Wireless Security Flashcards
(20 cards)
What was the first wireless security protocol?
Wired Equivalent Privacy (WEP).
Why is WEP insecure?
Uses a static key, short IV (24-bit), and weak encryption (RC4) prone to various attacks.
List some attacks against WEP.
FMS Attack, KoreK Attack, ChopChop Attack, Fragmentation Attack, PTW Attack.
What encryption protocol replaced WEP?
Wi-Fi Protected Access (WPA).
What improvements does WPA have over WEP?
Uses TKIP, provides dynamic keying, better integrity checks, and improved security.
What are the vulnerabilities of WPA?
Susceptible to dictionary and brute-force attacks due to PSKs.
What encryption standard is used by WPA2?
Advanced Encryption Standard (AES) with CCMP.
What vulnerabilities were discovered in WPA2?
KRACK attacks (Key Reinstallation AttaCKs).
What are the main improvements in WPA3?
Protection against offline dictionary attacks, forward secrecy, easier connection methods like Wi-Fi Easy Connect.
What is the Dragonfly handshake in WPA3?
A key exchange resistant to active/passive attacks and offline dictionary attacks.
What is a downgrade attack in WPA3 transitional mode?
Forcing WPA3 devices to revert to the less secure WPA2 handshake.
What does WPA Enterprise use for authentication?
802.1X, often combined with RADIUS servers.
What is the primary function of a RADIUS server?
Authentication, Authorization, and Accounting (AAA).
What is MAC address filtering?
Allowing network access only to devices with specific MAC addresses.
What is an SSID cloak?
Hiding the wireless network name from being broadcast publicly.
What security measure encrypts connections at both ends over public networks?
Virtual Private Network (VPN).
What tool can be used as a rogue access point for testing?
Wi-Fi Pineapple.
What is DHCP and why can it be insecure?
Dynamic Host Configuration Protocol; it dynamically assigns IP addresses, which can be exploited.
Why use static IP addresses for security?
Reduces vulnerability by eliminating DHCP attacks.
What should you regularly update on a wireless access point to maintain security?
Firmware and software patches.