Security Quiz Hub

Test your knowledge in Wireless Security and Mobile Attacks

πŸ“‘

Wireless Security Quiz

Test your knowledge on Wi-Fi protocols, WPA2/WPA3, wireless attacks, Bluetooth security, and network defense strategies.

24 Questions
πŸ“±

Mobile Attack Quiz

Test your knowledge on mobile vulnerabilities, BYOD risks, Android/iOS attacks, and mobile security tools.

20 Questions
πŸ“–

Glossary of Terms

Comprehensive reference of all security terms, protocols, tools, and attack methods covered in both quizzes.

Reference Guide

πŸ“– Glossary of Security Terms

πŸ“Ά Wireless Protocols & Standards

DSSS (Direct Sequence Spread Spectrum)

A spread spectrum technique that multiplies the original data signal with a pseudo-random noise-spreading code to protect signals from interference.

IEEE 802.16 / WiMAX

A wireless communications standard designed to provide multiple physical layer (PHY) and MAC options for broadband wireless access in metropolitan area networks.

ZigBee (IEEE 802.15.4)

A low-power wireless protocol that uses mesh networking to transmit long-distance data, ideal for IoT and sensor networks.

802.11e

The IEEE standard that defines Quality of Service (QoS) enhancements for wireless networks, enabling prioritization of voice and video traffic.

SS7 (Signaling System 7)

The core protocol used by cellular networks to manage roaming, route calls between carriers, and handle SMS delivery.

πŸ” Wi-Fi Security Standards

WPA2-Enterprise

Uses 802.1X/EAP with a RADIUS server for centralized authentication, supporting multiple methods like token cards, Kerberos, and certificates.

WPA (Wi-Fi Protected Access)

Uses TKIP for encryption with per-packet mixing functions, MICs, extended IVs, and re-keying mechanisms to fix WEP vulnerabilities.

WPA3-Personal

Uses SAE (Simultaneous Authentication of Equals) or Dragonfly Key Exchange for password-based authentication resistant to offline dictionary attacks.

WPA3

The latest Wi-Fi security standard using AES-GCMP-256 encryption, ECDH/ECDSA key management, and BIP-GMAC-256 integrity checks.

⚑ Wireless Attacks

Unauthorized Association

An attack where an attacker creates a soft AP on a laptop using a tool that makes the NIC appear as a legitimate AP.

Client Mis-association Attack

Attacker learns the target SSID, creates a rogue AP with a spoofed SSID, and sends beacons to lure clients to connect.

Key Reinstallation Attack (KRACK)

Exploits WPA2's four-way handshake by forcing nonce reuse, allowing attackers to decrypt network traffic.

Jamming Signal Attack

A denial-of-service attack that floods the wireless spectrum with noise or interference to disrupt communications.

Honeypot AP Attack

Exploits client probing behavior when multiple WLANs coexist; the rogue AP responds to client probes for specific SSIDs.

πŸ”§ Aircrack-ng Suite Tools

Airdecap-ng

Decrypts WEP/WPA/WPA2 capture files and strips wireless headers from Wi-Fi packets for analysis.

Airmon-ng

Enables/disables monitor mode on wireless interfaces and manages wireless driver conflicts.

Aireplay-ng

Performs packet injection and deauthentication attacks on wireless networks.

πŸ”΅ Bluetooth Attacks

Bluejacking

Sending unsolicited, annoying messages to Bluetooth-enabled devices within range.

Bluesmacking

A denial-of-service attack that sends oversized packets to cause buffer overflow in Bluetooth devices.

Bluebugging

Allows complete control of a Bluetooth device, including accessing calls, messages, and sensitive data.

BluePrinting

A reconnaissance technique for gathering detailed information about Bluetooth devices (make, model, vulnerabilities).

KNOB Attack

Exploits Bluetooth's key negotiation process to force weak encryption keys, enabling eavesdropping.

πŸ“± Mobile Security Concepts

Insecure Authentication

Risks from failure to identify users, maintain identity, or weaknesses in session management.

Extraneous Functionality

Unnecessary code, comments, or data left in an application (e.g., passwords in comments).

Reverse Engineering

Analyzing compiled binaries to determine source code, libraries, and application inner workings.

Rooting

Gaining superuser (root) access on Android devices, bypassing security restrictions.

Cross-Site Request Forgery (CSRF)

An attack that forces authenticated users to send unintended malicious requests to web applications.

⚠️ BYOD Risks

Data Leakage

Corporate data exposure through personal devices accessing organizational resources.

Disgruntled Employees

Insider threats where employees intentionally exfiltrate or misuse corporate data.

Mixing Personal and Private Data

Storing personal and business data together, leading to accidental disclosure.

Sharing on Unsecured Networks

Transferring sensitive data over public Wi-Fi without encryption or VPN protection.

πŸ› οΈ Security Tools

zANTI

Android penetration testing toolkit for creating rogue APs, MITM attacks, and traffic sniffing.

Spyic

Surveillance tool for tracking iOS/Android device activities without jailbreak.

IBM MaaS360

Enterprise Mobility Management (EMM) platform for deploying and managing mobile devices.

Zimperium's zIPS

Mobile intrusion prevention system providing comprehensive protection for iOS and Android devices.

Lookout Personal

Mobile security application with malware protection, anti-theft features, and privacy monitoring.

Agent Smith

Mobile malware that replaces legitimate apps with malicious versions to display advertisements.

πŸ“‘ Wireless Security Quiz

1 / 24
Score: 0 / 24
Question 1 of 24

πŸ’‘ Why this is the correct answer:

πŸ“Š Comparison of Options:

πŸ“š Additional Information:

Quiz Complete!

0 / 24
0%

πŸ“± Mobile Attack Quiz

1 / 20
Score: 0 / 20
Question 1 of 20

πŸ’‘ Why this is the correct answer:

πŸ“Š Comparison of Options:

πŸ“š Additional Information:

Quiz Complete!

0 / 20
0%