NACSA licence in progress
On-Site Wi-Fi Security Assessment

Wireless Penetration Testing Malaysia

On-site corporate wireless security assessment: evil-twin rogue APs, WPA2/WPA3-Enterprise PEAP credential harvesting, VLAN segregation failures, and guest/BYOD isolation testing. RMiT branch-network aligned.

The Risk

Wireless: the attack surface at every office, branch, and hotel meeting room

Corporate wireless infrastructure is treated as solved infrastructure by most organisations. WPA2-Enterprise or WPA3 is deployed, a RADIUS server authenticates users, and the guest SSID is on a separate VLAN. In practice, these controls frequently have gaps that allow a threat actor with physical proximity — a car park, a shared building lobby, or a public-facing office — to harvest domain credentials, reach internal resources from the guest network, or intercept employee traffic.

The PEAP/MSCHAPv2 vulnerability is the most commonly exploited gap in Malaysian corporate wireless deployments. WPA2-Enterprise with PEAP is the dominant authentication method at banks, telcos, and large enterprises — but without enforced server certificate validation on every client device, a rogue AP can harvest domain credentials from employees whose devices auto-associate. Those credentials work on VPN, Outlook Web Access, and Active Directory.

nCrypt's wireless penetration testing is conducted on-site with specialist RF equipment. We execute each attack scenario within agreed time-windows and document outcomes with timestamped evidence, not just configuration observations.

Attack Scenarios

What we actually test — named attack scenarios

Each scenario is executed within an agreed scope and time-window. Outcomes are documented with evidence: captured handshakes, VLAN route traces, or association logs.

Evil-Twin & Rogue Access Point

A rogue AP broadcasting a legitimate-looking SSID is the most effective way to intercept employee credentials without touching the corporate network. Our consultants deploy a controlled evil-twin in the target's RF environment and measure how quickly client devices auto-associate. We capture the WPA2-Enterprise handshake or PEAP challenge, demonstrating credential harvesting potential. Where captive portals are used for guest access, we bypass authentication to confirm that guest users can reach unexpected resources.

SSID spoofingAuto-associationPEAP captureCaptive portal bypass

WPA2/WPA3-Enterprise PEAP Credential Harvesting

WPA2-Enterprise with PEAP (MSCHAPv2) is deployed across most Malaysian corporate offices and bank branches as the “secure” Wi-Fi authentication method. The attack does not require cracking WPA2 itself — it exploits the inner authentication protocol. When a client auto-connects to our rogue AP, it completes the PEAP handshake, exposing the MSCHAPv2 challenge/response pair. This pair can be passed to an offline cracking service and converted to a plaintext domain credential. We demonstrate this end-to-end and confirm whether your NAC or certificate pinning controls prevent it.

MSCHAPv2 harvestOffline cracking demoCertificate validationNAC bypass

Guest & BYOD Network Segregation Failure

Guest Wi-Fi and BYOD SSID are intended to be isolated from the corporate network. In practice, misconfigured VLAN tagging, inter-VLAN routing rules, or shared firewall policies frequently allow a guest network client to reach internal resources. We connect to the guest SSID and attempt lateral movement: ARP scanning for internal RFC1918 ranges, DNS resolution of internal hostnames, and direct access to management interfaces reachable from the guest VLAN. BYOD SSID is tested for client isolation — whether a personal device can communicate directly with another BYOD device or with corporate endpoints.

VLAN hoppingInter-VLAN routingClient isolationInternal resource reach

WPA2-Personal PMKID & Handshake Capture

Smaller sites and retail branches often deploy WPA2-Personal (pre-shared key) networks. The PMKID attack allows handshake-less key capture — a single beacon frame from the AP yields the PMKID, which can be subjected to offline dictionary attack without any client being present. We capture PMKIDs during the site survey phase and run them against a wordlist reflecting common Malaysian password patterns (company names, addresses, registration numbers) under lab conditions to demonstrate feasibility. Findings document whether the PSK is derivable from public information.

PMKID captureOffline dictionary attackPSK strengthSite survey

802.1X & RADIUS Bypass Attempts

802.1X is the port-based network access control standard used on wired switches as well as wireless infrastructure. We test whether a non-compliant device can gain network access by exploiting EAP identity response spoofing, MAC address bypass (MAB), or timing gaps in the RADIUS authentication exchange. Findings confirm whether your NAC enforcement is operating as designed or whether an attacker with a managed device can bypass access control and reach internal segments.

EAP identity spoofingMAB bypassRADIUS timingNAC enforcement
Engagement Process

How a wireless pentest site visit works

Every engagement begins with scope agreement and ends with full decommissioning of test equipment. No persistent hardware is left at the site.

1

Pre-visit scope agreement

Floor plans, SSID list, number of APs, VLAN topology, and any NAC/MDM controls are agreed and documented before the site visit. Testing proceeds within the agreed perimeter.

2

Passive RF survey

We map all SSIDs visible at the target site, including hidden networks. Nearby third-party SSIDs are documented to establish the ambient RF environment and confirm our rogue AP does not interfere with non-target networks.

3

Active attack execution

Agreed attack scenarios are executed in sequence, with timestamped evidence capture. Each attack is documented with the outcome: success, partial, or mitigated — and the specific control that mitigated it if applicable.

4

Post-test clearance

All rogue APs are decommissioned at the end of each testing window. No persistent hardware is left at the site. Network logs generated by the test are provided to the customer for SIEM correlation.

Regulatory Context

BNM RMiT and wireless security for Malaysian financial institutions

BNM RMiT's technology risk management and cyber resilience requirements expect FIs to implement wireless network security controls and prohibit the connection of unauthorised devices to production networks.

RMiT expects network segmentation that isolates wireless access from production systems handling financial data.

A wireless pentest with explicit VLAN segregation and guest isolation testing provides direct evidence for RMiT technology risk examination.

Branch-network assessments are particularly relevant for banks with distributed Wi-Fi deployments across branch offices.

FAQ

Frequently asked questions

Common questions about wireless penetration testing for Malaysian corporate and financial sector organisations.

How long does a wireless penetration test take in Malaysia?

A single-site corporate wireless assessment typically takes one to two days on-site, plus half a day for report writing. Multi-site assessments covering branch office networks are scoped individually — typically one day per site with consolidated reporting. Engagements that include 802.1X bypass testing and RADIUS configuration review add approximately half a day. Final reports are delivered within five business days of on-site testing completion.

Will the wireless test disrupt employees or business operations?

We design the engagement to minimise operational impact. Passive survey and PMKID capture are entirely non-disruptive — they involve listening only. Active attack scenarios (evil-twin, rogue AP) are executed during agreed windows, typically outside peak hours or in agreed RF zones. We do not broadcast jamming signals or conduct denial-of-service testing against production APs unless explicitly scoped and agreed. Client auto-association testing targets test devices, not employee devices, unless the scope specifically includes measuring response time against live client devices.

Is WPA3 safe from the attacks you describe?

WPA3-Personal (SAE) is significantly stronger than WPA2-Personal against offline dictionary attacks — the Simultaneous Authentication of Equals handshake does not expose a crackable element the way WPA2-PSK PMKID does. However, WPA3 does not protect against evil-twin attacks if client devices do not enforce server certificate validation (Management Frame Protection alone is insufficient), and WPA3-Enterprise implementations using PEAP as the inner method retain the MSCHAPv2 vulnerability. Mixed WPA2/WPA3 transition mode also downgrades protections. We test the actual deployed configuration, not the theoretically strongest setting.

Does BNM RMiT require wireless penetration testing for Malaysian banks?

BNM RMiT does not mandate wireless penetration testing by name, but it does require documented network access controls, wireless security controls, and periodic technology risk assessments. RMiT's network segmentation and access control expectations require FIs to control wireless access and segment it from production systems. A wireless pentest with VLAN segregation and guest isolation findings is the most direct evidence that these controls function as intended. BNM technology risk examiners regularly request evidence of wireless control testing during examinations.

What is the difference between a wireless pentest and a wireless configuration review?

A configuration review is read-only — we examine AP and RADIUS server settings, VLAN configuration, and NAC policies against a checklist without connecting any attacking device. A wireless pentest actively exploits weaknesses: we deploy a rogue AP, capture handshakes, attempt VLAN hopping from a guest connection, and demonstrate actual attack outcomes rather than just identifying theoretical weaknesses. Both produce useful findings; the pentest provides proof-of-concept evidence that configuration review cannot.

Talk to a senior security consultant

Share your scope. We'll come back with a fixed-fee proposal.

Get a Free Quote

Share your scope. We'll come back with a fixed-fee proposal.

Reply within 1 business day. No spam, ever.

Find out if your corporate Wi-Fi is a credential harvesting target

An on-site wireless assessment answers the question your configuration review cannot: can an attacker in your car park harvest domain credentials from employees inside?

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.