Find the BSSID of the GrandTour AP (A) • Find the channel of the GrandTour AP (X
ID: 3797354 • Letter: F
Question
Find the BSSID of the GrandTour AP (A)
• Find the channel of the GrandTour AP (X)
• Find an associated end host ESSID (C)
• Run airodump-ng on the GrandTour channel, writing output to a file named “wpaauth”: # airodump-ng -c X --bssid A -w wpaauth wlan0mon • While airodump-ng is running, we want to disassociate an attached client in order to capture the authentication handshake when it reattaches. To send a spoofed disassociation frame that appears to originate from an AP with BSSID A to a client with MAC C, run, in a separate window: # aireplay-ng --deauth 5 -a A -c C wlan0mon
• Capture for approximately one-minute and ensure that you capture during the faked disassociation. Important: you should see a “[ WPA Handshake: xx]” message in the top right corner of airodump-ng. Don’t exit airodump-ng until you observe the handshake! Run the disassociation again until you observe the handshake, if necessary.
• Open the “wpaauth-XX.cap” trace in wireshark.
• Apply a filter expression, “eapol,” in wireshark so that it only displays EAPOL frames.
3.What is the purpose of the EAPOL frames?
4. Briefly explain why an attacker needs to capture the EAPOL frames.
5. What is the MAC address (6B media access control address) of the supplicant?
6. What are the first four bytes of the AP’s nonce? 7. What are the first four bytes of the Message Integrity Check (MIC) in the AP’s first packet of the authentication handshake?
8. What are the first four bytes of the supplicant nonce?
9. What are the first four bytes of the MIC in the supplicant’s authentication response (second packet of handshake)?
10. What key did the supplicant use to compute the MIC in question 9?
11. What MIC algorithm did the supplicant use to compute the MIC in question 9?
Explanation / Answer
3. EAPOL is the Extensible Authentication Protocol over LAN. It is a techinique used to transfer EAP packets between Supplicant and an Authenticator directly over LAN MAC service. The purpose of EAPOL frame is to carry EAP messages and for administrative tasks.
5. The MAC address of the supplicant is 08-00-27-B8-50-C3
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.