Wireless Attacks & Mobile Security
Complete quiz covering all wireless and mobile security concepts
Wireless encryption, attack types, Bluetooth hacks, and countermeasures
Mobile attack vectors, OWASP Top 10, and security guidelines
All terminology and definitions
Important information summaries from both handouts
A universal system used for mobile data transmission in wireless networks worldwide.
The amount of information that may be broadcast over a connection, measured in bits per second (bps).
Connects wireless devices to a wireless/wired network; serves as a switch or hub between a wired LAN and a wireless network.
The MAC address of an access point that has set up a basic service set (BSS).
A set of frequencies used by international industrial, scientific, and medical communities.
A 32-alphanumeric-character unique identifier given to a WLAN that acts as the wireless network identifier.
A method of encoding digital data on multiple carrier frequencies that are orthogonal to each other.
A technique that multiplies original data with a pseudo-random noise code to protect against interference/jamming.
Transmits radio signals by rapidly switching among many frequency channels to prevent interception.
An outdated encryption algorithm for 802.11 wireless networks that can be easily cracked.
An advanced encryption protocol using TKIP and MIC for strong encryption and authentication.
A temporary security protocol used in WPA as a replacement for WEP.
An upgrade to WPA using AES and CCMP for wireless data encryption.
A symmetric-key encryption used in WPA2 as a replacement for TKIP.
Third-generation Wi-Fi security using GCMP-256 and HMAC-SHA-384 for stronger protection.
Supports multiple authentication methods including token cards, Kerberos, and certificates.
Remote Authentication Dial-In User Service—a centralized authentication and authorization system.
An unauthorized access point that allows attackers to connect to a corporate network.
Attacker sets up a rogue AP with high-power antennas using the same SSID as the target network.
Exploits flaws in WPA2's four-way handshake process to intercept encrypted traffic.
Uses overwhelming malicious traffic to create a Denial of Service (DoS) on wireless networks.
Sending oversized ping packets to cause buffer overflow on a Bluetooth device.
Sending unsolicited messages to Bluetooth devices without the recipient's consent.
Gaining unauthorized access to data on a Bluetooth-enabled device by exploiting OBEX vulnerabilities.
Gaining remote access to a Bluetooth device to intercept calls, messages, and sensitive data.
Exploits Bluetooth key negotiation to perform MITM attacks and eavesdrop on paired devices.
Attacks on Bluetooth Low Energy (BLE) devices to sniff, jam, and take control of data transmission.
Phishing via SMS—sending deceptive links to malicious websites through text messages.
Malware that bypasses OTP verification systems by relaying SMS codes to attackers.
Removing Apple's security mechanisms to gain root access, bypassing sandbox restrictions.
Gaining privileged control (root access) within Android's subsystem.
Injecting SQL commands through a web application to execute unauthorized database operations.
Misuse of platform features or failure to use security controls (Android intents, Touch ID, Keychain).
Assuming users won't access file systems; jailbreaking bypasses encryption protection.
Poor handshaking, incorrect SSL versions, cleartext communication leading to account theft.
Failing to identify users, maintain identity, or manage sessions properly.
Cryptography applied but not performed correctly, allowing unauthorized data retrieval.
Failures in authorization decisions on client side and forced browsing vulnerabilities.
Code-level problems in mobile clients including buffer overflows and format string vulnerabilities.
Binary patching, resource modification, method hooking, and dynamic memory modification.
Analyzing binaries to determine source code, algorithms, and exploit vulnerabilities.
Hidden backdoors or security controls not intended for production (e.g., disabled 2FA in testing).
| Option | Status | Description |
|---|