Corporate Wi-Fi clients accept an evil-twin and surrender credentials
- Affected asset
- CORP-SECURE WPA2-Enterprise SSID at the head office
- Rating
- High Likely 4 × High 4 = 16
Description
Managed laptops do not validate the RADIUS server certificate before sending credentials. A consultant standing up a network with the same name captured domain credentials as devices connected automatically, without any user action.
Evidence
[*] Rogue AP 'CORP-SECURE' up on channel 6
[+] EAP identity: CORP\a.nguyen
[+] Captured MSCHAPv2 challenge/response
[+] Cracked: CORP\a.nguyen : Spring2026!
# device connected with no certificate warning
A laptop connected to a look-alike network and its domain credentials were captured and cracked offline.
Impact
An attacker in the car park can collect domain credentials from staff devices as they arrive each morning, then use them against the VPN, Microsoft 365 or the internal network. Because the devices trust any server presenting the right name, no user has to be tricked into anything.
Remediation
Configure client devices to validate the RADIUS server certificate and to trust only your named servers, enforced through group policy or your device management platform. Move towards WPA3-Enterprise, and monitor for rogue access points broadcasting your network names.