MitM conceptual question 11-24-2013, 11:41 PM
#1
Hello all,
I've read some Man in the Middle tutorials and demonstrations. I've never done it, though.
As far as I know, it's easy to execute a a MitM attack on a client connected to an open network.
The attacker only has to create a honeypot with the same essid as the open network where the client is connected. He may need to overlap the original network.
For that purpose, the client has to receive higher signal from the fake network than the original one. Then, the client is going to connect to the honeypot and he's going to be attacked by a MitM attack.
My question is: in a WEP/WPA/WPA2...Let's imagine a WPA2 network, which is protected by a password authentication.
The attacker has to create a honeypot whith the same essid and also set the same password as the original network, right?
Otherwise the client, who will try to connect automatically with the stored password, won't be able to connect to the network, because the passwords won't match.
In the case the fake network has different encryption configuracion from the original(like WEP, or open authentication), the client will not be able to match the original data remembered with the fake network, even if both have the same essid and bssid.
So, in order to do a MitM attack againts a client connected to a WEP/WPA/WPA2 you have to crack the password before. Is that correct?
Thaaaank you!
This is my first post, by the way
.
I've read some Man in the Middle tutorials and demonstrations. I've never done it, though.
As far as I know, it's easy to execute a a MitM attack on a client connected to an open network.
The attacker only has to create a honeypot with the same essid as the open network where the client is connected. He may need to overlap the original network.
For that purpose, the client has to receive higher signal from the fake network than the original one. Then, the client is going to connect to the honeypot and he's going to be attacked by a MitM attack.
My question is: in a WEP/WPA/WPA2...Let's imagine a WPA2 network, which is protected by a password authentication.
The attacker has to create a honeypot whith the same essid and also set the same password as the original network, right?
Otherwise the client, who will try to connect automatically with the stored password, won't be able to connect to the network, because the passwords won't match.
In the case the fake network has different encryption configuracion from the original(like WEP, or open authentication), the client will not be able to match the original data remembered with the fake network, even if both have the same essid and bssid.
So, in order to do a MitM attack againts a client connected to a WEP/WPA/WPA2 you have to crack the password before. Is that correct?
Thaaaank you!
This is my first post, by the way
.


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)


![[Image: wvBFmA5.png]](http://i.imgur.com/wvBFmA5.png)
