Skip to content

where exploits happen

sloth wiki-sync edited this page Sep 30, 2026 · 1 revision

Where exploits happen

Summary: A defender's map of the Wi-Fi attack surface. It walks the same join sequence a client experiences (how-wifi-works §3) and, at each step, names the attack classes that target it, what they look like to a passive listener, and the sloth detector that catches them. The framing is deliberate: attacks live at protocol seams, and sloth's job is to see the seam being worked.

Sources: docs/views/alerts.md, src/alerts.c, docs/wiki/{fragattacks,btm-abuse,action-frames,enterprise-rogue,captive-portal,evil-twin-reproducer}.md, research corpus under research/.

Last updated: 2026-09-30.


Why the seams

Wi-Fi's weak points are structural, not incidental:

  1. Management frames are unauthenticated by default. Without PMF (802.11w), a client cannot tell a real Deauth from a forged one.
  2. The passphrase handshake is passively capturable. WPA2's 4-way handshake and PMKID verify an offline guess.
  3. Clients advertise what they trust. Probe Requests name remembered networks, and a client will connect to any AP claiming that name.

Every attack below exploits one of those three. sloth cannot stop them — it is passive — but it can see all three being used.

The map — by join step

Step 1: Discover (beacons & probes)

Attack On-the-air signature sloth detector
Evil twin — clone an AP's SSID, lure clients duplicate SSID, mismatched BSSID/cipher/OUI EVIL_TWIN (+confidence), Twins [x], evil-twin-reproducer
KARMA / MANA — answer every probed SSID one radio responding as many SSIDs KARMA_AP, KARMA [y]
Beacon flood — spray fake SSIDs high rate of distinct SSIDs from one source BEACON_FLOOD
SSID confusion (CVE-2023-52424) client joins a network under the wrong name SSID_CONFUSION
Open onboarding AP left exposed open AP with a setup-shaped SSID OPEN_SETUP_AP
Rogue reconnaissance of your net client probing an SSID you designated as yours MY_NET_RECON (needs --my-ssid)

Step 2–3: Authenticate & associate

Attack On-the-air signature sloth detector
Deauth / disassoc flood — force disconnects burst of deauth/disassoc frames at a target DEAUTH_FLOOD, Deauth [a]
Auth / assoc flood — exhaust an AP burst of auth or assoc requests AUTH_FLOOD, ASSOC_FLOOD
Management fuzzing — malformed mgmt frames spec-violating frame fields MGMT_FUZZ
BTM steering abuse (802.11v) — move a client with no deauth BSS Transition Request w/ Disassoc-Imminent toward a chosen BSSID BTM_ABUSE, btm-abuse, action-frames
SA-Query storm / spoofed disassoc under PMF SA-Query flood as the symptom of a forged disassoc SA_QUERY_FLOOD, MFP_UNPROTECTED, action-frames
CSA abuse — forge a channel-switch to move clients Channel Switch Announcement from a non-AP CSA_ABUSE
RRM survey abuse (802.11k) — probe topology crafted radio-measurement requests RRM_SURVEY_ABUSE

Step 4: Key exchange & crypto

Attack On-the-air signature sloth detector
Handshake / PMKID capture — offline passphrase guessing captured 4-way handshake or PMKID EAPOL [e] captures it (your own net testing), wifi-sigint
WPA downgrade — force WPA1/weaker cipher a network advertising both, or a rollback WPA_DOWNGRADE, WEAK_TLS (TLS analogue)
SAE / Dragonblood (WPA3) — downgrade or split PSK/SAE mixed SAE/PSK advertisement, transition-mode abuse SAE_PSK_SPLIT, SAE_PSK_REGRESSION
FragAttacks (Vanhoef 2021) — 12 CVEs in fragmentation/aggregation plaintext/broadcast frags, mixed-key reassembly, A-MSDU abuse seven FRAG_* rules, FragAttacks [c], fragattacks
Block-Ack manipulation forged Block-Ack to drop frames BLOCKACK_ATTACK
RTS flood RTS control-frame flood RTS_FLOOD

After the join: enterprise & upper layers

Attack Signature sloth detector
Rogue RADIUS / EAP (WPA-Enterprise) rogue 802.1X authenticator, identity leak ROGUE_RADIUS, Rogue RADIUS [z], enterprise-rogue
PEAP with no server-cert check (CVE-2023-52160) — your own fleet client accepting an unverified server PEAP_NO_SERVER_CERT, enterprise-rogue
Captive-portal interception rogue portal answering the OS connectivity probe CAPTIVE_PORTAL, captive-portal
Rogue IPv6 RA (mitm6) crafted Router Advertisement ROGUE_RA, ipv6-ndp
ARP / DHCP spoofing one IP → two MACs; unexpected DHCP OFFER ARP_SPOOF, ROGUE_DHCP
Cleartext credentials username in the clear (HTTP/FTP/POP3/IMAP/SMTP) CLEARTEXT_CRED

Upper-layer service attacks (SMB1, Kerberos spray, LDAP recon, SSH/RDP/ SNMP/MQTT brute force, C2 beaconing, DGA, DNS/ICMP tunnels) ride the same capture and have their own snoop pages — see attack-map.

The honest limits

  • Passive detection sees behaviour on the air, not intent. A deauth flood and a flaky driver both produce deauth frames; sloth reports the frames and lets the operator judge. Confidence is separated from severity for exactly this reason (alerts).
  • One channel at a time (monitor-mode) — an attack on a channel you are not dwelling on is unseen.
  • Some detectors ship empty by design — the tool-fingerprint table (tool-fingerprints) and the threat-intel IOC list (threat-intel) — because a dishonest signature is worse than none.

Related pages

Clone this wiki locally