connect to the evil twin as it provides a stronger signal.
How to prevent evil twin attacks?
- It is always a good idea to use a VPN (What is a VPN and how does it make us more secure?) while accessing public Wi-Fi. VPN creates an encrypted tunnel before transmitting data. As a result, it is hard for an attacker to intercept that data.
- Network administrators can use some software like EvilAP_Defender to detect Evil Twin. This software tries to find out:
- Wi-Fi access points with similar SSID but different BSSID or MAC address.
- Access point with the same BSSID as the legitimate one, but with different attributes like channel, cipher, privacy protocol, authentication, etc.
- Access point with the same BSSID and attributes as the legitimate access point but with a different tagged parameter like OUI or Organizationally Unique Identifier. The OUI or Organizationally Unique Identifier is assigned by the IEEE registration authority.
- Before connecting to a Wi-Fi do not just rely on the name of the wireless access point, instead verify whether it is a legitimate one.
- It is always better to restrict browsing only to websites that do not require any sensitive data, like login credentials while using public Wi-Fi.
- Avoid providing sensitive information even if any website or login screen asks for that while using public Wi-Fi.
Attackers use various techniques for the purpose of phishing. Interested readers who want to learn about various techniques used by attackers in a phishing scam and how we can detect and prevent phishing may want to refer to the book “Phishing: Detection, Analysis And Prevention.”
Security Fundamentals Practice Tests
The Security Fundamentals Practice Tests test one’s fundamental knowledge of cyber security. The practice tests are good for those who are preparing for various certification exams like the CCNA, CCNP, or CompTIA. They are also good for students and IT/security professionals who want to improve their understanding of cybersecurity.










































0 Comments