Professional study notes for Wi-Fi / wireless security assessment, based on the material reviewed from today's screenshots and supplemented with terminology, methodology, hardware, advanced security topics, and validation guidance.
These notes cover:
- Wi-Fi penetration-testing fundamentals
- Wireless network types
- IEEE 802.11 standards
- Wi-Fi terminology: SSID, BSSID, ESSID, BSS, ESS, channel, NAV, RTS/CTS, encryption
- Wardriving and wireless reconnaissance
- Wi-Fi security: WEP, WPA, WPA2, WPA3
- Authentication and key management: PSK, 802.1X/EAP, RADIUS, 4-way handshake, PMK/PTK/GTK, SAE
- 802.11 management, control, and data frames
- Wireless attack-surface analysis
- Handshake/password auditing, deauthentication, PMKID, Evil Twin, KRACK, and WPA3 transition-mode risks
- Wi-Fi Pineapple, PineAP, Karma concepts, rogue AP simulation, captive portals, modules, and logging
- WPS, hidden SSIDs, PMF/802.11w, and client isolation
- Aircrack-ng-based assessment methodology
- Monitor mode, packet capture, authentication analysis, and reporting
- External Wi-Fi adapters and chipset selection
- Driver and compatibility considerations
- Common assessment mistakes and practical best practices
| Document | Contents |
|---|---|
| Wi-Fi Penetration Testing | Fundamentals, terminology, standards, network types, reconnaissance, assessment lifecycle, and reporting |
| Aircrack-ng Methodology | Authorized lab methodology and role of the Aircrack-ng toolset |
| External Wi-Fi Adapters | Adapter selection, chipsets, monitor mode, injection capability, drivers, VM passthrough, and compatibility |
| Advanced Wi-Fi Security Topics | 4-way handshake, TKIP, WPA2/WPA3 authentication, attack techniques, 802.11 frames, WPS, PMF, client isolation, and Wi-Fi Pineapple |
Wireless testing can affect nearby networks and clients. Perform active testing only against systems for which you have explicit authorization. Keep laboratory captures, credentials, MAC addresses, and other sensitive evidence out of public repositories.
Scope & Authorization
↓
Reconnaissance
↓
Interface / Hardware Validation
↓
Wireless Discovery
↓
Target Identification
↓
Packet Capture
↓
Authentication & Security Analysis
↓
Controlled Testing
↓
Risk Assessment
↓
Remediation
↓
Retest & Report
- Aircrack-ng documentation: https://www.aircrack-ng.org/documentation
- Airmon-ng documentation: https://www.aircrack-ng.org/doku.php?id=airmon-ng
- Airodump-ng documentation: https://www.aircrack-ng.org/doku.php?id=airodump-ng