APOLLOSEC

Wireless network penetration testing

We test your Wi-Fi from the car park inwards: who can connect, what they can reach, and whether your users can be lured onto a network that is not yours.

Your network does not stop at the walls

Wireless networks extend your network beyond your building. A weak pre-shared key, a misconfigured enterprise network or a guest network that reaches internal systems gives an attacker a way in without ever touching your firewall.

Wireless attacks also target people. Rogue access points that copy your network name can capture credentials from staff devices that connect automatically. We test the infrastructure and the behaviour of the devices that use it.

What we test

  • Discovery and signal

    Which networks are visible, from where, and how far your signal reaches outside the building.

  • Encryption and authentication

    WPA2 and WPA3 configuration, pre-shared key strength, and enterprise 802.1X authentication including certificate validation.

  • Rogue and evil twin access points

    Whether staff devices connect to a lookalike network and give up credentials.

  • Guest networks

    Client isolation, and whether guests can reach internal systems or management interfaces.

  • Segmentation

    What each wireless network can reach once a device is connected.

  • Unauthorised devices

    Personal hotspots and unmanaged access points plugged into your network.

How the engagement runs

  1. Plan the visit

    We agree locations, networks in scope and timings, and confirm who on site knows we are coming.

  2. Survey

    We map networks and signal coverage from inside and outside the building.

  3. Attack

    We test authentication, attempt to capture and crack keys, and run controlled rogue access point attacks against in-scope networks.

  4. Report and retest

    Findings with the configuration changes to make, the report within five working days, and a retest of changed settings.

What you get

  • A map of the networks we found and where each can be reached from.
  • Findings per network, with the configuration change that fixes each one.
  • Retest results after you make the changes.

When to commission it

  • When opening a new office or changing wireless vendor.
  • If you offer guest Wi-Fi to visitors or the public.
  • When moving from pre-shared keys to enterprise authentication.
  • Yearly for sites that handle sensitive data.

Questions we get asked

Do you need to be on site?

Yes. Wireless testing has to happen within range of your networks, so it is always on site. For organisations with several sites, we agree which locations are representative.

Will testing disconnect our users?

Some attacks briefly disconnect devices to capture authentication handshakes. We agree when and on which networks this is allowed, and avoid it on critical networks during working hours.

Is WPA3 secure?

It is a real improvement, but configuration matters. Transition modes that also accept WPA2 can leave you open to downgrade attacks. We test what your devices actually negotiate.

How long does it take?

Usually one to two days on site per location, depending on the size of the building and the number of networks.

Find out who else can use your Wi-Fi.

Talk to us