Bypassing web-based wireless authentication systems

Ahmed Ibrahim Hassan, Xiaowen Zhang · 2011

A lot of college wireless networks use software systems and web-based logins to authenticate users. In this paper we find that it is not hard to bypass such authentication. An attacker can use DHCP request to collect information about the users on the network. It makes the attacker much easier to gain unauthorized access to the network facilities. This can be done by putting the network card on monitor mode, and filter the network frames based on the collected MAC addresses. Once any client is disconnected from the network, the attacker can spoof the client's MAC address and connect to the network. The authentication system is going to accept the spoofed MAC address and let the attacker to connect to the network.

Read the paper · More papers on PaperTik