques are also described.
Finally, students will practice using the hacking tools that are utilized by hackers and security
professionals to either attack or protect a wireless network.
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Explain wireless technology
Describe wireless networking standards
Describe the process of authentication
Describe wardriving
Describe wireless hacking and tools used by hackers and security professionals
Teaching Tips
Understanding Wireless Technology
Components of a Wireless Network
1. Explain the basic components of a wireless network: a wireless network interface card
Access Points
1. Describe an access point (AP) as a radio transceiver that connects to an Ethernet cable
3. Illustrate how AP channels are detected using Figure 11-1.
Hands-On Ethical Hacking and Network Defense, Third Edition 11-3
Teaching
Tip
Visit http://kb.netgear.com/app/answers/detail/a_id/235/~/what-is-a-wireless-
access-point%3F?cid=wmt_netgear_organic for more information on access
points (APs).
Service Set Identifiers
1. Explain that a service set identifier (SSID) is a name used to identify the wireless local
2. Explain why wireless computers need to configure the SSID before connecting to a
wireless network.
3. Explain why it is not recommended to have default SSIDs configured on your
Configuring an Access Point
2. Use Figures 11-3 through 11-5 to illustrate the configuration process.
3. Emphasize the importance of changing the SSID and disabling the SSID broadcast to
better protect your WLAN.
Teaching
Tip
Read https://heimdalsecurity.com/blog/home-wireless-network-security/ for tips
for improving your wireless network.
Wireless NICs
1. Describe the role of a wireless NIC (WNIC) in a wireless network. For wireless
Understanding Wireless Network Standards
1. Explain that there are several standards defined by the Institute of Electrical and
The 802.11 Standard
2. Explain carrier sense multiple access/collision avoidance (CSMA/CA) and why it is
used on wireless networks instead of CSMA/CD.
Teaching
Tip
The following Web page defines CSMA/CA and how it relates to WLANs:
http://www.science.uva.nl/research/air/projects/old_projects/wlan/simulations/Intro_-
_WLAN/Intro_-_CSMA_CA/intro_-_csma_ca.html.
3. Explain other distinctions of wireless LANs such as stations, mobile stations, and
portable stations.
The Basic Architecture of 802.11
1. Define the main components of the 802.11 architecture, such as the basic service set
An Overview of Wireless Technology
1. Describe the following techniques in which wireless LANs can operate:
a. Infrared (IR)
b. Narrowband
c. Spread spectrum
Additional IEEE 802.11 Projects
1. Explain the main characteristics of 802.11b, such as its operating frequency range,
2. Explain the main characteristics of 802.11a, such as its operating frequency range,
throughput, and bands or frequencies.
4. Explain the security improvements of 802.11i over 802.11b.
6. Discuss the 802.11e standard that was released in 2005.
8. Describe the 802.11ac standard which allows for higher throughput by multiplying the
number of MIMO links and using high-density modulation.
Additional IEEE 802 Standards
1. Describe 802.15 as a technique to address networking devices within one person’s
2. Define 802.16 as the standard for wireless metropolitan area networks (MANs).
3. Introduce 802.20, the standard that addresses wireless MANs for mobile users who are
4. Use Table 11-3 to discuss the approved wireless standards.
Teaching
Tip
Find more complete specifications about these standards at
http://standards.ieee.org/getieee802/.
Hands-On Ethical Hacking and Network Defense, Third Edition 11-6
Quick Quiz 1
1. What term is used to describe a transceiver that connects to a network via an Ethernet
cable?
2. What is the name used to identify the wireless local area network (WLAN).
3. In 802.11, an addressable unit is called which of the following?
A. SSID
B. WNIC
C. STA
D. WLAN
4. In which type of modulation does data hop to other frequencies to avoid interference
that might occur over a frequency band?
A. OFDM
B. FHSS
C. DSSS
D. NBSS
5. What term is used to describe the coverage area an AP provides?
Understanding Authentication
1. This section explains several technologies to protect your wireless networks.
The 802.1X Standard
1. Explain that the 802.1X standard defines the process of authenticating and authorizing
users on a WLAN. To understand how authentication can take place on a wireless
network, review some basic concepts such as:
Hands-On Ethical Hacking and Network Defense, Third Edition 11-7
Point-to-Point Protocol (PPP)
Extensible Authentication Protocol (EAP)
1. Define EAP as an enhancement to PPP. The main difference between PPP and EAP is
2. Explain the methods used by EAP to protect wireless networks, including:
3. Explain the three 802.1X components, and explain how they interact when
authenticating a user. Components includes:
a. Supplicant
b. Authenticator
c. Authentication server
Teaching
Tip
Read RFC 2284: PPP Extensible Authentication Protocol (EAP) available at
http://www.faqs.org/rfcs/rfc2284.html.
Wired Equivalent Privacy
1. Explain that Wired Equivalent Privacy is part of the 802.11b standard and that it was
implemented specifically to encrypt data that traversed a wireless network.
Wi-Fi Protected Access
1. Explain that WPA was introduced with the 802.11i standard to replace WEP, which was
2. Describe and explain the four enhancements introduced by TKIP, including:
a. Message Integrity Check (MIC)
Hands-On Ethical Hacking and Network Defense, Third Edition 11-8
Wi-Fi Protected Setup (WPS)
1. Describe WPS as a wireless authentication standard created to allow users to easily add
Understanding Wardriving
1. Define wardriving as driving around with inexpensive hardware and software that
enables attackers to detect access points that haven’t been secured.
How It Works
1. Describe the equipment used by attackers or security testers when wardriving. The
equipment is composed of the following four components:
a. Laptop computer
b. Wireless NIC
c. Antenna
d. Software that scans the area for SSIDs
Hands-On Ethical Hacking and Network Defense, Third Edition 11-9
Kismet
2. Mention that Kismet runs on Linux, BSD UNIX, MAC OS X, and Linux PDAs.
4. List all the features available with Kismet, such as:
a. Wireshark- and Tcpdump-compatible data logging
b. Compatible with AirSnort and AirCrack
c. Network IP range detection
Understanding Wireless Hacking
Tools of the Trade
1. Explain that a wireless hacker usually has a laptop computer, a WNIC, an antenna,
Aircrack-ng
1. Define Aircrack-ng as the tool most hackers use who want to access WEP-enabled
WLANs.
Teaching
Tip
Check out http://www.aircrack-ng.org for more information on Aircrack-ng.
Hands-On Ethical Hacking and Network Defense, Third Edition 1110
WiFi Pineapple
1. Introduce students to WiFi Pineapple, which can perform scans for wireless APs and
Countermeasures for Wireless Attacks
2. Use the Internet to find other recommendations for protecting wireless networks.
Quick Quiz 2
1. Which standard defines the process of authenticating and authorizing users on a
WLAN?
A. 802.1X
B. 802.11ad
C. 802.11b
D. 802.11e
2. What term is used to describe a record that authenticates network entities, such as a
server or client?
3. Which part of the 802.11b standard, was developed to encrypt data traversing a wireless
network?
A. PPP
B. EAP
C. WEP
D. WPA
4. What term is used to describe driving around with inexpensive hardware and software
that enables attackers to detect access points that haven’t been secured?
5. True or False: One countermeasure for wireless attacks consists of placing the AP in the
company’s DMZ and using a firewall in front of the company’s internal network that
filters out all traffic from unauthorized IP addresses.
Hands-On Ethical Hacking and Network Defense, Third Edition 1111
Class Discussion Topics
1. You are asked to create your company’s wireless local area network (WLAN). Which
2. Do any of your students have a WLAN set up at home? If so, have they taken steps to
secure it? After learning about the topics covered in this chapter, do they feel the
measures they have taken are sufficient? Have any of their WLANs been compromised?
Additional Projects
1. Ask your students to install any sniffer software such as Ethereal or Tcpdump. Then,
ask them to listen to traffic sent over a wireless network and to try finding any of the
following information: SSID, AP’s MAC address, and transmitting computers MAC
and IP addresses. Is this task different from sniffing on wired network traffic? .
2. Ask your students to investigate WEP encryption cracking tools that run on Microsoft
systems and report their findings. How do these tools compare to AirCrack NG?
Additional Resources
1. Some Tips for Setting up Wireless Home Networks:
3. What is WPA2:
http://compnetworking.about.com/od/wirelesssecurity/f/what-is-wpa2.htm
4. Hacking Techniques in Wireless Networks:
5. Practically Networked, Securing Your Wireless Network:
Hands-On Ethical Hacking and Network Defense, Third Edition 1112
Key Terms
See Glossary for definitions of Key Terms.
802.11
802.1X standard
access point (AP)
chipping code
Extensible Authentication Protocol (EAP)
frequency
infrared (IR)
infrastructure mode
Institute of Electrical and Electronics Engineers (IEEE)
metropolitan area networks (MANs)