Skip to content

Cracking WPA2/WPA3

Wireless networks secured with WPA2 or WPA3 rely on Pre-Shared Keys (PSKs) for authentication. Understanding how attackers might exploit weak PSKs through dictionary or brute-force attacks is critical for defenders to harden their defenses. This section explores these methods, tools, and mitigation strategies for authorized testing environments.


Dictionary Attacks

Dictionary attacks leverage precomputed wordlists to guess the PSK. Attackers capture the 4-way handshake between a client and the access point (AP) and use tools to test passwords from a list. This method is effective if the PSK is a common word, phrase, or password from a known dictionary.

Example Workflow:
1. Capture the handshake using airodump-ng (WPA2) or wpa_supplicant (WPA3).
2. Use hashcat or john the ripper to crack the hash.

Command Example:

# Capture handshake (WPA2)  
airodump-ng --bssid <MAC> -c <channel> -w capture mon0  

# Crack with hashcat (using a dictionary)  
hashcat -m 2500 capture-01.hc2500 -w 3 rockyou.txt  
Note: Hashcat mode 2500 is for WPA/WPA2 hashes. For WPA3, use mode 26000 (if supported by the tool).


Brute-Force Attacks

Brute-force attacks systematically try all possible character combinations until the correct PSK is found. This method is computationally intensive and typically only feasible for short, low-entropy passwords (e.g., 8-character alphanumeric strings).

Example Workflow:
1. Capture the handshake.
2. Use hashcat with rules or custom character sets to generate permutations.

Command Example:

# Brute-force attack with hashcat  
hashcat -m 2500 capture-01.hc2500 -a 3 ?d?d?d?d?d?d?d?d  
This command tests 8-digit numeric passwords. Adjust the character set (?l, ?u, ?d, ?s) for complexity.


Tools and Techniques

  • hashcat: Primary tool for cracking WPA/WPA2 hashes. Supports dictionary, brute-force, and rule-based attacks.
  • john the ripper: Less common for wireless hashes but can crack hashes if converted to a format compatible with its rules.
  • airodump-ng: Captures handshake data (WPA2).
  • wpa_supplicant: Captures handshake data (WPA3).

Tip: Use GPU acceleration (via --gpu flag in hashcat) to speed up cracking.


Mitigations

  1. Strong PSKs: Use long, complex passwords (minimum 12 characters) with mixed case, numbers, and symbols.
  2. WPA3 Adoption: WPA3’s Simplicity Mode (SAE) resists dictionary attacks by using EAP methods.
  3. Regular Audits: Test PSKs with tools like wpa_passphrase to verify strength.
  4. Disable WPS: Wi-Fi Protected Setup (WPS) can expose PSKs via brute-force.

Key takeaways

  • Dictionary attacks succeed against weak, common passwords; brute-force is resource-intensive.
  • Tools like hashcat and john the ripper are critical for PSK recovery in authorized testing.
  • WPA3 offers improved resistance to dictionary attacks but still requires strong PSKs.
  • Defenders must prioritize PSK complexity and avoid default credentials.
  • Always capture and analyze handshakes in controlled environments to identify vulnerabilities.