PT0-003 · Question #76
During a security assessment, a penetration tester needs to exploit a vulnerability in a wireless network's authentication mechanism to gain unauthorized access to the network. Which of the…
The correct answer is A. KARMA attack. A KARMA attack exploits the behavior of wireless devices that automatically probe for previously connected Wi-Fi networks by broadcasting their preferred network list (PNL) without authentication. The attacker sets up a rogue access point that dynamically responds to these…
Question
During a security assessment, a penetration tester needs to exploit a vulnerability in a wireless network's authentication mechanism to gain unauthorized access to the network. Which of the following attacks would the tester most likely perform to gain access?
Options
- AKARMA attack
- BBeacon flooding
- CMAC address spoofing
- DEavesdropping
How the community answered
(24 responses)- A79% (19)
- B8% (2)
- C4% (1)
- D8% (2)
Explanation
A KARMA attack exploits the behavior of wireless devices that automatically probe for previously connected Wi-Fi networks by broadcasting their preferred network list (PNL) without authentication. The attacker sets up a rogue access point that dynamically responds to these probe requests by impersonating any SSID the client device is searching for, effectively tricking the device into connecting to the malicious network without user intervention. This allows the attacker to bypass authentication mechanisms and gain unauthorized access, often positioning themselves as a man-in-the-middle (MITM) to intercept data or further exploit the victim.
Topics
Community Discussion
No community discussion yet for this question.