EAPHammer Enterprise
Enterprise Wi-Fi networks rely on 803.1X/EAP (Extensible Authentication Protocol) for secure client authentication, using EAPOL (Ethernet Authentication Protocol) handshakes to exchange credentials between clients, authenticators, and RADIUS servers. EAP-Hammer exploits this process by leveraging deauthentication attacks to disrupt EAPOL handshakes, forcing clients into repeated re-authentication cycles and potentially capturing sensitive information or denying access. This section explores how EAP-Hammer targets enterprise authentication protocols and the implications for defensive analysis.
Understanding EAPOL in Enterprise Authentication¶
EAPOL handshakes are critical for 802.1X authentication, involving three phases:
1. EAPOL-Start: The client initiates the handshake by sending an EAPOL-Start frame to the authenticator.
2. EAP Exchange: The authenticator forwards EAP messages (e.g., EAP-Request/Identity) to the client, which responds with credentials (e.g., EAP-Response/Identity).
3. EAPOL-Logoff: The handshake concludes with EAPOL-Logoff, confirming successful authentication.
Disrupting any phase of this process can prevent clients from connecting to the network or force them into re-authentication, which is the core mechanism of EAP-Hammer.
EAP-Hammer Attack Mechanism¶
EAP-Hammer works by sending forged deauthentication frames to either the client or the authenticator, terminating the EAPOL handshake. This forces the client to re-initiate the authentication process, creating opportunities for:
- Credential interception: Capturing EAP messages (e.g., usernames, passwords) during re-authentication.
- Denial of service (DoS): Preventing legitimate clients from accessing the network.
- Replay attacks: Exploiting repeated EAPOL handshakes to extract session keys or other sensitive data.
The attack is particularly effective against networks using EAP methods like EAP-PEAP or EAP-TLS, where credentials are transmitted in plaintext or require repeated authentication.
Execution and Tools¶
EAP-Hammer is typically executed using tools like aireplay-ng (from the Aircrack-ng suite) to inject deauthentication frames. Below is a typical workflow:
# Put the wireless interface in monitor mode
airmon-ng start wlan0
# Deauthenticate the client from the AP
aireplay-ng -0 0 -a [BSSID] -c [Client_MAC] wlan0mon
Notes:
- Replace [BSSID] with the target access point's MAC address.
- Replace [Client_MAC] with the client's MAC address (optional; omitting it deauthenticates all connected clients).
- The attack requires proximity to the target network and knowledge of the BSSID.
Monitoring the EAPOL handshake with tools like Wireshark can reveal the disruption:
Defensive Mitigations¶
- Detect deauthentication attempts: Use tools like dsniff or Wireshark to monitor for abnormal deauthentication frames.
- Secure EAP configurations: Prioritize EAP methods with strong encryption (e.g., EAP-TLS) and avoid vulnerable protocols like EAP-PEAP.
- Network segmentation: Isolate guest and enterprise networks to limit the scope of deauthentication attacks.
- Implement EAPOL monitoring: Configure switches or RADIUS servers to log and alert on repeated EAPOL handshakes.
Key takeaways¶
- EAP-Hammer exploits EAPOL handshakes to disrupt enterprise Wi-Fi authentication, forcing clients into re-authentication cycles.
- Deauthentication attacks can intercept credentials or deny access, making them a critical threat to 802.1X networks.
- Defenders should monitor for deauthentication frames, secure EAP configurations, and implement EAPOL-specific detection mechanisms.
- Regular audits and network segmentation are essential to mitigate the impact of such attacks.