Wi-Fi (WPA2) to the internal network
Capturing a WPA2 handshake, cracking the pre-shared key offline, and joining the wireless network turns radio range into an internal foothold.
Scenario
An authorized wireless assessment within radio range of the target. Testing of the in-scope WPA2-PSK network is approved. The objective is to show whether the wireless pre-shared key can be recovered and used to reach the internal network.
- 1
Reconnaissance / Collection
Capture a WPA2 four-way handshake
Monitor the in-scope wireless network, enumerate its BSSID and clients, and capture a four-way handshake (optionally by waiting for a natural reconnection) without disrupting users.
DetectionA sudden drop and reconnection of a client, or an interface in monitor mode nearby, can be noticed by a wireless IDS/WIPS.
MitigationDeploy a wireless IPS, prefer WPA3/SAE which resists offline cracking, and watch for deauthentication floods.
- 2
Credential Access
Recover the pre-shared key offline
Run an offline dictionary/mask attack against the captured handshake. A weak or guessable passphrase is recovered; a long random one is reported as resistant — the strength of the PSK is the finding.
DetectionOffline cracking is invisible to the target by design — which is exactly why passphrase strength and rotation are the control.
MitigationUse a long, random passphrase (or 802.1X/EAP with per-user credentials), and rotate it after staff changes.
- 3
Initial Access
Join the wireless network
Authenticate to the WLAN with the recovered key to obtain an internal IP, or, where in scope, assess whether a rogue access point (evil twin) would lure clients — demonstrating the exposure without harming users.
DetectionA new, unrecognised device associating to the WLAN, or a duplicate SSID broadcasting, is detectable with WLAN client inventories and WIPS.
MitigationSegment wireless from sensitive internal zones, require 802.1X with certificate validation, and enable rogue-AP detection.
References aircrack-ng - 4
Discovery
Map the internal network
From the wireless segment, enumerate reachable hosts and services to show what the wireless foothold exposes, staying within the approved internal scope.
DetectionHost and service sweeps from a wireless client are visible to internal network monitoring and NAC.
MitigationPlace wireless clients behind a firewall with least-privilege rules, and use NAC to limit what a new device can reach.
Key takeaways
- A WPA2 network is only as strong as its passphrase — a weak PSK is an internal foothold at radio range.
- WPA3/SAE and 802.1X remove the offline-crackable shared secret entirely.
- Segment and monitor the wireless network so that joining it is not the same as being inside.