PEAP Relay Attacks with wpa_sycophant
ID: 861f34a9-d8fe-5e0b-b209-326acb76d930
STIX ID: report--861f34a9-d8fe-5e0b-b209-326acb76d930
Feed Name: SensePost Blog
This report explains a Wi‑Fi PEAP relay technique that uses hostapd-mana and a modified wpa_supplicant (wpa_sycophant) to proxy a victim’s MSCHAPv2 inner authentication to a legitimate access point/RADIUS server, enabling unauthorized association without password cracking when cryptographic binding is disabled; it details the two-stage workflow (rogue AP lures, then relays to the real AP), why the separation of outer TLS and inner auth enables the attack, and recommends mitigations such as enabling EAP cryptographic binding and enforcing strict certificate validation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
