Phase 07 · The Perimeter With No Cable

Wireless Attacks

You already have the networking background — monitor mode, the four-way handshake, and the basics of WPA all live in the Wireless & IoT module. This phase is deliberately tight, focused on the part that is offensively interesting today: what WPA3 actually fixed, and the downgrade attack that quietly defeats it in the real world.

00

About this phase

WPA3 (2018) closed the structural weaknesses that made WPA2 networks crackable — chiefly, it killed the offline handshake attack. So why is wireless still on the engagement? Because almost every WPA3 network runs in transition mode for backward compatibility, and that one setting hands an attacker a path straight back to the crackable WPA2 handshake. This phase covers exactly that: the WPA3 delta, and a hands-on red-team simulation of the downgrade attack from recon to host compromise.

The fundamentals — monitor mode, scanning, the four-way handshake, rogue APs, and the live WPA2 Handshake Crack lab — live in the Wireless & IoT module, alongside the WPA evolution page. This phase assumes them and builds the offensive view on top.
Focus
WPA3 + downgrade
Phase
07 of 08
Status
Complete
01

Lessons & labs in this phase