Wireless:
Exploitation
WEP/WPA cracking, evil twins, EAP harvest, rogue APs, WPS attacks
Captive Portal Credential Harvesting
Capturing Plaintext Traffic on Open Networks
Cracking MSCHAPv2 with Asleap and Hashcat
Evil Twin AP with hostapd-mana and Aireplay-ng
Creates a rogue AP cloning a legitimate SSID using hostapd-mana, forcing client deauthentication via Aireplay-ng to capture credentials or handshakes.
Harvesting EAP Credentials with hostapd-mana
WEP Cracking with Aircrack-ng
Wireless Attacks with Bettercap
Cracking WPA Handshakes and PMKIDs
Capture WPA/WPA2 handshakes or PMKIDs, then perform offline dictionary and brute-force attacks using hashcat or aircrack-ng to recover PSKs.
Capturing the WPA 4-Way Handshake
WPS Interference and Beacon Flooding with mdk3
WPS PIN Brute-Force with Reaver
WPS Pixie Dust Attack with Reaver and Pixiewps
What this phase covers
Exploitation uses confirmed weaknesses to gain access, recover credentials, or capture sensitive data. The techniques here range from passive traffic capture on open networks to active attacks that recover passphrases, harvest domain credentials, and intercept client traffic through rogue APs.
The attack path depends on what vulnerability discovery confirmed. For WPA2 PSK targets, start with handshake capture or check whether a PMKID was already captured by hcxdumptool during enumeration, then move to cracking. For WPS targets, try Pixie Dust first — it completes in seconds if the AP is vulnerable — before falling back to PIN brute-force. For enterprise networks, EAP credential harvesting with hostapd-mana is the primary attack, followed by MSCHAPv2 cracking. For captive portal networks, credential harvesting via a rogue portal is covered alongside the evil twin AP setup that drives clients to it.
Attack path quick reference
Open network → capture plaintext traffic immediately, no credentials needed.
WEP network → IV collection + aircrack-ng, accelerate with ARP replay if traffic is low.
WPA2 PSK, PMKID captured → crack directly with hashcat -m 22000, no deauth needed.
WPA2 PSK, no PMKID → deauth + handshake capture, then crack.
WPS unlocked, Ralink/Realtek → Pixie Dust first.
WPS unlocked, other chipset → PIN brute-force.
WPA Enterprise, PEAP, no cert validation → hostapd-mana rogue RADIUS → crack MSCHAPv2.
Joined network → ARP spoof + intercept with bettercap.
Flows into
Once access is gained, post-exploitation covers decrypting previously captured traffic with the recovered passphrase and mapping the internal network from the wireless foothold.