    Nice article. However, if I were going to deliberately attack a network and 802.1x was just not working for me - example knife to a gunfight (SOHO vs. Enterprise AP) then I'd just politely use the SSID in question and simply sniff out whatever I needed from the poor saps who inadvertently and unknowingly tried to associate with my rogue AP.

    Spoofing works well for scenarios like this and if manually managed by an attacker it would exceedingly hard for the local staff to figure out - if ever.  Given actual response times and normal operating procedures.



