PT0-002 · Question #242
A penetration tester opened a shell on a laptop at a client's office but is unable to pivot because of restrictive ACLs on the wireless subnet. The tester is also aware that all laptop users have a…
The correct answer is C. Span deauthentication packets to the wireless clients. The tester already has a shell on a laptop and knows that laptop users have wired connections available at their desks. By sending deauthentication packets to the wireless clients (including the compromised laptop), the wireless connection is disrupted, prompting the user or OS…
Question
A penetration tester opened a shell on a laptop at a client's office but is unable to pivot because of restrictive ACLs on the wireless subnet. The tester is also aware that all laptop users have a hard-wired connection available at their desks. Which of the following is the BEST method available to pivot and gain additional access to the network?
Options
- ASet up a captive portal with embedded malicious code.
- BCapture handshakes from wireless clients to crack.
- CSpan deauthentication packets to the wireless clients.
- DSet up another access point and perform an evil twin attack.
How the community answered
(46 responses)- A2% (1)
- B4% (2)
- C83% (38)
- D11% (5)
Explanation
The tester already has a shell on a laptop and knows that laptop users have wired connections available at their desks. By sending deauthentication packets to the wireless clients (including the compromised laptop), the wireless connection is disrupted, prompting the user or OS to automatically fall back to the available wired Ethernet connection. Since the tester already has a shell on the laptop, the laptop now becomes a pivot point on the wired network - bypassing the restrictive wireless ACLs. Option A (captive portal) and D (evil twin) require additional setup and do not leverage the existing shell. Option B (capturing handshakes) attacks wireless credentials, not network access.
Topics
Community Discussion
No community discussion yet for this question.