<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=APipinic</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=APipinic"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/APipinic"/>
	<updated>2026-09-10T15:33:16Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Wi-Fi_Pineapple_Mark_VII:_Initial_Setup&amp;diff=11124</id>
		<title>Wi-Fi Pineapple Mark VII: Initial Setup</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Wi-Fi_Pineapple_Mark_VII:_Initial_Setup&amp;diff=11124"/>
		<updated>2023-01-17T19:34:40Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Hak5 WiFi Pineapple is a highly advanced WiFi auditing and MITM platform. The original &amp;quot;RougeAP&amp;quot; device - the WiFi Pineapple provides an end-to-end workflow to bring WiFi clients from their trusted network to your rouge network.&lt;br /&gt;
&lt;br /&gt;
The Wi-Fi Pineapple is a wireless auditing platform from Hak5 that allows network security administrators to conduct penetration tests. Pen tests are a type of ethical hacking in which white hat hackers seek out security vulnerabilities that a black hat attacker could exploit. The labels white hat and black hat are derived from old-time Western movies in which the good guys wore white hats and the bad guys wore black hats.&lt;br /&gt;
&lt;br /&gt;
The Wi-Fi Pineapple can also be used as a rogue access point (AP) to conduct man in the middle (MitM) attacks. A MiTM attack is one in which the attacker secretly intercepts and relays messages between two parties that believe they are communicating directly with each other. The inexpensive price and friendly user interface (UI) enable attackers with little technical knowledge to eavesdrop on computing devices using public Wi-Fi networks in order to collect sensitive personal information, including passwords.&lt;br /&gt;
&lt;br /&gt;
When a Pineapple is used for pen testing, it is referred to as a honeypot. When a Pineapple is used as a rogue AP to conduct MitM security exploits, it is referred to as an evil twin or pineapple sandwich.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
[[WiFI Pineapple Mark VII: Cracking Wifi Password]]&lt;br /&gt;
&lt;br /&gt;
[[WiFI Pineapple Mark VII: Man in The Middle]]&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:mark7.png]]&lt;br /&gt;
&lt;br /&gt;
== Setup Basics ==&lt;br /&gt;
&lt;br /&gt;
To begin setting up the WiFi Pineapple Mark VII, you will first need to assemble the unit by attaching the included antennas. The antennas screw onto the RP-SMA ports around the device. Then, decide if you will be setting up the device by WiFi, by USB Ethernet, or by USB Flash Disk.&lt;br /&gt;
&lt;br /&gt;
=== Setup by WiFI ===&lt;br /&gt;
&lt;br /&gt;
1. Power the WiFi Pineapple Mark VII using the included cable and a 2-Amp USB power source. The light will begin blinking blue. When the light shows solid blue, the device is ready to setup.&lt;br /&gt;
&lt;br /&gt;
2. Using a computer or smartphone, connect to the WiFi Pineapple&#039;s open wireless network, named &amp;quot;Pineapple_XXXX&amp;quot; (where XXXX are the last 4 characters of the device&#039;s MAC address).&lt;br /&gt;
&lt;br /&gt;
3. Once connected to the wireless network, open a web browser to http://172.16.42.1:1471 and follow the on-screen instructions. The setup wizard will prompt you to connect the WiFi Pineapple to a wireless network, from which it will download and install the latest version of the WiFi Pineapple software. This process typically takes about 10 minutes—during which time it is important to keep the device plugged in and powered on.&lt;br /&gt;
&lt;br /&gt;
=== Setup by USB Ethernet ===&lt;br /&gt;
&lt;br /&gt;
The WiFi Pineapple Mark VII contains a built-in USB Ethernet adapter from the USB-C port. With this port, you can access the WiFi Pineapple LAN without needing a Cat6 Ethernet cable and RJ45 port.&lt;br /&gt;
&lt;br /&gt;
1. Connect the WiFi Pineapple Mark VII to a computer using the included USB cable. For Windows and Linux computers, the ASIX AX88772C USB Ethernet adapter drivers should install automatically. Mac OS Catalina and above may not install the driver automatically. If necessary, install the driver from the ASIX driver download page for the AX88772C.&lt;br /&gt;
&lt;br /&gt;
2.Once the WiFi Pineapple is connected to the computer, it will enumerate as a USB Ethernet adapter and that interface should receive an IP address from the WiFi Pineapple via DHCP in the 172.16.42.0/24 range.&lt;br /&gt;
&lt;br /&gt;
3.Open a web browser to http://172.16.42.1:1471 and follow the on-screen instructions. The setup wizard will prompt you to connect the WiFi Pineapple to a wireless network, from which it will download and install the latest version of the WiFi Pineapple software. This process typically takes about 10 minutes during which time it is important to keep the device plugged in and powered on.&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360004116253-WiFi-Pineapple-Mark-VII&lt;br /&gt;
* https://elvis.science/?w=WiFi_Pineapple_Mark_VII&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11123</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11123"/>
		<updated>2023-01-17T19:29:52Z</updated>

		<summary type="html">&lt;p&gt;APipinic: /* Alternative Way - Dictionary Attack via Hashcat */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
A dictionary attack using Hashcat is a type of brute-force attack that attempts to guess a password by trying a pre-defined list of words (a &amp;quot;dictionary&amp;quot;) as the password. Hashcat is a password cracking tool that uses the power of the GPU to perform the calculations needed for the attack. It can be used to crack many types of hashes, including those used in popular password storage systems such as Windows and Linux. The success of a dictionary attack using Hashcat depends on the quality of the dictionary used and the strength of the password being cracked.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Step 1 Setup WiFi Pineapple Mark VII ===&lt;br /&gt;
This step will describe you how to setup the WiFi Pineapple Mark VII&lt;br /&gt;
* Connect the WiFi Pineapple Mark VII to a stable USB power supply capable of delivering 9w for initial setup. When connecting to a PC, use the included USB-C cable.&lt;br /&gt;
* Download the latest WiFi Pineapple Mark VII firmware from the Hak5 Download Center.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point.&lt;br /&gt;
A recon scan is required to see which WiFi networks are in the area.&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded.&lt;br /&gt;
* Deauthenication is needed to create a &amp;quot;Full Capture&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Dictionary Attack) with aircrack-ng ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 (Brut Force Attack) via aircrack-ng ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
=== Alternative Way - Dictionary Attack via Hashcat === &lt;br /&gt;
&lt;br /&gt;
For this scenario a kali machine and a password list is beeing used as well as the converted WPA Handshake genereated in the previous chapters. &lt;br /&gt;
&lt;br /&gt;
* The downloaded *.pcap file needs to be converted to a *.hc22000&lt;br /&gt;
* The online tool on the official hashcat website command is used: https://hashcat.net/cap2hccapx/&lt;br /&gt;
* The result of the convert needs to be cracked via hashcat, for cracking the the following command is used: &amp;lt;code&amp;gt; hashcat.exe -m 22000 &amp;lt;converted_file&amp;gt;.hc22000 &amp;lt;password_list&amp;gt;.txt &amp;lt;/code&amp;gt;&lt;br /&gt;
* Hashcat will crack the password using a provided list. After a while the attempt will be finished&lt;br /&gt;
* The status should display: Cracked! We can see the WiFi (Melony’s-Castle) as well as the password.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11122</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11122"/>
		<updated>2023-01-17T19:28:46Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
A dictionary attack using Hashcat is a type of brute-force attack that attempts to guess a password by trying a pre-defined list of words (a &amp;quot;dictionary&amp;quot;) as the password. Hashcat is a password cracking tool that uses the power of the GPU to perform the calculations needed for the attack. It can be used to crack many types of hashes, including those used in popular password storage systems such as Windows and Linux. The success of a dictionary attack using Hashcat depends on the quality of the dictionary used and the strength of the password being cracked.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Step 1 Setup WiFi Pineapple Mark VII ===&lt;br /&gt;
This step will describe you how to setup the WiFi Pineapple Mark VII&lt;br /&gt;
* Connect the WiFi Pineapple Mark VII to a stable USB power supply capable of delivering 9w for initial setup. When connecting to a PC, use the included USB-C cable.&lt;br /&gt;
* Download the latest WiFi Pineapple Mark VII firmware from the Hak5 Download Center.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point.&lt;br /&gt;
A recon scan is required to see which WiFi networks are in the area.&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded.&lt;br /&gt;
* Deauthenication is needed to create a &amp;quot;Full Capture&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Dictionary Attack) with aircrack-ng ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 (Brut Force Attack) via aircrack-ng ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
=== Alternative Way - Dictionary Attack via Hashcat === &lt;br /&gt;
&lt;br /&gt;
For this scenario a kali machine and a password list isbeeing used as the so called &amp;quot;dictionary&amp;quot;. &lt;br /&gt;
&lt;br /&gt;
* The downloaded *.pcap file needs to be converted to a *.hc22000&lt;br /&gt;
* The online tool on the official hashcat website command is used: https://hashcat.net/cap2hccapx/&lt;br /&gt;
* The result of the convert needs to be cracked via hashcat, for cracking the the following command is used: &amp;lt;code&amp;gt; hashcat.exe -m 22000 &amp;lt;converted_file&amp;gt;.hc22000 &amp;lt;password_list&amp;gt;.txt &amp;lt;/code&amp;gt;&lt;br /&gt;
* Hashcat will crack the password using a provided list. After a while the attempt will be finished&lt;br /&gt;
* The status should display: Cracked! We can see the WiFi (Melony’s-Castle) as well as the password.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11121</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11121"/>
		<updated>2023-01-17T19:25:16Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Step 1 Setup WiFi Pineapple Mark VII ===&lt;br /&gt;
This step will describe you how to setup the WiFi Pineapple Mark VII&lt;br /&gt;
* Connect the WiFi Pineapple Mark VII to a stable USB power supply capable of delivering 9w for initial setup. When connecting to a PC, use the included USB-C cable.&lt;br /&gt;
* Download the latest WiFi Pineapple Mark VII firmware from the Hak5 Download Center.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point.&lt;br /&gt;
A recon scan is required to see which WiFi networks are in the area.&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded.&lt;br /&gt;
* Deauthenication is needed to create a &amp;quot;Full Capture&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Dictionary Attack) with aircrack-ng ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 (Brut Force Attack) via aircrack-ng ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
=== Alternative Way - Dictionary Attack via Hashcat === &lt;br /&gt;
&lt;br /&gt;
For this scenario a kali machine was used. Using a password list us beeing used as the so called &amp;quot;dictionary&amp;quot;. &lt;br /&gt;
&lt;br /&gt;
* The downloaded *.pcap file needs to be converted to a *.hc22000&lt;br /&gt;
* The online tool on the official hashcat website command is used: https://hashcat.net/cap2hccapx/&lt;br /&gt;
* The result of the convert needs to be cracked via hashcat, for cracking the the following command is used: &amp;lt;code&amp;gt; hashcat.exe -m 22000 &amp;lt;converted_file&amp;gt;.hc22000 &amp;lt;password_list&amp;gt;.txt &amp;lt;/code&amp;gt;&lt;br /&gt;
* Hashcat will crack the password using a provided list. After a while the attempt will be finished&lt;br /&gt;
* The status should display: Cracked! We can see the WiFi (Melony’s-Castle) as well as the password.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11120</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11120"/>
		<updated>2023-01-17T19:22:32Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Step 1 Setup WiFi Pineapple Mark VII ===&lt;br /&gt;
This step will describe you how to setup the WiFi Pineapple Mark VII&lt;br /&gt;
* Connect the WiFi Pineapple Mark VII to a stable USB power supply capable of delivering 9w for initial setup. When connecting to a PC, use the included USB-C cable.&lt;br /&gt;
* Download the latest WiFi Pineapple Mark VII firmware from the Hak5 Download Center.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point.&lt;br /&gt;
A recon scan is required to see which WiFi networks are in the area.&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded.&lt;br /&gt;
* Deauthenication is needed to create a &amp;quot;Full Capture&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Dictionary Attack) with aircrack-ng ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 (Brut Force Attack) via aircrack-ng ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
=== Alternative Way - Brute Force Attack via Hashcat === &lt;br /&gt;
&lt;br /&gt;
* The downloaded *.pcap file needs to be converted to a *.hc22000&lt;br /&gt;
* The online tool on the official hashcat website command is used: https://hashcat.net/cap2hccapx/&lt;br /&gt;
* The result of the convert needs to be cracked via hashcat, for cracking the the following command is used: &amp;lt;code&amp;gt; hashcat.exe -m 22000 5418_1669215647.hc22000 list.txt2 &amp;lt;/code&amp;gt;&lt;br /&gt;
* Hashcat will crack the password using a provided list, in our case ”list.txt”. After a while the attempt will be finished&lt;br /&gt;
* The status should display: Cracked! We can see the WiFi (Melony’s-Castle) as well as the password.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11119</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11119"/>
		<updated>2023-01-17T19:11:57Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Step 1 Setup WiFi Pineapple Mark VII ===&lt;br /&gt;
This step will describe you how to setup the WiFi Pineapple Mark VII&lt;br /&gt;
* Connect the WiFi Pineapple Mark VII to a stable USB power supply capable of delivering 9w for initial setup. When connecting to a PC, use the included USB-C cable.&lt;br /&gt;
* Download the latest WiFi Pineapple Mark VII firmware from the Hak5 Download Center.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point.&lt;br /&gt;
A recon scan is required to see which WiFi networks are in the area.&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded.&lt;br /&gt;
* Deauthenication is needed to create a &amp;quot;Full Capture&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Dictionary Attack) ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 (Brut Force Attack) ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11118</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11118"/>
		<updated>2023-01-17T19:11:46Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Step 1 Setup WiFi Pineapple Mark VII ===&lt;br /&gt;
This step will describe you how to setup the WiFi Pineapple Mark VII&lt;br /&gt;
* Connect the WiFi Pineapple Mark VII to a stable USB power supply capable of delivering 9w for initial setup. When connecting to a PC, use the included USB-C cable.&lt;br /&gt;
* Download the latest WiFi Pineapple Mark VII firmware from the Hak5 Download Center.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point.&lt;br /&gt;
A recon scan is required to see which WiFi networks are in the area.&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded.&lt;br /&gt;
* Deauthenication is needed to create a &amp;quot;Full Capture&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Dictionary Attack) ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 (Brut Force Attack) ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11117</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11117"/>
		<updated>2023-01-17T19:11:07Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Step 1 Setup WiFi Pineapple Mark VII ===&lt;br /&gt;
This step will describe you how to setup the WiFi Pineapple Mark VII&lt;br /&gt;
* Connect the WiFi Pineapple Mark VII to a stable USB power supply capable of delivering 9w for initial setup. When connecting to a PC, use the included USB-C cable.&lt;br /&gt;
* Download the latest WiFi Pineapple Mark VII firmware from the Hak5 Download Center.&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point.&lt;br /&gt;
A recon scan is required to see which WiFi networks are in the area.&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded.&lt;br /&gt;
* Deauthenication is needed to create a &amp;quot;Full Capture&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Dictionary Attack) ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 (Brut Force Attack) ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11116</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11116"/>
		<updated>2023-01-17T19:10:39Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Step 1 Setup WiFi Pineapple Mark VII ===&lt;br /&gt;
This step will describe you how to setup the WiFi Pineapple Mark VII&lt;br /&gt;
* Connect the WiFi Pineapple Mark VII to a stable USB power supply capable of delivering 9w for initial setup. When connecting to a PC, use the included USB-C cable.&lt;br /&gt;
* Download the latest WiFi Pineapple Mark VII firmware from the Hak5 Download Center.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point.&lt;br /&gt;
A recon scan is required to see which WiFi networks are in the area.&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded.&lt;br /&gt;
* Deauthenication is needed to create a &amp;quot;Full Capture&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Dictionary Attack) ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 4 (Brut Force Attack) ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11115</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11115"/>
		<updated>2023-01-17T19:09:21Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Step 1 Setup WiFi Pineapple Mark VII ===&lt;br /&gt;
This step will describe you how to setup the WiFi Pineapple Mark VII&lt;br /&gt;
* Connect the WiFi Pineapple Mark VII to a stable USB power supply capable of delivering 9w for initial setup. When connecting to a PC, use the included USB-C cable.&lt;br /&gt;
* Download the latest WiFi Pineapple Mark VII firmware from the Hak5 Download Center.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 1 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point.&lt;br /&gt;
A recon scan is required to see which WiFi networks are in the area.&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded.&lt;br /&gt;
* Deauthenication is needed to create a &amp;quot;Full Capture&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Dictionary Attack) ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Brut Force Attack) ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11114</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11114"/>
		<updated>2023-01-17T18:45:53Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Dictionary Attack) ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Brut Force Attack) ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11113</id>
		<title>WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=WiFi_Pineapple_Mark_VII:_Cracking_WPA/WPA2-PSK_with_a_dictionary/brut-force_attack&amp;diff=11113"/>
		<updated>2023-01-17T18:45:46Z</updated>

		<summary type="html">&lt;p&gt;APipinic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This Documentation will give you a guide how to retrieve a WPA2-PSK password with the Wi-Fi Pineapple Mark VII combined with the Linux Tool aircrack-ng. The Wi-Fi Pineapple Mark VII will be used to deauthenticate the clients of the victim&#039;s Wi-Fi. Simultaneously, the Wi-Fi Pineapple Mark VII will capture the 4-way handshake between client and access point and saves it as a PCAP or Hashcat file. This guide will use Linux to demonstrate how to use aircrack-ng&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
Remember: The hacking tools and knowledge that we share here should not be used on a target without prior mutual consent. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. We assume no liability and are not responsible for any misuse or damage caused by this site&lt;br /&gt;
&lt;br /&gt;
=== Mandatory ===&lt;br /&gt;
==== GNU/Linux ====&lt;br /&gt;
&lt;br /&gt;
* Install aircrack-ng suite: &amp;lt;code&amp;gt;sudo apt install aircrack-ng&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To complete these steps, you must have followed [[WiFI Pineapple Mark VII: Initial Setup]] before.&lt;br /&gt;
&lt;br /&gt;
=== Optional ===&lt;br /&gt;
==== Hashcat ====&lt;br /&gt;
* Clone GIT repository: &amp;lt;code&amp;gt;git clone https://github.com/hashcat/hashcat.git&amp;lt;/code&amp;gt;&lt;br /&gt;
* Build: &amp;lt;code&amp;gt;cd ./hashcat &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;lt;/code&amp;gt;&lt;br /&gt;
* Link: &amp;lt;code&amp;gt;sudo ln -s ./hashcat /usr/local/bin/hashcat&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 (Deauthenticate Client &amp;amp; Capture Handshake)===&lt;br /&gt;
&lt;br /&gt;
This step will describe you how to capture the handshake by deauthenticating the clients from its access point&lt;br /&gt;
&lt;br /&gt;
* Log in to Wi-Fi Pineapple Web GUI and open the tab &#039;&#039;&#039;Reacon&#039;&#039;&#039;&lt;br /&gt;
* As seen in figure &amp;quot;WiFI Pineapple GUI&amp;quot;, scan your environment for the victim&#039;s Wi-Fi (1). &lt;br /&gt;
* Choose the victim&#039;s Wi-Fi and select &amp;quot;Capture WPA Handshake&amp;quot;(4) &lt;br /&gt;
* Start deauthentication attack (3)&lt;br /&gt;
* When a handshake has been captured, it can be then downloaded&lt;br /&gt;
&lt;br /&gt;
[[File:Deauth.png||400px|thumb|middle| WiFI Pineapple Web GUI]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2 (Dictionary Attack) ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this step is to actually crack the WPA/WPA2 pre-shared key. To accomplish this, you need a dictionary of words as input. Basically, aircrack-ng takes each word and tests to see if this is, in fact, the pre-shared key.&lt;br /&gt;
&lt;br /&gt;
Open a console session in Linux and enter:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;aircrack-ng -w rockyou.txt -b 00:14:6C:7E:40:80 *.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
-w rockyou.txt&amp;lt;ref&amp;gt;https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt &amp;lt;/ref&amp;gt; is the name of the dictionary file. Remember to specify the full path if the file is not located in the same directory. Notice: any word list can be use for this attack. If the password you are looking for does not appear in the list, then the attack has failed.&lt;br /&gt;
&lt;br /&gt;
.cap is the file containing the captured packets of the handshake.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when there are no handshakes found:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt; &lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
&lt;br /&gt;
 No valid WPA handshakes found.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When this happens, you either have to redo step 3 (deauthenticating the wireless client) or wait longer if you are using the passive approach. When using the passive approach, you have to wait until a wireless client authenticates to the AP.&lt;br /&gt;
&lt;br /&gt;
Here is typical output when handshakes are found:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Opening psk-04.cap&lt;br /&gt;
 Read 1827 packets.&lt;br /&gt;
 &lt;br /&gt;
 #  BSSID              ESSID                     Encryption&lt;br /&gt;
&lt;br /&gt;
 1  00:14:6C:7E:40:80  teddy                     WPA (1 handshake)&lt;br /&gt;
 &lt;br /&gt;
 Choosing first network as target.&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, at this point, aircrack-ng will start attempting to crack the pre-shared key. Depending on the speed of your CPU and the size of the dictionary, this could take a long time, even days.&lt;br /&gt;
&lt;br /&gt;
Here is what successfully cracking the pre-shared key looks like:&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
                               Aircrack-ng 0.8&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                 [00:00:00] 2 keys tested (37.20 k/s)&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
                         KEY FOUND! [ 12345678 ]&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
    Master Key     : CD 69 0D 11 8E AC AA C5 C5 EC BB 59 85 7D 49 3E &lt;br /&gt;
                     B8 A6 13 C5 4A 72 82 38 ED C3 7E 2C 59 5E AB FD &lt;br /&gt;
 &lt;br /&gt;
    Transcient Key : 06 F8 BB F3 B1 55 AE EE 1F 66 AE 51 1F F8 12 98 &lt;br /&gt;
                     CE 8A 9D A0 FC ED A6 DE 70 84 BA 90 83 7E CD 40 &lt;br /&gt;
                     FF 1D 41 E1 65 17 93 0E 64 32 BF 25 50 D5 4A 5E &lt;br /&gt;
                     2B 20 90 8C EA 32 15 A6 26 62 93 27 66 66 E0 71 &lt;br /&gt;
 &lt;br /&gt;
    EAPOL HMAC     : 4E 27 D9 5B 00 91 53 57 88 9C 66 C8 B1 29 D1 CB &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Step 3 (Brut Force Attack) ===&lt;br /&gt;
In this method, we will be using both crunch and aircrack-ng inside Kali Linux to brute-force WPA2 passwords. But before we proceed, let me briefly introduce you to our tools:&lt;br /&gt;
&lt;br /&gt;
crunch - is a wordlist generator from a character set.&lt;br /&gt;
&lt;br /&gt;
aircrack-ng - a 802.11 WEP / WPA-PSK key cracker.&lt;br /&gt;
&lt;br /&gt;
I assume you already have aircrack-ng installed on your system, and you already have a captured handshake ready for offline cracking. If not, I will post another article soon on how to use aircrack-ng to capture WPA2 handshakes.&lt;br /&gt;
&lt;br /&gt;
For now let&#039;s get started and open a terminal!&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t have crunch, yet you can install it by typing:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install crunch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It usually takes crunch a long time to create a wordlist and consumes a lot of disk space too if you choose to save the ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠wordlist to your hard drive. Therefore, this technique can only be useful if somehow you already have an idea of what the password pattern is. The default Wi-Fi passwords of modem/routers provided by ISP&#039;s for example can be a target.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s say that after your research, you figured out that the default Wi-Fi password is an 8-digit number that always starts ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠with the number 7. From that information, we can now create a wordlist using crunch and deliver the output directly to aircrack-ng without writing the file to the hard drive.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This can be done using pipes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;crunch 8 8 0123456789 -s 70000000 | aircrack-ng -w - -b AA:BB:CC:DD:00:11 /path/to/handshake.cap&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first command above (the one before the pipe) means that we&#039;ll create a wordlist using crunch with a minimum of 8 characters and a maximum of 8 characters (since we know that the password always use 8 digits) using only numbers 0 to 9. The &amp;quot;-s&amp;quot; also tells crunch to start the list from 70000000.&lt;br /&gt;
&lt;br /&gt;
We can then use pipes to make the standard output (stdout) of the first command to be the standard input (stdin) of the second command. Thus, whatever output crunch generates will be used by aircrack-ng as the wordlist.&lt;br /&gt;
&lt;br /&gt;
In the second command, the &amp;quot;-w -&amp;quot; tells aircrack-ng to use the wordlist from stdin (that&#039;s what the dash means). The &amp;quot;-b&amp;quot; is used to specify ​‌​​​​​‌⁠​‌‌‌​‌​‌⁠​‌‌‌​‌​​⁠​‌‌​‌​​​⁠​‌‌​‌‌‌‌⁠​‌‌‌​​‌​⁠​​‌‌‌​‌​⁠​​‌​​​​​⁠​‌​​​​​‌⁠​‌‌​​​‌‌⁠​‌‌‌​​‌​⁠​‌‌​‌‌‌‌⁠​‌‌​‌‌‌​⁠​‌‌​‌​​‌⁠​‌‌‌‌​​​⁠​​‌​​​​​⁠​‌‌​​​‌‌⁠​‌‌​‌‌‌‌⁠​‌‌​​‌​​⁠​‌‌​​‌​‌⁠​‌‌‌​​‌​⁠​‌‌‌​​‌‌⁠​​‌​‌‌‌​⁠​‌‌‌​​​​⁠​‌‌​‌​​​⁠the bssid of the targer router (AA:BB:CC:DD:00:11) and the last parameter (/path/to/handshake.cap) is the absolute path to the captured WPA2 handshake. You can also use a relative path depending on your current working directory.&lt;br /&gt;
&lt;br /&gt;
Now, the cracking process may take a while depending on your processor speed, but I believe it is possible to crack that password pattern within a few seconds to a couple of hours.&lt;br /&gt;
&lt;br /&gt;
In my next articles I will show you how you can create rules with crunch even with complicated patterns such as passwords with common words inside.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[WiFi Pineapple Mark VII]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 28.01.2022&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360053346334-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=evsCXb7XHbM&amp;amp;t=274s&amp;amp;ab_channel=TigTec&lt;br /&gt;
* https://www.aircrack-ng.org/&lt;br /&gt;
* https://hashcat.net/wiki/doku.php?id=cracking_wpawpa2&lt;br /&gt;
* https://coders.ph/post/how-to-use-aircrack-ng-to-bruteforce-wpa2-passwords&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>APipinic</name></author>
	</entry>
</feed>