Capturing Handshakes
Wireless network security analysis often hinges on capturing and analyzing handshakes, which reveal critical authentication details. This section demonstrates how to capture WPA2/WPA3 handshakes using packet sniffing tools and analyze them for vulnerabilities, such as weak passwords or misconfigurations. The process is critical for understanding how attackers exploit wireless authentication weaknesses and how defenders can mitigate them.
Capturing WPA/WPA3 Handshakes¶
Tools and Setup¶
Use packet sniffing tools like airodump-ng (from the Aircrack-ng suite) or tcpdump to capture handshake packets. Ensure your wireless interface is in monitor mode:
Capturing the Handshake¶
-
Monitor the network:
Replace
00:11:22:33:44:55with the target access point's MAC address. This command captures packets and saves them tocapture-01.cap,capture-02.cap, etc. -
Force a reassociation:
Replace
Use aireplay-ng to deauthenticate a client, forcing it to reconnect and trigger the handshake:
11:22:33:44:55:66with the client's MAC address. This step is optional but increases the likelihood of capturing the handshake. -
Capture via tcpdump:
Adjust the filter to capture WPA-specific packets (e.g.,
For alternative analysis, usetcpdumpto save handshake packets:
wlan type mgmt subtype auth).
Analyzing Captured Handshakes¶
Identifying Vulnerabilities¶
-
Check for handshake files:
Look for a file named
Useairodump-ngto verify if the handshake was captured:
capture-01.cap(WPA2) orcapture-01.cap(WPA3). -
Analyze WPA2 handshakes:
If the password is in the wordlist, the tool will crack the handshake.
Use aircrack-ng to attempt dictionary attacks:
-
WPA3-specific considerations:
WPA3 uses Simultaneous Authentication of Equals (SAE), which is more secure. However, tools like WPA3-Handshake-Analyzer (Python-based) can analyze SAE handshakes for vulnerabilities like weak passwords or misconfigured PSKs.
Cracking the Handshake¶
For WPA2, the four-way handshake is the target. For WPA3, the handshake involves a more complex exchange, but the same principles apply:
- Use dictionary attacks if the password is simple.
- Use hybrid attacks with custom rules for stronger passwords.
Key takeaways¶
- Use packet sniffing tools like
airodump-ngandtcpdumpto capture WPA/WPA3 handshakes during client association. - Analyze captured data for vulnerabilities like weak passwords or misconfigurations using tools like
aircrack-ng. - WPA3 handshakes are more secure but require specialized analysis techniques.
- Always ensure authorized testing and compliance with legal frameworks when performing these activities.