CEH Day 11 — Complete Study Notes Wireless Security + Cloud Security + IoT Security Date: September 21, 2026 Status: Wireless, Cloud, and IoT modules completed Integrated Mini-Mock: 15/15 (100%) These notes consolidate today's theory, hands-on observations, tool recognition, attack distinctions, and CEH exam traps. PART 1 — WIRELESS NETWORK SECURITY 1. Wireless Fundamentals A Wireless LAN (WLAN) allows devices to communicate over radio frequency (RF), typically through an access point (AP). Term Meaning WLAN Wireless Local Area Network AP Access Point connecting wireless clients to a network SSID Name of a wireless network BSSID Identifier associated with a specific AP radio/interface ESSID Network name used across an extended wireless network RF Radio frequency used for wireless communication Infrastructure vs. Ad Hoc Infrastructure mode: Wireless clients communicate through an AP. Ad hoc mode: Devices communicate directly without a traditional AP. SSID vs. BSSID Multiple APs can broadcast the same SSID while having different BSSIDs. CEH trap: A hidden SSID is not a strong security control. It may still be exposed through wireless traffic and does not replace authentication or encryption. 2. Wireless Security Protocols Protocol Key Characteristics Security Status WEP Uses RC4; weak IV design Insecure WPA Introduced TKIP Legacy/obsolete WPA2 Commonly uses AES-CCMP Strong when properly configured WPA3 Uses SAE in Personal mode Improved protection against passive offline password guessing WPA2-Personal vs. WPA2-Enterprise WPA2-Personal WPA2-Enterprise Uses a shared pre-shared key (PSK) Commonly uses 802.1X/EAP Suitable for home/small networks Common in organizational networks Users share a network passphrase Supports centralized authentication Weak PSK may be vulnerable to offline guessing Authentication commonly integrates with RADIUS WPA2 Handshake Attack — Important Nuance If an attacker captures the relevant WPA2-Personal handshake, a weak passphrase may be subjected to offline guessing. This does not mean the handshake automatically reveals the password or decrypts all captured traffic. 3. Wireless Attacks Attack Description Key Recognition Clue Evil Twin Rogue AP impersonates a legitimate network Same SSID, fraudulent AP Rogue AP Unauthorized AP connected to or operating within a network Unauthorized wireless access point Deauthentication Disconnects wireless clients Forced disconnection WPS attack Attempts to exploit weaknesses in WPS authentication WPS PIN Wardriving Maps wireless networks while moving through an area Discovering and mapping APs KRACK Key Reinstallation Attack affecting vulnerable WPA2 implementations Reinstalling an already-used key WPA2 offline guessing Attempts to recover a weak PSK using captured handshake material Weak passphrase + handshake Evil Twin vs. Rogue AP A rogue AP is any unauthorized access point. An Evil Twin is a type of rogue AP specifically configured to impersonate a legitimate wireless network. Deauthentication — Key Distinction A deauthentication attack primarily targets availability by disconnecting clients. It may be used as part of a larger attack workflow, but deauthentication itself does not crack a wireless password. 4. Wireless Tools Tool Primary Purpose Aircrack-ng Wireless security auditing and captured handshake password recovery Airodump-ng Captures wireless traffic and observes APs/clients Aireplay-ng Wireless packet injection and replay Airbase-ng Creates a software-based wireless AP Kismet Wireless network detection, sniffing, and monitoring Reaver WPS PIN attacks Wireshark Packet capture and protocol analysis Aircrack-ng Suite — Memory Hook Airodump-ng → Observe and capture Aireplay-ng → Inject and replay Aircrack-ng → Crack/recover Airbase-ng → Create an AP 5. Wireless Defenses Use WPA3 or properly configured WPA2-Enterprise where appropriate. Disable WPS if unnecessary. Use strong, unique credentials. Deploy wireless IDS/IPS where appropriate. Apply network segmentation. Keep AP firmware updated. Validate certificates correctly when using enterprise authentication. Tune AP placement and RF coverage. CEH trap: MAC filtering is not strong authentication because MAC addresses can be spoofed. 6. Wireless Hands-on Lab — Environment and Observations Your Kali Linux VM did not have a dedicated USB wireless adapter. Environment observations iw dev returned no wireless interface. ip link show showed lo and eth0. The VM was using a VMware virtual network adapter. Therefore, direct 802.11 monitor-mode capture was unavailable. Existing PCAPNG analysis You inspected traffic.pcapng and observed: TCP HTTP TLS 1.2 / TLS 1.3 ARP SSDP DNS QUIC You also identified Ethernet II packet details. Key learning The capture was useful for network traffic interpretation, but it was not a raw 802.11 capture. You could not inspect wireless management frames or directly perform monitor-mode analysis. Packet interpretation takeaways ARP maps IPv4 addresses to MAC addresses. DNS may occur before a TLS connection. Unencrypted HTTP can expose application data. QUIC operates over UDP. Lab status: Wireless theory and adapted PCAP interpretation completed. Direct 802.11 monitor-mode lab deferred due to hardware limitations. PART 2 — CLOUD SECURITY 1. Cloud Service Models The cloud provider/customer responsibility boundary changes depending on the service model. Model Provider Typically Manages Customer Typically Manages IaaS Physical infrastructure and virtualization Guest OS, applications, configurations, IAM, data PaaS Infrastructure, OS, runtime/platform Applications, data, identities, configurations SaaS Hosted application and underlying platform User access, data use, and service configuration CEH trap: Moving to the cloud does not eliminate customer security responsibilities. The shared-responsibility boundary varies by service model and provider. 2. Cloud Deployment Models Model Description Public Cloud Cloud infrastructure offered for use by multiple customers Private Cloud Cloud infrastructure dedicated to one organization Hybrid Cloud Integrated use of distinct cloud environments Community Cloud Infrastructure shared by organizations with common concerns 3. Common Cloud Threats Threat Description Data breach Unauthorized access to sensitive cloud data Misconfiguration Incorrect security settings expose resources Account hijacking Attacker gains control of a cloud account Insecure APIs APIs expose data or functionality without adequate security Insider threat Authorized individual misuses access Data loss Data becomes unavailable, corrupted, or unrecoverable DoS/DDoS Cloud services experience resource exhaustion Shared technology weakness Vulnerability in shared infrastructure or isolation Critical Cloud Misconfiguration Example A storage bucket containing customer data is configured for public access. Primary issue: Incorrect access control. Direct remediation: Block unintended public access and correct the bucket's IAM/access policy. Encryption alone does not fix an incorrectly public bucket. 4. Cloud-Specific Attacks Attack Description VM Escape Attacker breaks out of a guest VM's isolation and interacts with the host/hypervisor Tenant Isolation Failure Weak isolation allows one tenant to affect or access another tenant's resources Side-Channel Attack Information is inferred from shared-resource behavior Cryptojacking Unauthorized use of computing resources for cryptocurrency mining Metadata Service Abuse Attacker abuses access to cloud instance metadata, potentially retrieving role credentials Insecure API Exploitation Attacker exploits weaknesses in cloud APIs to access data or functionality VM Escape vs. Tenant Isolation Failure VM escape: Guest VM → host/hypervisor boundary. Tenant isolation failure: One tenant's resources or data become accessible to another tenant. 5. Cloud Security Controls Risk Relevant Control Compromised administrator credentials MFA Excessive application permissions Least privilege Public storage bucket Restrict public access and correct IAM policy Unrestricted database exposure Security-group/firewall ingress restrictions Insecure APIs Strong authentication and authorization Data exposure in transit Encryption in transit Data exposure at rest Encryption at rest Cloud account misuse Logging, monitoring, and IAM reviews Data loss Backups and tested recovery procedures Least Privilege Grant each identity only the permissions required for its legitimate function. If a web application's identity has cloud-wide administrative permissions, compromising that identity could expose unrelated cloud resources. Network Security Groups vs. Network Segmentation Security groups/firewall rules: Restrict traffic to and from resources. Network segmentation: Separates systems into controlled network zones. CEH exam clue: If a database accepts connections from any IP address, think restrict inbound rules first. 6. Backup vs. Disaster Recovery Backup Disaster Recovery Recoverable copy of data Broader capability to restore systems and services Helps recover lost or corrupted data Addresses service restoration after disruption Must be protected and tested Requires recovery planning and validation A backup that has never been restored is not a proven recovery capability. Backups stored in the same environment as production may share failure or compromise risks. 7. Cloud Hands-on — Misconfiguration Review Finding Primary Control F1 — Public storage bucket Restrict public access; correct bucket/IAM policy F2 — Admin account without MFA Implement MFA F3 — App identity has cloud-wide admin Enforce least privilege F4 — Database accepts any IP Restrict inbound traffic with security-group/firewall rules F5 — Untested backups Test recovery and implement an appropriate DR strategy Key correction from the exercise A database being reachable from any IP does not mean that simply pinging it grants database access. An attacker would still need a reachable database service and a viable attack path. PART 3 — IoT SECURITY 1. What is IoT? The Internet of Things consists of physical devices with sensors, software, and network connectivity that collect, exchange, or act on data. Examples include: Smart cameras and locks Industrial sensors Wearables Connected vehicles Smart TVs and home assistants IoT devices often have limited processing power, memory, battery life, and security capabilities. 2. IoT Architecture Layer Function Example Perception / Device Collects environmental data or interacts with the physical world Temperature sensor Network / Transport Transfers data between devices, gateways, and services Wi-Fi, Bluetooth, cellular Application Processes data and provides user-facing services Cloud dashboard CEH trap: A sensor collecting environmental data belongs to the perception/device layer. 3. IoT Protocols Protocol Typical Use Key Recognition MQTT Lightweight publish/subscribe messaging Broker-based messaging CoAP Lightweight REST-like protocol Commonly uses UDP Zigbee Low-power wireless mesh networking Smart-home devices BLE Short-range, low-power wireless communication Wearables Z-Wave Low-power smart-home networking Home automation 6LoWPAN IPv6 over low-power wireless networks Constrained devices + IPv6 Memory Hooks MQTT → Message broker CoAP → Constrained devices + UDP Zigbee/Z-Wave → Smart-home mesh BLE → Low energy 6LoWPAN → IPv6 for low-power networks 4. IoT Vulnerabilities Vulnerability Security Impact Default credentials Unauthorized device access Hardcoded credentials Known or embedded secrets may be abused Insecure firmware updates Tampered or malicious firmware may be installed Outdated firmware Known vulnerabilities remain exploitable Unencrypted communication Data may be exposed in transit Insecure APIs Device data or functionality may be exposed Unnecessary open ports Expands the attack surface Weak authentication/authorization Unauthorized access or control Poor physical security Debug ports or storage may expose secrets CEH distinction: Default credentials → Authentication weakness Insecure firmware update → Firmware authenticity/integrity weakness 5. IoT Attacks Attack Description Default Credential Abuse Attacker logs in using unchanged manufacturer credentials Firmware Exploitation Attacker exploits vulnerable or tampered firmware Insecure API Exploitation Attacker abuses weak API security MITM Attacker intercepts or alters device communication Replay Attack Attacker retransmits captured valid messages DoS/DDoS Device or service is overwhelmed Botnet Recruitment Compromised devices are controlled collectively Jamming RF interference disrupts wireless communication Replay vs. MITM Replay: Reuses a previously captured valid message. MITM: Intercepts communication and may alter or relay it. Jamming Jamming primarily affects availability by disrupting wireless communication. 6. IoT Tools Tool Primary Purpose Nmap Host discovery, port scanning, and service detection Wireshark Network packet and protocol analysis Shodan Search for internet-exposed devices and services Binwalk Firmware analysis; identifies embedded filesystems and helps extract files Critical Tool Distinction Shodan ≠ exploitation tool. It helps discover internet-exposed devices and services. Binwalk ≠ Wireshark. Binwalk → Firmware image analysis Wireshark → Network traffic analysis 7. IoT Defenses Change default credentials and enforce unique passwords. Apply strong authentication and least-privilege authorization. Use signed firmware and integrity verification. Maintain secure firmware-update processes. Patch and update devices. Encrypt communication where appropriate. Disable unnecessary services. Restrict network access. Segment IoT devices from sensitive corporate systems. Restrict physical/debug-port access. Maintain an asset inventory and monitor device behavior. CEH trap: Network segmentation limits lateral movement; it does not patch the vulnerable device itself. PART 4 — DAY 11 MASTER DISTINCTIONS Concept A Concept B Key Difference SSID BSSID Network name vs. AP radio/interface identifier Evil Twin Rogue AP Impersonating AP vs. any unauthorized AP Deauthentication Password cracking Disconnects clients vs. attempts credential recovery WPA2-Personal WPA2-Enterprise Shared PSK vs. centralized 802.1X/EAP authentication Aircrack-ng Airodump-ng Password recovery vs. capture/observation IaaS SaaS Customer manages guest OS/apps vs. provider manages hosted application VM Escape Metadata Abuse VM isolation breakout vs. metadata credential access Least Privilege MFA Limits permissions vs. strengthens authentication Security Group Network Segmentation Traffic filtering vs. separating network zones Backup Disaster Recovery Recoverable data copy vs. broader service restoration MQTT CoAP Broker-based publish/subscribe vs. lightweight REST-like protocol Replay MITM Reuses captured messages vs. intercepts/relays/modifies communication Shodan Binwalk Internet-exposed device discovery vs. firmware analysis Binwalk Wireshark Firmware analysis vs. packet analysis
90