Chapter 2. Wireless Network Scanning

Scanning wireless networks in the target environment and collecting information about the access points and clients connected to them are the primary tasks in any wireless pentest. The outcome of the scanning phase is a list of access points in operation, connected wireless clients, MAC addresses of APs and clients, the channel(s) they are operating on, the signal strength, the authentication methods deployed, and the encryption schemes being used.

In this chapter, we will be covering the following topics:

  • The 802.11 terminology
  • 802.11 network composition
  • Scanning tools

Wireless network discovery

Scanning wireless networks is often called wireless network discovery or Stumbling, which is an act of discovering available wireless networks in a target area. In a penetration testing exercise, scanning is the initial phase, where the attacker gathers enough information that can be used in the later stages of the attack. The amount of information gathered in this stage will affect the test plans and define the additional actions that will be conducted in subsequent stages.

Wireless scanning or discovery can be broadly categorized into either passive scanning or active scanning. In passive scanning, an attacker silently discovers the target network in an unintrusive way, which will typically leave no trace of evidence on the target network. In active scanning, an attacker probes the target and interactively interrogates the target, which may leave some forensic data, such as logs, performance degradation, or an impact on user sessions. Passive scanning is the preferred method for wireless penetration tests; however, it may need to be augmented with active methods if the passive-only discovery techniques stall or do not produce the required results. We will revisit these two techniques later in the chapter.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.