office@safebyte.io Bucharest, Romania ISO 27001:2023 · ISO 9001:2023
Offensive testing

Wi-Fi security

Wi-Fi is the part of your network an attacker can reach from the car park — we test whether they could impersonate your Enterprise network, steal domain credentials via an evil-twin or jump from the guest network into the internal one.

Wi-Fi security

Wi-Fi is the only part of your network an attacker can target without phishing and without internet exposure — from a laptop in the car park or the café downstairs. And with Enterprise networks (WPA2/WPA3-Enterprise, 802.1X), the problem is almost never the protocol — it’s a configuration detail that most overlook: clients that don’t validate the RADIUS server certificate. That’s exactly where we strike.

What we test

  • Reconnaissance and site survey — with directional antennas we map SSIDs, access points, channels, encryption type, connected clients and, crucially, how far the signal carries outside the building; we detect unknown (rogue) access points or ones left on factory settings
  • WPA2/WPA3-PSK — we capture the handshake (4-way or PMKID) and test the pre-shared key’s strength offline; we verify WPS
  • WPA2/WPA3-Enterprise (802.1X) — we set up a rogue access point (evil-twin) with a fake RADIUS server, trigger 802.1X and attempt to capture and crack domain credentials (EAP-PEAP/TTLS, MSCHAPv2). If your clients don’t enforce certificate validation, an employee in the car park gives away their password without knowing it
  • Deauthentication — deauth frames to disconnect clients and force reconnection (to the evil-twin or to recapture handshakes); we verify whether Protected Management Frames (802.11w) are enforced
  • Client-side — devices that automatically seek out “known” networks and connect to them (KARMA-style); captive portal and guest network weaknesses
  • Segmentation — client isolation and whether the guest or corporate network reaches the wired internal network and sensitive systems

How it runs

Site survey → SSID and access-point enumeration → encryption and authentication analysis → active attacks → client-side attacks → post-exploitation (what wireless access reaches in the internal network) → reporting. The test requires on-site presence or a “drop-box” device that we ship and you plug in.

What you get

  • Executive summary + findings with evidence (captured handshakes or credentials, evil-twin proof, screenshots), reproduction steps and concrete remediation: enforcing certificate validation on 802.1X clients, enabling PMF, strong password policy, correct VLAN segmentation
  • Retesting after remediation and a presentation session