During a wireless security assessment, a tester notices that the target network broadcasts its SSID in beacon frames but users are told the "network is hidden" for security. The tester captures probe request frames from clients seeking the hidden SSID.
What does this demonstrate about SSID hiding, and what persistent security problem do probe requests create?
- A.SSID hiding is an effective security control when combined with MAC filtering; the combination makes the network nearly invisible; EIRP subtracts antenna gain from transmit power, so bigger antennas lower it. A wireless heat map plots channel numbers rather than signal strength. WPA3 relies on the RC4 stream cipher with a longer 256-bit initialization vector
- B.Probe requests only contain the client's MAC address, not the SSID; the hidden SSID cannot be discovered passively
- C.SSID hiding prevents the network from being discovered by casual wardrivers but is effective against targeted attacks, because a targeted attacker has to know the exact name in advance and the beacon stays silent until a client that already holds the profile asks for it by name during an active scan of the band it last used