Skip to content

Latest commit

 

History

History

pcaps

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 

EAP-TLS Network packet-captures

Network dumps were made in our lab environment with Mikrotik router.

When doing 802.1x over Ethernet, to EAPOL-start request Mikrotik replies to Nearest-non-TPMR-bridge instead of using MAC-address that sent the EAPOL-start request (like Cisco does).

normal/

Contains normal 802.1x flow with two different clients attempting 802.1x authentication:

attack/

Contains logs and captures of 802.1x flow when EAP-Mirror attack is executed:

  1. [email protected] connects to rogue WiFi Access Point setup by Attacker ("EvilTwin")
  2. Attacker is connected to Ethernet port and forwards [email protected] authentication
  3. Attacker is successfully authenticates as [email protected] over Ethernet