Module 12 · The unwired attack surface

Wireless & IoT Security

Every modern network has an edge that doesn't end at a cable. Phones roam between APs, badges open doors over Bluetooth, smart bulbs talk Zigbee to a hub that talks WiFi to your router, and a factory floor runs on LoRaWAN. Each of those protocols has its own security model, its own historical mistakes, and its own current attacks. This module covers all of them.

6
Reference pages
3
Wireless stacks (WiFi, BT, IoT)
1
Handshake capture lab

Wireless and IoT are the network you can't see — and increasingly, the network you can't avoid. A 2024 enterprise has more WiFi clients than wired ones, more BLE peripherals than USB ones, and a building full of IoT (cameras, badge readers, HVAC controllers, printers, projectors, smart TVs) that most security teams don't even inventory.

This module covers the protocols, the attacks that target each one, and the defenses that actually work. The goal is dual fluency: enough to talk credibly with a wireless or IoT engineer, evaluate an enterprise WiFi or IoT proposal, and know what to demand of vendors when their hardware lands on your network.

12.A

Reference pages

12.01
WiFi Fundamentals · 802.11, channels, the 2.4/5/6 GHz radio reality
802.11 standards from a/b/g through Wi-Fi 7. Channels, frequencies, BSS/ESS/SSID/BSSID, the management frames (beacons, probes, associations) that drive every attack on the next page. Why "5 GHz is just faster" misses the point.
Live
12.02
WPA Evolution · WEP → WPA → WPA2 → WPA3
The encryption history that everyone in security needs to know cold. The 4-way handshake. WPA3's SAE (Dragonfly) and what it fixed. PSK vs Enterprise (802.1X/EAP). Why WPS is forbidden. Opportunistic Wireless Encryption.
Live
12.03
Wireless Attacks · Evil twins, deauth, KRACK, PMKID
The actual offense: evil twin APs, deauthentication floods, KRACK, PMKID-based offline cracking, war driving with Wigle, rogue APs, Pixie Dust against WPS, captive portal phishing. Each attack with the prerequisite, the move, and the defense.
Live
12.04
Bluetooth Security · Classic vs BLE, pairing, the named attacks
Bluetooth Classic versus BLE, the four pairing modes (Just Works, Passkey, OOB, Numeric Comparison), and the named attacks: BlueBorne, KNOB, BIAS, BlueSmacking, BLE eavesdropping. Why your AirPods are doing more cryptography than you think.
Live
12.05
The IoT Landscape · Zigbee, Z-Wave, LoRaWAN, MQTT, Matter
The constrained-device problem: kilobytes of RAM, no full TLS stack, often no firmware update path. Zigbee, Z-Wave, LoRaWAN, Thread, Matter, and the application-layer protocols (MQTT, CoAP) that ride on top. Why "just put a cert on it" doesn't work.
Live
12.06
IoT Threats & Defenses · Mirai to Matter
Mirai and the botnet era of default credentials. Shodan as a recon weapon. Firmware extraction and analysis. The defenses that actually work: VLAN segmentation, OTA updates, certificate provisioning, NIST IR 8259, the EU Cyber Resilience Act.
Live
12.B

Hands-on lab

LAB
WPA2 Handshake Capture & Crack
A browser-only simulator of capturing a WPA2 4-way handshake from a deauth-induced reconnect, then running an offline dictionary attack against the PSK. See exactly why "Password123" loses in milliseconds and a 16-character random PSK doesn't.
Lab