BackTrack 5 Wireless Penetration Testing
Time for action – installing BackTrack
Time for action – configuring the access point
Time for action – configuring your wireless card
Connecting to the access point
Time for action – configuring your wireless card
WLAN and Its Inherent Insecurities
Time for action – creating a monitor mode interface
Time for action – sniffing wireless packets
Time for action – viewing Management, Control, and Data frames
Time for action – sniffing data packets for our network
Time for action – packet injection
Important note on WLAN sniffing and injection
Time for action – expermenting with your Alfa card
Role of regulatory domains in wireless
Time for acton – experimenting with your Alfa card
Time for action – uncovering hidden SSIDs
Time for action – beating MAC filters
Time for action – bypassing Open Authentication
Time for action – bypassing Shared Authentication
Time for action – cracking WEP
Time for action – cracking WPA-PSK weak passphrase
Speeding up WPA/WPA2 PSK cracking
Time for action – speeding up the cracking process
Decrypting WEP and WPA packets
Time for action – decrypting WEP and WPA packets
Connecting to WEP and WPA networks
Time for action – connecting to a WEP network
Time for action – connecting to a WPA network
Attacks on the WLANInfrastructure
Default accounts and credentials on the access point
Time for action – cracking default accounts on the access points
Time for action – De-Authentication DoS attack
Evil twin and access point MAC spoofing
Time for action – evil twin with MAC spoofing
Time for action – Rogue access point
Honeypot and Mis-Association attacks
Time for action – orchestrating a Mis-Association attack
Time for action – conducting the Caffe Latte attack
De-Authentication and Dis-Association attacks
Time for action – De-Authenticating the client
Time for action – cracking WEP with the Hirte attack
Time for action – AP-less WPA cracking
Time for action – Man-in-the-Middle attack
Wireless Eavesdropping using MITM
Time for action – wireless eavesdropping
Session Hijacking over wireless
Time for action – session hijacking over wireless
Finding security configurations on the client
Time for action – enumerating wireless security profiles
Attacking WPA-Enterprise and RADIUS
Time for action – setting up the AP with FreeRadius-WPE
Time for action – cracking PEAP
Time for action – cracking EAP-TTLS
Security best practices for Enterprises
WLAN Penetration Testing Methodology