GPEN · Question #375
Victor wants to use Wireless Zero Configuration (WZC) to establish a wireless network connection using his computer running on Windows XP operating system. Which of the following are the most likely…
The correct answer is A. Attacker by creating a fake wireless network with high power antenna cause Victor's computer B. Information of probing for networks can be viewed using a wireless analyzer and may be used. WZC on Windows XP automatically connects to remembered networks and continuously probes for them, making computers vulnerable to rogue access points and passive wireless reconnaissance.
Question
Victor wants to use Wireless Zero Configuration (WZC) to establish a wireless network connection using his computer running on Windows XP operating system. Which of the following are the most likely threats to his computer? Each correct answer represents a complete solution. Choose two.
Options
- AAttacker by creating a fake wireless network with high power antenna cause Victor's computer
- BInformation of probing for networks can be viewed using a wireless analyzer and may be used
- CAttacker can use the Ping Flood DoS attack if WZC is used.
- DIt will not allow the configuration of encryption and MAC filtering. Sending information is not
How the community answered
(29 responses)- A83% (24)
- C14% (4)
- D3% (1)
Why each option
WZC on Windows XP automatically connects to remembered networks and continuously probes for them, making computers vulnerable to rogue access points and passive wireless reconnaissance.
An attacker can deploy a rogue access point broadcasting the SSID of a trusted network with a high-power antenna, causing WZC to automatically associate with it, exposing the user to man-in-the-middle attacks and credential theft. Because WZC selects networks based on remembered SSIDs and signal strength without mutual authentication, it cannot distinguish a legitimate AP from an evil twin.
WZC continuously broadcasts probe request frames containing the SSIDs of all stored preferred networks, and any nearby attacker running a wireless packet analyzer can passively capture these frames. The captured SSID list can then be used to craft targeted rogue AP attacks or to map the user's network habits.
A Ping Flood DoS attack is a generic ICMP-based attack unrelated to WZC; using WZC does not introduce any additional vulnerability to ICMP flood attacks.
WZC does support configuration of wireless encryption such as WEP and WPA as well as MAC filtering, so the claim that it prevents these security configurations is factually incorrect.
Concept tested: WZC vulnerabilities - rogue AP and probe request exposure
Source: https://learn.microsoft.com/en-us/troubleshoot/windows-client/networking/wireless-zero-configuration-service-overview
Topics
Community Discussion
No community discussion yet for this question.