Testing scope

Penetration testing of
wireless networks

Wi-Fi is the only part of your infrastructure someone can walk up to from the car park. We check whether it can be entered without credentials, whether the guest network is genuinely separated, and whether employee laptops obediently connect to an access point we set up outside the building.

  • WPA2 and WPA3, both Personal and Enterprise
  • Verification of guest network and personal device isolation
  • Client device testing, not just access points

Wireless networks

Duration
usually 3-7 working days
We work to
  • OSSTMM (wireless section)
  • PTES
  • NIST SP 800-153
  • MITRE ATT&CK

What exactly we check

We tailor the scope to your environment, but these areas are always covered.

1

Authentication and encryption

WPA2 and WPA3 configuration, EAP methods in the Enterprise variant, RADIUS server certificate validation on the client side, key quality in the Personal variant, support for older and weaker modes.

2

Evil Twin and impersonation

An access point using the same network name, attempts to capture domain credentials, a captive portal imitating the login page, forcing a downgrade to a weaker authentication method.

3

Network isolation

Whether corporate resources are reachable from the guest network, whether devices on the same network can see each other, how personal phones and IoT devices are treated.

4

Client devices

Preferred network lists broadcast by laptops and phones, automatic connection to open networks with a known name, KARMA-style attacks, behaviour after losing signal.

5

Access points and controllers

Management panels and default credentials, firmware currency, active WPS, management reachable from the user network, broadcast and transmit power configuration.

6

Coverage and physical layer

Measuring coverage outside the building and beyond the controlled area, detecting rogue access points connected to the corporate network, resistance to deauthentication and jamming.

What we find most often

Examples from our projects in this area. Client names and technical details stay in the reports.

  • A corporate Wi-Fi key crackable within a few hours
  • Clients accepting any RADIUS server certificate, allowing domain credentials to be captured
  • A guest network with access to internal servers
  • No client isolation: guest devices can see each other
  • The same key in use for years, known to former employees and contractors
  • An access point with the default administrator password
  • Active WPS allowing authentication to be bypassed
  • Corporate network coverage reaching the car park and the neighbouring building

Selected tools

aircrack-nghcxdumptooleaphammerKismethashcatspectrum analyser

Tools take care of the repetitive work. The conclusions and attack chains are built by hand.

How the test runs and what you get

The testing process, the report format and the retest rules are the same across every scope.

See the full process and report contents

Frequently asked questions

Do you have to be on site?

Yes, this scope requires being within range of the network. One or two days on location is usually enough. The rest of the work, including controlled cracking of captured hashes, is done remotely.

Will the test disrupt our Wi-Fi?

Most of the work is passive. Tests that can briefly disconnect devices, such as deauthentication, are run in an agreed window and against a limited set of devices.

Do you capture employee passwords?

In the Evil Twin scenario we capture credential hashes to prove the attack works. We do not recover passwords beyond what is needed to demonstrate the vulnerability, and the captured material is deleted when the project closes. That rule is written into the contract.

Do you test multiple locations?

Yes. For a distributed network we usually propose a full test at headquarters and a shorter review at selected branches, because configuration tends to be copied and the same mistakes repeat everywhere.