All modules

Module 10 · Advanced

Wireless & Adjacent Surfaces

Wireless assessments demand strict authorization, careful RF hygiene, and deep understanding of 802.11 authentication, encryption, and client behavior. This module covers lab-only Wi-Fi attack learning paths, evidence standards, and home/AP hardening plus operator OPSEC so you never confuse “interesting signal” with legal permission. Practice only on networks and hardware you own or are explicitly contracted to test.

2 lessons
12 deep sections
~125 min guided
Progress…

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Outcomes

  • State legal and RoE constraints for any wireless work before transmitting or capturing
  • Build a controlled Wi-Fi lab and perform authorized WPA/WPA2 assessment workflows
  • Explain handshake capture, PMKID, and offline cracking limits without magical thinking
  • Harden a home or small-office AP with modern defaults and guest isolation
  • Apply RF OPSEC habits that protect your household and keep practice ethical

Lessons

Lesson 1
70 min6 sections

Wi-Fi assessment in a controlled lab

Authorized 802.11 lab work: adapters, monitor mode, handshakes, and professional reporting — never against strangers’ networks.

Learning objectives

  • Define legal boundaries: only owned or contract-authorized wireless networks
  • Configure a compatible adapter for monitor mode and controlled capture in a lab
  • Capture and verify a WPA/WPA2 four-way handshake or PMKID under lab conditions
  • Run offline wordlist attacks ethically against lab credentials you set
  • Document wireless findings with impact, likelihood, and remediation suitable for clients

Deep teach-through

Law, ethics, and the non-negotiable rule

Wireless only on owned networks or networks where a written authorization explicitly covers RF testing. Capturing traffic from a neighbor, café, hotel, workplace guest SSID without permission, or random BSSID is not “practice” — it can be illegal interception or unauthorized access.

Even passive capture can be regulated depending on jurisdiction and content. Active attacks (deauth, evil twin, jamming) are higher risk and often illegal outside authorized tests. Jamming is widely restricted and should not be used as a casual lab trick on shared spectrum in ways that disrupt others.

RoE for wireless must name SSIDs/BSSIDs, physical locations, time windows, allowed techniques (passive only vs deauth, client attacks, rogue AP), and safety constraints for medical or industrial environments.

If a probe request or interesting enterprise SSID appears from outside your lab, ignore it. Curiosity is not scope.

Lab topology that keeps others safe

Ideal home lab: a dedicated lab access point (or spare router) on a channel plan you control, a client device you own, and an attacker machine with a compatible wireless NIC. Prefer a spare AP not used for household production traffic.

Use a known lab SSID and strong but intentionally crackable passphrase only when you are practicing cracking; otherwise use production-grade secrets and do not attempt to crack them. Never reuse personal banking or email passwords as lab PSK material.

Faraday bags, distance, low transmit power, and off-hours reduce accidental impact on neighbors. You are still responsible for frames you transmit.

Document BSSID, channel, security mode (WPA2-PSK, WPA3, enterprise), and adapter chipset/driver notes. Wireless troubleshooting is half driver reality.

802.11 security modes operators must name correctly

Open networks provide no encryption; anything above RF can be observed. Captive portals are not encryption. WEP is obsolete and should be reported as critical if found live.

WPA2-PSK (Personal) protects airtime with a shared secret; weak passphrases fall to offline attacks after handshake or PMKID capture. WPA3-Personal improves resistance to offline dictionary attacks when properly implemented, but misconfigurations and transition modes still appear.

WPA2/WPA3-Enterprise uses 802.1X and a RADIUS backend. Assessment shifts toward certificate validation, EAP method strength, client trust behavior, and RADIUS integration — not simple PSK cracking.

Management frame protection, PMF, client isolation, and band steering affect both attack paths and user experience. Report the mode the network actually negotiates, not the marketing label on the box.

Capture workflow: handshake and PMKID

Monitor mode and packet capture tools let you observe beacons, probes, and authentication exchanges for in-scope BSSIDs. Verify you are associated with the correct BSSID — multi-AP sites and mesh systems confuse beginners.

The four-way handshake occurs when a client authenticates to a PSK network. Controlled reauthentication of your own lab client is the professional way to obtain a handshake in a test. Mass deauthentication of third parties is often out of scope and can be unlawful or harmful.

PMKID-based techniques can obtain material for offline attacks against some WPA2-PSK configurations without a full client handshake, depending on AP behavior. Still only against authorized targets.

Validate captures before burning GPU time: incomplete handshakes waste hours. Confirm message completeness with your cracking tool’s verification features.

Offline cracking and evidence standards

Hash extraction tools convert captures into formats accepted by hashcat or similar. Wordlists and rules simulate realistic password guessing; pure brute force of strong random PSKs is usually infeasible — that is the point of good passphrases.

Success against a lab weak password teaches process. Against a client network, a cracked PSK is high impact: network access, lateral movement to LAN hosts, and often capture of other client traffic depending on isolation.

Evidence: sanitized capture metadata, hash type, wordlist policy used, time-to-crack class, and LAN exposure after association. Do not publish client PSKs in clear text in wide-distribution slides; use controlled vault handling.

If cracking fails, the finding may still be “PSK entropy unknown / not assessed offline within window” rather than “secure forever.” Be precise.

Beyond PSK: evil twin thinking and enterprise notes

Rogue AP / evil twin demonstrations show how users and devices trust SSIDs and certificates. Only run against consenting lab clients or explicit RoE. Capturing real user credentials from unaware humans is a social engineering activity with separate authorization.

Enterprise assessments evaluate whether clients validate server certificates, whether weak EAP methods are offered, and whether users can be trained to click through warnings — coordinated with the client.

Adjacent surfaces include guest networks bridging to LAN, WPS remaining enabled, default admin passwords on AP web UIs, and management interfaces on the WAN. Many “wireless” findings are really insecure network device administration.

Always close the loop: after lab attacks, restore AP config, remove rogue interfaces, and stop monitor mode so your laptop is not a permanent RF mess.

Key concepts

Monitor mode
Wireless interface mode that captures 802.11 frames without associating as a normal station, used in authorized assessments.
Four-way handshake
WPA/WPA2 key confirmation exchange between client and AP from which offline PSK attacks may be mounted if the passphrase is weak.
PMKID
Optional RSN element material some APs expose that can enable offline PSK attacks without a full client handshake.
WPA3-Personal
Modern personal Wi-Fi mode designed to resist offline dictionary attacks better than WPA2-PSK when correctly deployed.
Client isolation
AP/switch feature preventing wireless clients from talking directly to each other, reducing post-association lateral movement.

Common mistakes

  • Capturing or attacking any SSID that is not explicitly owned or authorized
  • Deauthenticating production users without RoE and change-window agreement
  • Spending days cracking without validating the capture is complete
  • Reporting “WPA2 is insecure” without passphrase strength or design context
  • Leaving monitor mode, rogue APs, or lab weak PSKs in place after the exercise

Defender view

  • Strong unique PSKs or enterprise 802.1X, WPA3 where compatible, and disabled WPS remove most casual wireless break-ins.
  • Guest segmentation and client isolation limit damage after a passphrase leak or compromised IoT client.
  • Detecting floods of deauth frames, unexpected evil twins, and new rogue BSSIDs is a practical SOC wireless use case.

Operator checklist

  • Written authorization or ownership is confirmed for every BSSID I will capture or attack
  • Lab AP and clients are mine; household production SSID is out of scope unless explicitly included
  • Capture is verified before offline cracking resources are used
  • I understand whether deauth, rogue AP, or enterprise attacks are allowed
  • Findings include remediation (WPA3/enterprise, PSK policy, isolation, admin hardening), not only cracked password pride

Example commands & patterns

# Only against lab/owned BSSID — replace placeholders
ip link show
sudo airmon-ng check kill
sudo airmon-ng start wlan0
sudo airodump-ng -c <channel> --bssid <lab-bssid> -w labcap wlan0mon
# After verified capture (lab PSK you set):
aircrack-ng -w wordlist.txt labcap-01.cap
hcxpcapngtool -o lab.hc22000 labcap-01.cap
hashcat -m 22000 lab.hc22000 wordlist.txt

Practice drills

  1. Write a one-page wireless RoE for your home lab AP including in-scope BSSID and forbidden techniques
  2. Put a spare adapter into monitor mode and capture beacons for your lab SSID only; document channel and BSSID
  3. Join a lab client, capture a complete handshake, verify it, and crack a deliberately weak lab passphrase
  4. Repeat with a strong random PSK and record why offline attack fails within a time box
  5. Draft a client-facing finding for weak PSK with impact on LAN assets and clear remediation

Next: Harden the home AP and practice RF OPSEC so daily living networks stay out of accidental scope.

Lesson 2
55 min6 sections

RF OPSEC and home AP hardening

Make the household wireless estate boring to attackers: modern crypto, segmentation, admin hygiene, and operator self-control around RF.

Learning objectives

  • Hardening a consumer or prosumer AP to a defensible baseline
  • Segment IoT and guests away from workstations and NAS devices
  • Apply operator OPSEC so practice gear never targets the wrong SSID
  • Inventory wireless-adjacent risks: WPS, UPnP, remote admin, default creds
  • Create a household wireless security checklist you can reuse quarterly

Deep teach-through

Why home networks are both lab and liability

Home Wi-Fi often hosts work laptops, cameras, medical-adjacent gadgets, and cloud-connected appliances. A weak PSK or exposed router admin UI is a full-lifecycle risk, not a CTF curiosity.

Operators who practice wireless techniques must keep a hard mental wall between lab SSIDs and family production SSIDs. Mis-aimed deauth or association tests can drop video calls, smart locks, or someone else’s work VPN.

Treat the household network as a small enterprise: inventory devices, separate trust tiers, patch the gateway, and monitor for strangers.

If roommates or family share the network, document what is production vs lab. Shared consent matters when experiments generate noise.

AP hardening baseline

Change default admin passwords; disable remote (WAN) administration unless you have a strong need and restrictive controls. Keep router firmware updated from vendor channels you trust.

Prefer WPA3 or WPA2 with a long random PSK stored in a password manager; avoid common phrases and reused passwords. Disable WPS. Disable legacy protocols (WEP, TKIP-only modes) if compatibility allows.

Use a unique SSID that does not advertise your name or address. Hiding the SSID is not a security control; do not rely on it. Reduce power only if it still covers needed areas without inviting edge clients to sticky-roam poorly.

Turn off universal features you do not need: UPnP when not required, WPS, insecure cloud management, and guest features that bridge into LAN.

Segmentation: guest, IoT, and trusted LAN

Put untrusted IoT on a guest or VLAN-like SSID that cannot initiate connections to workstations or NAS. Many consumer routers support “AP/client isolation” and guest networks — use them.

Work devices and password managers deserve the trusted segment. Backups and file shares should not be reachable from the smart fridge VLAN.

Document DHCP ranges and static assignments for easier anomaly spotting. A new MAC on the trusted SSID deserves a question.

For operators, a dedicated lab AP (even a travel router) is cheaper than apologizing for taking down household Wi-Fi during a deauth demo.

Operator RF OPSEC habits

Label adapters and scripts with intended interface names. Keep a sticky note or checklist: “Lab BSSID only.” Automation that auto-selects the strongest signal is how accidents happen.

Store captures in engagement-like folders with clear names. Never “just crack” a capture file whose origin you do not remember.

In public spaces, do not run offensive wireless tools “for fun.” Passive observation of networks you do not own can still cross legal and ethical lines. Leave the gear bag closed.

Travel routers and portable lab kits should ship with known-good configs and strong admin secrets. Factory-default travel APs are a gift to hotel-side attackers — including you as the victim.

Adjacent physical and RF-aware thinking

Evil twin risk works both ways: your family devices may join malicious SSIDs that mimic coffee shops. Prefer known networks, VPN on untrusted networks, and certificate-aware enterprise configs for work.

Bluetooth, Zigbee, and proprietary IoT radios expand the home attack surface. You do not need to attack them to inventory them: what can open a door, record audio, or bridge to LAN?

Physical access to the AP often bypasses wireless crypto entirely (reset buttons, Ethernet admin). Placement and physical security still matter.

Logging: even consumer routers sometimes show connected clients. Review periodically. Advanced homes may run separate firewalls (opnSense, etc.) with better visibility — optional depth, not required for this lesson’s baseline.

Quarterly review and metrics that matter

Checklist: firmware current, admin secret rotated if shared, WPS off, guest/IoT isolation verified with a phone test, PSK strength, remote admin off, unused features off, device inventory updated.

Test isolation by associating a phone to guest and attempting to reach a trusted LAN IP you own. Failure to connect is success.

After any wireless lab day, confirm production SSID still uses strong settings and that you did not leave a second DHCP server or rogue AP running.

Teach non-operator household members a simple rule: only known SSIDs, no clicking through certificate warnings on work profiles, report strange captive portals.

Key concepts

WPS
Wi-Fi Protected Setup convenience feature frequently abused historically; should be disabled on hardened networks.
Guest segmentation
Placing untrusted wireless clients on a network path that cannot reach internal trusted hosts.
RF OPSEC
Operational discipline ensuring wireless tooling, captures, and transmissions stay within owned or authorized targets.
UPnP
Automatic port-mapping convenience on many routers that can expose internal services unintentionally.
Management plane exposure
Router/AP admin interfaces reachable from WAN or open Wi-Fi; often more severe than weak client isolation alone.

Common mistakes

  • Practicing deauth or evil twin against the household production SSID during work hours
  • Leaving WPS enabled because setup was convenient once
  • IoT cameras and NAS on the same flat LAN as laptops with file shares
  • Remote admin from WAN with a default or reused password
  • Keeping unlabeled capture files from mixed sources on the attack laptop

Defender view

  • Isolation and strong PSK/enterprise auth turn many opportunistic wireless attacks into non-events.
  • Firmware updates and disabled legacy features close entire classes of router compromise.
  • Simple client inventory reviews catch unknown devices before they become long-term footholds.

Operator checklist

  • Production and lab SSIDs are visually and operationally distinct in my notes
  • WPS and remote admin are disabled on home gateways I administer
  • Guest/IoT cannot reach trusted LAN services in a live test I performed
  • Captures and wordlists on disk are clearly lab-sourced
  • I have a quarterly wireless hardening checklist dated with last review

Example commands & patterns

# Verify your association target (lab only) — examples vary by OS
nmcli dev wifi list
iw dev
# On a hardened lab AP web UI / controller: confirm WPA3/WPA2, WPS off, guest isolation on
# Isolation test from guest phone: attempt SSH/HTTP to a trusted LAN host you own; expect failure
# Kismet may be used for authorized site surveys only — not drive-by targeting of third parties

Practice drills

  1. Export or photograph your AP security settings page; fix any gap against the baseline in this lesson
  2. Create or enable a guest/IoT SSID and prove isolation from a trusted host
  3. Rotate the home Wi-Fi PSK to a password-manager-generated secret and reconnect all critical devices
  4. Write a personal RF OPSEC policy (10 rules) for your attack laptop
  5. Inventory every wireless client on your LAN; remove or segment anything unknown or unneeded

Next: Translate technical proof into professional findings and methodologies in the reporting module.