A capture on a city Enterprise SSID shows EAP identities such as [email protected]. What recon lesson should the assessor take away?
Select an answer to reveal the explanation.
Short Explanation
Seeing [email protected] in EAP is like spotting employee badges in a lobby camera. Usernames and realms can feed later password-spray classes, so treat them as sensitive recon—not proof of PMKs, WPS weakness, or the RADIUS secret.
Full Explanation
Outer or clear EAP identity fields can leak usernames and realms during Enterprise authentication. That recon is valuable and sensitive because it can chain into directory password-spraying or phishing classes outside the wireless frame. It does not by itself prove PMK disclosure, WPS vulnerability, or knowledge of the RADIUS shared secret between controller and AAA.