Blacksec

Administrator
Staff member
ROOT
VIP
Wi-Fi is a conversation shouted through open air — anyone nearby can hear every word. WPA2 locks that conversation with a handshake, and everything interesting in wireless security lives inside that handshake. This guide covers the capture, the crack, the evil twin, and the fixes — explained so clean a kid could follow it from the driveway.

TL;DR — Wi-Fi traffic is radio — sniffable by anyone in range. WPA2 protects the key exchange with a 4-way handshake; capture it, crack the PSK offline with a wordlist. Evil twin skips the crack entirely. Full breakdown below.

1. RADIO IN A BOX (KID VERSION)

Two kids in a field with walkie-talkies. Their conversation is encrypted — a third kid with a scanner nearby hears static. UNLESS the third kid records the handshake where they agree on the secret code. Record that moment, take it home, test every code he has ever heard until one matches. That is WPA2 cracking in a playground.

Your router and your device constantly negotiate: join this network, here is proof I know the password, here is proof back. Those negotiation messages — the 4-way handshake — contain no password, but they CONTAIN A HASH of it. Which means: handshake in hand equals unlimited offline guessing time. The network cannot lock you out, cannot rate-limit your tries, cannot even know you are trying. The battle moves from the air into your GPU.

2. THE 4-WAY HANDSHAKE (WHAT IT ACTUALLY IS)

When a device joins a WPA2 network, router and device prove they share the password WITHOUT sending it. Four messages:

  • Message 1 — router sends a random challenge (ANonce).
  • Message 2 — device combines the password, the challenge, and its own randomness into a cryptographic proof (the MIC) and sends it.
  • Message 3 — router confirms, adds its own confirmation.
  • Message 4 — device acknowledges. Session keys derived, encrypted tunnel starts.

The password never crosses the air. What crosses is a MESSAGE AUTHENTICATION CODE — a hash built from the pre-shared key (PSK). The PSK itself is derived from the password through 4,096 rounds of PBKDF2-SHA1 with the network name (SSID) as salt. Note the salt — it is just the SSID, often a common name like "linksys" broadcast publicly. No real protection there.

Attacker's play: record messages 1 and 2, take them offline, run PBKDF2 on every candidate password until the MIC matches. No lockouts. No alarms. Just a GPU humming through rockyou.txt.

3. CAPTURE (AIRCRACK SUITE)

The classic toolkit runs on Linux with a monitor-mode adapter — your laptop's built-in card usually refuses monitor mode, USB adapters with Atheros or Realtek chipsets obey:

Bash:
#1. Put interface in monitor mode (see everything in the air)
airmon-ng start wlan0

#2. Watch networks, pick target, note channel + BSSID
airodump-ng wlan0mon

#3. Capture the handshake of THAT network only
airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w capture wlan0mon

#4. (Optional) nudge a connected client to re-handshake fast
aireplay-ng -0 5 -a AA:BB:CC:DD:EE:FF wlan0mon

#5. Crack the captured handshake with your wordlist
aircrack-ng capture-01.cap -w rockyou.txt

The deauth step in #4 is the accelerant: kicking a connected client briefly forces it to reconnect, generating a handshake immediately instead of waiting for a natural one. Active attacks like this are only legal on your own gear with permission — deauth frames are illegal interference on someone else's network in most jurisdictions.

4. EVIL TWIN — SKIP THE CRACK ENTIRELY

Why crack the password when you can BECOME the network?

An evil twin broadcasts the same network name (SSID) as the real one, stronger signal, open or fake-login portal. Devices with "auto-join open networks" hop over. The twin can then:

  • Relay the victim's traffic to the real network while sniffing everything unencrypted.
  • Serve a captive portal demanding the Wi-Fi password "again after the update" — harvested plaintext, no cracking needed.
  • Push DNS to attacker-controlled servers, phishing every page the victim opens.

Coffee-shop twin attacks work because devices trust SSIDs like they trust logos. Defenses: WPA3 (kills the offline crack), enterprise auth (per-user credentials, no shared PSK), and the habit of checking the BSSID — evil twins rarely clone the router's MAC exactly.

5. WHY SOME NETWORKS RESIST

ProtectionWhat it changesStill weak against
Long random PSKDictionary attacks die — 20+ char key impossible to guessCapture + nothing — uncrackable in practice
WPA3-SAEReplaces handshake — no offline guessing at allDowngrade attacks on mixed-mode routers
Enterprise (802.1X)Per-user credentials, no shared PSKPhishing the individual user instead
Hidden SSIDNetwork doesn't broadcast nameTrivial — the name lives in every probe frame
MAC filteringOnly listed devices joinSniffing + MAC spoofing in seconds

The pattern: password strength only matters against guessing, and protocol version (WPA3) matters more than any single setting. Hidden SSIDs and MAC filters are security theater — both bypassed in under a minute by anyone with the basic tools above.

6. THE DEFENSE SIDE

  • WPA3 if the hardware supports it — SAE handshake makes offline cracking impossible. Buy a WPA3 router in 2026; WPA2-only gear is a decade old at this point.
  • Password length over cleverness — a 24-character random passphrase survives any wordlist on earth. Write it on a card taped to the router; guests type it once.
  • Separate networks — IoT gadgets on their own SSID, work devices on another. Compromised smart bulb does not share air with the laptop.
  • Disable WPS and auto-join — WPS PIN brute force is ancient but still shipping enabled; auto-join is what walks devices into evil twins.
  • VPN on public Wi-Fi — turns evil-twin sniffing into garbage — encrypted tunnel from the device out.

7. FIELD CHEAT SHEET

TaskCommand / Move
Monitor modeairmon-ng start wlan0
Scan networksairodump-ng wlan0mon
Capture handshakeairodump-ng -c CH --bssid MAC -w out wlan0mon
Force handshakeaireplay-ng -0 5 -a MAC wlan0mon (own lab only)
Crack itaircrack-ng out-01.cap -w rockyou.txt
DefenseWPA3, 24-char random PSK, VPN on public nets

— RELATED GUIDES —

Radio captured, handshake recorded, wordlist loaded — the air has ears and every negotiation in it is a puzzle piece. Monitor mode on, target picked, crack queued — and on your own gear only, because the same frames on someone else's network are where the lawyers start their day.
 
Last edited: