Wireless (802.11)
No tool matches.
-
airgeddonhome
Menu-driven wireless audit helper that wraps capture and WPA/WPS checks against access points you own.
-
asleaphome
Recovers weak LEAP/MS-CHAPv2 material from captured wireless authentication on networks you may test.
-
bullyhome
Alternative WPS attack tool for lab access points that still expose weak PIN modes.
help
bully v1.4 the fork that actually works! maintained by kimocoder - https://twitter.com/kimocoder usage: bully <options> interface Required arguments: interface : Wireless interface in monitor mode (root required) -b, --bssid macaddr : MAC address of the target access point Or -e, --essid string : Extended SSID for the access point Optional arguments: -c, --channel N[,N...] : Channel number of AP, or list to hop [b/g] -i, --index N : Starting pin index (7 or 8 digits) [Auto] -l, --lockwait N : Seconds to wait if the AP locks WPS [43] -o, --outfile file : Output file for messages [stdout] -p, --pin N : Starting pin number (7 or 8 digits) [Auto] -s, --source macaddr : Source (hardware) MAC address [Probe] -u, --lua : Lua script file -v, --verbosity N : Verbosity level 1-4, 1 is quietest [3] -w, --workdir path : Location of pin/session files [~/.bully/] -5, --5ghz : Hop on 5GHz a/n default channel list [No] -B, --bruteforce : Bruteforce the WPS pin checksum digit [No] -F, --force : Force continue in spite of warnings [No] -S, --sequential : Sequential pins (do not randomize) [No] -T, --test : Test mode (do not inject any packets) [No] Advanced arguments: -d, --pixiewps : Attempt to use pixiewps [No] -a, --acktime N : Deprecated/ignored [Auto] -r, --retries N : Resend packets N times when not acked [2] -m, --m13time N : Deprecated/ignored [Auto] -t, --timeout N : Deprecated/ignored [Auto] -1, --pin1delay M,N : Delay M seconds every Nth nack at M5 [0,1] -2, --pin2delay M,N : Delay M seconds every Nth nack at M7 [5,1] -A, --noacks : Disable ACK check for sent packets [No] -C, --nocheck : Skip CRC/FCS validation (performance) [No] -D, --detectlock : Detect WPS lockouts unreported by AP [No] -E, --eapfail : EAP Failure terminate every exchange [No] -L, --lockignore : Ignore WPS locks reported by the AP [No] … (9 more lines — see the tool's home page) -
cowpattyhome
Offline WPA-PSK dictionary attacks against captured handshakes from networks you may crack.
-
eapmd5passhome
Recovers EAP-MD5 material from wireless captures when the lab still uses that weak method.
-
fern-wifi-crackerhome
GUI wrapper around wireless audit tools for teaching labs; verify each step manually.
help
Traceback (most recent call last): File "/usr/share/fern-wifi-cracker/execute.py", line 101, in <module> initialize() ~~~~~~~~~~^^ File "/usr/share/fern-wifi-cracker/execute.py", line 46, in initialize create_directory() ~~~~~~~~~~~~~~~~^^ File "/usr/share/fern-wifi-cracker/execute.py", line 88, in create_directory os.mkdir('fern-settings') # Create permanent settings directory ~~~~~~~~^^^^^^^^^^^^^^^^^ PermissionError: [Errno 13] Permission denied: 'fern-settings' -
freeradius-wpehome
Wireless PSK exploitation helper built around a patched FreeRADIUS for lab APs.
-
hostapd-wpehome
Runs a rogue access point that also captures wireless handshakes, so you can study AP impersonation only on networks you own or have in writing.
-
iwhome
Configures Linux wireless interfaces: mode, channel, and link state when you are building or tearing down a lab radio path.
help
Usage: iw [options] command Options: --debug enable netlink debugging --version show version (6.17) Commands: dev <devname> ap stop Stop AP functionality dev <devname> ap start <SSID> <SSID> <freq> [NOHT|HT20|HT40+|HT40-|5MHz|10MHz|80MHz|160MHz|320MHz] [punct <bitmap>] <beacon interval in TU> <DTIM period> [hidden-ssid|zeroed-ssid] head <beacon head in hexadecimal> [tail <beacon tail in hexadecimal>] [inactivity-time <inactivity time in seconds>] [key0:abcde d:1:6162636465] dev <devname> ap start <SSID> <control freq> [5|10|20|40|80|80+80|160|320] [<center1_freq> [<center2_freq>]] [punct <bitmap>] <beacon interval in TU> <DTIM period> [hidden-ssid|zeroed-ssid] head <beacon head in hexadecimal> [tail <beacon tail in hexadecimal>] [inactivity-time <inactivity time in seconds>] [key0:abcde d:1:6162636465] Start an AP. Note that this usually requires hostapd or similar. phy <phyname> coalesce show Show coalesce status. phy <phyname> coalesce disable Disable coalesce. phy <phyname> coalesce enable <config-file> Enable coalesce with given configuration. The configuration file contains coalesce rules: delay=<delay> condition=<condition> patterns=<[offset1+]<pattern1>,<[offset2+]<pattern2>,...> delay=<delay> condition=<condition> patterns=<[offset1+]<pattern1>,<[offset2+]<pattern2>,...> ... delay: maximum coalescing delay in msec. condition: 1/0 i.e. 'not match'/'match' the patterns patterns: each pattern is given as a bytestring with '-' in places where any byte may be present, e.g. 00:11:22:-:44 will match 00:11:22:33:44 and 00:11:22:33:ff:44 etc. Offset and pattern should be separated by '+', e.g. 18+43:34:00:12 will match '43:34:00:12' after 18 bytes of offset in Rx packet. dev <devname> auth <SSID> <bssid> <type:open|shared> <freq in MHz> [key 0:abcde d:1:6162636465] Authenticate with the given network. dev <devname> connect [-w] <SSID> [<freq in MHz>] [<bssid>] [auth open|shared] [key 0:abcde d:1:6162636465] [mfp:req/opt/no] Join the network with the given SSID (and frequency, BSSID). With -w, wait for the connect to finish or fail. dev <devname> disconnect Disconnect from the current network. … (102 more lines — see the tool's home page) -
kismethome
Wireless network detector and sniffer for surveying SSIDs and devices in RF scope.
-
mdk3home
Stresses IEEE 802.11 networks with deauth and related frame floods; keep it on a licensed range and a written scope.
-
mdk4home
Successor-style 802.11 stress toolkit for authorized wireless labs where you need controlled disruption to test detection.
-
pixiewpshome
Offline WPS PIN recovery helper for captures you already own; useful when a lab AP still ships with WPS enabled.
help
Pixiewps 1.4 WPS pixie-dust attack tool Copyright (c) 2015-2017, wiire <wi7ire@gmail.com> Description of arguments: -e, --pke Enrollee's DH public key, found in M1. -r, --pkr Registrar's DH public key, found in M2. -s, --e-hash1 Enrollee hash-1, found in M3. It's the hash of the first half of the PIN. -z, --e-hash2 Enrollee hash-2, found in M3. It's the hash of the second half of the PIN. -a, --authkey Authentication session key. Although for this parameter a modified version of Reaver or Bully is needed, it can be avoided by specifying small Diffie-Hellman keys in both Reaver and Pixiewps and supplying --e-nonce, --r-nonce and --e-bssid. [?] pixiewps -e <pke> -s <e-hash1> -z <e-hash2> -S -n <e-nonce> -m <r-nonce> -b <e-bssid> -n, --e-nonce Enrollee's nonce, found in M1. -m, --r-nonce Registrar's nonce, found in M2. Used with other parameters to compute the session keys. -b, --e-bssid Enrollee's BSSID. Used with other parameters to compute the session keys. -S, --dh-small (deprecated) Small Diffie-Hellman keys. The same option must be specified in Reaver too. Some Access Points seem to be buggy and don't behave correctly with this option. Avoid using it with Reaver when possible --mode N[,... N] … (25 more lines — see the tool's home page) -
reaverhome
WPS PIN brute force against vulnerable access points in wireless ranges you may test.
help
Reaver v1.6.6 WiFi Protected Setup Attack Tool Copyright (c) 2011, Tactical Network Solutions, Craig Heffner <cheffner@tacnetsol.com> Required Arguments: -i, --interface=<wlan> Name of the monitor-mode interface to use -b, --bssid=<mac> BSSID of the target AP Optional Arguments: -m, --mac=<mac> MAC of the host system -e, --essid=<ssid> ESSID of the target AP -c, --channel=<channel> Set the 802.11 channel for the interface (implies -f) -s, --session=<file> Restore a previous session file -C, --exec=<command> Execute the supplied command upon successful pin recovery -f, --fixed Disable channel hopping -5, --5ghz Use 5GHz 802.11 channels -v, --verbose Display non-critical warnings (-vv or -vvv for more) -q, --quiet Only display critical messages -h, --help Show help Advanced Options: -p, --pin=<wps pin> Use the specified pin (may be arbitrary string or 4/8 digit WPS pin) -d, --delay=<seconds> Set the delay between pin attempts [1] -l, --lock-delay=<seconds> Set the time to wait if the AP locks WPS pin attempts [60] -g, --max-attempts=<num> Quit after num pin attempts -x, --fail-wait=<seconds> Set the time to sleep after 10 unexpected failures [0] -r, --recurring-delay=<x:y> Sleep for y seconds every x pin attempts -t, --timeout=<seconds> Set the receive timeout period [10] -T, --m57-timeout=<seconds> Set the M5/M7 timeout period [0.40] -A, --no-associate Do not associate with the AP (association must be done by another application) -N, --no-nacks Do not send NACK messages when out of order packets are received -S, --dh-small Use small DH keys to improve crack speed -L, --ignore-locks Ignore locked state reported by the target AP -E, --eap-terminate Terminate each WPS session with an EAP FAIL packet -J, --timeout-is-nack Treat timeout as NACK (DIR-300/320) -F, --ignore-fcs Ignore frame checksum errors -w, --win7 Mimic a Windows 7 registrar [False] -K, --pixie-dust Run pixiedust attack -Z Run pixiedust attack -O, --output-file=<filename> Write packets of interest into pcap file Example: reaver -i wlan0mon -b 00:90:4C:C1:AC:21 -vv -
wifitehome
Automates common wireless attacks with aircrack-ng tools; still requires RF authorization.
help
. . .´ · . . · `. wifite2 2.8.1 : : : (¯) : : : a wireless auditor by derv82 `. · ` /¯\ ´ · .´ maintained by kimocoder ` /¯¯¯\ ´ https://github.com/kimocoder/wifite2 options: -h, --help show this help message and exit SETTINGS: -v, --verbose Shows more options (-h -v). Prints commands and outputs. (default: quiet) -i [interface] Wireless interface to use, e.g. wlan0mon (default: ask) -c [channel] Wireless channel to scan e.g. 1,3-6 (default: all 2Ghz channels) -inf, --infinite Enable infinite attack mode. Modify scanning time with -p (default: off) -mac, --random-mac Randomize wireless card MAC address (default: off) -p [scan_time] Pillage: Attack all targets after scan_time (seconds) --kill Kill processes that conflict with Airmon/Airodump (default: off) -pow, --power [min_power] Attacks any targets with at least min_power signal strength --skip-crack Skip cracking captured handshakes/pmkid (default: off) -first, --first [attack_max] Attacks the first attack_max targets -ic, --ignore-cracked Hides previously-cracked targets. (default: off) --clients-only Only show targets that have associated clients (default: off) --nodeauths Passive mode: Never deauthenticates clients (default: deauth targets) --daemon Puts device back in managed mode after quitting (default: off) WEP: --wep Show only WEP-encrypted networks --require-fakeauth Fails attacks if fake-auth fails (default: off) --keep-ivs Retain .IVS files and reuse when cracking (default: off) WPA: --wpa Show only WPA/WPA2-encrypted networks (may include WPS) --wpa3 Show only WPA3-encrypted networks (SAE/OWE) --owe Show only OWE-encrypted networks (Enhanced Open) --new-hs Captures new handshakes, ignores existing handshakes in hs (default: off) --dict [file] File containing passwords for cracking (default: /usr/share/dict/wordlist-probable.txt) WPS: --wps Show only WPS-enabled networks --wps-only Only use WPS PIN & Pixie-Dust attacks (default: off) --bully Use bully program for WPS PIN & Pixie-Dust attacks (default: reaver) --reaver Use reaver program for WPS PIN & Pixie-Dust attacks (default: reaver) --ignore-locks Do not stop WPS PIN attack if AP becomes locked (default: stop) PMKID: … (10 more lines — see the tool's home page)
Where an authored purpose exists, it is written for this path. Otherwise you see the package summary. Help text is captured live from a Kali system where available.