Courses

Learn more about the training offered at INFILTRATE

SensePost Unplugged: Modern Wi-Fi Hacking

If you want to learn how to understand and compromise Wi-Fi networks, this is your course.

Learning modern Wi-Fi hacking can be a pain. There is lots of outdated material for technologies we rarely see deployed in the real world anymore. Numerous tools overly rely on automation, and leave you wondering when they don’t work, because neither the fundamentals nor underlying attack is understood. Even worse, some popular attacks will rarely if ever work in the real world.

If you want to really understand what’s going on, and master the attacks in such a way that you can vary them when you encounter real world complexities, this course will teach you what you need to know.

We’ve been pentesting Wi-Fi networks for nearly two decades, and have built some popular Wi-Fi hacking tools such as Snoopy and Mana.

This course is highly practical, with concepts taught through theory delivered while your hands are on the keyboard, and semi-self directed practicals at the end of each section to reinforce the learning. The course is hosted in a “Wi-Fi in the cloud” environment we invented several years ago, which means no more fiddling with faulty hardware or turning the classroom into a microwave.

Learning Objectives

  • How Wi-Fi hacking fits into wider attack or defence objectives
  • Important physical and low level RF concepts and how to reasonthrough/debug strange situations
  • Understanding how monitor mode works, when to use or not use it, and practical examples of what to do with collected frames or data
  • Grokking the WPA2 4-way handshake and the numerous ways of recovering PSKs and what do with them
  • First looks at attacking WPA3’s Dragonfly handshake with downgrades
  • Grokking EAP & EAP vulnerabilities relating to certificate validation, tunnelled mode key derivation and how to practically attack them with downgrades, relays and manipulating state

Course Information

Date: October 11th - October 14th
Course Fee: $4,900
CPE Credits: 0

View the Conference Calendar

More Infiltrate Courses

If you are trying to determine which course is best suited for you, email us at infiltrate@immunityinc[dot]com and we will assist you.

See all the courses

Syllabus

Course Length: 4 Days

INTRODUCTION

  • How & Why
    • When and why to use Wi-Fi attacks
  • Physical & Low Level
    • Understanding spectrum, signals and propagation
    • Peculiarities of crowded Wi-Fi spectrum & resulting behaviour in Tx & Rx
    • Understanding hardware - cards, antennas. Practical recommendations
    • Specifics of Wi-Fi signalling
  • Practical: Getting comfortable & understanding your tools

MONITOR MODE

  • What it is
    • How it works. What you get. Why it isn’t promiscuous.
    • Prism/Radiotap headers & how driver implementations differ.
  • How to use it
    • Practical: Interception & Cookie Theft

PROBING, TRACKING & DEANONYMISATION

  • Management frames - beacons & probes
  • Device probe’ing behaviour
  • Practical: Snoopy Tracking, Spectrum & Deanonymisation

WPA/2/3 PSK

  • What it is
    • IEEE & WEP history
    • 4-way handshake crypto
  • Handshakes
    • Capturing, deauthing
    • Practical: Vanilla de-auth & capture handshake
    • Practical: Decrypting traffic
  • Broken handshake debugging
    • Practical: Rogue AP Half Handshake
    • Practical: Detecting/Fixing broken handshakes
  • PMKID attacks
  • WPS attacks
  • Advanced
    • Approaches and methodologies for the real world
    • Practical: Real World WPA/2
  • WPA3
    • The Dragonfly handshake
    • Other WPA3 improvements/defences
    • Practical: WPA3 downgrade

EAP

  • What it is
    • Generic EAP flow
    • Specific EAP types and how they work
  • PEAP
    • Deep inside the second tunnel
    • CVE-2019-6203
    • Practical: Evil-Twin WPE
    • EAP-GTC downgrade attack
  • EAP-TLS
    • Understanding/breaking cert validation
    • Practical: EAP-TLS isn’t safe
  • Tunneled EAP Relays
    • Practical: Sycophant; Relaying Tunnelled Modes

Infiltrate Sponsors

Register Now

Tickets will be released soon.

Training & Workshops

Learn more about the technical training and workshops offered at INFILTRATE

Attend a session